Cracking & Capture
hcxtools
PCAP and hash conversion tools for WPA captures: convert handshakes to hashcat-compatible formats.
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
PCAP and hash conversion tools for WPA captures: convert handshakes to hashcat-compatible formats.
sudo apt install hcxtools
| Tool | Purpose |
|---|---|
hcxpcapngtool | Convert pcap/pcapng to hashcat 22000 format |
hcxhash2cap | Convert hccapx (mode 2500) to pcap |
hcxdumptool | Active capture with PMKID and EAPOL (separate package — apt install hcxdumptool, not part of hcxtools) |
hcxpcapngtool [options] <input.cap> -o <output.22000>
hcxpcapngtool capture.cap -o hash.22000
hashcat -a 0 -m 22000 hash.22000 ~/rockyou.txt --force
hcxhash2cap --hccapx=<file.hccapx> -c <output.pcap>
hcxhash2cap --hccapx=hostapd.hccapx -c aux.pcap
hcxpcapngtool aux.pcap -o hash.22000
hcxdumptool [options] -o <output.pcapng> -i <interface>
| Flag | Description |
|---|---|
-i <iface> | Monitor mode interface |
-o <file> | Output pcapng file |
--enable_status=3 | Show live status |
--filterlist_ap=<file> --filtermode=2 | Only target listed BSSIDs (--filtermode is mandatory; =2 = target list, =1 = ignore list). Removed in 6.3.0+, which uses --bpf= |
sudo hcxdumptool -i wlan0mon -o capture.pcapng --enable_status=3
hcxpcapngtool capture.pcapng -o hash.22000
hashcat -a 0 -m 22000 hash.22000 ~/rockyou.txt