
The open-source wireless research platform for ESP32.
The open-source wireless research platform for ESP32.
Turn a $10–20 ESP32 board into a wireless research tool with a full touchscreen UI - no soldering, no Arduino IDE.
New to GhostESP? Grab a compatible device and be running in under 5 minutes with the web flasher - no drivers, no build toolchain.
⭐️ Enjoying GhostESP? Please give the repo a star. It helps a lot.
v2.0 was the biggest update yet: a rebuilt UI, a native app ecosystem, and expanded radio workflows. v2.1 (Revival) keeps that going with on-device OTA, a second NFC backend, a Cloud Store, and a sandboxed scripting runtime.

v2.1 highlights:
echo, ping, version), aliases, scripts, and env vars.v2.0 highlights:
gbt). C5 builds can run app code from flash (XIP).type_char CLI, dedicated WebUI page.wdstream wardriving.Full history in CHANGELOG.md.
| Flash your device | Community & support | Learn more |
The short version — see the full 130+ row comparison below for everything else.
type_char CLI for typing individual ASCII characters.ir file support.nfc import/export.sub filesgbt) for scaffolding, building, and packaging apps and firmwaregpsinfo) with WiGLE manual upload, runtime baud config, and wdstream companion streamingpowerprinter, PJL)timezone) + NTP time set/camera)Note: Feature availability varies by chip. S2 lacks Bluetooth hardware; C5 has 5 GHz and 802.15.4/Zigbee support.
46 board targets build in CI (.github/workflows/compile_all.yml) from 45 configs in configs/; Awok V5 shares the generic ESP32-S2 config. Feature support below is derived from those configs.
This comparison is based on GhostESP's feature set and publicly available source for the listed projects. It is not a complete feature list for every firmware. HaleHound and nyanBOX are compared against the latest public source available to us; if newer releases are closed source, this table cannot be independently updated or verified against those builds.
Special thanks to:
GhostESP welcomes contributions — from a one-line board config to a new feature.
good first issue is a solid place to start.gbt (Ghost Build Tool) docs and example apps (Device Inspector, ESP32Finder) for the SDK pattern.Ghost ESP is intended solely for educational and ethical security research. Unauthorized or malicious use is illegal. Be sure to familiarize your local laws, and always obtain proper permissions before conducting any network tests.
Note: this is a detached fork of Spooky's GhostESP which has been archived and not in development anymore.
For guidelines on using the GhostESP name and logo, please see the Brand Guidelines. Brand assets are available at ghostesp.net/brand-assets.
Interested in becoming an official partner? Email [email protected].
This project is open source and welcomes your contributions. If you've added new features or enhanced device support, please submit your changes!
| Discord |
| Documentation · Website |
| GhostESP | Others |
|---|
| EMV / payment-card reading | ✓ | — |
| MIFARE DESFire tree reads | ✓ | — |
| Transit card parsers (Opal, myki, ITSO, Gallagher) | ✓ | — |
| Native app ecosystem + Cloud Store + Lua sandbox | ✓ | — |
| Dual-ESP32 GhostLink (remote radio, BLE bridge) | ✓ | — |
| Full LVGL graphical UI (carousel/grid/list) | ✓ | Partial or none |
| Board targets in CI | 46 | 1–42 |
| Board | Bluetooth | NFC (PN532) | NFC (Chameleon) | IR TX | IR RX | GPS Default | Keyboard | Display | SD | OTA | Native SD Apps |
|---|
| ESP32-Wroom DevKitC | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| ESP32-S2 DevKitC | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| ESP32-S3 DevKitC | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| ESP32-C3 DevKitC | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| ESP32-C5 DevKitC | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| ESP32-C6 DevKitC | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| Awok V5 | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| GhostBoard | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✗ | — | ✓ | ✗ | ✗ |
| Marauder v4 | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✗ | Full | ✓ | ✓ | ✗ |
| Marauder v6 | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✗ | ✗ | ✗ |
| AWOK Mini | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ | ✗ | Full | ✗ | ✗ | ✓ |
| Cardputer | ✓ | ✗ | ✓ | ✓ | ✗ | ✓ | ✓ | Full | ✓ | ✓ | ✗ |
| Heltec V3 | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Status | ✓ | ✗ | ✗ |
| CYD2 USB | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✗ |
| CYD2 Micro USB | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✗ |
| CYD2 Dual USB | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✗ |
| CYD2 USB 2.4" | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✗ |
| CYD2 USB 2.4" (C variant) | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✗ |
| CYD 2432S028R | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✗ | ✗ |
| Waveshare 7" Touch | ✓ | ✗ | ✓* | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| Crowtech 7" | ✓ | ✗ | ✓* | ✗ | ✗ | ✗ | ✗ | Full | ✗ | ✗ | ✓ |
| Sunton 7" | ✓ | ✗ | ✓* | ✗ | ✗ | ✗ | ✗ | Full | ✗ | ✓ | ✓ |
| JC3248W535EN | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| Flipper JCMK GPS | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ | ✗ | — | ✓ | ✗ | ✗ |
| T-Deck | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✓ | Full | ✓ | ✗ | ✓ |
| T-Embed CC1101 | ✓ | ✓ | ✓ | ✓ | ✓ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| T-Dongle-S3 | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✗ |
| T-Dongle-C5 | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| S3TWatch | ✓ | ✗ | ✓ | ✓ | ✗ | ✗ | ✗ | Full | ✗ | ✓ | ✗ |
| T-Display S3 Touch | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✗ | Full | ✓ | ✗ | ✗ |
| JCMK Devboard Pro | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✗ | — | ✓ | ✗ | ✗ |
| Minion | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| Lolin S3 Pro | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| Cardputer ADV | ✓ | ✗ | ✓ | ✓ | ✗ | ✓ | ✓ | Full | ✓ | ✓ | ✗ |
| Poltergeist | ✓ | ✗ | ✓ | ✓ | ✓ | ✗ | ✗ | Status | ✓ | ✗ | ✗ |
| Banshee (C5 display MCU) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✗ | Full + Status | ✓ | ✓ | ✓ |
| Banshee (S3 main) | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✗ | — | ✗ | ✓ | ✗ |
| Febris Pro | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✗ | — | ✗ | ✗ | ✗ |
| ACE C5 | ✓ | ✗ | ✓ | ✗ | ✗ | ✓ | ✗ | — | ✓ | ✗ | ✗ |
| NM-CYD-C5 | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | Full | ✓ | ✓ | ✓ |
| ACE S3 | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| Seeed XIAO ESP32-S3 Sense | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✓ | ✗ |
| Seeed XIAO ESP32-S3 | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✓ | ✗ |
| Seeed XIAO ESP32-C5 | ✓ | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ | — | ✓ | ✗ | ✗ |
| Marauder v8 | ✓ | ✗ | ✗ | ✗ | ✗ | ✓ | ✗ | Full | ✓ | ✗ | ✓ |
| Pancake C5 | ✓ | ✗ | ✗ | ✗ | ✗ | ✓ | ✗ | Full | ✓ | ✗ | ✓ |
* — the checked-in config for this board predates a Kconfig option (NFC_CHAMELEON) that defaults on for BLE-capable boards; no board-specific override is present, so this reflects the Kconfig default rather than an explicit setting in the file. Most unstarred BLE-capable boards set the symbol explicitly, but some generic configs may also rely on the Kconfig default.
Display: Full = LVGL graphical UI. Status = secondary small status display only (shares the IO-expander I2C bus), no full UI. — = headless, no display.
SD: most boards use SPI-mode SD. JC3248W535EN and T-Dongle-S3 use SDMMC 1-bit mode instead; the SDMMC bus option exists in Kconfig for other boards.
NFC (Chameleon): Chameleon Ultra support rides over BLE, so it's on by default for any BLE-capable board and off where BLE is unavailable (ESP32-S2 boards) or explicitly disabled (Marauder v8, Pancake C5).
Native SD Apps: at compile time the feature depends only on CONFIG_SPIRAM (main/Kconfig.projbuild:1410). At runtime the app gallery checks MALLOC_CAP_SPIRAM and renders into the full LVGL screen, so a display is required for the UI to be usable. That leaves it enabled on: AWOK Mini, Waveshare/Crowtech/Sunton 7″, JC3248W535EN, T-Deck, T-Embed CC1101, T-Dongle-C5, NM-CYD-C5, Banshee (C5), and Marauder v8/Pancake C5. Boards with a screen but no PSRAM (Cardputer, Cardputer ADV, the CYD2 family, S3TWatch, T-Dongle-S3, etc.) don't get it.
