Passpoint Scanner

Passpoint Scanner
Download Copy
Title: Passpoint Scanner
Author: WiFivomFranMan

Scanner for true Passpoint/Hotspot 2.0 networks. Detects Passpoint APs via IE 221 (HS2.0 Vendor Specific OUI 50:6f:9a:10), including non-transmitted BSSIDs in MBSSID (6GHz),and queries ANQP data (NAI Realms, PLMNs, Domains, Venue)

🏆   Recognized with a Payload Award in January 2026

 

Reconnaissance, or recon, is all about gathering information on a target — be it an individual computer or the network at large. Individual computers may be scanned using a hotplug tool like the Bash Bunny or USB Rubber Ducky coupled with keystroke injection techniques to obtain valuable information without the need to elevate privileges.

Network reconnaissance techniques involve active scans, which may be observed by intrusion detection systems, or passive scans, which may go quietly undetected. The information obtained in a recon operation may assist in the red team's audit plan for future missions such as phishing campaigns or exfiltration. On the network enumeration side, many techniques exist for scanning the network from the outside. The same techniques may be applied to scanning inside the network, which is where hotplug Ethernet attack tools like the Shark Jack excel. See all recon payloads.

This payload is for Pineapple Pager — Two decades of WiFi exploits & payload mastery have come together. Pocket-sized. DuckyScript™ powered.

Submit your own payload, or browse more featured Pineapple Pager Payloads.

 

 

Related Payloads

Simple Client Info
Simple Client Info
Hosts a DHCP server and displays the hostname, IP address and MAC address of each connected client.
Read More
HashMaster
HashMaster
Report captured handshakes using the HashMaster database
Read More
Noise Maker
Noise Maker
Prank-style “Noise Maker” tool that turns pager into a portable chaos machine. It lets you pick from a collection of ann
Read More