Wireless methods

How the wireless analyzer reviews capture evidence.

The current analyzer works from uploaded evidence files. It does not perform live capture, distance estimation, cracking, or payload decryption.

Capture summary

capinfos metadata, evidence hash, file size, capture timing, and private case token handling.

802.11 event extraction

Association requests, authentication responses, authentication failures, EAPOL key exchanges, deauthentication events, and data pairs.

Management timeline

Readable subtype labels for beacon, probe, association, authentication, and deauthentication activity.

Network review

SSID/BSSID observation, channel, frame counts, hidden/non-text SSID handling, and WPA/WPA2/WPA3 posture.

Rogue AP candidate review

Passive candidates from same-SSID BSSID differences, OUI flags, security posture mismatches, and beacon timing.

Reports and exports

Raw JSON and Markdown report output for analyst review.