WiFi Pineapple: Enterprise (Top-Tier Rack-Mounted Hacking Hardware)
- Biohazard

- Jul 22
- 6 min read

WiFi Pineapple: Enterprise (The Elite Beast)
This is the top-tier, fixed-installation WiFi auditing platform from Hak5. Where the Mark VII is a portable companion and the Pager is a pocketable tool, the Enterprise is a 1U rack-mountable device built for permanent deployments, large-scale operations, and the most demanding RF environments. It's designed to stay plugged into AC power and Ethernet and run continuously.
Full Hardware Specifications
Component | Detail |
CPU | Quad-core ARM Cortex A7 @ 717 MHz |
RAM | 1 GB DDR3L |
Storage | 4 GB eMMC |
Radios | 5 total — 2 embedded + 3 USB-based |
Radio 0/1 | Qualcomm IPQ4019 — dual-band 2.4 GHz + 5 GHz, 802.11ac Wave 2 |
Radio 0/1 Peak | 1.733 Gbps |
Radio 2/3/4 | MediaTek MT7612U — dual-band 2.4 GHz + 5 GHz |
Radio 2/3/4 Peak | 866 Mbps each |
WiFi Features | MU-MIMO, TxBF, Qualcomm Wi-Fi SON |
Standards | 802.11 a/b/g/n/ac/ac Wave 2 |
Channel Width | 20/40/80 MHz and 5/10/20/40 MHz |
MIMO | 2×2 (2-stream) per radio |
Antennas | 8× high-gain, external (RP-SMA or similar) |
Ethernet | 2× Gigabit RJ45 (1000BASE-T) |
USB Ethernet | 1× USB-C 3.0 (ASIX chipset) |
USB Host | 1× USB 3.0 host port |
Power | 100V–240V AC, 50/60 Hz (internal PSU, IEC connector) |
Dimensions | 160 × 244 × 41 mm (standard 1U width, shallow depth) |
Operating Temp | -25°C to +50°C |
LEDs | 4× RGB indicators |
Cooling | Passive (metal chassis acts as heatsink) |
Five Radios - What That Actually Means
This is the Enterprise's defining characteristic. With five simultaneous radios, you can run multiple independent operations in parallel without time-slicing or radio sharing:
Management AP — one radio dedicated to your admin interface, so control traffic never interferes with attack operations.
PineAP Rogue AP — one radio impersonating target networks, serving Open/WPA/Enterprise portals.
Recon — one radio permanently scanning, capturing probes, beacons, and handshakes.
Deauth / Injection — one radio dedicated to sending deauth frames, beacon floods, or injection.
Spare — fifth radio for whatever else: a second rogue AP on a different band, additional recon on another channel, or a client-mode radio bridging to an upstream network.
Each radio can be assigned a role independently through the web UI. You're not multiplexing — you have actual parallel hardware.
Enterprise-Grade PineAP Features
The PineAP suite on the Enterprise includes everything the Mark VII has, plus capabilities unique to the platform:
Evil WPA
Serve a rogue WPA2-PSK access point. When clients connect, capture the 4-way handshake and crack the PSK offline with hashcat. You can also set a known PSK and let clients connect fully — useful for transparent MITM once you've cracked the key or for targeted attacks where you know the password.
Evil Enterprise (WPA-Enterprise / 802.1X)
This is the Enterprise's killer feature and the reason for the name. It sets up a rogue WPA-Enterprise (RADIUS/802.1X) access point that captures domain credentials:
Three authentication modes:
Mode | Behavior |
Any | Accepts whatever the client offers. Most clients default to MSCHAPv2 — they won't fully connect, but the challenge hash is captured. |
MSCHAPv2 | Captures the MSCHAPv2 NetNTLMv1-equivalent challenge/response hash. Client won't connect fully, but the hash can be cracked offline with hashcat (mode 14000) or relayed in real time. |
GTC | Generic Token Card mode — the client sends the password in cleartext (actually GTC exchanges it in plaintext). Client will fully connect to your rogue AP. Username and password logged directly. |
The Pineapple generates its own RADIUS server certificate on-device. Misconfigured enterprise clients that don't validate certificates (shockingly common) will connect and send credentials. Combined with hostapd-wpe style attacks, this can harvest domain credentials from corporate laptops that automatically connect to the corporate SSID.
Key Exchange Degradation
The Enterprise can force weaker authentication methods. Many clients configured for PEAP-MSCHAPv2 will fall back to GTC if the RADIUS server requests it — meaning you can force plaintext password capture from clients that "should" be doing hashed authentication.
Recon At Scale
The Enterprise's quad-core CPU and 1 GB RAM let it handle workloads the Mark VII chokes on:
Thousands of APs and clients simultaneously tracked (Mark VII: a few hundred).
Up to 100 concurrent DHCP clients on your rogue AP (Mark VII: 5–10).
Continuous full-band scanning across 2.4 and 5 GHz simultaneously on separate radios.
Handshake capture on one channel while recon runs on another — no radio time-slicing.
Deployment Models
Fixed / Permanent Installation
