pkg.sopackage field notes

brew / rank 1722

Install bettercap with Homebrew

Swiss army knife for network attacks and monitoring. Version 2.41.7 via Homebrew; verified 2026-07-15.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install bettercap

provider-native install command

overview

Package summary

Swiss army knife for network attacks and monitoring

Commands and aliases

  • bettercap

history

Project history and usage

bettercap is a Go-based network reconnaissance and attack framework packaged as a command-line tool for security researchers, red teamers, and reverse engineers. Its official description frames it as an all-in-one toolkit for Wi-Fi, Bluetooth Low Energy, HID, CAN-bus, IPv4, and IPv6 reconnaissance and MITM work.

Project history

The current public repository was created in January 2018 and hosts the Go implementation, documentation links, caplets, modules, tests, and release automation for bettercap 2.x. The project replaced the older single-purpose idea of a LAN MITM helper with a modular framework covering wireless and wired network attack surfaces.

Official release tags show the 2.x line continuing through regular maintenance and feature releases, including v2.40.0 in September 2024, v2.41.0 in January 2025, and v2.41.7 in May 2026.

Adoption history

bettercap became a common package-manager install for offensive-security labs because it combines sniffing, spoofing, Wi-Fi handshakes, BLE enumeration, packet/protocol proxies, and a REST/web UI under one executable. Homebrew, Debian/Ubuntu, Arch, Alpine, Nix, MacPorts, and openSUSE packaging in the input reflects that cross-platform adoption.

The GitHub repository's large star and fork counts, Docker image badge, and active release stream indicate that bettercap is used beyond macOS packaging: it is a standard tool people expect to be available in disposable lab machines, containers, and security-focused Unix environments.

How it is used

Users typically run bettercap interactively or with caplets to discover hosts, inspect traffic, run spoofers, capture Wi-Fi handshakes, enumerate BLE devices, or script network experiments. Its official docs emphasize an interactive session workflow and module-driven operation rather than a single fire-and-forget scan command.

Because the tool performs real attack and monitoring functions, its practical use belongs in authorized security testing, lab networks, red-team exercises, and research settings.

Why package nerds care

bettercap is package-nerd interesting because it is one of the few security CLI packages that collapses many historically separate tools into one Go binary with modules, a web UI, REST API, caplets, and packaged defaults. It sits at the intersection of classic Unix networking tools, wireless security suites, and modern self-contained Go distribution.

For Homebrew-style package history, bettercap also illustrates how offensive-security tooling moved from language/runtime-heavy installs toward portable binaries that can be installed quickly on a laptop, container, or lab host and then extended with scripts and modules.

Timeline

  • 2018: Current bettercap/bettercap GitHub repository created for the Go-based 2.x project.
  • 2024: v2.40.0 released, showing the mature 2.x line still receiving updates.
  • 2025: v2.41.0 released.
  • 2026: v2.41.7 published in May, with repository activity continuing in June.

Related projects

  • Related tools include Wireshark and tcpdump for packet inspection, aircrack-ng for Wi-Fi security workflows, mitmproxy for programmable proxying, nmap for network discovery, and ettercap as an older MITM-oriented tool whose niche bettercap partly modernized.

security posture

Risk level: red

network interception and offensive security tool.

Risk classifier

red risk · high confidence · escape-surveillance-offensive

Why

  • network interception and offensive security tool

Signals

  • override:bettercap

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
~/bettercap.env

executables

Installed executables

CommandKindExposureNote
bettercapexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version2.41.7
manager updated2026-07-15
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:bettercap
Version2.41.7
Package managerHomebrew
Homepagehttps://www.bettercap.org/
Repositoryhttps://github.com/bettercap/bettercap
Last updated2026-07-15T21:02:52-04:00
Pulseupdated
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation