← Back to Help
WarpedWing Labs

Wi-Fi / Network Report Generator

This module parses macOS Wi-Fi and network artifacts to generate an HTML report summarizing network activity.

Disclaimer

This report is for informational and investigative purposes only. The data presented should be independently verified before being relied upon for any legal, regulatory, or evidentiary purpose.

Limitations

Report Sections

Known Networks

Displays Wi-Fi networks the device has connected to, extracted from:

Shows SSID, BSSID, security type, first/last connection times, and auto-join settings.

BSSID Activity

Aggregates BSSID (access point MAC address) sightings across all parsed sources. Includes vendor lookup from OUI database, signal strength (RSSI), and channel/band information where available.

BSSID Cross-References

Cross-references BSSIDs found in multiple sources (logs, plists, DHCP leases) to identify consistent network associations.

Wi-Fi Log Activity

Events extracted from traditional Wi-Fi log files (/var/log/wifi.log and rotated variants). Note: Modern macOS increasingly uses unified logging, which is not parsed by this module.

Scan Burst Summary

Groups Wi-Fi scanning events that occurred in rapid succession, which may indicate device wake events, location changes, or active network searching.

Daily Presence Rollup

When DHCP lease data is available, summarizes daily network presence by correlating lease timestamps with Wi-Fi events.

Sightings Around Leases

Shows Wi-Fi events that occurred near DHCP lease acquisition times, helping correlate network connections with specific access points.

DHCP Leases

Parses DHCP lease plists from /var/db/dhcpclient/leases/ showing IP address assignments, lease durations, and router information.

Interfaces & Service Mapping

Network interface configuration from NetworkInterfaces.plist, showing hardware addresses and interface types.

Wi-Fi Message Tracer Metrics

Parses com.apple.wifi.message-tracer.plist for aggregate Wi-Fi statistics and metrics.

Network Locations Map

When geographic data is available (from CoreLocation caches or similar), displays an interactive map of network locations.

Data Sources

Artifact Path Pattern macOS Versions
Airport Preferences com.apple.airport.preferences.plist 10.6 - 10.15
Known Networks (Modern) com.apple.wifi.known-networks.plist 11.0+
Wi-Fi Message Tracer com.apple.wifi.message-tracer.plist Various
DHCP Leases /var/db/dhcpclient/leases/* All
Network Interfaces NetworkInterfaces.plist All
Network Preferences preferences.plist All
EAPOL Client com.apple.eapolclient.plist All
Wi-Fi Logs /var/log/wifi.log* Pre-10.12 (legacy)

Not Currently Parsed

Output Files

File Provenance

The wifi_summary.json output includes a file_provenance array with cryptographic hashes and metadata for all parsed source files:

{
  "file_provenance": [
    {
      "path": "/path/to/com.apple.wifi.known-networks.plist",
      "sha256": "abc123...",
      "size_bytes": 12345,
      "mtime_iso": "2024-03-15T10:23:45+00:00"
    }
  ]
}

This enables verification that source files have not been modified since analysis. The SHA256 hash can be compared against known-good values or chain-of-custody records.