Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Sniffle — Bluetooth 5 and 4.x LE sniffer for TI CC1352/CC26x2 hardware with support for extended advertising, all PHY modes, MAC/RSSI filtering, and PCAP export compatible with Wireshark. | Kitploit
Tools/GitHubGitHub/nccgroup/sniffle
Embedded Systems SecurityPacket Sniffing & AnalysisBluetooth SecurityNetwork MappingWireless SecurityHardware HackingHardware SecurityHardware & IoT SecurityTop in Bluetooth Security #4Top in Hardware Hacking #16
1.2k1621521 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Top in Hardware & IoT Security #15
Top in Hardware Security #18
GitHubnccgroup/sniffle

Sniffle

Bluetooth 5 and 4.x LE sniffer for TI CC1352/CC26x2 hardware with support for extended advertising, all PHY modes, MAC/RSSI filtering, and PCAP export compatible with Wireshark.

View RepositoryWebsite

Sniffle

Sniffle is a sniffer for Bluetooth 5 and 4.x (LE) using TI CC1352/CC26x2 hardware.

Sniffle has a number of useful features, including:

  • Support for BT5/4.2 extended length advertisement and data packets
  • Support for BT5 Channel Selection Algorithms #1 and #2
  • Support for all BT5 PHY modes (regular 1M, 2M, and coded modes)
  • Support for sniffing only advertisements and ignoring connections
  • Support for channel map, connection parameter, and PHY change operations
  • Support for advertisement filtering by MAC address and RSSI
  • Support for BT5 extended advertising (non-periodic)
  • Support for capturing advertisements from a target MAC on all three primary advertising channels using a single sniffer. This makes connection detection nearly 3x more reliable than most other sniffers that only sniff one advertising channel.
  • Easy to extend host-side software written in Python
  • PCAP export compatible with the Ubertooth
  • Wireshark compatible plugin

Prerequisites

  • Any of the following hardware devices (functionally equivalent for Sniffle)
    • TI CC26x2R Launchpad Board: https://www.ti.com/tool/LAUNCHXL-CC26X2R1
    • TI CC2652RB Launchpad Board: https://www.ti.com/tool/LP-CC2652RB
    • TI CC1352R Launchpad Board: https://www.ti.com/tool/LAUNCHXL-CC1352R1
    • TI CC1352P Launchpad Board: https://www.ti.com/tool/LAUNCHXL-CC1352P
    • TI CC2652R7 Launchpad Board: https://www.ti.com/tool/LP-CC2652R7
    • TI CC1352P7 Launchpad Board: https://www.ti.com/tool/LP-CC1352P7
    • TI CC2651P3 Launchpad Board: https://www.ti.com/tool/LP-CC2651P3
    • TI CC1354P10 Launchpad Board: https://www.ti.com/tool/LP-EM-CC1354P10
    • SONOFF CC2652P USB Dongle Plus: https://itead.cc/product/sonoff-zigbee-3-0-usb-dongle-plus/
    • EC Catsniffer V3 CC1352 & RP2040 https://github.com/ElectronicCats/CatSniffer
  • ARM GNU Toolchain for AArch32 bare-metal target (arm-none-eabi): https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads
  • TI SimpleLink Low Power F2 SDK 8.30.01.01: https://www.ti.com/tool/download/SIMPLELINK-LOWPOWER-F2-SDK/8.30.01.01
  • TI DSLite Programmer Software: see below
  • Python 3.9+ with PySerial installed

If you don't want to go through the effort of setting up a build environment for the firmware, you can just flash prebuilt firmware binaries using UniFlash/DSLite. Prebuilt firmware binaries are attached to releases on the GitHub releases tab of this project. When using prebuilt firmware, be sure to use the Python code corresponding to the release tag rather than master to avoid compatibility issues with firmware that is behind the master branch.

Installing GCC

The arm-none-eabi-gcc provided through various Linux distributions' package manager often lacks some header files or requires some changes to linker configuration. For minimal hassle, I suggest using the ARM GCC linked above. You can just download and extract the prebuilt executables.

Installing the TI SDK

The TI SDK is provided as an executable binary that extracts a bunch of source code once you accept the license agreement. On Linux and Mac, the default installation directory is inside~/ti/. This works fine and my makefiles expect this path, so I suggest just going with the default here. The same applies for the TI SysConfig tool.

