wireless-rf

Featured

Use when the target has a non-Wi-Fi radio attack surface — Bluetooth/BLE (GATT, pairing, KNOB/BIAS/BleedingTooth), Zigbee/Thread/Matter & Z-Wave mesh (Touchlink, S0 downgrade), LoRaWAN/Sub-GHz LPWAN, SDR capture/replay/rolljam, smart locks/medical/IoT radios. For Wi-Fi/WPA/evil-twin see network-attack.

AI & Automation 382 stars 66 forks Updated 5 days ago MIT

Install

View on GitHub

Quality Score: 95/100

Stars 20%
86
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Wireless / RF (non-Wi-Fi radio) Radio attack surface **beyond Wi-Fi**: Bluetooth (BLE + Classic), 802.15.4 mesh (Zigbee/Thread/Matter), Z-Wave, and LPWAN/Sub-GHz (LoRaWAN, ISM rolling-code / OOK-ASK). For Wi-Fi, WPA2/WPA3, evil-twin and 802.1X, use `network-attack` (`references/wireless-attacks.md`, which also now carries KRACK/FragAttacks and WPS). Adapted in part from Claude-Red (MIT, Kai Aizen/SnailSploit) — see `THIRD-PARTY-NOTICES.md`. ## When to Activate - Auditing a **BLE** device (smart lock, wearable, medical, tracker): GATT enumeration, unauthenticated characteristic R/W, pairing-mode identification, LTK recovery, sniffing, companion-app RE. - **Bluetooth Classic** targets: encryption-key entropy downgrade (KNOB), impersonation (BIAS), BlueZ/stack memory-corruption (BlueBorne / BleedingTooth). - **Zigbee / Thread / Matter / Z-Wave** home/building automation: Touchlink commissioning abuse, key transport in the clear, S0 key-exchange downgrade, replay/AiTM on mesh commands. - **LoRaWAN / Sub-GHz**: join-accept / uplink replay, ABP counter & nonce reuse, and generic ISM capture→replay / rolljam of OOK-ASK remotes (garage, gate, some auto keyfobs). - You have (or can request) the right radio: a dual-mode BT adapter + BLE sniffer (Sniffle/Ubertooth), a KillerBee-supported 802.15.4 stick, an RfCat dongle (CC1111), and/or an SDR (RTL-SDR, HackRF). - **STOP if the RF target or its band is out of scope.** RF is trivially cross-boundary (you will hear neighbo...

Details

Author
hypnguyen1209
Repository
hypnguyen1209/offensive-claude
Created
4 months ago
Last Updated
5 days ago
Language
Python
License
MIT

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Featured

offensive-lorawan-sub-ghz

LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz protocol replay (KeeLoq garage doors, fixed-code remotes, TPMS spoofing, smart plug telemetry), HackRF / RTL-SDR / Flipper Zero workflows, signal analysis with Inspectrum / Universal Radio Hacker, and reconstruction of proprietary packet formats. Use for LoRaWAN deployments (smart cities, asset tracking, industrial telemetry), or any wireless device using the unlicensed 433/868/915 MHz bands (garage openers, doorbells, IoT sensors, RC equipment).

719 Updated 1 months ago
0xwilliamortiz
AI & Automation Featured

offensive-lorawan-sub-ghz

LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz protocol replay (KeeLoq garage doors, fixed-code remotes, TPMS spoofing, smart plug telemetry), HackRF / RTL-SDR / Flipper Zero workflows, signal analysis with Inspectrum / Universal Radio Hacker, and reconstruction of proprietary packet formats. Use for LoRaWAN deployments (smart cities, asset tracking, industrial telemetry), or any wireless device using the unlicensed 433/868/915 MHz bands (garage openers, doorbells, IoT sensors, RC equipment).

6,950 Updated 6 days ago
SnailSploit
AI & Automation Featured

network-attack

Use when attacking a network or moving laterally — L2/L3 poisoning (LLMNR/mDNS, ARP/DHCP, mitm6), coercion + NTLM relay (CVE-2025-33073), TUN pivoting (Ligolo-ng/Chisel), MitM, network-service RCE (CVE-2024-38077), WPA2/WPA3 wireless

382 Updated 5 days ago
hypnguyen1209