// what it is
Description
evilsocket's modular MITM and network attack toolkit. ARP spoofing, DNS spoofing, HTTPS proxy, BLE/Wi-Fi attacks, scriptable via 'caplets'. The active option for LAN attacks in 2026.
// use cases
What people use it for
- LAN MITM
- Wi-Fi handshake capture
- BLE reconnaissance
// commands
The commands you'll type
Interactive on eth0
$ bettercap -iface eth0Run a caplet
$ bettercap -caplet http-ui