
The open-source wireless research platform for ESP32.
The ESP-IDF-native wireless security platform for ESP32. Deep Wi-Fi and BLE assessment, research-grade capture and export, and a real app ecosystem. Built directly on Espressif's ESP-IDF rather than through the Arduino core, so new silicon and radio features land first and there is no abstraction layer between GhostESP and the hardware.
⭐️ Enjoying GhostESP? Please give the repo a star. It helps a lot.
v2.0 rebuilt the UI, added a native app ecosystem, and expanded the radio workflows. v2.1 (Revival) adds on-device OTA with rollback protection, a second NFC backend (ST25R3916), a Cloud Store for apps and scripts and asset packs, and GhostScript, a sandboxed Lua runtime.

Full history in CHANGELOG.md.
| Flash your device | Community and support | Learn more |
|---|---|---|
| ghostesp.net/flasher | Discord | Documentation · Website |
GhostESP is a platform, not a bag of tools. Five things set it apart:
gbt and a plugin SDK, installed from the Cloud Store, plus a Lua runtime for scripts. Examples: Device Inspector, ESP32Finder, a Doom port, a QR generator.type_char CLI for typing individual ASCII characters.ir file support.nfc import/export.sub filesgbt) for scaffolding, building, and packaging apps and firmwaregpsinfo) with WiGLE manual upload, runtime baud config, and wdstream companion streamingpowerprinter, PJL)timezone) + NTP time set/camera)Note: Feature availability varies by chip. S2 lacks Bluetooth hardware. C5 has 5 GHz and 802.15.4 or Zigbee support. P4 uses an external ESP32-C6 for Wi-Fi and Bluetooth via ESP-Hosted.
61 board targets build in CI (.github/workflows/compile_all.yml) from 60 configs in configs/. Awok V5 shares the generic ESP32-S2 config.
Marauder is the focused, hardware-first Wi-Fi and BLE toolset that much of this space grew out of, and GhostESP credits it directly (see Credits). GhostESP covers the same Wi-Fi and BLE ground and adds the capture-to-analysis pipeline, multi-device control through GhostLink, and the native app ecosystem described above, on an ESP-IDF base rather than Arduino.
The table below compares GhostESP against other broad-scope firmware. It is based on GhostESP's feature set and the publicly available source for each listed project. It is not a complete feature list for every firmware. HaleHound and nyanBOX are compared against the latest public source available to us. If newer releases are closed source, this table cannot be independently verified against those builds.
Special thanks to:
GhostESP welcomes contributions — from a one-line board config to a new feature.
good first issue is a solid place to start.gbt (Ghost Build Tool) docs and example apps (Device Inspector, ESP32Finder) for the SDK pattern.Ghost ESP is intended solely for educational and ethical security research. Unauthorized or malicious use is illegal. Familiarize yourself with your local laws, and always obtain proper permission before conducting any network tests.
Note: this is a detached fork of Spooky's GhostESP, which has been archived and is no longer in development.
For guidelines on using the GhostESP name and logo, see BRAND GUIDELINES.
Interested in becoming an official partner? Email [email protected].
This project is open source and welcomes your contributions. If you've added new features or enhanced device support, please submit your changes!
