How the wireless analyzer reviews capture evidence.
The current analyzer works from uploaded evidence files. It does not perform live capture, distance estimation, cracking, or payload decryption.
Capture summary
capinfos metadata, evidence hash, file size, capture timing, and private case token handling.
802.11 event extraction
Association requests, authentication responses, authentication failures, EAPOL key exchanges, deauthentication events, and data pairs.
Management timeline
Readable subtype labels for beacon, probe, association, authentication, and deauthentication activity.
Network review
SSID/BSSID observation, channel, frame counts, hidden/non-text SSID handling, and WPA/WPA2/WPA3 posture.
Rogue AP candidate review
Passive candidates from same-SSID BSSID differences, OUI flags, security posture mismatches, and beacon timing.
Reports and exports
Raw JSON and Markdown report output for analyst review.