← How-Tos
flipper-zero Jul 3, 2026 ◯ 2 min read

Deauth Detection & Defense: Testing Your Own Network

flipper zerodeauthwifi securitypmfnetwork defense

What You're Actually Testing

Deauthentication frames are a legitimate part of the 802.11 WiFi standard (used for normal disconnect handling), but they're unauthenticated in older WiFi security models — meaning anyone in range can forge one and force a client off your network. Testing your own network's resilience to this is legitimate security validation; using it against networks you don't own is not (see the Marauder setup guide's legal section).

Why This Matters

A network vulnerable to deauth attacks can be knocked offline trivially, and — more seriously — deauth is sometimes used as a precursor to capturing a WPA handshake for offline password cracking (forcing a client to reconnect gives an attacker a fresh handshake to capture). Testing your own network's resistance to this tells you whether you're exposed to that follow-on attack.

The Real Fix: Protected Management Frames (PMF/802.11w)

Modern WiFi security (WPA3, and WPA2 with PMF enabled) cryptographically signs management frames including deauth — a forged deauth frame without the correct signature is simply ignored by PMF-aware clients and access points. This is the actual solution, not something you can bolt on after the fact at the client level.

Checking If Your Network Has PMF Enabled

Testing With the WiFi Dev Board

With Marauder (see setup guide), run the Deauth function targeting your own network's AP/clients specifically (select your own SSID from the scan list, never a network you don't own). On a PMF-protected network, connected clients should show no disruption — that's the test passing. On a network without PMF, you'll see genuine disconnects, confirming the exposure.

Practical Steps If Your Network Fails This Test

  1. Enable PMF/802.11w in your router's wireless security settings if it's supported but currently off.
  2. If your router doesn't support PMF at all, this is a genuine argument for a router upgrade — it's become a fairly standard feature on hardware from the last several years.
  3. Move to WPA3 if all your client devices support it — this makes PMF mandatory rather than optional and closes the gap entirely.

What This Doesn't Protect Against

PMF stops forged deauth frames specifically — it doesn't address other WiFi attack surfaces (WPS vulnerabilities, weak passwords enabling dictionary attacks on captured handshakes, rogue AP/evil twin attacks). Deauth resistance is one piece of a broader WiFi security posture, not the whole picture.