top of page

WiFi Pineapple: Enterprise (Top-Tier Rack-Mounted Hacking Hardware)

WiFi Pineapple: Enterprise (Top-Tier Rack-Mounted Hacking Hardware) | Black Hat HQ

WiFi Pineapple: Enterprise (The Elite Beast)


This is the top-tier, fixed-installation WiFi auditing platform from Hak5. Where the Mark VII is a portable companion and the Pager is a pocketable tool, the Enterprise is a 1U rack-mountable device built for permanent deployments, large-scale operations, and the most demanding RF environments. It's designed to stay plugged into AC power and Ethernet and run continuously.


Full Hardware Specifications


Component

Detail

CPU

Quad-core ARM Cortex A7 @ 717 MHz

RAM

1 GB DDR3L

Storage

4 GB eMMC

Radios

5 total — 2 embedded + 3 USB-based

Radio 0/1

Qualcomm IPQ4019 — dual-band 2.4 GHz + 5 GHz, 802.11ac Wave 2

Radio 0/1 Peak

1.733 Gbps

Radio 2/3/4

MediaTek MT7612U — dual-band 2.4 GHz + 5 GHz

Radio 2/3/4 Peak

866 Mbps each

WiFi Features

MU-MIMO, TxBF, Qualcomm Wi-Fi SON

Standards

802.11 a/b/g/n/ac/ac Wave 2

Channel Width

20/40/80 MHz and 5/10/20/40 MHz

MIMO

2×2 (2-stream) per radio

Antennas

8× high-gain, external (RP-SMA or similar)

Ethernet

2× Gigabit RJ45 (1000BASE-T)

USB Ethernet

1× USB-C 3.0 (ASIX chipset)

USB Host

1× USB 3.0 host port

Power

100V–240V AC, 50/60 Hz (internal PSU, IEC connector)

Dimensions

160 × 244 × 41 mm (standard 1U width, shallow depth)

Operating Temp

-25°C to +50°C

LEDs

4× RGB indicators

Cooling

Passive (metal chassis acts as heatsink)


Five Radios - What That Actually Means


This is the Enterprise's defining characteristic. With five simultaneous radios, you can run multiple independent operations in parallel without time-slicing or radio sharing:


  1. Management AP — one radio dedicated to your admin interface, so control traffic never interferes with attack operations.

  2. PineAP Rogue AP — one radio impersonating target networks, serving Open/WPA/Enterprise portals.

  3. Recon — one radio permanently scanning, capturing probes, beacons, and handshakes.

  4. Deauth / Injection — one radio dedicated to sending deauth frames, beacon floods, or injection.

  5. Spare — fifth radio for whatever else: a second rogue AP on a different band, additional recon on another channel, or a client-mode radio bridging to an upstream network.


Each radio can be assigned a role independently through the web UI. You're not multiplexing — you have actual parallel hardware.


Enterprise-Grade PineAP Features


The PineAP suite on the Enterprise includes everything the Mark VII has, plus capabilities unique to the platform:


Evil WPA


Serve a rogue WPA2-PSK access point. When clients connect, capture the 4-way handshake and crack the PSK offline with hashcat. You can also set a known PSK and let clients connect fully — useful for transparent MITM once you've cracked the key or for targeted attacks where you know the password.


Evil Enterprise (WPA-Enterprise / 802.1X)


This is the Enterprise's killer feature and the reason for the name. It sets up a rogue WPA-Enterprise (RADIUS/802.1X) access point that captures domain credentials:


Three authentication modes:


Mode

Behavior

Any

Accepts whatever the client offers. Most clients default to MSCHAPv2 — they won't fully connect, but the challenge hash is captured.

MSCHAPv2

Captures the MSCHAPv2 NetNTLMv1-equivalent challenge/response hash. Client won't connect fully, but the hash can be cracked offline with hashcat (mode 14000) or relayed in real time.

GTC

Generic Token Card mode — the client sends the password in cleartext (actually GTC exchanges it in plaintext). Client will fully connect to your rogue AP. Username and password logged directly.


The Pineapple generates its own RADIUS server certificate on-device. Misconfigured enterprise clients that don't validate certificates (shockingly common) will connect and send credentials. Combined with hostapd-wpe style attacks, this can harvest domain credentials from corporate laptops that automatically connect to the corporate SSID.


Key Exchange Degradation


The Enterprise can force weaker authentication methods. Many clients configured for PEAP-MSCHAPv2 will fall back to GTC if the RADIUS server requests it — meaning you can force plaintext password capture from clients that "should" be doing hashed authentication.


Recon At Scale


The Enterprise's quad-core CPU and 1 GB RAM let it handle workloads the Mark VII chokes on:


  • Thousands of APs and clients simultaneously tracked (Mark VII: a few hundred).

  • Up to 100 concurrent DHCP clients on your rogue AP (Mark VII: 5–10).

  • Continuous full-band scanning across 2.4 and 5 GHz simultaneously on separate radios.

  • Handshake capture on one channel while recon runs on another — no radio time-slicing.


