How to Use Bettercap for Network Penetration Testing: A Beginner's Guide to Detection and Defence
Learn how to use Bettercap for network penetration testing, MITM attacks, ARP spoofing, and Wi-Fi auditing. This guide explains installation, key modules, command examples, caplet automation, and real-world usage for ethical hackers and SOC analysts.
Quick answer: Bettercap is an open-source network reconnaissance and man-in-the-middle framework written in Go. Ethical hackers and SOC analysts use it to study how traffic interception, ARP and DNS spoofing, and rogue Wi-Fi access points work, so they can detect and defend against them. Use it only on a lab you own or a network you are written-authorised to test. On any other network in India it is an offence under the IT Act, 2000.
Key takeaways
- Bettercap is a Go-based MITM framework that has largely replaced Ettercap in labs, so learn it to understand ARP and DNS spoofing.
- Run it only in an isolated lab you own, starting with passive reconnaissance, since using it elsewhere breaks the IT Act, 2000.
- Defend with dynamic ARP inspection, DNS over HTTPS or TLS and HTTPS everywhere, and watch for duplicate ARP replies as the detection sign.
This guide explains what Bettercap does, how to run it safely in an isolated lab, and, most importantly, how defenders spot the activity it generates. It is written for students and SOC analysts who need to understand the tool to defend against it, not a recipe for attacking live networks.
What is Bettercap?
Bettercap is an open-source framework for network reconnaissance and man-in-the-middle (MITM) research. Its own project describes it as a tool for Wi-Fi, Bluetooth Low Energy, wireless HID, CAN-bus and IPv4/IPv6 networks. It is written in Go and is actively maintained, which is why it has largely replaced older tools like Ettercap in training labs.
Security teams care about it for two reasons. Red teams use it under contract to show how an unsegmented network can be intercepted. Blue teams study the same behaviour so their monitoring can flag it. Both uses depend on one thing: explicit authorisation.
Is it legal to use Bettercap?
Only on systems you own or are authorised in writing to test. Intercepting or spoofing traffic on a network you do not control is illegal in India. Sections 43 and 66 of the Information Technology Act, 2000 cover unauthorised access and data interception, and penalties include fines and imprisonment. "I was only learning" is not a defence.
Keep your practice inside a closed lab: a couple of virtual machines or spare devices on an isolated switch or a dedicated test Wi-Fi, with no path to the internet or to other people's devices. Treat written scope as the first step of every engagement, the same way a professional penetration tester does.
Installing Bettercap in a lab
Bettercap runs on Linux, macOS and Windows, and is usually run from Kali Linux or Parrot OS in a training setup. On Kali:
sudo apt update
sudo apt install bettercap
bettercap -version
You can also build the latest release from source with Go. Confirm the version before you rely on any module, because module names and defaults change between releases. Launch it against your lab interface:
sudo bettercap -iface eth0
That drops you into the interactive session. From here, the safe first command is passive discovery of your own lab.
What the main modules do
Understanding the modules matters more for defence than memorising commands. Each one maps to activity a defender can detect.
| Module | What it does | How defenders see it |
|---|---|---|
net.recon | Passively lists hosts on the local network | Usually silent; pairs with later active modules |
arp.spoof | Sends forged ARP replies to reroute traffic | Duplicate or changing MAC-to-IP mappings; dynamic ARP inspection alerts |
dns.spoof | Returns forged DNS answers | DNS responses that do not match the resolver; DNSSEC validation failures |
net.sniff | Captures packets passing through the host | No direct signature; the spoofing that enables it is the signal |
http.proxy / https.proxy | Intercepts web traffic; attempts SSL stripping on sites without HSTS | Certificate warnings; unexpected downgrade to HTTP; HSTS blocks it outright |
wifi.recon | Scans nearby access points and clients | Needs monitor mode; wireless IDS can flag the adapter |
wifi.ap | Stands up a rogue access point | A new SSID or a duplicate of a known one; rogue-AP detection flags it |
For a deeper look at how interception works end to end, see our walkthrough on understanding man-in-the-middle attacks.
A safe starting point: passive recon on your own lab
The one command worth running early is passive host discovery, because it generates almost no risk and teaches you to read a network:
net.recon on
net.show
net.recon watches ARP traffic to build a list of live hosts; net.show prints it. Nothing is being attacked here. Compare the output against what you expect to see on your lab. On a real monitored network, this habit is exactly what a defender uses an IDS for.
The active modules (ARP spoofing, DNS spoofing, proxies, rogue APs) are where interception actually happens. This guide deliberately does not hand you a ready-to-run interception chain, because the goal here is recognition and defence, not a copy-paste attack. If you need to exercise those modules, do it inside an isolated lab with devices you own, and watch the traffic from a second machine so you learn the detection side at the same time.
How to detect Bettercap activity
This is the part that matters on the job. ARP spoofing, the core of most Bettercap MITM activity, is noisy and detectable:
- Watch the ARP table. A gateway IP whose MAC address suddenly changes, or two IPs sharing one MAC, is the classic sign of ARP poisoning.
- Enable Dynamic ARP Inspection (DAI) on managed switches so forged ARP replies are dropped before they reach clients.
- Baseline DNS. Responses that resolve a known domain to an unexpected IP, or sudden DNSSEC validation failures, point to DNS spoofing.
- Catch downgrades. Unexpected HTTP where HTTPS is expected, or certificate warnings on normally clean sites, suggest SSL stripping.
- Scan for rogue APs. A wireless IDS or a periodic survey can flag a duplicate SSID or an access point that should not exist.
Tools like Wireshark, Zeek and Suricata turn these signals into alerts. If you are new to packet analysis, start with Wireshark for packet analysis, then learn to recognise the patterns in how network sniffing works.
How to defend a network against MITM
Defence is mostly good hygiene applied consistently:
| Control | What it stops |
|---|---|
| Dynamic ARP Inspection and DHCP snooping | ARP spoofing and rogue DHCP |
| HSTS and HTTPS everywhere | SSL stripping and HTTP downgrade |
| DNSSEC and trusted resolvers | DNS spoofing |
| WPA3, strong Wi-Fi passphrases, client isolation | Rogue APs and Evil Twin capture |
| Network segmentation and 802.1X | Limits what an intercepting host can reach |
| IDS/IPS (Zeek, Suricata) | Turns the above activity into alerts |
Common mistakes beginners make
- Testing on a shared or public network. This is the mistake that turns a learning exercise into an offence. Keep everything in an isolated lab.
- Leaving IP forwarding or spoofing running. If you do exercise active modules, stop them cleanly so you do not black-hole your own lab traffic.
- Treating captured lab data as a trophy. The value is in understanding the method and the detection, not in the data.
- Skipping the defender's view. Run a packet capture from a second machine while you test, so you learn what the attack looks like on the wire.
Where this fits in a security career
Understanding MITM tooling is foundational for both offensive and defensive roles. On the offensive side it maps to authorised network and wireless assessment work; on the defensive side it maps to SOC monitoring and network defence. If you want structured, lab-based practice, the Certified Ethical Hacker (CEH) training covers these techniques with the legal and ethical framing an employer expects.
Next step: set up a two-VM isolated lab, run net.recon, and practise spotting a MAC-address change in the ARP table from a second machine before you ever touch an active module.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0