Mobile Pentesting with Kali Netunter
Brayden Houston (CyberSecurity Engineer)
SAINTCON 2025 · Day 3 · Main Track 2
Overview
In this insightful talk titled "Mobile Pentesting with Kali NetHunter" at SAINTCON, cybersecurity engineer Brayden Houston demystifies Kali NetHunter, a powerful mobile penetration testing platform. Houston guides the audience through what NetHunter is, how to get started with it, and the diverse range of offensive security capabilities it unlocks on a portable device. The presentation highlights NetHunter's ability to transform an ordinary Android phone or tablet into a versatile hacking tool, leveraging existing hardware for discreet and on-the-go security assessments.

Key moments
- 0:00 Welcome and speaker introduction
- 2:40 Ethical hacking reminder and Kali Linux overview
- 3:37 Introducing Kali NetHunter: Kali on your phone
- 4:00 NetHunter interface and turning your phone into a cyber deck
- 5:58 Exploring advanced NetHunter attack capabilities: BadUSB, Wi-Fi, Bluetooth
Mobile Pentesting with Kali NetHunter
Speakers: Brayden Houston, CyberSecurity Engineer
Conference: SAINTCON
YouTube: https://www.youtube.com/watch?v=wjeodmRuAHs
Overview
In this insightful talk titled "Mobile Pentesting with Kali NetHunter" at SAINTCON, cybersecurity engineer Brayden Houston demystifies Kali NetHunter, a powerful mobile penetration testing platform. Houston guides the audience through what NetHunter is, how to get started with it, and the diverse range of offensive security capabilities it unlocks on a portable device. The presentation highlights NetHunter's ability to transform an ordinary Android phone or tablet into a versatile hacking tool, leveraging existing hardware for discreet and on-the-go security assessments.
The talk is particularly relevant for security professionals, ethical hackers, and enthusiasts looking to expand their toolkit beyond traditional desktop environments. Houston emphasizes the practical benefits of NetHunter, such as its portability and the ability to conduct sophisticated attacks without drawing undue attention. By detailing the setup process, exploring various editions, and showcasing practical demonstrations, he illustrates how NetHunter empowers users to perform tasks ranging from Wi-Fi analysis and BadUSB attacks to more advanced car hacking techniques, all from the palm of their hand.
Houston's presentation underscores the strategic advantage of having a full-fledged Kali Linux environment readily available on a mobile device. This approach not only enhances the flexibility of penetration testers but also serves as a potent reminder for defenders about the evolving landscape of attack vectors. The ability to discreetly deploy a wide array of security tools from a seemingly innocuous smartphone presents both powerful opportunities for ethical hacking and significant challenges for maintaining robust digital defenses.
Background
▶ Watch: Welcome and speaker introduction (0:00)
Kali Linux has long been established as the de facto standard operating system for penetration testing and digital forensics. Developed by Offensive Security, it comes pre-loaded with hundreds of tools for various security tasks, including password cracking, network monitoring with Wireshark, web application analysis with Burp Suite, and vulnerability scanning. Its comprehensive nature makes it the go-to distribution for security professionals operating in traditional desktop or virtual machine environments.
However, the need for portable and discreet penetration testing solutions has grown significantly. While devices like the Raspberry Pi or the Flipper Zero offer some level of portability, they often stand out as dedicated hacking tools. This is where Kali NetHunter emerges as a compelling alternative. NetHunter takes the core power and extensive toolset of Kali Linux and adapts it for Android devices, effectively turning a smartphone into a pocket-sized cyber deck. This innovation addresses the challenge of conducting security assessments in environments where a laptop or specialized hardware might be conspicuous or impractical.
The concept of leveraging mobile hardware for security operations isn't entirely new. Communities like WiGLE.net have long encouraged wardriving—the act of driving around to discover Wi-Fi networks—using mobile devices equipped with GPS and Wi-Fi scanning capabilities. NetHunter builds upon this by integrating a much broader range of offensive tools, enabling sophisticated attacks such as HID (Human Interface Device) injection, often associated with devices like the HackFive Bash Bunny or USB Rubber Ducky, directly from a phone. The problem NetHunter solves is providing a fully integrated, powerful, and relatively discreet platform that combines the ubiquity of smartphones with the extensive capabilities of Kali Linux.
