Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
unleashed-firmware — Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing. | Kitploit
Tools/GitHubGitHub/darkflippers/unleashed-firmware
Embedded Systems SecurityRFID/NFC ToolsFuzzingWireless SecurityHardware HackingPenetration TestingRed TeamingPayload Development

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
darkflippers/unleashed-firmware

unleashed-firmware

Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

View RepositoryWebsite
22.1k1.9k0 days agoReviewed by Kitploit

Unleashed Firmware Logo

English Telegram Chat Russian Telegram Chat Ukraine Telegram Chat Discord Server

Flipper Zero Unleashed Firmware

This firmware is a fork of the original (OFW) version of flipperdevices/flipperzero-firmware and represents the most stable custom build, incorporating new features and improvements to the original components while remaining fully compatible with the API and applications of the original firmware.

[!WARNING] This software is intended solely for experimental purposes and is not meant for any illegal activities. We do not condone unlawful behavior and strongly encourage you to use it only within the bounds of the law.

This project is developed independently and is not affiliated with Flipper Devices.

Also be aware, DarkFlippers/unleashed-firmware is the only official page of the project, there is no paid, premium or closed source versions and if someone contacts you and say they are from our team and try to offer something like that - they are scammers, block that user ASAP


🚀 Usage

Before getting started:

  • Review the Official Documentation: docs.flipper.net

  • Installation Guide & Version Info:
    How to install the firmware by following the Installation Guide and check the version information (e, , c)

  • FAQ:
    Find answers to common questions in the FAQ

  • Web Installer: -> Unleashed FW Web Installer

📦 Releases

Release builds (stable)

  • Telegram Telegram: t.me/unleashed_fw
  • GitHub GitHub Releases

Dev builds (unstable)

[!NOTE] Built automatically from dev branch

  • Web site: dev.unleashedflip.com
  • Telegram Telegram: t.me/kotnehleb

🧰 Companion App & Web Tools

  • qUnleashed — app for mobile and PC:
    Companion app to manage your Flipper from your phone or computer — DarkFlippers/qUnleashed

  • Sub-GHz & Coordinates Map:
    Online map to view your Sub-GHz wardriving files, and any other files with coordinates in them — map.unleashedflip.com

  • Wi-Fi Wardriving Map:
    Combine and display multiple WiGLE-formatted captures from ESP32 Marauder and others — wdmap.unleashedflip.com

  • ESP32 Web Flasher:
    Easy to use flasher for popular ESP32 modules, fully in your browser — espflasher.unleashedflip.com

🆕 What's New

Sub‑GHz Library & HAL
  • Many new protocols added
  • Regional TX restrictions removed
  • Extra Sub-GHz frequencies added
  • Frequency range can be extended in settings file (warning: It can damage Flipper's hardware)
  • Many rolling code protocols now have the ability to save & send captured signals
  • FAAC SLH (Spa) & BFT Mitto (keeloq secure with seed) manual creation
  • External CC1101 module support (by quen0n)
Sub‑GHz Main App
  • Save last used settings (by derskythe)
  • New frequency analyzer (by ClusterM)
  • Press OK in frequency analyzer to use detected frequency in Read modes (by derskythe)
  • Long press OK button in Sub-GHz Frequency analyzer to switch to Read menu (by derskythe)
  • New option to use timestamps + protocol name when you saving file, instead of random name or timestamp only - Enable in Radio Settings -> Protocol Names = ON
  • Read mode UI improvements (shows time when signal was received) (by @wosk)
  • External CC1101 module support (Hardware SPI used)
  • External CC1101 module amplifier control (or LED control) support (enabled by default)
  • Hold right in received signal list to delete selected signal
  • Custom buttons for Keeloq / Alutech AT4N / Nice Flor S / Somfy Telis / Security+ 2.0 / CAME Atomo - now you can use arrow buttons to send signal with different button code
  • Add manually menu extended with new protocols
  • FAAC SLH, BFT Mitto / Somfy Telis / Nice Flor S / CAME Atomo, etc. manual creation with programming new remote into receiver (use button 0xF for BFT Mitto, 0x8 (Prog) on Somfy Telis, (right arrow button for other protocols))
  • Debug mode counter increase settings (+1 → +5, +10, default: +1)
  • Debug PIN output settings for protocol development
  • Ignore options - Alarms: Hollarm, GangQi | ReversRB2: Revers RB-2(M) protocol | Sensors: Magellan, Honeywell Sec, Honeywell WDB (doorbells), Legrand (doorbells), Feron (RGB lights) | NiceFlorS: Nice Flor-S protocol
Sub‑GHz Apps (by Unleashed Team)
  • Sub-GHz Bruteforce - static code brute-force plugin
  • Time delay (between signals) setting (hold Up in main screen (says Up to Save)) + configure repeats in protocols list by pressing right button on selected protocol
  • Load your own file and select bytes you want to bruteforce or use preconfigured options in protocols list
  • Sub-GHz Remote - remote control for 5 sub-ghz files | bind one file for each button
  • use the built-in constructor or make config file by following this instruction
Infrared (IR)
  • Recompiled IR TV Universal Remote for ALL buttons
  • Universal remotes for Projectors, Fans, A/Cs and Audio(soundbars, etc.) → Also always updated and verified by our team
  • Infrared → RCA Protocol
  • Infrared → External IR modules support (with autodetect by OFW)
NFC/RFID/iButton
  • LFRFID and iButton Fuzzer plugins
  • Add DEZ 8 display form for EM4100 (by @korden32)
  • Extra Mifare Classic keys in system dict
  • EMV Protocol + Public data parser (by @Leptopt1los and @wosk)
  • NFC Add manually → Mifare Classic with custom UID
  • NFC parsers: Umarsh, Zolotaya Korona, Kazan, Metromoney, Moscow Social Card, Troika (reworked) and many others (by @Leptopt1los and @assasinfil)
Quality of Life & Other Features
  • Customizable Flipper name Update! Now can be changed in Settings → Desktop (by @xMasterX and @Willy-JL)
  • Text Input UI element → Cursor feature (by @Willy-JL)
  • Byte Input Mini editor → Press UP multiple times until the nibble editor appears (by @gid9798)
  • Clock on Desktop Settings -> Desktop -> Show Clock (by @gid9798)
  • Battery percentage display with different styles Settings -> Desktop -> Battery View
  • More games in Dummy Mode → click or hold any of arrow buttons
  • Lock device with pin (or regular lock if pin not set) by holding UP button on main screen (by an4tur0r)
  • BadKB (BadUSB) (by Willy-JL, ClaraCrazy, XFW contributors) - (Integrated into BadUSB app now!) - (aka BadUSB via Bluetooth)
  • BadUSB → Keyboard layouts (by rien > dummy-decoy)
  • Custom community plugins and games added + all known working apps can be downloaded in extra pack in every release
  • Other small fixes and changes throughout
  • See other changes in readme below

