The AirPcap Product Family is a complete range of 802.11 USB-Based WLAN packet capture solutions for Windows
The AirPcap family is the first open, affordable and easy-to-deploy packet capture solution for Windows. AirPcap captures full 802.11 data, management, and control frames that can be viewed in Wireshark providing in-depth protocol dissection and analysis capabilities. The feature matrix below gives a high-level overview of each adapter in the AirPcap Product Family. More detailed information regarding each can be found on the relevant corresponding product pages.
| ||AirPcap Classic||AirPcap Tx||AirPcap Nx|
(requires 2+ adapters)
External Antenna Connector
How AirPcap Adapters Operate
All AirPcap adapters can operate in a completely passive mode. In this mode, the AirPcap adapter will capture all of the frames that are transferred on a channel, not just frames that are addressed to it. This includes data frames, control frames and management frames. When more than one BSS shares the same channel, the AirPcap adapter will capture the data, control, and management frames from all of the BSSs that are sharing the channel within range of the AirPcap adapter.
AirPcap adapters capture traffic on a single channel at a time. The channel setting for the AirPcap adapter can be changed using the AirPcap Control Panel, or from the "Advanced Wireless Settings" dialog in Wireshark. Depending on the capabilities of a specific AirPcap adapter, it can be set to any valid 802.11 channel for packet capture.
The AirPcap software can be configured to decrypt WEP-encrypted frames. An arbitrary number of keys can be configured in the driver at the same time, so that the driver can decrypt the traffic of more than one access point simultaneously. WPA and WPA2 support is handled by Wireshark.
Multiple Channel Capture
When monitoring on a single channel is not enough, multiple AirPcap adapters can be plugged into your laptop or a USB hub and provide industry-leading capability for simultaneous multi-channel capture and traffic aggregation. The AirPcap driver provides support for this operation through CACE Multi-Channel Aggregator technology that exports capture streams from multiple AirPcap adapters as a single capture stream. The Multi-Channel Aggregator consists of a virtual interface that can be used from Wireshark or any other AirPcap-based application. Using this interface, the application will receive the traffic from all installed AirPcap adapters, as if it was coming from a single device. The Multi-Channel Aggregator can be configured like any AirPcap device, and therefore can have its own decryption, FCS checking, and packet filtering settings.
The First Open, Affordable, and Easy-to-Deploy WLAN (802.11b/g) Packet Capture and Transmission Solution
AirPcap Tx retains all of the functionality of AirPcap Classic and, additionally, supports packet injection. AirPcap Tx, like AirPcap Classic, enables troubleshooting tools like Wireshark to provide information about wireless protocols and radio signals. AirPcap Tx gives you the power to capture and analyze low-level 802.11b/g wireless traffic, including control, management, and data frames on your Windows workstation or laptop. Per packet information is also available, such as signal strength, CPU-based timestamps (in microseconds), and receive rate. It also lets you send any of these frame types over the air.
Transmit Raw 802.11 Frames on Your Network.
AirPcap Tx and Airpcap Nx has the ability to inject raw 802.11 frames into your wireless network which makes them an invaluable aid in assessing the security of your wireless network. AirPcap Tx (and AirPcap Ex/AirPcap Nx) can inject any kind of frame, including control, management, and data frames. These frames can be transmitted at any allowable rate depending upon your adapter.
An application, called AirPcapReplay, is included in the AirPcap Software Distribution. The purpose of this application, as the name suggests, is to replay 802.11 network traffic that is contained in a trace file. In addition to the replay feature, AirPcapReplay also allows the user to edit individual packets using a built-in hex editor.
In addition to AirPcpaReplay, there are several third-party freeware and open-source tools that are compatible with AirPcap Tx. These tools are typically for advanced users who are interested in securing and/or auditing their wireless networks. One of these, Aircrack-ng, is a well-known suite of tools for auditing wireless networks. It allows various types of penetration tests on a wireless network: http://www.aircrack-ng.org
Unlike passive reception, there are restrictions on the transmission frequencies/channels imposed by various countries. While there are no channel restrictions for monitoring 802.11 traffic, AirPcap Tx will allow transmission on only those channels that are permitted according to the ship-to country.
Industry-leading capability to simultaneously capture on multiple channels.
When monitoring on a single channel is not enough, multiple AirPcap Tx adapters can be plugged into your laptop or a USB hub and provide industry-leading capability for simultaneous multi-channel capture and traffic aggregation. To facilitate the use of this feature, we offer the AirPcap 3-Pack.