Key Findings
▶ Watch: Ethical hacking reminder and Kali Linux overview (2:40)
Brayden Houston's presentation illuminated several key findings regarding the capabilities and implications of Kali NetHunter:
First, NetHunter effectively transforms an Android device into a full Kali Linux instance, running either alongside the Android operating system or as a dedicated Linux phone. This allows users to access the vast array of Kali tools directly from their mobile device, making it an incredibly portable and versatile platform for penetration testing.
Second, the talk detailed the different editions of NetHunter, each offering varying levels of hardware integration and functionality. The Custom Kernel edition provides the most comprehensive experience, granting full access to the device's hardware, including USB, modem, and cellular capabilities. The Standard edition allows Android and Kali to coexist, offering a balance between a functional smartphone and a pentesting tool. For those seeking a purely Linux experience, the Pro edition, exemplified by devices like the Pine Phone, runs a full Linux OS without Android, effectively turning the phone into a dedicated Linux computer.
Third, NetHunter brilliantly leverages the existing hardware of a smartphone. This includes the built-in Wi-Fi and Bluetooth modules for scanning, deauthing, and various attacks, as well as the device's battery for extended on-the-go operations. Furthermore, the platform supports the integration of USB peripherals, such as Software-Defined Radio (SDR) dongles or external Wi-Fi adapters, significantly expanding its capabilities for specialized tasks and monitoring different frequencies or channels.
Fourth, a significant advantage highlighted is the discretion and stealth offered by using a smartphone. Unlike more obvious hacking tools like Raspberry Pis or Flipper Zeros, a phone blends seamlessly into any environment, making it less likely to attract suspicion during security assessments. This "commonplace" appearance provides a tactical edge in various scenarios.
Fifth, Houston showcased a range of specific attack capabilities enabled by NetHunter. These include Bad USB attacks, where the phone emulates a keyboard or mouse for HID injection (similar to Ducky Script); Wi-Fi scanning and deauthing using tools like Wi-Fi Pumpkin to create rogue access points and captive portals; various Bluetooth attacks, including spamming; and even car hacking functionalities, which are a newer addition to the NetHunter suite.
Finally, the presentation touched upon alternative platforms like the Pine Phone, offering a native Linux phone experience, and the emergence of rootless options and Android developer tools (such as a full Demi instance on Pixel/Samsung devices). While these alternatives might have limitations compared to a fully rooted NetHunter installation, they indicate a broader trend towards bringing powerful Linux environments and security tools to mobile form factors.
Technical Deep Dive
▶ Watch: Introducing Kali NetHunter: Kali on your phone (3:37)
The technical foundation of Kali NetHunter lies in its ability to run a full Kali Linux environment on Android devices, offering varying degrees of hardware integration depending on the installation method and device support. The process typically begins with rooting the Android phone, which grants privileged access to the device's operating system, a prerequisite for most NetHunter installations. Following rooting, users proceed to image their device with a NetHunter-specific ROM, often based on a custom kernel for optimal performance and hardware access. Kali provides comprehensive documentation, including device-specific instructions and generic images, to guide users through this potentially complex process.
NetHunter offers distinct editions that cater to different user needs and device capabilities:
- Custom Kernel Edition: This is the most feature-rich version, requiring a device with specific kernel support. It provides full access to the device hardware, including the USB interface, modem, and cellular functionalities. This level of access is crucial for advanced attacks like HID injection (emulating a keyboard for arbitrary command execution) and comprehensive Wi-Fi monitoring and injection with external adapters.
- Standard Edition (or Light): This is the more common and widely supported option, where Kali Linux runs alongside the Android operating system. While it offers a robust Kali environment, it typically has less kernel support than the custom kernel version. This can lead to limitations, such as reduced Wi-Fi control, inability to fully control the USB interface for HID attacks, and potential issues with certain Bluetooth or car hacking functionalities. Despite these limitations, it still provides access to the CEX feature, Metasploit, and the NetHunter app.
- Pro Edition (Full Linux Phone): This edition transforms the device into a dedicated Linux phone, completely replacing Android. Devices like the Pine Phone are prime examples, running distributions like PostmarketOS with the NetHunter overlay. This offers a pure Linux experience, though often with its own set of quirks, such as battery optimization challenges, as noted by Houston regarding the Pine Phone.
Central to the NetHunter experience is the NetHunter app, an Android application that serves as a control panel for various Kali functionalities. This app allows users to quickly toggle settings, change USB modes (e.g., to act as a HID device or a network adapter), write and execute Ducky Scripts on the fly, and manage services. For instance, the app's USB Arsenal module provides an intuitive interface to switch the phone's USB role, enabling Bad USB attacks without needing to delve into the command line.
Another core feature is the CEX (Chroot Environment X) feature, which provides a virtual VNC desktop. This allows users to access a full Kali Linux graphical user interface (GUI) either directly on the phone's screen (via a VNC client app) or by connecting the phone to an external monitor with a Bluetooth mouse and keyboard, effectively creating a portable workstation.
The NetHunter App Store, a fork of F-Droid, comes pre-loaded with NetHunter installations. It offers a curated selection of security-focused Android applications, including custom keyboards, NFC tools, and other utilities that complement the Kali environment. While Metasploit is available, its full functionality, particularly database support, can be limited in versions without full kernel access.
Houston also highlighted how specific device hardware can be creatively integrated. For his OnePlus 6, which features a physical slider, he configured it to trigger scripts, such as initiating a WiGLE instance for wardriving or acting as a multi-stage toggle similar to a Bash Bunny. This demonstrates the potential for deep hardware customization.
For network-based attacks, tools like Wi-Fi Pumpkin are natively integrated. This module allows the NetHunter device to create rogue access points, impersonating legitimate networks or setting up open access points with captive portals. These portals can be designed to harvest credentials (e.g., a fake Facebook login page) or distribute malware, showcasing a potent phishing vector. The ability to deploy such sophisticated network attacks from a discreet mobile device significantly enhances the capabilities of a penetration tester.
The talk also briefly touched on rootless NetHunter options and emerging Android developer tools. While rootless installations offer limited features (e.g., virtual desktop, Metasploit without database, restricted file system access to the downloads folder), they represent an evolving landscape where some Kali-like functionalities might become accessible on unrooted devices, particularly with advancements like the full Demi instance on Pixel and Samsung phones running Android 16. This indicates a future where even more users might gain access to powerful mobile Linux environments, albeit with varying degrees of control and capability.
Demo / Proof of Concept
▶ Watch: NetHunter interface and turning your phone into a cyber deck (4:00)
During the talk, Brayden Houston demonstrated several key functionalities of Kali NetHunter, primarily focusing on the Android version running on his OnePlus 6, alongside a brief overview of the Pine Phone experience.
The initial demonstration involved a quick tour of the NetHunter app interface on his Android phone. This app serves as the central hub for managing various NetHunter modules and functionalities. He navigated through options like USB Arsenal, which allows changing the phone's USB mode. This module is critical for Bad USB attacks, enabling the phone to emulate a keyboard or other Human Interface Devices for HID injection. While he attempted to show a live change of the USB function, a minor technical glitch occurred, which he quickly recovered from.
The primary live demonstration focused on the Wi-Fi Pumpkin module. Houston initiated Wi-Fi Pumpkin from the NetHunter app, which configured his phone to create a rogue access point named "pumpkin." This access point was designed to present a captive portal, specifically a simulated Facebook login page, to any connecting clients. He encouraged audience members to connect to "pumpkin" (though explicitly advised against entering actual credentials), demonstrating the ease with which a malicious access point and credential phishing portal could be deployed in a public setting. He noted the quick response from audience members connecting, showcasing the effectiveness of such an attack in gathering potential victim data.
A planned demonstration of HID injection (Bad USB) using Ducky Script was unfortunately postponed due to the minor technical hiccup with the USB function toggle. However, Houston described its capabilities, explaining how the phone could simulate keyboard input to execute commands on a target system, much like a traditional USB Rubber Ducky. He offered to demonstrate this privately in the halls after the talk for those interested.
Earlier in the presentation, Houston also provided a screen recording of the Pine Phone running the NetHunter app. This showcased the NetHunter interface on a dedicated Linux phone, highlighting the Posh Shell desktop environment and the Hijacker app, another tool for Wi-Fi-based reconnaissance and analysis. This segment served to illustrate NetHunter's adaptability across different mobile Linux platforms, even if the Pine Phone experience was described as somewhat "quirky" and still under development.
Overall, the demonstrations, particularly the Wi-Fi Pumpkin setup, effectively conveyed the power and ease of deploying sophisticated network attacks using Kali NetHunter on a standard mobile device, reinforcing the talk's core message about portable penetration testing.
Defensive Implications
▶ Watch: Exploring advanced NetHunter attack capabilities: BadUSB, Wi-Fi, Bluetooth (5:58)
The capabilities showcased by Kali NetHunter carry significant defensive implications for individuals and organizations. The ease with which a common smartphone can be transformed into a potent attack tool necessitates a re-evaluation of security postures, particularly concerning mobile devices and network access.
