Does Wireshark supports decryption of 802.11 packets with PTK as user's input (instead of PMK/password)?

asked 2020-01-01

Yedivach

updated 2020-01-01

When Wireshark decrypt 802.11 packets, it uses the password to generate the PMK. The next step is to take the 4-way handshake (EAPOLS) and create (using the PMK and the EAPOLS) the unicast keys - Pairwise transient key (PTK).

In case of not capturing the 4-way handshake the calculation of the PTK is impossible.

Does provide the PTK straight from the user is something possible on Wireshark (bypass the PTK calculation that exists today)?

answered 2020-01-02

Bob Jones

Not directly, no. The UI entry that is exposed is to enter in either the passphrase/SSID or the PMK directly, but at least part of the 4-way handshake is needed to derive the PTK and GTK (you didn't mention the group key, but it may be important to others).

You could enter an enhancement request over at

Asked: 2020-01-01

Last updated: Jan 02 '20