Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
sparrow-wifi — Next-Gen GUI-based WiFi and Bluetooth Analyzer for Linux | Kitploit
Tools/GitHubGitHub/ghostop14/sparrow-wifi
OSINT (Open Source Intelligence)ReconnaissanceWi-Fi AuditingBluetooth SecurityNetwork MappingInformation GatheringWireless SecurityLog Analysis
GitHubghostop14/sparrow-wifi

sparrow-wifi

Next-Gen GUI-based WiFi and Bluetooth Analyzer for Linux

View Repository
1.6k190331 day agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Sparrow-WiFi

Sparrow-WiFi is a 2.4 GHz and 5 GHz WiFi and Bluetooth spectral awareness tool for Linux. It integrates WiFi scanning, Bluetooth Low Energy and Classic discovery, software-defined radio spectrum analysis (HackRF, Ubertooth), GPS tracking, FAA RemoteID drone detection, drone/rover-mounted remote operations, and ECS 8.17 indexing into Elasticsearch or OpenSearch into a single platform. Written entirely in Python 3.

The project includes four components that work standalone or together:

ComponentInterfacePurpose
Sparrow-WiFiPyQt5 desktop GUIWiFi/BT scanning, spectrum analysis, source tracking, wardriving
Sparrow AgentHeadless HTTP serverRemote scanning, drone/rover deployments, third-party integration
Sparrow DroneIDWeb-based (browser)FAA RemoteID drone detection via WiFi and Bluetooth LE
Sparrow Elastic BridgeHeadless CLI serviceECS 8.17 indexing of WiFi/BT observations into Elasticsearch / OpenSearch

The Sparrow Agent and Sparrow DroneID expose JSON REST APIs that allow other applications to query scan results, trigger scans, retrieve drone detections, and integrate wireless/drone awareness into their own workflows. The Elastic Bridge consumes the agent's REST API and ships ECS 8.17 documents with bundled Kibana dashboards.


What's New (April 2026)

This release covers three significant improvements over the prior version:

  • Sparrow Agent: single-flight WiFi scan coalescing. When multiple HTTP clients (the DroneID app, the Elasticsearch bridge, the GUI) hit /wireless/networks/<iface> simultaneously, the agent previously kicked off N redundant iw scan calls that serialized on the per-interface lock, multiplying scan latency by the number of clients. The first request is now the "leader" that actually scans; concurrent requests wait on a threading.Event and share the leader's result. Also includes lock-creation TOCTOU fix and exception-safety on per-interface locks.
  • Sparrow DroneID — new web-based application for FAA RemoteID detection via WiFi (ASTM F3411 NAN, beacon vendor IEs, DJI's proprietary DroneID protocol) and Bluetooth LE (BT4/BT5 Legacy advertising). Includes geozone overlays, multi-state alerts with Slack integration, KML export, Cursor-on-Target output, optional ECS 8.17 indexing to Elasticsearch / OpenSearch (with a custom droneid.* namespace), and a multi-device responsive web UI. See the Sparrow DroneID section below.
  • Modernized Elasticsearch / OpenSearch bridge — the sparrow-elastic.py bridge has been rewritten to produce ECS 8.17 documents (was ECS 1.5), now supports both Elasticsearch 8.x and OpenSearch 2.x, bootstraps composable index templates with ILM/ISM lifecycle policies and rollover write aliases automatically, performs OUI vendor enrichment and rule-based device classification (with optional Fingerbank fingerprinting), and ships four bundled Kibana dashboards plus six legacy-preserved visualizations. The legacy ECS 1.5 bridge is preserved at legacy/sparrow-elastic.py. See Elasticsearch / OpenSearch Integration.

Sparrow-WiFi (Desktop GUI)

The original Sparrow application provides a comprehensive GUI-based replacement for tools like inSSIDer and LinSSID, with capabilities well beyond basic scanning:

  • WiFi scanning — 2.4 GHz and 5 GHz SSID discovery, signal strength, channel utilization
  • Source tracking — Hunt mode with high sample rates and telemetry windows for locating WiFi and Bluetooth sources
  • Spectrum analysis — Real-time 2.4/5 GHz spectral overlays via Ubertooth One or HackRF One
  • Bluetooth — BLE advertisement scanning, iBeacon detection/advertising, Ubertooth promiscuous mode for classic + LE
  • Remote agent — Headless agent (sparrowwifiagent.py) for distributed scanning, drone/rover-mounted operations, and Raspberry Pi deployments
  • GPS integration — gpsd, static coordinates, or MAVLink (drone GPS)
  • Mapping — Google Maps / OpenStreetMap visualization of scan results with GPS tracks
  • Import/Export — CSV, JSON, and raw iw scan output
  • Elasticsearch / OpenSearch — ECS 8.17 compliant indexing of WiFi and Bluetooth scan data with ILM/ISM lifecycle management, device classification, optional Fingerbank fingerprinting, and bundled Kibana dashboards
  • Falcon plugin — Aircrack-ng integration for penetration testing (monitor mode, hidden SSID discovery, deauth, WEP/WPA capture)

Screenshots


Sparrow DroneID (Web Application)

A standalone web-based drone detection and tracking system that decodes FAA-mandated Remote Identification (RemoteID) broadcasts. Runs as a Python HTTP server with a browser-based UI accessible from any device on the network.

Capabilities

  • WiFi capture — Decodes ASTM F3411 NAN action frames, beacon vendor IEs, and DJI proprietary DroneID
  • Bluetooth LE capture — Decodes ASTM F3411 BT4/BT5 Legacy advertising (UUID 0xFFFA)
  • Real-time map — Leaflet-based map with quadcopter icons, heading indicators, operator position markers, and drone-to-operator lines
  • At-a-glance labels — Operator ID and altitude AGL displayed under each drone icon on the map
  • Detail popups — Click a drone for serial, registration ID, operator ID, type, speed, heading, altitude, bearing/range from receiver, BVLOS status
  • Alert system — Configurable alerts for new drones, altitude violations, speed violations, and signal loss with audio tones, visual toasts, Slack webhook notifications, and optional bearer-token JSON POSTs to a generic external alert-ingest API (see API-Based Alerting below)
  • Alert acknowledgment — Three-state workflow (Active/Acknowledged/Resolved) with operator identity, shared across all connected devices
  • Airport geozones — Automatic download and display of nearby airports (OurAirports data) and FAA Prohibited/Restricted airspace polygons, cached locally for offline operation
  • GPS — gpsd integration or configurable static coordinates
  • History & replay — SQLite-backed detection history with timeline replay and KML export
  • Cursor-on-Target (CoT) — Multicast CoT output for SA integration
  • Multi-device — Web UI works on desktop, tablet, and phone simultaneously
  • Metric / Imperial — Full unit preference support throughout the UI and alerts

Web UI runs at http://localhost:8097 once started. See Installation below for setup, and the API reference for programmatic access.

API-Based Alerting

In addition to Slack webhooks, Sparrow DroneID can POST each fired alert to a generic external alert-ingest endpoint. The channel is disabled by default; configure it in Settings → Alerts → API-Based Alerting:

Download Tool