Firstly, the prevalence of NetHunter-enabled devices means that physical security around sensitive systems and unattended workstations becomes even more critical. Bad USB attacks, where a phone can emulate a keyboard to inject malicious commands, can compromise systems within seconds if physical access is gained. Organizations should enforce strict policies regarding unattended devices, secure USB ports, and educate employees about the risks of plugging unknown devices into their computers.
Secondly, the demonstration of Wi-Fi Pumpkin highlights the threat of rogue access points and captive portal phishing. Defenders must implement robust network monitoring to detect unauthorized Wi-Fi access points operating within or near their premises. Enterprise Wi-Fi systems should ideally employ 802.1X authentication and strong encryption to prevent unauthorized connections. User education is paramount: employees should be trained to identify suspicious Wi-Fi networks and phishing attempts, especially those masquerading as legitimate login pages for common services like social media or corporate portals. They should be advised to always verify URLs and avoid entering credentials on unverified pages.
Thirdly, the ability to perform Wi-Fi deauthentication attacks and extensive Wi-Fi analysis from a mobile device underscores the importance of resilient wireless networks. Organizations should consider deploying Wireless Intrusion Detection/Prevention Systems (WIDS/WIPS) to detect and mitigate such attacks, ensuring the availability and integrity of their wireless infrastructure.
Fourth, the talk's emphasis on rooting phones for NetHunter installation brings to light the risks associated with Bring Your Own Device (BYOD) policies. Rooted devices inherently have compromised security models, making them more vulnerable to malware and data breaches. Employers should have clear BYOD policies that prohibit the use of rooted devices for accessing corporate resources or, at the very least, implement strong mobile device management (MDM) solutions that can detect and isolate rooted devices. Houston himself cautioned against using a rooted NetHunter phone as a daily driver or with an employer's BYOD policy.
Finally, the general concept of discreet mobile pentesting means that traditional security measures that rely on detecting obvious hacking hardware may be insufficient. Defenders need to shift towards more behavioral and network-level anomaly detection. This includes monitoring for unusual network traffic patterns, unauthorized device connections, and suspicious user activities that could indicate a compromise initiated by a subtle, phone-based attack. Regularly auditing network configurations and device security settings is also crucial to minimize the attack surface accessible to such portable tools.
Key Takeaways
- Kali NetHunter Transforms Android Devices: It converts standard Android smartphones and tablets into powerful, portable penetration testing platforms, leveraging existing mobile hardware.
- Versatile Attack Capabilities: NetHunter enables a wide array of offensive operations, including Bad USB (HID injection), Wi-Fi scanning and deauthing (e.g., Wi-Fi Pumpkin for rogue APs and phishing), Bluetooth attacks, and even car hacking.
- Multiple Editions for Diverse Needs: Users can choose between Custom Kernel (full hardware access), Standard (Android + Kali instance), and Pro (dedicated Linux phone) editions, each offering different levels of functionality and device support.
- Discreet and Portable: The use of a smartphone as a pentesting tool offers significant discretion compared to more specialized hardware, allowing for more covert security assessments on the go.
- Rooting Comes with Risks: Full NetHunter installation typically requires rooting the device, which can void warranties and introduce security vulnerabilities. It's not recommended for daily driver phones or devices used in BYOD corporate environments.
- Emerging Rootless Options: While full functionality is limited, new Android developer tools and rootless NetHunter versions are making some Kali-like capabilities accessible on unrooted Pixel and Samsung devices, indicating a future trend in mobile security tooling.
About the Speaker(s)
Brayden Houston is a CyberSecurity Engineer with a unique background, having recently transitioned into cybersecurity from a career as a software engineer. He describes himself as a "recovering software engineer," highlighting his fresh perspective and eagerness to learn in the cyber domain. Houston is an active member of the cybersecurity community, known online as @8bitfish on Discord and other social platforms.
Based out of Wisconsin, he is involved with several local groups, including DC 608, a growing DevCon group for which he is part of the team. Additionally, Brayden is a vital member of the Wisconsin Cyber Response Team (CRT), a volunteer, state-run initiative that operates in combination with CISA and the National Guard. This team responds to various cyber incidents affecting State, Local, Tribal (SLT) governments, municipalities, and schools across Wisconsin, providing crucial support and learning opportunities as he hones his cybersecurity skills. Outside of his professional life, Brayden enjoys tinkering in his home lab, automating systems, and recently completed his first marathon.