NOTES
The Pineapple is most useful as a dedicated wireless observation and controlled access-point platform. I use it to inventory authorized radio space, examine client behavior, collect evidence, and run narrowly scoped client-association tests.
Wireless authorization must cover locations, SSIDs, BSSIDs, channels, client interaction, deauthentication, credential capture, and any upstream network connection.
WORKFLOW
- Confirm country and radio settings before transmission.
- Record the physical location, time, channels, SSIDs, BSSIDs, encryption, and signal observations.
- Use recon before enabling campaigns or active client interaction.
- Allowlist or target only explicitly authorized identifiers.
- Monitor storage and export captures before they are overwritten.
- Stop transmit activity immediately if it affects out-of-scope clients.
SCOPE
- Management access is protected and not exposed to the assessment network.
- Time is correct for capture correlation.
- Modules and firmware come from trusted sources.
- Campaign names do not impersonate unrelated third parties.
- Captured handshakes and client data are stored and transferred securely.
- The device is shut down cleanly before power removal.
GOTCHAS
- Observed probe requests do not prove a client will join.
- A captured handshake does not prove the passphrase is weak.
- Evil-twin impact depends on client decisions, certificate behavior, and network context.
- Document segmentation and defensive behavior that prevented impact.