Deployment Models


Fixed / Permanent Installation


The Enterprise is built for this. Mount it in a server rack, plug into AC power and dual GigE, and leave it running 24/7. Use one Ethernet port for management and the other for bridged traffic if you're doing full MITM. Combine with Cloud C2 for remote access from anywhere.


Long-Term Red Team Drop Box


The metal chassis and wide temperature tolerance (-25°C to +50°C) mean you can stash it in harsh environments — a drop ceiling, an IDF closet, a mechanical room. It'll survive heat, cold, and dust that would kill a Mark VII. The AC power requirement is a constraint (you need an outlet, not USB), but in most commercial buildings, that's easy to find.


Conference Room / Lobby Operations


Set up in a target area for hours or days. Eight antennas give you serious range and signal quality. Run Evil Enterprise to harvest credentials from corporate devices that auto-connect to the company SSID. The dual GigE ports let you backhaul traffic through the target's own network if you've got a wired drop.


Three Product Tiers


Hak5 sells the Enterprise in three editions:


Edition

Target

Standard

Commercial red teams, pentesters, security consultancies

Advanced

TAA-compliant, final assembly in USA, for MIL/GOV agencies and defense contractors

Pentest

Includes Cloud C2 and advanced modules


Comparison: Enterprise vs. Mark VII vs. Pager


Feature

Mark VII

Pager

Enterprise

Radios

3× 2.4 GHz only

2× internal + USB dongle

5× dual-band

5 GHz

Needs MK7AC dongle

Built-in

Built-in (all 5 radios)

6 GHz

✅ Built-in

WiFi 6 (802.11ax)

❌ (ac Wave 2)

Bluetooth

✅ 5.2 + BLE 4.2

CPU

Single-core MIPS

580 MHz MIPS

Quad-core ARM A7 @ 717 MHz

RAM

256 MB

256 MB

1 GB

Ethernet

USB-C only

USB-C adapter

2× Gigabit RJ45 + USB-C

Power

USB-C (from laptop)

2000 mAh battery

Internal AC PSU (100-240V)

Form factor

Small desktop

Pocket pager

1U rack-mount

AP/client capacity

~10 DHCP / few hundred APs

Low (dongle-dependent)

100 DHCP / thousands APs

Evil Enterprise

Via payloads

✅ Full built-in

Standalone

Needs laptop

✅ Battery

✅ AC power

Antennas

3× fixed

Dongle-dependent

8× external high-gain

Operating temp

0–40°C

0–40°C

-25°C to +50°C

Price

~$140

~$180–200

$500+ (varies by tier)


Practical Attack Scenarios


1. Corporate credential harvesting via Evil Enterprise Drop the Enterprise in an IDF closet near target offices with AC power and a network drop. Configure Evil Enterprise to broadcast the target's corporate SSID with WPA-Enterprise. Client laptops configured for PEAP-MSCHAPv2 will auto-connect. Capture NetNTLMv1-equivalent hashes, crack offline, or relay to the legitimate RADIUS server if you're feeling ambitious. With GTC downgrade, capture passwords in plaintext.


2. Multi-channel persistent recon Three radios on recon duty across channels 1, 6, and 11 on 2.4 GHz plus key 5 GHz channels. The other two radios stay available for PineAP or deauth. You get a complete, continuous picture of the RF environment, every AP, every client, every probe request, every handshake — for days or weeks.


3. High-capacity rogue AP With support for 100 concurrent DHCP clients, you can serve a convincing captive portal to an entire floor of a building simultaneously. The Mark VII would buckle under the DHCP load. The Enterprise handles it without breaking a sweat.


4. Deauth + Evil WPA at scale Dedicate one radio to continuous targeted deauth (kicking clients off the legitimate AP). Dedicate another to Evil WPA impersonating that same SSID. Dedicate a third to handshake capture. All three run in parallel on separate hardware radios. Clients get deauthenticated, reconnect to your rogue AP, and their handshake is captured — all without radio contention.


Limitations To Know


  • No 6 GHz / WiFi 6E support — the Qualcomm IPQ4019 and MT7612U radios top out at 5 GHz ac Wave 2. For 6 GHz you'd need the Pager or third-party adapters.

  • No Bluetooth / BLE — purely WiFi. If you need Bluetooth recon, bring a Pager or a separate dongle.

  • Not portable — this is a fixed-installation device. No battery, internal AC PSU, 1U metal chassis. You're not walking around with it.

  • No DuckyScript — the Enterprise runs the traditional Pineapple module system, not the Pager's payload framework.

  • Price and availability — more expensive and less consumer-available than the Mark VII. B2B application required for some tiers.


Final Thoughts?


The Enterprise is the right choice when you need a permanent or long-term installation, when you're targeting WPA-Enterprise corporate networks for credential harvesting, or when you simply need five simultaneous radios doing five different things without compromise. For walk-around engagements, grab the Pager. For the standard laptop-tethered pentest, the Mark VII. For the serious fixed-site op, the Enterprise.


Enroll In Online Cybersecurity & Hacking Classes/Courses | Black Hat HQ

Comments


bottom of page