68 diagrams of how WiFi attacks actually work.
Every diagram we drew to explain an attack or a detection, in one place — and yours to reuse. Published under CC BY 4.0: take any of them for a talk, a write-up, or a class, as long as you credit the source.
Free to use. Credit required.
These diagrams are released under the Creative Commons Attribution 4.0 International licence. Commercial use is fine. Modification is fine.
Name the source and link back to the page the diagram came from. Every card below has a Copy embed code button that produces correctly-attributed HTML, so you don't have to think about it.
Diagram by WifiThreatWatch — CC BY 4.0Most people never see a clear picture of what an attacker on their network is actually doing. Explaining that well is worth more to us than keeping the drawings to ourselves — and the diagrams are only useful if people can use them.
Attacks23
Cache vs Wire
reading the table can't witness the poisoning happen; sniffing the wire can
Deauth Flood
the AP is still right there — but you keep getting kicked off
One Verified Alert
an evil twin and a gateway ARP spoof are often one attack — we de-duplicate them so you act once
Layered Defense
awareness is the first line — if you connect to the impostor anyway, two more layers are waiting
DNS Answer Integrity
the resolver IP looks the same — the answer is what gives it away
DNS Redirect
the same lookup, answered by whichever resolver sits in the middle
Suppression Gate
a resolver change we caused ourselves is not an attack
Escalation
a new device is informational — until it acts like an attacker, and the same detection turns critical
Evil Twin
same SSID, stronger signal — the device prefers the attacker's access point
Sealed Path
the attacker made itself your gateway and DNS — so all it gets to forward is ciphertext it can’t read
Man in the Middle
the same connection, re-routed so your traffic passes through the adversary
Reclaim Loop
if the attacker re-poisons, we change identity again — up to five times — until the lock breaks
Reconnect Guard
we can’t stop the radio frames — but we name the attack and treat the network offering you back as suspect
Rogue DHCP
one broadcast, two answers — a second server volunteers as your gateway
Device Roster
a MAC the baseline has never seen is surfaced as new
Subnet Sweep
every host pinged at once — one MAC answers that shouldn't
Canonical Key
different bytes that reduce to the same key are the tell
SSID Look-alike
same pixels, different bytes — one letter isn't Latin
ARP MITM
every packet detours through the attacker before reaching your router
Identity Reset
a fresh MAC and IP break the attacker's lock before the tunnel comes up
Resolved in the Tunnel
the same canary that came back tampered on the local network resolves correctly through Active Defense
DNS on the Tunnel
your lookups ride the encrypted tunnel to a resolver we control — the swapped local one never sees them
Baseline Check
the current association weighed against the saved BSSID, gateway MAC and DNS
Detection guides16
Your Baseline + 1
four devices you authorized — and one you didn't
Same Name, Two Radios
two access points broadcasting one SSID — only one is your real router
The Real Goal
denial of service is rarely the point — it’s the setup for the twin
Snapshot vs. Watch
a snapshot sees one moment; a watch sees the moment it joins
Passive DHCP Watch
every OFFER and ACK checked against the one legitimate server — a stranger stands out
Resolver Baseline
a resolver you didn’t set, on a network you didn’t change — that’s the anomaly
One Foothold, Whole Map
a hostile device quietly maps the network and reads what flows past
Same Entry, Two Identities
a device list shows the row — not which one it is
Invisible Characters
some look-alike tricks use characters that render as nothing at all
Lock It Down
a few minutes turns an open door into a closed one
Mesh vs Twin
your mesh uses many radios on purpose — the trick is flagging only the one that doesn’t belong
Answer, Not Resolver
resolve a name whose correct IP you already know — the answer is what gives it away
Encrypted, Still Routed
a VPN hides what you send — not the fact that an attacker is on your path
Rogue, in Buckets
one label, four very different things
Attached Devices
every device accounted for — except one you didn't invite
Everyday Tells
none prove it alone — together, worth two minutes
How it works5
ARP MITM
the route you assume vs. the one you get — every packet detours through the attacker first
New Identity
the adapter rolls a fresh MAC and pulls a new DHCP lease — the address the attacker was poisoning no longer exists
Protect Me
six stages in one fixed order — the encrypted tunnel comes up last, not first
Retry
a new identity every attempt — up to five — until one beats the re-poison
And
both signals must agree before we interrupt you — a stale cache entry alone stays quiet
Shared intelligence14
24 / 7 vs When You’re Awake
the app watches while your PC is on — the Nano never blinks, so the 3 a.m. attack is still caught
Stronger, Not Louder
every extra reporter raises one shared count — it never multiplies the warnings on your screen
One Device vs the Whole Network
the app guards the machine it runs on — the Nano watches everything on the WiFi, installed or not
Re-checked ~Every 30s
flagged after you already joined? you’re warned in the app on the next re-check, not at your next scan
Symptom vs Frame
Windows can only infer an attack from its symptoms — a monitor radio reads the attack frames themselves
WifiThreatWatch Nano
a small always-on sentry you plug into any Wi-Fi — two radios, no screen, never off
Read It on Join
the moment you connect, the app finds the Nano and reads what it has already seen — before you trust the network
WifiThreatWatch Nano
a headless sensor running the same detectors 24/7 — even when your PC is asleep
It Compounds
the database is young — every device that joins makes the next warning likelier to already be there
See Threats Before You Join
every nearby network checked against the shared database — before you tap connect
What a Report Sends
the attack is documented so the next device recognizes it — your browsing, files, exact location and identity stay out of it
Defense That Compounds
one attack caught, reported, and turned into an early warning for the next person
Two Channels, Not One
the cloud database answers questions your device asks · the Nano announces itself only on your own WiFi
No Push, No Broadcast
a detection climbs into one shared row; the next device finds it only when it asks — devices never message each other
Coverage1
Two Kinds of Cover
both encrypt the line; only WifiThreatWatch watches the room the attacker is standing in
Overview3
The Fake Hotspot Trick
a stranger nearby broadcasts a friendly network name and waits — WifiThreatWatch stands in the middle, warns you in plain English, and cuts him off
Mesh AP Panel
every node broadcasting your network name — signal, load, and trust at a glance
The Report vs. You
a confirmed attack names the threat in full — and is never tied to you
Field reports6
ARP Cache
airline-lounge net — one IP’s hardware address kept flipping (~37 devices present)
Encryption Audit
every airport network the scan saw was open — no WiFi-layer encryption
SSID Roster
73 access points, one network name — 52 recognized, 18 suspicious BSSID, 3 evil-twin-nearby
ARP Timeline
two brief blips, both randomized (LAA) MACs — consistent with MAC rotation, not a sustained attack
Open Segment
85 devices new to this laptop — everyone else in the terminal on the same open network, not 85 attackers
DNS Resolver
PNS ran on Quad9 (9.9.9.9), which blocks known-malicious domains — a security-conscious choice



































