The Enterprise is built for this. Mount it in a server rack, plug into AC power and dual GigE, and leave it running 24/7. Use one Ethernet port for management and the other for bridged traffic if you're doing full MITM. Combine with Cloud C2 for remote access from anywhere.
Long-Term Red Team Drop Box
The metal chassis and wide temperature tolerance (-25°C to +50°C) mean you can stash it in harsh environments — a drop ceiling, an IDF closet, a mechanical room. It'll survive heat, cold, and dust that would kill a Mark VII. The AC power requirement is a constraint (you need an outlet, not USB), but in most commercial buildings, that's easy to find.
Conference Room / Lobby Operations
Set up in a target area for hours or days. Eight antennas give you serious range and signal quality. Run Evil Enterprise to harvest credentials from corporate devices that auto-connect to the company SSID. The dual GigE ports let you backhaul traffic through the target's own network if you've got a wired drop.
Three Product Tiers
Hak5 sells the Enterprise in three editions:
Edition | Target |
Standard | Commercial red teams, pentesters, security consultancies |
Advanced | TAA-compliant, final assembly in USA, for MIL/GOV agencies and defense contractors |
Pentest | Includes Cloud C2 and advanced modules |
Comparison: Enterprise vs. Mark VII vs. Pager
Feature | Mark VII | Pager | Enterprise |
Radios | 3× 2.4 GHz only | 2× internal + USB dongle | 5× dual-band |
5 GHz | Needs MK7AC dongle | Built-in | Built-in (all 5 radios) |
6 GHz | ❌ | ✅ Built-in | ❌ |
WiFi 6 (802.11ax) | ❌ | ✅ | ❌ (ac Wave 2) |
Bluetooth | ❌ | ✅ 5.2 + BLE 4.2 | ❌ |
CPU | Single-core MIPS | 580 MHz MIPS | Quad-core ARM A7 @ 717 MHz |
RAM | 256 MB | 256 MB | 1 GB |
Ethernet | USB-C only | USB-C adapter | 2× Gigabit RJ45 + USB-C |
Power | USB-C (from laptop) | 2000 mAh battery | Internal AC PSU (100-240V) |
Form factor | Small desktop | Pocket pager | 1U rack-mount |
AP/client capacity | ~10 DHCP / few hundred APs | Low (dongle-dependent) | 100 DHCP / thousands APs |
Evil Enterprise | ❌ | Via payloads | ✅ Full built-in |
Standalone | Needs laptop | ✅ Battery | ✅ AC power |
Antennas | 3× fixed | Dongle-dependent | 8× external high-gain |
Operating temp | 0–40°C | 0–40°C | -25°C to +50°C |
Price | ~$140 | ~$180–200 | $500+ (varies by tier) |
Practical Attack Scenarios
1. Corporate credential harvesting via Evil Enterprise Drop the Enterprise in an IDF closet near target offices with AC power and a network drop. Configure Evil Enterprise to broadcast the target's corporate SSID with WPA-Enterprise. Client laptops configured for PEAP-MSCHAPv2 will auto-connect. Capture NetNTLMv1-equivalent hashes, crack offline, or relay to the legitimate RADIUS server if you're feeling ambitious. With GTC downgrade, capture passwords in plaintext.
2. Multi-channel persistent recon Three radios on recon duty across channels 1, 6, and 11 on 2.4 GHz plus key 5 GHz channels. The other two radios stay available for PineAP or deauth. You get a complete, continuous picture of the RF environment, every AP, every client, every probe request, every handshake — for days or weeks.
3. High-capacity rogue AP With support for 100 concurrent DHCP clients, you can serve a convincing captive portal to an entire floor of a building simultaneously. The Mark VII would buckle under the DHCP load. The Enterprise handles it without breaking a sweat.
4. Deauth + Evil WPA at scale Dedicate one radio to continuous targeted deauth (kicking clients off the legitimate AP). Dedicate another to Evil WPA impersonating that same SSID. Dedicate a third to handshake capture. All three run in parallel on separate hardware radios. Clients get deauthenticated, reconnect to your rogue AP, and their handshake is captured — all without radio contention.
Limitations To Know
No 6 GHz / WiFi 6E support — the Qualcomm IPQ4019 and MT7612U radios top out at 5 GHz ac Wave 2. For 6 GHz you'd need the Pager or third-party adapters.
No Bluetooth / BLE — purely WiFi. If you need Bluetooth recon, bring a Pager or a separate dongle.
Not portable — this is a fixed-installation device. No battery, internal AC PSU, 1U metal chassis. You're not walking around with it.
No DuckyScript — the Enterprise runs the traditional Pineapple module system, not the Pager's payload framework.
Price and availability — more expensive and less consumer-available than the Mark VII. B2B application required for some tiers.
Final Thoughts?
The Enterprise is the right choice when you need a permanent or long-term installation, when you're targeting WPA-Enterprise corporate networks for credential harvesting, or when you simply need five simultaneous radios doing five different things without compromise. For walk-around engagements, grab the Pager. For the standard laptop-tethered pentest, the Mark VII. For the serious fixed-site op, the Enterprise.






Comments