
Specter-FlipperZero v2.7
Specter — passive 13.56 MHz NFC reader/skimmer bug-sweep for Flipper Zero. Counter-surveillance EMF meter using the onboard NFC chip. No extra hardware, never transmits.
The waveform is not a graphic. It is 128 columns of 13.56 MHz carrier that Specter recorded off a real polling reader at 8 ms per column, read back out of the screenshot beside it. Its duty measures 28% where the device's own counter printed 27%, and both numbers are on the banner.
Sweep for the readers you can't see.
Project site · Download · Changelog
Specter turns your Flipper Zero into a pocket counter-surveillance bug-sweep for active 13.56 MHz NFC readers. It passively listens for the RF field that a powered-on reader is constantly emitting — a hidden card skimmer slipped into a payment terminal, a covert reader behind a door panel, a rogue logger taped under a desk — then tells you where it is, what kind of thing it is, whether the room is clean, and — left on watch — the moment one appears while you're away. It never transmits.
The readers are invisible. Specter makes them visible.
As featured in
Help Net Security
·
Cyber Security News
On the Flipper
A sweep, start to finish: quiet room → closing in → locked on → what it is → the room's verdict.
The screens no single mode owns
The quiet states and the intro — the four modes below each carry their own
capture, so these are the ones they do not. Every image
in this README is a capture off a real device, taken over the Flipper's
own RPC session by tools_screenshot.py. There is no mockup
renderer in this project any more — a drawing of the UI is a second
implementation of it, and it disagreed with the firmware while looking
perfectly convincing (see 3.0.1).
The five modes
Specter is five tools around one sensor. Each answers a different question, so the right one depends on what you are actually trying to find out:
| Mode | The question it answers | Use it when |
|---|---|---|
| Sweep | Where is it? | You suspect a device and want to pinpoint it by moving around |
| Fingerprint | What kind of thing is it? | You have found an emitter and want to know how it behaves |
| Site Survey | Is this room clean? | You want one verdict for a whole space, hands-free |
| Watch Mode | Did one appear while I was away? | You are leaving the Flipper somewhere to stand guard |
| Logbook | What did I find, and when? | You are writing it up, or comparing today with last week — filter by finding type |
Sweep — where is it?
What it does. A live EMF-style meter. Hold the Flipper flat and move it slowly over the thing you're checking — a card terminal, a door reader, the underside of an ATM lip, a parcel, a desk. The needle rides the field strength in real time.
What you see.
- The dial — needle = live reading, the small dot = peak-hold (the strongest spot you've touched, so you can compare positions).
FIELD %— the same reading as a number, with a ▲ / ▼ trend arrow telling you whether the last half-second made things warmer or colder. When you're hunting, that arrow matters more than the number.PEAK %— the strongest reading since you armed, the number behind the peak-hold dot.- The mark across the dial — where
READERbegins at your current sensitivity. Everything past it is what Specter will call a hit, so the dial answers "what counts?" instead of leaving you to guess. - Bottom strip — until you've found your first reader it carries the two keys
you can't discover by pressing things (
LEFT=cal,hold OK=log); after that, your sensitivity and a live waveform. It flips to a black● ACTIVE READERalarm bar with a proximity word the moment a carrier is detected. - Proximity —
FAINT → NEAR → CLOSE → STRONG → PEGGED.PEGGEDmeans the meter is pegged: you're as close as this measurement can resolve.