Also check the changelog in releases for latest updates!

Current modified and new Sub-GHz protocols list:

Full list of supported protocols and their frequencies/modulations (to use in Read mode)

Thanks to Official team (to their SubGHz Developer, Skorp) for implementing support (decoder + encoder / or decode only) for most protocols in OFW.

And thanks to our contributors who took part in SubGHz improvements and making of new features:

@RocketGod-git, @zero-mega, @ashphx, @pkooiman, Vitaly, Carlos, @li0ard, @mishamyte, d82k, Steffen (bastelbudenbuben de), @assasinfil, @gid9798

❤️ Please support development of the project

The majority of this project is developed and maintained by me, @xMasterX. Our team is small and the guys are working on this project as much as they can solely based on the enthusiasm they have for this project and the community.

  • @mishamyte - NFC, RFID, SubGHz and chats moderation
  • @quen0n - Hardware, SubGHz and chats moderation
  • @Drone1950 - Reverse Engineering, telegram bot and chats moderation
  • @HackcatDev - Support and chats moderation
  • @Leptopt1los - NFC, RFID, Plugins, chat moderation and many other things
  • @gid9798 - SubGHz, Plugins, many other things - currently offline :(
  • @assasinfil - SubGHz protocols, NFC parsers, chat moderation
  • @Svaarich - UI design and animations
  • @amec0e - Infrared assets
  • Community moderators in Telegram, Discord, and Reddit
  • And of course our GitHub community. Your PRs are a very important part of this firmware and open-source development.

The amount of work done on this project is huge and we need your support, no matter how large or small. Even if you just say, "Thank you Unleashed firmware developers!" somewhere. Doing so will help us continue our work and will help drive us to make the firmware better every time. Also, regarding our releases, every build has and always will be free and open-source. There will be no paywall releases or closed-source apps within the firmware. As long as I am working on this project it will never happen.
You can support us by using links or addresses below:

📱 Community Apps

Enhance your Flipper Zero with apps and plugins created by the community:

  • Extra Plugins & Packs:
    Check out the latest extra plugins and plugin packs (Extra Pack and Base Pack) on GitHub.

  • Source Code & Full List:
    Find the complete list and source code at xMasterX/all-the-plugins.

  • Official Apps Catalog:
    Browse the official Flipper Zero Apps Catalog on the web or via the mobile app.

📁 Where I can find IR, Sub-GHz, ... files, DBs, and other stuff?

