AirTag Scanner
Passive / detectDetects Apple AirTags and other FindMy BLE trackers nearby, to surface possible stalking devices.
49 community and in-house builds, grouped by what they actually do. Flash any of them over USB from the app, then drive it from the same screen. There is also a Custom slot for your own .bin.
Detects Apple AirTags and other FindMy BLE trackers nearby, to surface possible stalking devices.
Passive multiprotocol RF sniffer (802.15.4/Zigbee/Thread, BLE, sub-GHz) with live Wireshark capture.
Counter-surveillance detector. Flags devices that keep reappearing near you over time.
Passive BLE advertisement logger. Records name, MAC, vendor and RSSI to SD. Receive only.
Passive dual-band WiFi and BLE wardriver. Logs to SD in WiGLE format.
Passively detects Flock Safety ALPR cameras by the beacons they emit.
Passive Zigbee and Thread (802.15.4) capture into Wireshark.
Fingerprints nearby WiFi and BLE devices by manufacturer (OUI) prefix.
IMSI-catcher and stingray detector that runs on an Orbic LTE hotspot.
Passively listens for WiFi Remote-ID broadcasts to spot nearby drones.
Passively decodes WiFi Remote-ID broadcasts from nearby drones; can relay detections over Meshtastic.
Espressif’s official AT-command WiFi and BT modem firmware. No attack surface.
Lean MeshCore-compatible mesh for T-Deck and T-Watch: encrypted channels, GPS share, SOS.
Hybrid flood and routed LoRa mesh, companion role.
The popular off-grid LoRa mesh networking firmware.
Turns an ESP32 LoRa board into a Reticulum (RNS) radio interface.
Reticulum LoRa transport for nRF52840 LoRa boards.
Zigbee 3.x coordinator and router firmware for TI CC2652/CC1352 dongles.
Handheld multi-tool for WiFi, BLE, IR, sub-GHz and RFID/NFC.
BW16 dual-band Vampire Deauther firmware with an AT+ serial CLI.
Bus-Pirate-style hardware hacking across I2C, UART, SPI, 1-Wire, BLE, WiFi, sub-GHz and RFID.
The well-known WiFi and BLE security firmware for the ESP32.
WiFi attack and recon toolkit: deauth, PMKID and WPA handshake capture, PCAP export.
WiFi, BLE and 2.4 GHz pen-test multi-tool: scan, sniff, analyze.
Spacehuhn’s classic WiFi testing tool: scan, deauth, beacon and probe spam.
Momentum custom firmware for the Flipper Zero.
RogueMaster custom firmware for the Flipper Zero.
Unleashed custom firmware for the Flipper Zero.
Lightweight WiFi and BLE scanning, monitoring and deauth firmware.
Multi-protocol IoT toolkit for CYD touchscreen boards: WiFi, BLE, sub-GHz, 2.4 GHz, NFC.
WiFi recon and deauth toolkit for the ESP32 DevKit.
The full Kali Linux pentest distro, pre-built for Raspberry Pi and other ARM boards.
LxveLabs’ own security-panel OS: passive recon, defensive detectors and an arm-gated offensive set.
Pwnagotchi-style passive handshake collector for M5Stack devices.
M5Cardputer packet-sniffer and pentest-game firmware.
M5Stack multi-tool: WiFi and BLE recon, IR, sub-GHz, RF and BadUSB.
Pwnagotchi-style handshake collector. Needs a dual-core ESP32.
Sub-GHz (CC1101) receive and transmit firmware for the LilyGo T-Embed. Authorized use only.
HackRF and PortaPack SDR firmware: ADS-B, POCSAG, TPMS, spectrum recon and more.
Raspberry Pi WiFi AI that roams and collects WPA handshakes.
Raspberry Pi network-attack toolkit with an LCD HAT menu: MITM, responder, nmap.
BLE 4.x and 5.x link-layer sniffer for TI CC13xx/CC26xx, with Wireshark relay.
Pocket pentest terminal for the LilyGo T-Deck: WiFi, BLE, recon and BadUSB.
Multi-protocol research firmware (BLE, Zigbee, ESB, Unifying, Mosart, ANT), host-driven.
WiFi-controlled BadUSB and keystroke-injection tool.
The BW16 controller half of the BlueJammer-V2 study rig.
The ESP32 engine half of the BlueJammer-V2 study rig (drives nRF24 radios).
LxveLabs in-house 2.4 GHz RF disruption instrument. Boots idle; a two-factor arm is required before any transmit.
A 2.4 GHz nRF24 noise study rig. No serial control; it transmits on power-up, so the app cannot drive it.