Wireless analysis, sub-GHz signal review, and controlled application security labs.
> Mission Dashboard
Current operator status, evidence routes, and fast access to the strongest portfolio areas.
URH-assisted packet comparison with rolling-code behavior documented.
Hardware gallery, RF audio conversion, wardriving screenshots, and video lab route.
Try terminal commands: reports, tools, contact,
open videos.
> Live Terminal Console
Type 'help' to see system flags. Try 'hack' or 'ctf' to test security controls.
> About Me
Welcome to my security portfolio. I focus on web application testing, network assessment, RF analysis, field reconnaissance, and vulnerability research. The work below is framed as controlled, legal, evidence-led security practice.
> Technical Skills
> Armed Toolkit & Weaponry
Operational proficiency profiles across standard industry security frameworks:
[+] Network & Infrastructure
[+] Web Application Security
[+] Radio Hacking & SDR
RF Signal Observations
| Signal | Source | Observed Frequency | Characteristics |
|---|---|---|---|
| Jammer 1 | LilyGO C1101 (Bruce) | ~890 MHz | Clean, low-power; consistent binary output. |
| Jammer 2 | ESP32-DIV 2 | ~890 MHz (Estimated) | High-noise, square-wave, dense signal patterns. |
| Signal 3 | Unknown Smart Doorbell | ~430 MHz | Clean, repeating patterns; high signal integrity. |
RF Recon Analysis: Sub-GHz Protocol Reverse Engineering
1. Executive Summary
This report documents the ongoing reverse-engineering process of an unidentified sub-GHz IoT device captured via the M5Stack Cardputer. The analysis was conducted using Universal Radio Hacker (URH) to demystify packet structure, modulation, and cryptographic properties.
2. Methodology
- Data Collection: Raw sub-GHz signals were captured in the field using the M5Stack Cardputer.
- Preprocessing: Captured files were imported into URH, where the Samples/Symbol and Threshold settings were calibrated to align the raw waveform with digital logic.
- Comparative Analysis: Multiple captures were grouped and processed using the Mark Diffs functionality to isolate static identifiers from dynamic payloads.
3. Technical Findings
- Protocol Classification: The signal was identified as a Rolling Code (Dynamic) Protocol. This conclusion is based on the observation that the entire packet structure exhibits bit-level variations across consecutive captures, indicating the presence of a sequence counter and encrypted payload.
- Packet Structure: The identified sequence (
d7 2aored cf) acts as the synchronization layer, signaling the receiver to initiate message processing. - Payload Dynamics: Comparison across multiple signals confirms that the protocol does not utilize static identification for the data transmission, necessitating cryptographic analysis for further deconstruction.
4. Observed Limitations
- The Mark Diffs tool highlighted the entire packet as variable, which precludes a simple replay attack.
- Current analysis indicates that the sequence counter and command data are likely encapsulated within an encrypted block, preventing immediate human-readable decoding without the underlying algorithm or master key.
RF Key Fob Signal: Audible Pitch Conversion
Raw RF key fob signal captured at ~433 MHz, converted and transposed to audible frequency range for pattern analysis and acoustic signature documentation. This audio representation reveals the underlying modulation structure and timing patterns that would otherwise be invisible to human perception.
[+] Physical Field Gear
New Device Inbound: ESP32-DIV Reconnaissance Platform
A new ESP32-DIV device is currently inbound, featuring enhanced recon capabilities for C1101 WiFi, Bluetooth, NF24 signals, and beyond. The DIV 2 variant was acquired but exhibits several firmware limitations: touch screen lag, off-target touch responsiveness, and broken SD card saving functionality. However, the DIV 1 platform supports installation of Hale Hound firmware, which provides critical bug fixes and signal amplification capabilities, making it the superior choice for sustained field operations.
> Wardriving
Wardriving captures, mapping, and signal reconnaissance with WiGLE integration and documented local scans.