Banshee ships as two configs: the S3 main board (headless) and the C5 module that drives its display and status LED, paired over GhostLink.
| Feature | GhostESP | Bruce | HaleHound | nyanBOX |
|---|
| Current source available for audit | [x] | [x] | Limited / older public source | Limited / older public source |
| ESP-IDF-native architecture | [x] | |||
| Arduino / PlatformIO architecture | [x] | [x] | [x] | |
| Supported board targets | 46 CI targets | 42+ | 4 | 1 |
| Full LVGL graphical UI | [x] | |||
| Web dashboard / REST control | [x] | [x] | ||
| Captive portal web server | [x] | [x] | [x] | [x] |
| AP / station WiFi scanning | [x] | [x] | [x] | [x] |
| Deauth / disassoc testing | [x] | [x] | [x] | [x] |
| Beacon spam | [x] | [x] | [x] | [x] |
| Karma / probe response attack | [x] | [x] | [x] | |
| Handshake / EAPOL capture | [x] | [x] | [x] | |
| On-device PCAP browser / hc22000 export | [x] | |||
| PMKID capture / export | [x] | [x] | ||
| Live Wireshark USB streaming | [x] | |||
| SAE flood / WPA3-specific testing | [x] | |||
| WPA3 compliance checker | [x] | |||
| EAPOL logoff attack | [x] | |||
| Channel switch attack | [x] | |||
| GTK abuse / client isolation testing | [x] | |||
| DHCP starvation | [x] | [x] | ||
| ARP / port / SSH scanners | [x] | [x] | ||
| mDNS discovery | [x] | |||
| NetBIOS scanner | [x] | |||
| HTTP banner scanner | [x] | |||
| SNMP probe | [x] | |||
| WiFi OUI vendor lookup | [x] | [x] | [x] | |
| PineAP / Evil Twin detection | [x] | [x] | ||
| WPS detection / reporting | [x] | [x] | ||
| Pwnagotchi-style automated capture mode | [x] | [x] | ||
| Pwnagotchi detector / spam | [x] | [x] | ||
| Channel congestion analysis | [x] | [x] | ||
| Live WiFi packet monitor / visualizer | [x] | [x] | [x] | |
| WiFi Airspace Monitor | [x] | |||
| DNS sinkhole / blocklist NXDOMAIN | [x] | |||
| GPS WiFi wardriving | [x] | [x] | [x] | |
| BLE wardriving | [x] | [x] | [x] | |
| WiGLE upload integration | [x] | [x] | ||
| 802.15.4 capture and PCAP export | [x] | |||
| GhostLink dual-ESP control | [x] | |||
| GhostLink BLE bridge to Android | [x] | |||
| Split-channel wardriving helper | [x] | |||
| GhostLink remote radio support | [x] | |||
| Drone / OpenDroneID detect | [x] | [x] | ||
| Drone / OpenDroneID spoof | [x] | [x] | ||
| BLE scanning | [x] | [x] | [x] | [x] |
| Raw BLE scanner | [x] | |||
| BLE spam modes | [x] | [x] | [x] | [x] |
| AirTag scan / spoof | [x] | [x] | [x] | [x] |
| BLE tracker detection tools | [x] | [x] | [x] | |
| Flipper Zero finder | [x] | [x] | ||
| GATT / service enumeration | [x] | [x] | ||
| BLE device tracking by RSSI | [x] | |||
| BLE stream to Wireshark | [x] | |||
| BLE skimmer detection | [x] | [x] | ||
| FastPair / pairing exploit research | [x] | [x] | [x] | |
| BLE HID injection / DuckyScript over BLE | [x] | |||
| BLE keyboard mode | [x] | |||
| BLE GATT honeypot / cloned peripheral | [x] | [x] | ||
| BLE vulnerability profiling | [x] | |||
| Flock / surveillance detector | [x] | [x] | [x] | |
| PN532 NFC support | [x] | [x] | [x] | |
| ST25R3916 NFC support | [x] | [x] | ||
| Chameleon Ultra support | [x] | [x] | ||
| Chameleon Ultra BLE control | [x] | [x] | ||
Flipper .nfc import/export | [x] | |||
| Flipper NFC parser collection | [x] | |||
| MIFARE Classic default-key attack | [x] | [x] | [x] | |
| MIFARE Classic embedded dictionary | [x] | |||
| MIFARE Classic user dictionary file | [x] | [x] | ||
| MIFARE Classic session key reuse / sector sweep | [x] | |||
| MIFARE Classic hardnested recovery | [x] | |||
| PicoPass / iCLASS reading | [x] | |||
| MIFARE DESFire application / file tree reads | [x] | |||
| EMV / payment card reader | [x] | [x] | ||
| BadUSB / DuckyScript | [x] | [x] | ||
| USB keyboard host mode | [x] | |||
| USB HID keyboard output mode | [x] | [x] | ||
| Remote keyboard over dual-device link | [x] | |||
| BadUSB VID/PID identity options | [x] | [x] | ||
| BadUSB mouse jiggler / trackpad | [x] | |||
| IR learn / capture / replay | [x] | [x] | ||