  • UberGuidoZ Playground - Large collection of files - Github
  • Awesome Flipper Zero - Github
  • IRDB - Infrared remotes database - Github

📘 Instructions

Tools Icon Badge Firmware & main Apps feature

  • System: How to change Flipper name
  • BadUSB: How to add new keyboard layouts
  • Infrared: How to make captures to add them into Universal IR remotes

SubGhz Icon Badge Sub-GHz

  • Full list of supported protocols and their frequencies/modulations (to use in Read mode)
  • How to use Flipper as rolling code remote (Doorhan, Nice FlorS, BFT Mitto, Somfy Telis, Aprimatic, AN-Motors, etc..)
  • Experimental rolling code counter modes (avoid desync)
  • External Radio: How to connect CC1101 module
  • Transmission is blocked? How to extend Sub-GHz frequency range
  • How to add extra Sub-GHz frequencies
  • Configure Sub-GHz Remote App ⚠️ Not recommended, please use embedded configurator

Plugins Icon Badge Plugins

  • TOTP (Authenticator): config description
  • Barcode Generator: How to use
  • Multi Converter: How to use
  • WAV Player: sample files & how to convert
  • Sub-GHz playlist: generator script

GPIO Icon Badge GPIO - Plugins that works with external hardware

  • Unitemp - Temperature sensors reader: How to use & supported sensors
  • [NMEA] GPS: How to use
  • i2c Tools How to use
  • [NRF24] plugins: How to use
  • [WiFi] Scanner: How to use | Web Flasher
  • [ESP8266] Deauther: How to use | Web Flasher
  • [ESP32] WiFi Marauder: How to use docs by UberGuidoZ | Marauder repo
  • [ESP32-CAM] Camera Suite: How to use
  • How to Upload .bin to ESP32/ESP8266: Windows | FAP "ESP flasher"
  • [GPIO] SentrySafe plugin: How to use

👨‍💻 Firmware & Development

  • Developer Documentation - developer.flipper.net
  • How to build | Project-structure
  • Build apps on Android with Termux - compile .fap files on your phone, no PC needed by @CamsShaft
  • CLion IDE - How to setup workspace for flipper firmware development by Savely Krasovsky
  • "Hello world!" - plugin tutorial English by DroomOne | Russian by Pavel Yakovlev
  • How to write your own app.

Project structure

  • applications - Applications and services used in firmware
  • assets - Assets used by applications and services
  • furi - Furi Core: OS-level primitives and helpers
  • debug - Debug tool: GDB-plugins, SVD-file and etc
  • documentation - Documentation generation system configs and input files
  • firmware - Firmware source code
  • lib - Our and 3rd party libraries, drivers and etc...
  • site_scons - Build helpers
  • scripts - Supplementary scripts and python libraries home

Also, pay attention to the ReadMe.md files inside those directories.

🔗 Links

  • Unleashed web page: flipperunleashed.com

  • Unleashed FW Web Installer: web.unleashedflip.com

  • Unleashed domain used for direct .tgz update links for web updater or direct download: unleashedflip.com

  • Unleashed directory json for ufbt builds: up.unleashedflip.com/directory.json

  • Official Docs: docs.flipper.net

  • Official Forum: forum.flipperzero.one

  • Update! Official Developer Documentation developer.flipper.net

Download Tool
ServiceRemarkQR CodeLink/Wallet
Patreon Patreon
QR image
patreon.com/mmxdev
Boosty Boostypatreon alternative
QR image
boosty.to/mmxdev
Cloudtips CloudTipsonly RU payments accepted
QR image
pay.cloudtips.ru/p/7b3e9d65
YooMoney YooMoneyonly RU payments accepted
QR image
yoomoney.ru/fundraise/XA49mgQLPA0.221209
USDT USDTTRC20
QR image
TSXcitMSnWXUFqiUfEXrTVpVewXy2cYhrs
ETH ETHBSC/ERC20-Tokens
QR image
0xFebF1bBc8229418FF2408C07AF6Afa49152fEc6a
BTC BTC
QR image
bc1q0np836jk9jwr4dd7p6qv66d04vamtqkxrecck9
SOL SOLSolana/Tokens
QR image
DSgwouAEgu8iP5yr7EHHDqMNYWZxAqXWsTEeqCAXGLj8
DOGE DOGE
QR image
D6R6gYgBn5LwTNmPyvAQR6bZ9EtGgFCpvv
LTC LTC
QR image
ltc1q3ex4ejkl0xpx3znwrmth4lyuadr5qgv8tmq8z9
BCH BCH
QR image
qquxfyzntuqufy2dx0hrfr4sndp0tucvky4sw8qyu3
XMR XMRMonero
QR image
41xUz92suUu1u5Mu4qkrcs52gtfpu9rnZRdBpCJ244KRHf6xXSvVFevdf2cnjS7RAeYr5hn9MsEfxKoFDRSctFjG5fv1Mhn
TON TON
QR image
UQCOqcnYkvzOZUV_9bPE_8oTbOrOF03MnF-VcJyjisTZmsxa