| Board | Bluetooth | NFC (PN532) | NFC (Chameleon) | IR TX | IR RX | GPS Default | Keyboard | Display | SD | OTA | Native SD Apps |
|---|
| ESP32-Wroom DevKitC | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| ESP32-S2 DevKitC | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| ESP32-S3 DevKitC | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| ESP32-C3 DevKitC | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| ESP32-C5 DevKitC | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| ESP32-C6 DevKitC | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| Awok V5 | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| GhostBoard | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✗ | — | ✓ | ✗ | ✗ |
| Marauder v4 | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✗ | Full | ✓ | ✓ | ✗ |
| Marauder v6 | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✗ | ✗ | ✗ |
| AWOK Mini | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ | ✗ | Full | ✗ | ✗ | ✓ |
| Cardputer | ✓ | ✗ | ✓ | ✓ | ✗ | ✓ | ✓ | Full | ✓ | ✓ | ✗ |
| Heltec V3 | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Status | ✓ | ✗ | ✗ |
| CYD2 USB | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✗ |
| CYD2 Micro USB | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✗ |
| CYD2 Dual USB | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✗ |
| CYD2 USB 2.4" | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✗ |
| CYD2 USB 2.4" (C variant) | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✗ |
| CYD 2432S028R | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✗ |
| Waveshare 7" Touch | ✓ | ✗ | ✓* | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| Crowtech 7" | ✓ | ✗ | ✓* | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✓ |
| CrowPanel Advance 7" (S3, TFCard mode) | ✓ | ✗ | ✓* | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| CrowPanel 4.2" E-paper (400×300) | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | E-paper | ✓ | ✗ | ✗ |
| CrowPanel 5.79" E-paper (792×272) | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | E-paper | ✓ | ✗ | ✗ |
| CrowPanel Advance 2.4" (S3, 320×240) | ✓ | ✗ | ✓* | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| CrowPanel Advance 2.8" (S3, 320×240) | ✓ | ✗ | ✓* | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| CrowPanel Advance 3.5" (S3, 480×320) | ✓ | ✗ | ✓* | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| CrowPanel Advance 4.3" (S3, 800×480) | ✓ | ✗ | ✓* | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| CrowPanel Advance 5" (S3, 800×480) | ✓ | ✗ | ✓* | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| CrowPanel Advanced P4 7/9/10.1" (v1.2+) | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✓ |
| CrowPanel Advanced P4 7/9/10.1" (v1.1) | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✓ |
| CrowPanel Advanced P4 5" RGB | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✓ |
| Sunton 7" | ✓ | ✗ | ✓* | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| JC3248W535EN | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| Flipper JCMK GPS | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ | ✗ | — | ✓ | ✗ | ✗ |
| T-Deck | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✓ | Full | ✓ | ✗ | ✓ |
| T-Embed CC1101 | ✓ | ✓ | ✓ | ✓ | ✓ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| GhostLink P1 Core | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✓ |
| GhostLink P1 Peer | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| T-Dongle-S3 | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✗ |
| T-Dongle-C5 | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| S3TWatch | ✓ | ✗ | ✓ | ✓ | ✗ | ✗ | ✗ | Full | has 4MB vfs partition | ✓ | ✗ |
| T-Display S3 Touch | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✗ | Full | ✓ | ✗ | ✗ |
| JCMK Devboard Pro | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✗ | — | ✓ | ✗ | ✗ |
| Minion | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| Lolin S3 Pro | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| Cardputer ADV | ✓ | ✗ | ✓ | ✓ | ✗ | ✓ | ✓ | Full | ✓ | ✓ | ✗ |
| Poltergeist | ✓ | ✗ | ✓ | ✓ | ✓ | ✗ | ✗ | Status | ✓ | ✗ | ✗ |
| Banshee (C5 display MCU) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✗ | Full + Status | ✓ | ✓ | ✓ |
| Banshee (S3 main) | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✗ | — | ✗ | ✓ | ✗ |
| Febris Pro | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✗ | — | ✗ | ✗ | ✗ |
| ACE C5 | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✗ | — | ✓ | ✗ | ✗ |
| NM-CYD-C5 | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| ACE S3 | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| Seeed XIAO ESP32-S3 Sense | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✓ | ✗ |
| Seeed XIAO ESP32-S3 | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✓ | ✗ |
| Seeed XIAO ESP32-C5 | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| Marauder v8 | ✓ | ✗ | ✗ | ✗ | ✗ | ✓ | ✗ | Full | ✓ | ✗ | ✓ |
| Pancake C5 | ✓ | ✗ | ✗ | ✗ | ✗ | ✓ | ✗ | Full | ✓ | ✗ | ✓ |
| M5Stack CoreS3-SE | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✗ | Full | ✓ | ✗ | ✓ |
| M5Stack AtomS3R | ✓ | ✗ | ✓ | ✓ | ✗ | ✓ | ✗ | Full | has 1MB vfs partition | ✗ | ✗ |
* — the checked-in config for this board predates a Kconfig option (NFC_CHAMELEON) that defaults on for BLE-capable boards; no board-specific override is present, so this reflects the Kconfig default rather than an explicit setting in the file. Most unstarred BLE-capable boards set the symbol explicitly, but some generic configs may also rely on the Kconfig default.
