hcxtools
brew install hcxtools
v7.1.2
MIT
Utils for conversion of cap/pcap/pcapng WiFi dump files
304
30-day installs · #2213
891
90-day · #2313
4.3k
365-day · #2066
2.4k
★ GitHub stars · updated 2mo ago
Runtime dependencies
Build dependencies
GitHub topics
handshake
hashcat
hccapx
john-the-ripper
pcap
pcapng
penetration-testing-framework
raspberry-pi
wifi
wifi-security
wlan
wlan-traffic
wpa
wpa2
Links
- https://github.com/ZerBea/hcxtools
- GitHub: ZerBea/hcxtools
- Brew formula source: Formula/h/hcxtools.rb
Raw metadata
{
"aliases": [],
"alternatives": [],
"build_dependencies": [
"pkgconf"
],
"categories": [],
"caveats": null,
"conflicts_with": [],
"dependencies": [
"openssl@3"
],
"deprecated": 0,
"deprecation_reason": null,
"desc": "Utils for conversion of cap/pcap/pcapng WiFi dump files",
"disable_reason": null,
"disabled": 0,
"enrichment_fetched_at": "2026-06-20T23:38:35+00:00",
"first_seen": "2026-06-20T23:34:18+00:00",
"full_name": "hcxtools",
"github_default_branch": "master",
"github_last_commit_at": "2026-06-15T05:47:13Z",
"github_readme_excerpt": "hcxtools\n=========\n\nA small set of tools to convert packets from capture files to hash files for use with Hashcat or John the Ripper. \n\nThese tools are 100% compatible with Hashcat and John the Ripper and are endorsed by Hashcat.\n\nBrief Description\n------------------\n\nThe main purpose of hcxtools is to detect weak points within one\u0027s own WiFi network by analyzing the hashes.\nTherefore, the conversion of the dump file to WPA-PBKDF2-PMKID+EAPOL hash file allows the user to check if the WLAN-KEY or PMK was transmitted unencrypted.\nOr upload the \"uncleaned\" dump file (pcapng, pcap, cap) [here](https://wpa-sec.stanev.org/?submit) to find out if your AP or the CLIENT is vulnerable by using common wordlists or a weak password generation algorithm.\n\n* Support for Hashcat hash-modes: 4800, 5500, 2200x, 16100, 250x (deprecated), and 1680x (deprecated).\n \n* Support for John the Ripper hash-modes: WPAPSK-PMK, PBKDF2-HMAC-SHA1, chap, netntlm, and tacacs-plus.\n\n* Support for gzip (.gz) single file compression.\n\nAn overview of Hashcat mode 22000. - (https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2)\n\nOld but still applicable write-up by **atom** of the Hashcat forums covering a new attack on WPA/WPA2 using PMKID. - (https://hashcat.net/forum/thread-7717.html)\n\nHashcat mode 22000 write-up by **atom** of the Hashcat forums. - (https://hashcat.net/forum/thread-10253.html)\n\n**Unsupported:** Windows OS, macOS, Android, emulators or wrappers!\n\nWhat Don\u0027t hcxtools Do?\n------------------------\n\n* They do not crack WPA PSK related hashes. (Use Hashcat or JtR to recover the PSK.)\n\n* They do not crack WEP. (Use the aircrack-ng suite instead.)\n\n* They do not crack WPS. (Use Reaver or Bully instead.)\n\n* They do not decrypt encrypted traffic. (Use tshark or Wireshark to do so.)\n\nDetailed Description\n---------------------\n\n| Tool | Description |\n| -------------- | -----------",
"github_repo": "ZerBea/hcxtools",
"github_stars": 2394,
"github_topics": [
"handshake",
"hashcat",
"hccapx",
"john-the-ripper",
"pcap",
"pcapng",
"penetration-testing-framework",
"raspberry-pi",
"wifi",
"wifi-security",
"wlan",
"wlan-traffic",
"wpa",
"wpa2"
],
"homepage": "https://github.com/ZerBea/hcxtools",
"homepage_og_description": null,
"homepage_og_image": null,
"homepage_title": null,
"installs_30d": 304,
"installs_365d": 4279,
"installs_90d": 891,
"keg_only": 0,
"keg_only_reason": null,
"last_seen": "2026-06-20T23:34:18+00:00",
"license": "MIT",
"llm_generated_at": null,
"llm_model": null,
"name": "hcxtools",
"oldnames": [],
"one_liner": null,
"optional_dependencies": [],
"rank_30d": 2213,
"rank_365d": 2066,
"rank_90d": 2313,
"raw_hash": "2daff741b51a794e",
"recommended_dependencies": [],
"revision": 0,
"ruby_source_path": "Formula/h/hcxtools.rb",
"tap": "homebrew/core",
"test_dependencies": [],
"uses_from_macos": [
"curl"
],
"version_head": "HEAD",
"version_stable": "7.1.2",
"versioned_formulae": [],
"why_use_this": null
}