Browse by domain.
A NEW tag marks what’s new in v2.1.
WiFi Suite
2.4 & 5 GHz testing, capture, and monitoring.
- Deauth, beacon spam & karma
- Evil portal with custom HTML
- WPA3 / SAE testing + compliance checker
- PCAP, PMKID & hc22000 export · live Wireshark over USB
- WiFi airspace monitor: deauth fingerprinting, evil twins & Karma v2.1
- Packet Visualizer & channel congestion charts v2.1
- Recon: ARP · mDNS · NetBIOS · SSH · SNMP · HTTP banner
- SMB/NetBIOS enumeration & SNMP MIB walk v2.1
- GPS wardriving & WiGLE export
Bluetooth LE
Scan, capture, and spoof BLE devices.
- BLE scan & raw scanner
- Device spam modes
- AirTag scan / spoof · Flipper Zero finder
- GATT enumeration · device tracking (live RSSI)
- BLE → Wireshark · skimmer & Flock detection
- BLE wardriving & WiGLE export
- Drone / OpenDroneID scan, track & spoof
- GhostLink BLE bridge to Android app
NFC & Infrared
Read, write, and replay NFC and IR signals.
- PN532 & ST25R3916 · Chameleon Ultra (BLE control)
- NTAG read/write · MIFARE dictionary + nested recovery
- EMV payment-card reading v2.1
- DESFire tree reads · PicoPass / iCLASS · NDEF creation v2.1
- Opal, myki, ITSO & Gallagher card parsers v2.1
- Flipper
.nfcimport/export & parser collection - IR learn / capture / replay · all Flipper IR protocols TX
- Universal IR library · Flipper
.irsupport · IR dazzler
SubGHz & RF
Analyze, capture, and replay across the bands.
- CC1101 scan / replay · 315–915 MHz
- Waterfall spectrum analyzer
- 20+ protocol decoders · Flipper
.sub - NRF24 spectrum analyzer & sniff
- Zigbee / 802.15.4 capture
- Passive jamming detection · GhostLink remote radio
Network & Ethernet
Wired attacks and live traffic interception.
- Ethernet / W5500
- ARP poisoning & MITM tools
- Fingerprint, port, ping, DNS, NTP & trace tools
- DNS intercept / sinkhole (NXDOMAIN)
- Credential capture: TLS SNI · HTTP · FTP
- DIAL / Chromecast · network printer (PJL)
- Camera streaming & Discord motion alerts
BadUSB & HID
HID payloads and host-side control.
- BadUSB / DuckyScript
- VID/PID identity options
- USB keyboard host mode
- USB HID keyboard output
- Trackpad cursor & mouse jiggler
- type_char CLI & dedicated WebUI page
Platform & UI
Control, extend, and theme the whole device.
- LVGL UI · 60 FPS · 17+ themes ·
.gthemeasset packs - Carousel, grid & list layouts with paginated nav
- Cloud Store: install apps, scripts & packs on-device v2.1
- GhostScript: sandboxed Lua runtime on SD v2.1
- Native SD apps:
.gapp, App Gallery, gbt SDK, XIP on C5 - OTA Wi-Fi firmware updates with rollback protection v2.1
- Ghostchi: 50 levels, 27 XP sources & moods
- PIN lockscreen & setup wizard
- GhostLink dual-ESP · Android app · Flipper companion
Watch it work.
Third-party video demos of GhostESP hardware and firmware. Demos cover the authors' own hardware; the authorized-use rules apply.
The Wired Hatter's Banshee
Walkthrough of the dual-ESP32 Banshee device: second-radio operation and GhostLink communication.
Dual ESP32 /// 5 GHz
5GHz deauth on ESP32-C5
5 GHz deauthentication test with the ESP32-C5 on a lab network, with full capture.
5 GHz /// ESP32-C5
Deauthenticating a test camera
GhostESP and Flipper Zero deauthenticating a camera from a lab 2.4 GHz network.
Flipper /// 2.4 GHz
T-Watch S3: bootloader to flash
Entering bootloader mode and flashing GhostESP on the LilyGo T-Watch S3.
Tutorial /// T-Watch S3
Dual communication
How two ESP32s coordinate over GhostLink, and which setups use the second radio.
GhostLink /// Dual-ESP