M5Stack Grove ports: the M5Stack CoreS3-SE and AtomS3R configs expose their HY2.0-4P Grove connectors on I2C port 1 (PORT.A: SDA=G2, SCL=G1; the CoreS3-SE also has PORT.B G8/G9 and PORT.C G17/G18). Plug an ST25R3916 NFC module (I2C, 0x50) and/or an M5Stack ENV III unit (SHT30 0x44 + QMP6988 0x70) into Grove PORT.A and open the NFC or ENV III app — both devices share the same bus.
Display: Full = LVGL graphical UI. Status = secondary small status display only (shares the IO-expander I2C bus), no full UI. — = headless, no display.
SD: most boards use SPI-mode SD. JC3248W535EN and T-Dongle-S3 use SDMMC 1-bit mode instead; the SDMMC bus option exists in Kconfig for other boards.
NFC (Chameleon): Chameleon Ultra support rides over BLE, so it's on by default for any BLE-capable board and off where BLE is unavailable (ESP32-S2 boards) or explicitly disabled (Marauder v8, Pancake C5).
Native SD Apps: at compile time the feature depends only on CONFIG_SPIRAM (main/Kconfig.projbuild:1410). At runtime the app gallery checks MALLOC_CAP_SPIRAM and renders into the full LVGL screen, so a display is required for the UI to be usable. That leaves it enabled on: AWOK Mini, Waveshare/Crowtech/Sunton 7″, CrowPanel Advance 2.4/2.8/3.5/4.3/5″, CrowPanel Advanced P4 5″/7/9/10.1″ (v1.1/v1.2+), JC3248W535EN, T-Deck, T-Embed CC1101, GhostLink P1 Core, T-Dongle-C5, NM-CYD-C5, M5Stack CoreS3-SE, Banshee (C5), and Marauder v8/Pancake C5. Boards with a screen but no PSRAM (Cardputer, Cardputer ADV, the CYD2 family, S3TWatch, T-Dongle-S3, M5Stack AtomS3R, etc.) don't get it.
Banshee ships as two configs: the S3 main board (headless) and the C5 module that drives its display and status LED, paired over GhostLink.
| Feature | GhostESP | Bruce | HaleHound | nyanBOX |
|---|
| Current source available for audit | [x] | [x] | Limited / older public source | Limited / older public source |
| ESP-IDF-native architecture | [x] | |||
| Arduino / PlatformIO architecture | [x] | [x] | [x] | |
| Supported board targets | 61 CI targets | 42+ | 4 | 1 |
| Full LVGL graphical UI | [x] | |||
| Web dashboard / REST control | [x] | [x] | ||
| Captive portal web server | [x] | [x] | [x] | [x] |
| AP / station WiFi scanning | [x] | [x] | [x] | [x] |
| Deauth / disassoc testing | [x] | [x] | [x] | [x] |
| Beacon spam | [x] | [x] | [x] | [x] |
| Karma / probe response attack | [x] | [x] | [x] | |
| Handshake / EAPOL capture | [x] | [x] | [x] | |
| On-device PCAP browser / hc22000 export | [x] | |||
| PMKID capture / export | [x] | [x] | ||
| Live Wireshark USB streaming | [x] | |||
| SAE flood / WPA3-specific testing | [x] | |||
| WPA3 compliance checker | [x] | |||
| EAPOL logoff attack | [x] | |||
| Channel switch attack | [x] | |||
| GTK abuse / client isolation testing | [x] | |||
| DHCP starvation | [x] | [x] | ||
| ARP / port / SSH scanners | [x] | [x] | ||
| mDNS discovery | [x] | |||
| NetBIOS scanner | [x] | |||
| HTTP banner scanner | [x] | |||
| SNMP probe | [x] | |||
| WiFi OUI vendor lookup | [x] | [x] | [x] | |
| PineAP / Evil Twin detection | [x] | [x] | ||
| WPS detection / reporting | [x] | [x] | ||
| Pwnagotchi-style automated capture mode | [x] | [x] | ||
| Pwnagotchi detector / spam | [x] | [x] | ||
