
Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.
This firmware is a fork of the original (OFW) version of flipperdevices/flipperzero-firmware and represents the most stable custom build, incorporating new features and improvements to the original components while remaining fully compatible with the API and applications of the original firmware.
[!WARNING] This software is intended solely for experimental purposes and is not meant for any illegal activities. We do not condone unlawful behavior and strongly encourage you to use it only within the bounds of the law.
This project is developed independently and is not affiliated with Flipper Devices.
Also be aware, DarkFlippers/unleashed-firmware is the only official page of the project, there is no paid, premium or closed source versions and if someone contacts you and say they are from our team and try to offer something like that - they are scammers, block that user ASAP
Before getting started:
Review the Official Documentation: docs.flipper.net
Installation Guide & Version Info:
How to install the firmware by following the Installation Guide and check the version information (e, , c)
FAQ:
Find answers to common questions in the FAQ
Web Installer: -> Unleashed FW Web Installer
[!NOTE] Built automatically from dev branch
qUnleashed — app for mobile and PC:
Companion app to manage your Flipper from your phone or computer — DarkFlippers/qUnleashed
Sub-GHz & Coordinates Map:
Online map to view your Sub-GHz wardriving files, and any other files with coordinates in them — map.unleashedflip.com
Wi-Fi Wardriving Map:
Combine and display multiple WiGLE-formatted captures from ESP32 Marauder and others — wdmap.unleashedflip.com
ESP32 Web Flasher:
Easy to use flasher for popular ESP32 modules, fully in your browser — espflasher.unleashedflip.com
Sub‑GHz Library & HAL
- Many new protocols added
- Regional TX restrictions removed
- Extra Sub-GHz frequencies added
- Frequency range can be extended in settings file (warning: It can damage Flipper's hardware)
- Many rolling code protocols now have the ability to save & send captured signals
- FAAC SLH (Spa) & BFT Mitto (keeloq secure with seed) manual creation
- External CC1101 module support (by quen0n)
Sub‑GHz Main App
- Save last used settings (by derskythe)
- New frequency analyzer (by ClusterM)
- Press OK in frequency analyzer to use detected frequency in Read modes (by derskythe)
- Long press OK button in Sub-GHz Frequency analyzer to switch to Read menu (by derskythe)
- New option to use timestamps + protocol name when you saving file, instead of random name or timestamp only - Enable in
Radio Settings -> Protocol Names = ON- Read mode UI improvements (shows time when signal was received) (by @wosk)
- External CC1101 module support (Hardware SPI used)
- External CC1101 module amplifier control (or LED control) support (enabled by default)
- Hold right in received signal list to delete selected signal
- Custom buttons for Keeloq / Alutech AT4N / Nice Flor S / Somfy Telis / Security+ 2.0 / CAME Atomo - now you can use arrow buttons to send signal with different button code
Add manuallymenu extended with new protocols- FAAC SLH, BFT Mitto / Somfy Telis / Nice Flor S / CAME Atomo, etc. manual creation with programming new remote into receiver (use button 0xF for BFT Mitto, 0x8 (Prog) on Somfy Telis, (right arrow button for other protocols))
- Debug mode counter increase settings (+1 → +5, +10, default: +1)
- Debug PIN output settings for protocol development
- Ignore options - Alarms: Hollarm, GangQi | ReversRB2: Revers RB-2(M) protocol | Sensors: Magellan, Honeywell Sec, Honeywell WDB (doorbells), Legrand (doorbells), Feron (RGB lights) | NiceFlorS: Nice Flor-S protocol
Sub‑GHz Apps (by Unleashed Team)
- Sub-GHz Bruteforce - static code brute-force plugin
- Time delay (between signals) setting (hold Up in main screen (says Up to Save)) + configure repeats in protocols list by pressing right button on selected protocol
- Load your own file and select bytes you want to bruteforce or use preconfigured options in protocols list
- Sub-GHz Remote - remote control for 5 sub-ghz files | bind one file for each button
- use the built-in constructor or make config file by following this instruction