Once the SDK has been extracted, you will need to edit one makefile to match your build environment. Within ~/ti/simplelink_cc13xx_cc26xx_sdk_8_30_01_01 (or wherever the SDK was installed) there is a makefile named imports.mak. The only paths that need to be set here to build Sniffle are for GCC, XDC, cmake and SysConfig. We don't need the CCS compiler. See the diff below as an example, and adapt for wherever you installed things.

diff --git a/imports.mak b/imports.mak
index b2cf5bf59..389d1a7c3 100644
--- a/imports.mak
+++ b/imports.mak
@@ -18,14 +18,14 @@
 # will build using each non-empty *_ARMCOMPILER cgtool.
 #
 
-XDC_INSTALL_DIR        ?= /home/username/ti/xdctools_3_62_01_15_core
-SYSCONFIG_TOOL         ?= /home/username/ti/ccs1270/ccs/utils/sysconfig_1.21.1/sysconfig_cli.sh
+XDC_INSTALL_DIR        ?= $(HOME)/ti/xdctools_3_62_01_15_core
+SYSCONFIG_TOOL         ?= $(HOME)/ti/sysconfig_1.21.1/sysconfig_cli.sh
 
-CMAKE                  ?= /home/username/cmake-3.21.3/bin/cmake
+CMAKE                  ?= cmake
 PYTHON                 ?= python3
 
 TICLANG_ARMCOMPILER    ?= /home/username/ti/ccs1270/ccs/tools/compiler/ti-cgt-armllvm_3.2.2.LTS-0
-GCC_ARMCOMPILER        ?= /home/username/arm-none-eabi-gcc/12.3.Rel1-0
+GCC_ARMCOMPILER        ?= $(HOME)/arm_tools/arm-gnu-toolchain-14.3.rel1-x86_64-arm-none-eabi
 IAR_ARMCOMPILER        ?= /home/username/iar9.50.2
 
 # Uncomment this to enable the TFM build

As of SDK version 8.30.01.01, to compile with recent versions of GCC (and binutils), a small modification to the SDK is needed to avoid linking errors "Unknown destination type (ARM/Thumb)" and "dangerous relocation: unsupported relocation".

diff --git a/kernel/tirtos7/packages/ti/sysbios/family/arm/m3/Hwi_asm_gcc.s b/kernel/tirtos7/packages/ti/sysbios/family/arm/m3/Hwi_asm_gcc.s
index 187cfd744..4cbf0d384 100644
--- a/kernel/tirtos7/packages/ti/sysbios/family/arm/m3/Hwi_asm_gcc.s
+++ b/kernel/tirtos7/packages/ti/sysbios/family/arm/m3/Hwi_asm_gcc.s
@@ -236,6 +236,7 @@ lab$1:
 @ user code has set the PRIMASK and not cleared it, or when single
 @ stepping with interrupts disabled.
 
+.type ti_sysbios_family_arm_m3_Hwi_interruptsAreDisabledButShouldNotBe, %function
 ti_sysbios_family_arm_m3_Hwi_interruptsAreDisabledButShouldNotBe:
         b   ti_sysbios_family_arm_m3_Hwi_interruptsAreDisabledButShouldNotBe
 
diff --git a/kernel/tirtos7/packages/ti/sysbios/family/arm/v8m/Hwi_asm_gcc.s b/kernel/tirtos7/packages/ti/sysbios/family/arm/v8m/Hwi_asm_gcc.s
index 717f49c9a..1c83ed725 100644
--- a/kernel/tirtos7/packages/ti/sysbios/family/arm/v8m/Hwi_asm_gcc.s
+++ b/kernel/tirtos7/packages/ti/sysbios/family/arm/v8m/Hwi_asm_gcc.s
@@ -226,6 +226,7 @@ lab$1:
 @ user code has set the PRIMASK and not cleared it, or when single
 @ stepping with interrupts disabled.
 
+.type ti_sysbios_family_arm_v8m_Hwi_interruptsAreDisabledButShouldNotBe, %function
 ti_sysbios_family_arm_v8m_Hwi_interruptsAreDisabledButShouldNotBe:
         b   ti_sysbios_family_arm_v8m_Hwi_interruptsAreDisabledButShouldNotBe

After making this modification, you will need to recompile the SDK.

cd ~/ti/simplelink_cc13xx_cc26xx_sdk_8_30_01_01
make build-gcc -j5

Obtaining DSLite

DSLite is TI's command line programming and debug server tool for XDS110 debuggers. The CC26xx and CC13xx Launchpad boards both include XDS110 debuggers. Unfortunately, TI does not provide a standalone command line DSLite download. The easiest way to obtain DSLite is to install UniFlash from TI. It's available for Linux, Mac, and Windows. The DSLite executable will be located at deskdb/content/TICloudAgent/linux/ccs_base/DebugServer/bin/DSLite relative to the UniFlash installation directory. On Linux, the default UniFlash installation directory is inside ~/ti/.

You should place the DSLite executable directory within your $PATH.

Firmware Building

Once the GCC, DSLite, and the SDK is installed and operational, building Sniffle should be straight forward. Just navigate to the fw directory and run make. If you didn't install the SDK to the default directory, you may need to edit SIMPLELINK_SDK_INSTALL_DIR in the makefile.

If building for or installing on a some variant of Launchpad other than CC26x2R, you must specify PLATFORM=xxx, either as an argument to make, or by defining it as an environment variable prior to invoking make. Supported values for PLATFORM can be found in the firmware makefile. Be sure to perform a make clean before building for a different platform.

Firmware Installation (TI Launchpad Board)

Download Tool