Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitLabGitLab/sacriphanius/zhilly
Embedded Systems SecurityReconnaissanceIoT SecurityPayload GenerationRFID/NFC ToolsWireless SecurityHardware HackingPenetration TestingRed Teaming
GitLabsacriphanius/zhilly

Zhilly

View Repository
11541 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

🛡️ AI-powered portable cybersecurity & pentesting assistant built on ESP32-S3 (LilyGO T-Embed CC1101 & T-Watch S3). Features voice-controlled RF jamming, BadUSB/HID emulation, IR replay, Sub-GHz signal capture, NFC tools, ARP/port scanning, and animated eye display. Powered by XiaoZhi AI framework.

Website
Share

Zhilly Web Flasher

AI Pentester Assistant

🛡️ Zhilly AI Pentester Assistant

AI-Powered, Portable Cyber Security & Cyber Interaction Tool
Yapay Zeka Destekli, Taşınabilir Siber Güvenlik ve Siber Etkileşim Aracı

🇬🇧 English • 🇹🇷 Türkçe • ⚡ Web Flasher

Total Visitors


🇬🇧 English / English Version

📖 About the Project

This project is an advanced AI Pentester Assistant based on the Xiaozhi-esp32 (小智) infrastructure, optimized for the LilyGO T-Embed CC1101 hardware. It combines natural language AI interaction with physical hardware testing tools, making it a versitile companion for cybersecurity research and daily technical tasks.

🚀 Key Features

🤖 AI & Interaction

  • Natural Conversation: Speak to your assistant using the wake word "Nihao Miaoban". It listens, learns, and responds in natural language.
  • Emote Display: High-quality eye animations on the ST7789 display provide emotional feedback and status indicators (listening, thinking, speaking).

📰 Smart News (News API)

  • Fetch the latest global or local headlines via voice commands.
    • Example: "Tell me the latest technology news" or "What's the news in Turkey?"
  • Integrated via the news.get_top_headlines tool using NewsAPI.

📡 RF & IR Pentest Tools

Complete control over Sub-GHz and Infrared spectrums:

  • RF Jammer: Start/Stop signal jamming on specific Sub-GHz frequencies.
  • RF Replay (Test): Re-transmit .sub files stored on your SD card.
  • IR Jammer: Disrupt and evaluate infrared-controlled devices.
  • TV-B-Gone: Universal remote off-codes to switch off nearby TVs.
  • IR Replay (Test): Record and re-transmit infrared signals.
  • RAW Capture: Capture Sub-GHz signals with microsecond precision.
  • SD Card Storage: Save captured signals to the SD card for later use.

⌨️ Bad USB & HID (AI-Powered Voice Commands Only)

  • Keyboard Emulation: Your assistant can act as a standard USB keyboard when connected to a computer.
  • Voice-Driven Support: Run automated keystroke scripts (DuckyScript) stored on the SD card exclusively via AI voice commands. No manual interface is provided, ensuring a hands-free pentesting experience.
    • Voice Command: "Run BadUSB script 'hello_world.txt'" or "Type this: 'I am your AI assistant'".
  • HID Tools: Fully integrated via usb.bad_usb_run, usb.bad_usb_type, and usb.bad_usb_stop tools.

⌚ LilyGO T-Watch S3 Exclusive Features

Specifically built for the T-Watch S3, Zhilly includes the following tools without needing a connected computer:

  • High-Speed ARP Scanner: Sweeps your subnet using direct Layer-2 ARP table inspection to instantly uncloak hidden network devices (IoT, secure cameras) along with their physical MAC Addresses.
    • Voice Command: "Scan the network for devices"
  • Port Scanner: Performs rapid concurrent select() TCP checks on the top 21 vulnerable/administration ports of a target IP.
    • Voice Command: "Scan ports on 192.168.1.10"
  • DNS Resolver: Converts website domains directly into physical IPv4 addresses on the watch display.
  • IR Hacking: Transmit TV-B-Gone kill codes (NA/EU) or initiate directed Infrared parrasite Jamming directly from the watch.
    • Voice Command: "Turn off the TV" or "Start the IR jammer"
  • OTA Upgrade & Power: Update the watch firmware via URL or perform software reboots entirely through voice chat.

🌍 Supported Keyboard Layouts

You can set the keyboard language via voice command (e.g. "Set keyboard layout to Turkish").

#LanguageCodeVoice Command Example
1🇺🇸 English (US)en_US"Set layout to English"
2🇬🇧 English (UK)en_UK"Set layout to English UK"
3🇹🇷 Turkishtr_TR"Set layout to Turkish"
4🇩🇪 Germande_DE"Set layout to German"
5🇫🇷 Frenchfr_FR"Set layout to French"
6🇪🇸 Spanishes_ES"Set layout to Spanish"
7🇮🇹 Italianit_IT"Set layout to Italian"
8🇵🇹 Portuguese (BR)pt_BR"Set layout to Portuguese Brazil"
9🇵🇹 Portuguese (PT)pt_PT"Set layout to Portuguese"
10🇩🇰 Danishda_DK"Set layout to Danish"
11🇸🇪 Swedishsv_SE"Set layout to Swedish"
12🇭🇺 Hungarianhu_HU"Set layout to Hungarian"
13🇸🇮 Sloveniansi_SI"Set layout to Slovenian"

Default layout: en_US — The layout resets to US English after each session.

🌈 LED Strip & Visual Effects

Control the 8x WS2812 RGB LED ring:

  • Dynamic Control: Set colors, brightness (0-8), and animations like Blink or Scroll.
    • Voice Command: "Make the LEDs blue and set brightness to max."

🔋 System & Power

  • Battery Status: Ask about battery level or charging status.
  • Deep Sleep: Long-press the Power (PWR) button to enter deep sleep for maximum battery saving.
  • Brightness Control: Voice-adjust screen and LED intensity.

🛠️ Installation & Flashing

Zhilly Web Flasher

Flash directly from your browser via Google Chrome / MS Edge using the Zhilly Web Flasher, or manually write the firmware binaries using EspTool.py below:

# Flash the ready-made firmware using EspTool.py:
esptool.py -p /dev/ttyACM0 -b 460800 write_flash 0x0 flash_binaries/xiaozhi.bin 0x0800000 flash_binaries/expression_assets.bin

IMPORTANT : Please Enter This Prompt in your devices Role Introduction

Download Tool