
Predatory ESP32 Firmware

Bruce is a versatile ESP32 firmware packed with offensive-security tools, built to make Red Team operations fast and portable.
It also supports M5Stack, LILYGO , RockBase IoT and Elecrow products, and works great with the Cardputer, Sticks, M5Cores, T-Decks and T-Embeds.
RF REAPER is our custom PCB devkit, purpose-built for Bruce!
Every major feature works natively, right out of the box. Sub-GHz, NFC/RFID, IR, 2.4GHz(NRF), GPS-ready, and a microSD, all driven by a beefy ESP32-S3 (16MB Flash / 8MB PSRAM). Tons of GPIOs via the AW9523 expander plus Flipper Zero & iButton header compatibility mean you can hack, mod, and build on it endlessly. Want a specific function? Ask us with an issue, we'll check it.
👉 Buy the RF REAPER and official boards
Check our fully open-source hardware too: https://bruce.computer/boards
More custom devkit boards coming soon! Stay across our communities!
Alternatively, you can download the latest binary from releases or actions and flash locally using esptool.py
esptool.py --port /dev/ttyACM0 write_flash 0x00000 Bruce-<device>.bin
For m5stack devices
If you already use M5Launcher to manage your m5stack device, you can install it with OTA
Or you can burn it directly from the m5burner tool, just search for 'Bruce' (My official builds will be uploaded by "owner" and have photos.) on the device category you want to and click on burn
Contact us in our Discord Server!
For more information on each function supported by Bruce, read our wiki here. Also, read our FAQ
LITE_VERSION: TelNet, SSH, WireGuard, ScanHosts, RawSniffer, Brucegotchi, BLEBacon, BLEScan and Interpreter are NOT available for M5Launcher Compatibility
Bruce stems from a keen observation within the community focused on devices like Flipper Zero. While these devices offered a glimpse into the world of offensive security, there was a palpable sense that something more could be achieved without being that overpriced, particularly with the robust and modular hardware ecosystem provided by ESP32 Devices, Lilygo and M5Stack products.

Other media can be found here.
Bruce also stands on the shoulders of other great open-source firmware projects, which inspired features and code across the project:
Bruce builds on many free-software libraries, and parts of the RF and NFC/RFID modules are derived from other projects. See THIRD_PARTY.md for third-party attribution and copyleft-compliance details.
Bruce is a tool for cyber offensive and red team operations, distributed under the terms of the Affero General Public License (AGPL). It is intended for legal and authorized security testing purposes only. Use of this software for any malicious or unauthorized activities is strictly prohibited. By downloading, installing, or using Bruce, you agree to comply with all applicable laws and regulations. This software is provided free of charge, and we do not accept payments for copies or modifications. The developers of Bruce assume no liability for any misuse of the software. Use at your own risk.
| Device | CC1101 | NRF24 | FM Radio | PN532 | Mic | BadUSB | RGB Led | Speaker | Fuel Gauge | LITE_VERSION |
|---|
| M5Stack Cardputer (and ADV) | 🆗 | 🆗 | 🆗 | 🆗 | 🆗 | 🆗 | 🆗 | NS4168 | ❌ | ❌ |
| M5Stack M5StickC PLUS2 | 🆗 | 🆗 | 🆗 | 🆗 | 🆗 | 🆗¹ | ❌ | Tone | ❌ | ❌ |
| M5Stack M5StickC PLUS | 🆗 | 🆗 | 🆗 | 🆗 | 🆗 | 🆗¹ | ❌ | Tone | ❌ | ❌² |
| M5Stack M5Core BASIC | 🆗 | 🆗 | 🆗 | 🆗 | 🆗 | 🆗¹ | ❌ | Tone | ❌ | ❌ |
| M5Stack M5Core2 | 🆗 | 🆗 | 🆗 | 🆗 | 🆗 | 🆗¹ | ❌ | ❌ | ❌ | ❌ |
| M5Stack M5CoreS3/SE | 🆗 | 🆗 | 🆗 | 🆗 | ❌ | 🆗 | ❌ | ❌ | ❌ | ❌ |
| JCZN CYD‑2432S028 | 🆗 | 🆗 | 🆗 | 🆗 | ❌ | 🆗¹ | ❌ | ❌ | ❌ | ❌² |
| Lilygo T‑Embed CC1101 | 🆗 | 🆗 | 🆗 | 🆗 | 🆗 | 🆗 | 🆗 | 🆗 | 🆗 | ❌ |
| Lilygo T‑Embed | 🆗 | 🆗 | 🆗 | 🆗 | 🆗 | 🆗 | 🆗 | 🆗 | ❌ | ❌ |
| Lilygo T-Display-S3 | 🆗 | 🆗 | ❌ | ❌ | ❌ | 🆗 | ❌ | ❌ | ❌ | ❌ |
| Lilygo T‑Deck (and pro) | 🆗 | ❌ | ❌ | ❌ | ❌ | 🆗 | ❌ | ❌ | ❌ | ❌ |
| Lilygo T-Watch-S3 | ❌ | ❌ | ❌ | ❌ | ❌ | 🆗 | ❌ | ❌ | ❌ | ❌ |
| Lilygo T-LoRa Pager | ❌ | ❌ | ❌ | ❌ | ❌ | 🆗 | ❌ | ❌ | ❌ | ❌ |
| Smoochiee V2 | 🆗 | 🆗 | ❌ | 🆗 | ❌ | 🆗 | ❌ | ❌ | ❌ | ❌ |
| ESP32-C5 | 🆗 | 🆗 | ❌ | 🆗 | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
| Bruce RF Reaper | 🆗 | 🆗 | ❌ | 🆗 but w/ ST25R3916 | ❌ | 🆗 | 🆗 | ❌ | 🆗 | ❌ |
| Elecrow 24B | 🆗 | 🆗 | 🆗 | 🆗 | ❌ | 🆗¹ | ❌ | ❌ | ❌ | ❌² |
| Elecrow 3.5" | 🆗 | 🆗 | 🆗 | 🆗 | ❌ | 🆗¹ | ❌ | ❌ | ❌ | ❌² |
| NM-CYD-C5 + RF HAT | 🆗 | 🆗 | ❌ | 🆗 | ❌ | 🆗 | 🆗 | ❌ | 🆗 | ❌ |
| ² CYD have a LITE_VERSION version for Launcher Compatibility | ||||||||||
| ¹ Core, CYD and StickCs Bad-USB: here |