
Next-Gen GUI-based WiFi and Bluetooth Analyzer for Linux
Sparrow-WiFi is a 2.4 GHz and 5 GHz WiFi and Bluetooth spectral awareness tool for Linux. It integrates WiFi scanning, Bluetooth Low Energy and Classic discovery, software-defined radio spectrum analysis (HackRF, Ubertooth), GPS tracking, FAA RemoteID drone detection, drone/rover-mounted remote operations, and ECS 8.17 indexing into Elasticsearch or OpenSearch into a single platform. Written entirely in Python 3.
The project includes four components that work standalone or together:
| Component | Interface | Purpose |
|---|---|---|
| Sparrow-WiFi | PyQt5 desktop GUI | WiFi/BT scanning, spectrum analysis, source tracking, wardriving |
| Sparrow Agent | Headless HTTP server | Remote scanning, drone/rover deployments, third-party integration |
| Sparrow DroneID | Web-based (browser) | FAA RemoteID drone detection via WiFi and Bluetooth LE |
| Sparrow Elastic Bridge | Headless CLI service | ECS 8.17 indexing of WiFi/BT observations into Elasticsearch / OpenSearch |
The Sparrow Agent and Sparrow DroneID expose JSON REST APIs that allow other applications to query scan results, trigger scans, retrieve drone detections, and integrate wireless/drone awareness into their own workflows. The Elastic Bridge consumes the agent's REST API and ships ECS 8.17 documents with bundled Kibana dashboards.
This release covers three significant improvements over the prior version:
/wireless/networks/<iface> simultaneously, the agent previously kicked off N redundant iw scan calls that serialized on the per-interface lock, multiplying scan latency by the number of clients. The first request is now the "leader" that actually scans; concurrent requests wait on a threading.Event and share the leader's result. Also includes lock-creation TOCTOU fix and exception-safety on per-interface locks.droneid.* namespace), and a multi-device responsive web UI. See the Sparrow DroneID section below.sparrow-elastic.py bridge has been rewritten to produce ECS 8.17 documents (was ECS 1.5), now supports both Elasticsearch 8.x and OpenSearch 2.x, bootstraps composable index templates with ILM/ISM lifecycle policies and rollover write aliases automatically, performs OUI vendor enrichment and rule-based device classification (with optional Fingerbank fingerprinting), and ships four bundled Kibana dashboards plus six legacy-preserved visualizations. The legacy ECS 1.5 bridge is preserved at legacy/sparrow-elastic.py. See Elasticsearch / OpenSearch Integration.The original Sparrow application provides a comprehensive GUI-based replacement for tools like inSSIDer and LinSSID, with capabilities well beyond basic scanning:
sparrowwifiagent.py) for distributed scanning, drone/rover-mounted operations, and Raspberry Pi deploymentsiw scan output
A standalone web-based drone detection and tracking system that decodes FAA-mandated Remote Identification (RemoteID) broadcasts. Runs as a Python HTTP server with a browser-based UI accessible from any device on the network.
Web UI runs at http://localhost:8097 once started. See Installation below for setup, and the API reference for programmatic access.
In addition to Slack webhooks, Sparrow DroneID can POST each fired alert to a generic external alert-ingest endpoint. The channel is disabled by default; configure it in Settings → Alerts → API-Based Alerting: