# Install hcxtools with Homebrew, apt, dnf, Nix, pacman

Utils for conversion of cap/pcap/pcapng WiFi dump files. Version 7.1.2 via Homebrew; verified from local package data. Also installable with debian: sudo apt install hcxtools.

## Install

```sh
sudo av install brew:hcxtools
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install hcxtools
```

  Evidence: local Homebrew formula metadata

### Linux

- Debian apt (92%):

```sh
sudo apt install hcxtools
```

  Evidence: Debian stable package indexes: hcxtools from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz

- dnf (92%):

```sh
sudo dnf install hcxtools
```

  Evidence: Fedora Rawhide package metadata: hcxtools from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst

- Nix (92%):

```sh
nix profile install nixpkgs#hcxtools
```

  Evidence: nixpkgs package indexes: pkgs/by-name/hc/hcxtools/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

- pacman (92%):

```sh
sudo pacman -S hcxtools
```

  Evidence: Arch Linux sync databases: hcxtools from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

## Package facts

- **Package key:** brew:hcxtools
- **Package manager:** Homebrew
- **Version:** 7.1.2
- **Source summary:** Utils for conversion of cap/pcap/pcapng WiFi dump files
- **Homepage:** <https://github.com/ZerBea/hcxtools>
- **Repository:** <https://github.com/ZerBea/hcxtools>
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- hcxeiutool (alias)
- hcxhash2cap (alias)
- hcxhashtool (alias)
- hcxpcapngtool (alias)
- hcxpmktool (alias)
- hcxpottool (alias)
- hcxpsktool (alias)
- hcxwltool (alias)
- whoismac (alias)
- wlancap2wpasec (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 7.1.2
## Project history and usage

hcxtools is a Linux-focused suite for converting Wi-Fi capture files into hash formats consumed by Hashcat and John the Ripper. The upstream description frames it as an analysis toolkit for finding weak points in one's own wireless networks rather than as a password-cracking engine.

### Project history

The GitHub repository was created in April 2017. Its scope settled around the conversion and post-processing side of WPA/WPA2 auditing: hcxpcapngtool converts capture files, hcxhashtool filters hash files, hcxpmktool verifies PSKs or PMKs, hcxpottool handles pot files, and related tools handle wordlist candidates, vendor lookup, and upload workflows.

The toolkit is closely paired with ZerBea's hcxdumptool, which performs packet capture and layer-2 WPA protocol tests. The documented workflow is hcxdumptool to hcxpcapngtool to hcxhashtool, optionally to hcxpsktool or hcxeiutool, and then to Hashcat or John the Ripper.

hcxtools evolved with Hashcat's WPA formats. The README emphasizes Hashcat mode 22000/22001 over older 2500/2501 and 16800/16801 formats, while the changelog records later work on FT-PSK PMKID and EAPOL conversion for mode 37100 and ongoing handling of EAPOL length limits.

### Adoption history

The package spread through security-oriented Linux distributions and general package managers because it solves a specific interoperability problem: turning packet captures into forms that established cracking and auditing tools can read. The batch input records Homebrew, Debian, Fedora, Nix, Arch, and Ubuntu packaging, but upstream itself warns that operating systems outside its Linux target are unsupported.

Its audience is narrower than a general network utility. Upstream expects knowledge of radio technology, 802.11 protocol behavior, key derivation, Linux drivers, capture filters, and related tooling. That technical bar shaped adoption among wireless-security practitioners and package users who already know the Hashcat/JtR workflow.

### How it is used

hcxtools does not capture traffic, crack hashes, attack WEP or WPS, or decrypt encrypted traffic. Instead, it converts, filters, verifies, and prepares artifacts: pcapng/pcap/cap input, PMKID and EAPOL hash lines, pot files, ESSID-derived candidate lists, vendor OUI lookups, and wpa-sec upload workflows.

The upstream README is explicit that output files may be appended to, that dump files should not be merged in ways that destroy custom block hash assignments, and that nonce-error correction is not performed by the tools. These details are why package users often care about exact upstream versions matching hcxdumptool and Hashcat behavior.

### Why package nerds care

hcxtools is package-nerd significant because it sits at a brittle boundary between kernel Wi-Fi capture behavior, pcapng file semantics, WPA handshake interpretation, and Hashcat/JtR hash formats. Small changes in any layer can make a packaged version too old for a user's capture workflow.

The suite is also notable as a source-built C toolkit with many small executables rather than one command. Packaging therefore exposes a toolbox: hcxpcapngtool for conversion, hcxhashtool for filtering, hcxhash2cap for reverse conversion, hcxpottool for pot files, whoismac for OUI data, and more.

### Timeline

- 2017: hcxtools repository created.
- 2019: 5.x releases published through GitHub releases.
- 2020: 6.0.0 and 6.1.x releases published.
- 2021: 6.2.x releases published.
- 2024: README simplified distribution-specific compile instructions and pointed users back to their distribution dependency names.
- 2025: 7.0.0 added support for relayed EAPOL messages.
- 2026: changelog recorded FT-PSK PMKID and EAPOL conversion work for Hashcat mode 37100.

### Related projects

- hcxdumptool captures the wireless packets that hcxtools converts and filters.
- Hashcat consumes the WPA/WPA2 hash formats that hcxtools prepares.
- John the Ripper is the other major password-auditing tool named in the README.
- wpa-sec is an upload target documented by the toolkit for testing captured material against common weak-key data.

### Sources

- <https://api.github.com/repos/ZerBea/hcxdumptool>
- <https://api.github.com/repos/ZerBea/hcxtools>
- <https://api.github.com/repos/ZerBea/hcxtools/releases>
- <https://github.com/ZerBea/hcxdumptool>
- <https://github.com/ZerBea/hcxtools>
- <https://github.com/ZerBea/hcxtools/blob/master/changelog>
- <https://github.com/hashcat/hashcat>


## Security Notes

narrow executable package without higher-risk signals.

- **Geiger risk:** green / low
- narrow executable package without higher-risk signals

## Other Package-Manager Records

- Debian apt - hcxtools - 6.3.5-1: normalized package name match | Debian stable package indexes: hcxtools from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | Tools for converting captures to use with hashcat or John the Ripper | https://github.com/ZerBea/hcxtools
- Nix - hcxtools: normalized package name match | nixpkgs package indexes: pkgs/by-name/hc/hcxtools/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- Ubuntu apt - hcxtools - 6.2.7-2build3: normalized package name match | Ubuntu 24.04 LTS package indexes: hcxtools from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz | Tools for converting captures to use with hashcat or John the Ripper | https://github.com/ZerBea/hcxtools
- dnf - hcxtools - 7.1.2-3.fc45: normalized package name match | Fedora Rawhide package metadata: hcxtools from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst | Set of tools to convert packets from capture files to hash files | https://github.com/ZerBea/hcxtools
- pacman - hcxtools - 7.1.2-1: normalized package name match | Arch Linux sync databases: hcxtools from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz | Portable solution for capturing wlan traffic and conversion to hashcat and John the Ripper formats | https://github.com/ZerBea/hcxtools


## Combined YAML source

View the package source record on GitHub. [combined/hcxtools.yml](https://github.com/mxcl/pkgdb/blob/main/combined/hcxtools.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