| Channel congestion analysis | [x] | [x] | ||
| Live WiFi packet monitor / visualizer | [x] | [x] | [x] | |
| WiFi Airspace Monitor | [x] | |||
| DNS sinkhole / blocklist NXDOMAIN | [x] | |||
| GPS WiFi wardriving | [x] | [x] | [x] | |
| BLE wardriving | [x] | [x] | [x] | |
| WiGLE upload integration | [x] | [x] | ||
| 802.15.4 capture and PCAP export | [x] | |||
| GhostLink dual-ESP control | [x] | |||
| GhostLink BLE bridge to Android | [x] | |||
| Split-channel wardriving helper | [x] | |||
| GhostLink remote radio support | [x] | |||
| Drone / OpenDroneID detect | [x] | [x] | ||
| Drone / OpenDroneID spoof | [x] | [x] | ||
| BLE scanning | [x] | [x] | [x] | [x] |
| Raw BLE scanner | [x] | |||
| BLE spam modes | [x] | [x] | [x] | [x] |
| AirTag scan / spoof | [x] | [x] | [x] | [x] |
| BLE tracker detection tools | [x] | [x] | [x] | |
| Flipper Zero finder | [x] | [x] | ||
| GATT / service enumeration | [x] | [x] | ||
| BLE device tracking by RSSI | [x] | |||
| BLE stream to Wireshark | [x] | |||
| BLE skimmer detection | [x] | [x] | ||
| FastPair / pairing exploit research | [x] | [x] | [x] | |
| BLE HID injection / DuckyScript over BLE | [x] | |||
| BLE keyboard mode | [x] | |||
| BLE GATT honeypot / cloned peripheral | [x] | [x] | ||
| BLE vulnerability profiling | [x] | |||
| Flock / surveillance detector | [x] | [x] | [x] | |
| PN532 NFC support | [x] | [x] | [x] | |
| ST25R3916 NFC support | [x] | [x] | ||
| Chameleon Ultra support | [x] | [x] | ||
| Chameleon Ultra BLE control | [x] | [x] | ||
Flipper .nfc import/export | [x] | |||
| Flipper NFC parser collection | [x] | |||
| MIFARE Classic default-key attack | [x] | [x] | [x] | |
| MIFARE Classic embedded dictionary | [x] | |||
| MIFARE Classic user dictionary file | [x] | [x] | ||
| MIFARE Classic session key reuse / sector sweep | [x] | |||
| MIFARE Classic hardnested recovery | [x] | |||
| PicoPass / iCLASS reading | [x] | |||
| MIFARE DESFire application / file tree reads | [x] | |||
| EMV / payment card reader | [x] | [x] | ||
| BadUSB / DuckyScript | [x] | [x] | ||
| USB keyboard host mode | [x] | |||
| USB HID keyboard output mode | [x] | [x] | ||
| Remote keyboard over dual-device link | [x] | |||
| BadUSB VID/PID identity options | [x] | [x] | ||
| BadUSB mouse jiggler / trackpad | [x] | |||
| IR learn / capture / replay | [x] | [x] | ||
Flipper .ir file support | [x] | [x] | ||
| Universal IR library transmit | [x] | [x] | ||
| CC1101 SubGHz scan / replay | [x] | [x] | [x] | |
| CC1101 waterfall spectrum analyzer | [x] | [x] | [x] | |
Flipper .sub read/write support | [x] | [x] | [x] | [x] |
| SubGHz protocol decoders | [x] | [x] | [x] | |
| NRF24 spectrum analyzer | [x] | [x] | [x] | [x] |
| NRF24 MouseJack | [x] | [x] | ||
| Passive jamming detection | [x] | [x] | ||
| Active RF jamming shipped | Not shipped | [x] | [x] | [x] |
| Zigbee / 802.15.4 packet capture | [x] | |||
| Ethernet W5500 support | [x] | [x] | ||
| Ethernet ARP poisoning / MITM tools | [x] | [x] | ||
| Ethernet fingerprint / port / ping tools | [x] | |||
| Ethernet DNS / NTP / HTTP / trace tools | [x] | |||
| TLS SNI / HTTP / FTP credential capture over Ethernet | [x] | |||