This section documents recent wardriving activity, including signal mapping and GPS-tagged network discoveries. The badge below links to WiGLE, the wireless network mapping service used to visualize collected SSIDs, BSSIDs, and radio locations.
Wardriving Findings
Scanned local streets and parking areas for exposed wireless networks, recording both 2.4GHz and 5GHz SSIDs. The collected captures were later analyzed for weak security settings, open guest networks, and suspicious unauthorized access points.
Wardriving route capture with GPS annotation.
Detected wireless networks and channel heatmap.
> Operations Directory Logs
[+] Tactical Briefing: All field reconnaissance activities were conducted ethically through legal passive observation and analysis in public spaces. Select an operation module profile below to review text logs and engineering briefs across different engagement disciplines:
[+] Operations Disclaimer: All field reconnaissance activities were conducted ethically through legal passive observation and analysis in public spaces.
[Field Operation] Investigation of Anomalous Rogue AP Network
Detecting, profiling, and analyzing an evasive wireless access point observed in a public transit sector through passive observation.
[+] Field Intel Summary:
1. Public Transit Area Reconnaissance
Passive observation conducted using a mobile device with standard security configurations. The gateway presented a simplified captive portal login page — test inputs returned submission failures, suggesting suspicious authentication-handling logic (without confirming any specific purpose or outcome).
2. Hardware Reconnaissance & RF Auditing
Deployed an M5Stack Cardputer running EvilM5 / Bruce firmware alongside a LilyGO T-Display-S3 running Bruce firmware to observe and map the wireless infrastructure. Observed an isolated topology with 0 other connected hosts; passive port sweeps returned closed/filtered states.
3. Observed Behavioural Patterns
MAC profiling suggests the node may be a Hak5 Wi-Fi Pineapple or custom ESP32-based framework. The access point was observed entering a dormant state after approximately 3 minutes of monitoring, followed by a total SSID disappearance until the following day — consistent with an evasive or low-observability configuration.
4. Assessment Conclusion
After extended passive reconnaissance of this access point, further investigation was paused. The login mechanism appeared unreliable for any meaningful analysis, and the high-traffic nature of the area meant most users were observed connecting via mobile data rather than open Wi-Fi. This operation was concluded and documented for educational reference.
[Field Operation] Detection & Profiling of Anomalous Wireless Surveillance Assets
Passive RF observation to identify and profile unexpected wireless devices in a public retail environment.
[+] Passive Observation Briefing:
1. Signature Profiling & Hardware Limitations
An anomalous wireless signature was observed near a large retail parking area. Passive scanning was conducted using an M5Stack Cardputer running EvilM5. The device exhibited a low duty cycle with aggressive power-saving sleep configurations, consistent with a compact wireless camera module architecture.
2. Traffic Analysis & Verification
By shifting focus to hidden ad-hoc infrastructure networks, the node footprint was isolated through passive observation. The device was observed broadcasting status frames over the 2.4GHz spectrum, consistent with a localized receiver application expecting to pull video feeds.
[bWAPP] Web App Vulnerability Lab
Demonstrating denial-of-service vectors and system breaches on local bWAPP servers.
[+] Exploitation Log Summary:
Successfully executed localized application layer stress assessments, profiling threshold constraints, session token vulnerabilities, and authentication bypass behaviors inside unhardened testing sandboxes.
[PCAP] Phase 1 & 2 Network Analysis
Analyzing network captures to isolate command-and-control communication channels.
[+] Forensics Packet Brief:
Filtered traffic strings to trace suspicious reverse-connection style network hooks. Isolated obfuscated TCP payload handshakes communicating outwards to an external listening gateway server (details intentionally kept non-specific for safety).
[PCAP] Wireless Environment Reconnaissance: Public Transit Hub
Raw wireless packet capture analysis of enterprise-grade infrastructure in a public transit hub.
