TAU-HOME.COM
LOADING

Airgorah: Modern WiFi Security Auditing Tool Built With Rust and GTK4 for Linux

An overview of Airgorah, an open-source Linux WiFi auditing tool in Rust and GTK4 that captures traffic, detects clients, and collects handshakes and PMKIDs.

tau · October 8, 2026

#airgorah #rust #gtk4 #wifi-security #pentesting #linux

Airgorah: Modern WiFi Security Auditing Tool Built With Rust and GTK4 for Linux

Airgorah is an open-source wireless network security auditing tool developed in Rust and GTK4 specifically for Linux environments. Created by developer martin-olivier (the AUR package metadata lists the MIT license), the application consolidates wireless traffic capture, connected client discovery, deauthentication attacks, handshake and PMKID collection, and password cracking into an intuitive graphical interface.

Airgorah GUI dashboard visualizing nearby wireless networks and connected clients using Rust and GTK4

Image source: Tom Dörr (@tom_doerr) / martin-olivier

Earlier Airgorah releases ran as a single root GTK process; the project has since split that process into an unprivileged GUI plus a small privileged helper, so the program now works under Wayland as well as X11.

Privilege Separation Architecture and Wayland Support

A defining architectural feature of Airgorah is its clean division of responsibilities between an unprivileged graphical interface and a small privileged helper process.

Previously, Airgorah itself ran as a single root GTK process to configure network interfaces and inject packets; the release notes describe splitting that process so the program now works under Wayland sessions on modern Linux distributions.

  • Unprivileged GUI with airgorah-agent: The primary GTK4 user interface runs with standard user privileges, providing support for both Wayland and X11 sessions.
  • Single-Prompt polkit Authentication: When an operation requires elevated privileges after interface selection, Airgorah launches a lightweight privileged background helper, airgorah-agent, via polkit (pkexec), prompting the operator for authorization once.
  • Isolated Local IPC: Communication between the GUI and the privileged agent flows over a dedicated Unix domain socket under /run/airgorah/, with one socket per GUI instance keyed by launching user uid and instance (GUI-process) id (pattern /run/airgorah/{uid}-{instance}.sock). The IPC protocol employs a 4-byte big-endian length prefix and JSON-encoded messages, allowing multiple instances to run without socket collisions.

Real-Time Scanning, Deauthentication, and PMKID Harvesting

Airgorah packages the core techniques required for wireless vulnerability testing into structured views.

Upon launching, operators select an available wireless interface to begin scanning nearby wireless networks in real time. The status bar displays the channel the interface is currently listening on, and the application can keep the scan parked on targeted channels during deauthentication attacks.

  • Connected Client Discovery: The interface updates surrounding wireless networks in real time and lists client stations connected to the selected access point.
  • Deauthentication Attacks: Operators can launch deauthentication attacks against a selected network, opening a window to choose target client stations.
  • Handshake Capture: Airgorah captures handshakes as clients reconnect.
  • Direct PMKID Solicitation: Airgorah supports PMKID detection, display, and solicitation directly from the access point; one third-party reply describes this flow as yielding a crackable hash straight from the AP without waiting for a client to reconnect.

Captured handshakes and PMKIDs can then be used directly within Airgorah to crack access point passwords.

Removing aircrack-ng Suite and mergecap Dependencies With a Rust Implementation

A notable milestone in Airgorah's development is its removal of the aircrack-ng suite and mergecap dependencies.

The 0.7.4-era README describes the project as based on the aircrack-ng tool suite, and the captured usage-wiki snapshot describes displaying parsed airodump-ng result data (an older documented flow, not current behavior).

The captured release notes list removing the aircrack-ng suite and mergecap dependencies, implementing network auditing capabilities in Rust code.

This change results in a leaner dependency footprint and simplified deployment. In addition to source builds from the GitHub repository, Airgorah is distributed through the official Rust package registry crates.io (airgorah, with the airgorah-common IPC crate documented on docs.rs) and the Arch User Repository (airgorah).

Platform Scope and Authorized-Use Guidelines

Deploying Airgorah effectively requires checking platform scope and operating within authorized boundaries.

The software is built exclusively for Linux; at launch, operators select one of the system's available wireless interfaces for scans and attacks.

Furthermore, wireless auditing utilities must be operated strictly within authorized boundaries:

  • Authorized Assessments Only: Airgorah is intended solely for evaluating networks you personally own or have formal authorization to test.
  • Legal Compliance: Only operate within authorized boundaries and applicable law.

When deployed in legitimate environments, Airgorah provides network administrators and security auditors with a modern, straightforward toolkit to audit wireless network security.

Sources