| Camera streaming / motion detection | [x] | |||
| Motion alerts with webhook support | [x] | |||
| Network printer / PJL output | [x] | |||
| DIAL / Chromecast testing | [x] | |||
| On-device setup wizard | [x] | |||
| PIN / password lock | [x] | [x] | [x] | |
| On-device OTA / SD firmware update | [x] | [x] | ||
| Firmware verification / rollback protection | [x] | |||
| GhostLink peer firmware update | [x] | |||
| Wired screen mirroring | [x] | [x] | ||
| Web screen mirroring | [x] | [x] | ||
| SD config backup / restore | [x] | |||
| SD file manager / browser | [x] | [x] | [x] | |
| Native SD app/plugin system | [x] | |||
| Native app SDK / build tooling | [x] | |||
| Sandboxed on-device scripting runtime | Lua 5.4 | JavaScript | ||
| Cloud app / script / asset store | [x] | |||
| Apps gallery / launcher | [x] | |||
| Ghostchi / virtual pet | [x] | [x] | ||
| Audio player | [x] | [x] | ||
| Microphone spectrum / visualizer | [x] | [x] | ||
| RGB LED visualizer modes | [x] | [x] | ||
| Clock / RTC screen | [x] | [x] | ||
| Compass screen | [x] | |||
| Accelerometer screen | [x] | |||
| ENV-III temperature / humidity / pressure | [x] | |||
| Battery monitoring / fuel gauge support | [x] | [x] | [x] | |
| Sensor / RTC hardware support | [x] | [x] | ||
| M5 Cardputer keyboard support | [x] | [x] | ||
| Android companion app | [x] | |||
| Accessibility modes / reduced motion | [x] | [x] | ||
| Custom theme / UI palette system | [x] | [x] | [x] | |
| Custom SD asset packs | [x] | |||
| LoRa support | [x] | |||
| FM radio support | [x] |
GhostESP does not ship active jamming features. Distribution, promotion, sale, and use of jamming devices or firmware is illegal in many jurisdictions.
![]() JustCallMeKoKo ESP32Marauder foundational development |
![]() thibauts CastV2 protocol insights |
![]() MarcoLucidi01 DIAL protocol integration |
![]() SpacehuhnTech Reference deauthentication code |
![]() Spooks4576 Original GhostESP Developer |
![]() Tototo31 Large contributions to the project |
![]() WillyJL Core Flipper Firmware functionality and BLE Spam code |
![]() Flipper Zero firmware Core IR & NFC implementation (flipperdevices/flipperzero-firmware & contributors) |
![]() Garag Core NFC library |
![]() connornishijima SensoryBridge - MIC RGB visualizer algorithms & inspiration |
![]() DarkFlippers Flipper Zero Unleashed firmware (SubGHz protocol decoders) |
![]() xMasterX Flipper Zero Unleashed SubGHz improvements |
![]() DecentLabs officeAir - multi-pass ARP scanning & lwIP thread-safety techniques |
![]() jaylikesbunda Project maintainer |
![]() Play2BReal WiGLE upload & IO expander support |
![]() the1anonlypr3 Art and assets |
![]() Billi-Green Audio & ENV-III sensor support |
![]() Next-Flip Momentum-Firmware - NFC parser base (EMV, DESFire, hardnested, transit parsers; Gallagher by Nick Mooney) |
![]() noproto MIFARE Classic hardnested / nested recovery |
![]() Leptopt1los EMV payment-card parser |
![]() bettse picopass - PicoPass / iCLASS support |
![]() micolous Opal transit card parser |
![]() emilytrau myki transit card parser |
![]() holiman loclass - MIFARE key recovery algorithms |
![]() RfidResearchGroup proxmark3 - RFID research tooling |