← LibraryTechnique entry
WIFI-DEAUTHImpact
Deauthentication DoS
Spam 802.11 deauth frames at clients of a target AP — disrupts service, also a primer for handshake capture / evil twin.
§ Where this technique fits
WIFI-DEAUTH is catalogued under the Impact tactic of the offensive-security kill-chain. It appears in 3 approved dossiers in the registry, typically at step 2.3 on average.
§ Dossiers chaining this technique
- step 2 / 5
Zigbee network key sniff → smart-home control
Sniff a fresh device-join with an Atmel RZRAVEN — Zigbee broadcasts the network key in plaintext during pairing. Decrypt all subsequent traffic + send commands.
- step 2 / 6
WPA2-PSK handshake capture + crack → LAN access
Deauth a connected client to force re-association, capture the 4-way handshake with airodump-ng, crack the PSK offline with hashcat.
- step 3 / 5
Evil twin + captive portal → credential harvest
Spoof the corporate SSID with a stronger signal and a captive portal that looks like the company AD login. Auto-connecting clients submit creds to the attacker page.
§ What commonly comes next
- 01Valid Accountsseen 1×T1078 · Initial Access
- 02WPA2-PSK Handshake Capture + Crackseen 1×WIFI-WPA2-PSK · Credential Access
- 03Zigbee Network Key Extractionseen 1×IOT-ZIGBEE-KEY · Credential Access