[+] Wireless Environment Reconnaissance Report: Public Transit Hub
Privacy & Data Handling Note: The wireless capture details shown here were sanitized for publication: sensitive identifiers (e.g., SSIDs/BSSIDs and related labels) may be AI-rephrased or replaced with non-real placeholders to avoid exposing real-world networks.
Executive Summary
This report summarizes the analysis of wireless network beacon and probe frames captured while stationed at a public transit hub. The objective was to practice capturing raw wireless packets in a public, high-traffic environment for later offline analysis in Wireshark. The capture, consisting of 4,872 packets, identifies a managed wireless infrastructure characterized by enterprise-grade security and localized segment isolation.
1. Infrastructure Overview
The wireless environment at the location is primarily supported by Huawei Technologies and Hewlett Packard infrastructure, with a total of 50 unique devices identified as active participants in the broadcast layer.
Network Segmentation: The infrastructure utilizes multiple SSIDs to segment traffic, indicating a managed environment likely deployed for a multi-tenant or campus facility. The observed network segments include:
- Managed Enterprise Networks: "CORP-GUEST", "STAFF-SECURE (802.1x)", "ENTERPRISE-WIFI".
- IoT & Specialized Segments: "IOT-DEVICES-2.4G", "INTERNET-ONLY", "RESTRICTED", "SENSOR-SWARM".
- Standalone/Other Devices: "CLIENT-DEVICE-A", "CLIENT-DEVICE-B".
2. Infrastructure Inventory
The environment is dominated by two primary vendors, suggesting a tiered hardware deployment strategy.
| Vendor | Packet Count | Observation |
|---|---|---|
| Huawei | 3,592 | Core infrastructure provider. |
| HP | 1,066 | Secondary infrastructure/access points. |
| Other | 211 | Includes localized/randomized devices. |
| Edup | 3 | Client-side hardware (e.g., adapters). |
3. Key Findings & Observations
- Security Posture: The enterprise wireless network employs enterprise-grade authentication (802.1X/EAP), requiring RADIUS-based authentication.
- Anomalous Behavior: Probe requests were observed broadcasting an anomalous or non-standard (null-like) SSID, which can be indicative of misconfigured hardware, SDR activity, or hidden network probing.
- Client Behavior: Various consumer IoT device types were visible via metadata labels, indicating normal device presence within the public environment.
4. Recommendations
- Monitor Anomaly Sources: Further investigation is recommended for devices using locally administered MAC addresses (starting with 0x42/0x46/0x4A/0x4E) to determine if these are authorized specialized devices or potential rogue hardware.
- Verify Security Policies: Conduct an audit to ensure that networks labeled "Restricted" enforce Privacy flags correctly, confirming encryption is required for all connected clients.
- Baseline IoT Traffic: Given the presence of consumer IoT devices, ensure these are isolated from the enterprise/staff segments to prevent lateral movement risks.
5. Applied Wireshark Filters
The following display filters were utilized throughout the reconnaissance process:
- General Beacon Filter:
wlan.fc.type_subtype == 0x08 - Probe Request Filter:
wlan.fc.type_subtype == 0x04 - Hidden SSID Probes:
wlan.fc.type_subtype == 0x04 && wlan.ssid == "" - Enterprise (802.1X) Traffic:
wlan.rsn.akm.type == 1 - Vendor Specific Tag Search:
wlan.tag.number == 221 - Anomalous/Null SSID Filter:
wlan.ssid == "000000000000000000000000000000000000000000"
Device used: Cardputer with EVILM5 firmware
> CTFs & Exploitation Video Gallery
The video gallery has moved to /videos.
Visual documentation of operational equipment and hardware assets. Click any image to enlarge.
LEAFOSEC Logo
M5Stack Cardputer
LilyGO T-Display (Bruce)
M5Stack Core2 (EvilM5)
Radio Hacking Hardware Unit 1
Radio Hacking Hardware Unit 2
RF Recon Analysis: Sub-GHz Protocol
ESP32-DIV Reconnaissance Platform