What monitor mode does and why you need it
Monitor mode lets your network card listen to all wireless traffic in range, not just packets meant for your device. In normal mode, your card ignores traffic between other devices. In monitor mode, it captures everything — which is why it's the foundation for wireless security testing in Kali Linux.
When you enable monitor mode, your card stops connecting to Wi-Fi networks and becomes a passive listener. This is essential for tools like Wireshark (packet capture), Aircrack-ng (password cracking), and Airodump-ng (network discovery). Without monitor mode, these tools cannot see the traffic they need to analyze.
Not all network cards support monitor mode. Older cards, built-in laptop adapters, and some USB dongles lack the hardware capability. Before you start, you need to know whether your card can do this.
Key Takeaways
- Monitor mode is enabled through the airmon-ng tool in Kali, which puts your wireless card into a listening-only state that captures all nearby traffic.
- You must first check whether your network card supports monitor mode using the iwconfig command or airmon-ng check output.
- Enabling monitor mode requires stopping network services (usually via airmon-ng check kill) so your card is not trying to connect to networks while listening.
- Monitor mode creates a new virtual interface (usually named mon0 or wlan0mon) that you use with security testing tools instead of your original adapter.
- You disable monitor mode by stopping the virtual interface and restarting your network services, returning your card to normal operation.
Check whether your card supports monitor mode
Open a terminal and run iwconfig to see your network adapters and their current capabilities:
iwconfig
Look for a line that says "Mode:Managed" or "Mode:Monitor" next to your wireless interface name (usually wlan0, wlp3s0, or similar). If you see "Mode:Managed", your card can switch modes. If iwconfig does not list your wireless card at all, it may not be recognized by the system.
A more direct test is to run airmon-ng, which is Kali's tool for managing monitor mode. Type:
sudo airmon-ng
This shows all wireless interfaces Kali detects. If your card appears in the list, it likely supports monitor mode. If nothing appears, your card either is not installed, not recognized, or does not support the feature.
Stop conflicting network services
Before switching to monitor mode, you must stop services that try to manage your network connection. These services will interfere with monitor mode and may cause the switch to fail or revert automatically.
Run:
sudo airmon-ng check kill
This command stops NetworkManager, wpa_supplicant, and other services that would conflict. On some systems, it may also kill your SSH connection if you are working remotely — be aware of this before running it.
If you prefer to stop services manually instead, you can disable NetworkManager with sudo systemctl stop NetworkManager and wpa_supplicant with sudo systemctl stop wpa_supplicant. The airmon-ng check kill method is faster and more reliable.
Enable monitor mode with airmon-ng
Now enable monitor mode on your wireless interface. Replace wlan0 with your actual interface name if it is different:
sudo airmon-ng start wlan0
Kali will output something like "monitor mode enabled on wlan0mon" or "monitor mode enabled on mon0". The exact name depends on your system and driver. This new interface name is what you use for packet capture and network testing.
Verify the switch worked by running iwconfig again:
iwconfig
You should now see "Mode:Monitor" next to your new interface (mon0, wlan0mon, or similar). Your original interface (wlan0) may disappear from the list or show as down — this is normal.
Use monitor mode with security testing tools
Once monitor mode is active, you can use it with Kali's wireless testing tools. The most common starting point is airodump-ng, which lists all Wi-Fi networks in range:
sudo airodump-ng mon0
Replace mon0 with your actual monitor mode interface name. You will see a table of networks with SSID, BSSID (MAC address), channel, signal strength, and connected clients.
Other tools that require monitor mode include Wireshark (for packet inspection), Aircrack-ng (for password recovery), and Kismet (for network mapping). All of them use the same monitor mode interface you just created.
Disable monitor mode and restore normal networking
When you are finished testing, disable monitor mode to return your card to normal operation:
sudo airmon-ng stop mon0
Replace mon0 with your actual monitor mode interface name. This stops the virtual interface and restores your original adapter.
Restart the network services you stopped earlier:
sudo systemctl start NetworkManager
Or, if you used airmon-ng check kill, you can restart everything at once by rebooting. After a few seconds, your network manager should reconnect to your saved Wi-Fi networks automatically.
Troubleshooting common problems
If airmon-ng start fails or says "monitor mode enabled" but iwconfig still shows "Mode:Managed", your driver may not support monitor mode properly. Some Broadcom, Realtek, and Intel cards have incomplete driver support in Linux. Check the Kali Linux documentation for your specific card model — you may need to install a different driver or use an external USB adapter.
If monitor mode enables but you see no networks in airodump-ng, make sure you are scanning the correct channel range. By default, airodump-ng scans 2.4 GHz channels. Add the -b a flag to scan 5 GHz networks instead: sudo airodump-ng -b a mon0. Also check that your antenna is not physically disabled (some laptops have a hardware switch or BIOS setting).
If your monitor mode interface disappears after a few minutes, a background service is probably killing it. Run sudo airmon-ng check to see what services are still running, then stop them manually with systemctl.
Frequently Asked Questions
Can I use monitor mode on a built-in laptop Wi-Fi card?
Some built-in cards support it, but many do not. Intel and Qualcomm cards often lack full driver support in Linux. The easiest solution is a USB wireless adapter designed for Kali — brands like Alfa, TP-Link, and Ralink are known to work well. Check the Kali documentation for your specific card before buying.
Do I need to be root to enable monitor mode?
Yes, all airmon-ng commands require sudo. You cannot enable monitor mode as a regular user. If you are running Kali in a virtual machine, make sure your hypervisor has passed the USB adapter through to the guest OS, or monitor mode will not work.
Will monitor mode work on a 5 GHz network?
Yes, but your card must support 5 GHz channels. Most modern adapters do. When you run airodump-ng, add the -b a flag to scan 5 GHz networks: sudo airodump-ng -b a mon0. Some cards can scan both 2.4 and 5 GHz simultaneously if you create multiple monitor mode interfaces.
What happens to my internet connection when I enable monitor mode?
You lose internet access on that wireless card because it stops connecting to networks. If you have a second network adapter (Ethernet, second Wi-Fi card, or USB adapter), you can keep internet on that while using monitor mode on the other. This is useful for uploading test results or downloading tools while testing.
Can I switch back to normal mode without rebooting?
Yes. Run sudo airmon-ng stop mon0 to disable monitor mode, then restart NetworkManager with sudo systemctl start NetworkManager. Your card will reconnect to saved networks within a few seconds. You do not need to reboot unless something goes wrong.