Flipper .ir file support | [x] | [x] | ||
| Universal IR library transmit | [x] | [x] | ||
| CC1101 SubGHz scan / replay | [x] | [x] | [x] | |
| CC1101 waterfall spectrum analyzer | [x] | [x] | [x] | |
Flipper .sub read/write support | [x] | [x] | [x] | [x] |
| SubGHz protocol decoders | [x] | [x] | [x] | |
| NRF24 spectrum analyzer | [x] | [x] | [x] | [x] |
| NRF24 MouseJack | [x] | [x] | ||
| Passive jamming detection | [x] | [x] | ||
| Active RF jamming shipped | Not shipped | [x] | [x] | [x] |
| Zigbee / 802.15.4 packet capture | [x] | |||
| Ethernet W5500 support | [x] | [x] | ||
| Ethernet ARP poisoning / MITM tools | [x] | [x] | ||
| Ethernet fingerprint / port / ping tools | [x] | |||
| Ethernet DNS / NTP / HTTP / trace tools | [x] | |||
| TLS SNI / HTTP / FTP credential capture over Ethernet | [x] | |||
| Camera streaming / motion detection | [x] | |||
| Motion alerts with webhook support | [x] | |||
| Network printer / PJL output | [x] | |||
| DIAL / Chromecast testing | [x] | |||
| On-device setup wizard | [x] | |||
| PIN / password lock | [x] | [x] | [x] | |
| On-device OTA / SD firmware update | [x] | [x] | ||
| Firmware verification / rollback protection | [x] | |||
| GhostLink peer firmware update | [x] | |||
| Wired screen mirroring | [x] | [x] | ||
| Web screen mirroring | [x] | [x] | ||
| SD config backup / restore | [x] | |||
| SD file manager / browser | [x] | [x] | [x] | |
| Native SD app/plugin system | [x] | |||
| Native app SDK / build tooling | [x] | |||
| Sandboxed on-device scripting runtime | Lua 5.4 | JavaScript | ||
| Cloud app / script / asset store | [x] | |||
| Apps gallery / launcher | [x] | |||
| Ghostchi / virtual pet | [x] | [x] | ||
| Audio player | [x] | [x] | ||
| Microphone spectrum / visualizer | [x] | [x] | ||
| RGB LED visualizer modes | [x] | [x] | ||
| Clock / RTC screen | [x] | [x] | ||
| Compass screen | [x] | |||
| Accelerometer screen | [x] | |||
| ENV-III temperature / humidity / pressure | [x] | |||
| Battery monitoring / fuel gauge support | [x] | [x] | [x] | |
| Sensor / RTC hardware support | [x] | [x] | ||
| M5 Cardputer keyboard support | [x] | [x] | ||
| Android companion app | [x] | |||
| Accessibility modes / reduced motion | [x] | [x] | ||
| Custom theme / UI palette system | [x] | [x] | [x] | |
| Custom SD asset packs | [x] | |||
| LoRa support | [x] | |||
| FM radio support | [x] |
GhostESP does not ship active jamming features. Distribution, promotion, sale and use of jamming devices or firmware is illegal in many jurisdictions.
![]() JustCallMeKoKo ESP32Marauder foundational development |
![]() thibauts CastV2 protocol insights |
![]() MarcoLucidi01 DIAL protocol integration |
![]() SpacehuhnTech Reference deauthentication code |
![]() Spooks4576 Original GhostESP Developer |
![]() Tototo31 Large contributions to the project |
![]() WillyJL Core Flipper Firmware functionality and BLE Spam code |
![]() Flipper Zero firmware Core IR & NFC implementation (flipperdevices/flipperzero-firmware & contributors) |
![]() Garag Core NFC library |
![]() connornishijima SensoryBridge - MIC RGB visualizer algorithms & inspiration |
![]() DarkFlippers Flipper Zero Unleashed firmware (SubGHz protocol decoders) |
![]() xMasterX Flipper Zero Unleashed SubGHz improvements |
![]() DecentLabs officeAir - multi-pass ARP scanning & lwIP thread-safety techniques |
![]() jaylikesbunda Project maintainer |
![]() Play2BReal WiGLE upload & IO expander support |
![]() the1anonlypr3 Art and assets |
![]() Billi-Green Audio & ENV-III sensor support |
![]() Next-Flip Momentum-Firmware - NFC parser base (EMV, DESFire, hardnested, transit parsers; Gallagher by Nick Mooney) |
![]() noproto MIFARE Classic hardnested / nested recovery |
![]() Leptopt1los EMV payment-card parser |
![]() bettse picopass - PicoPass / iCLASS support |
![]() micolous Opal transit card parser |
![]() emilytrau myki transit card parser |
![]() holiman loclass - MIFARE key recovery algorithms |
![]() RfidResearchGroup proxmark3 - RFID research tooling |