
Escáner de Bluetooth Low Energy (BLE) con resolución de direcciones privadas resolubles (RPA) mediante claves de resolución de identidad (IRKs)
Un escáner Bluetooth Low Energy (BLE) con resolución avanzada de direcciones privadas resolubles (RPA). Descubre dispositivos BLE cercanos, rastrea un dispositivo específico por dirección MAC o resuelve direcciones aleatorizadas por privacidad mediante una clave de resolución de identidad (IRK).
Escrito por: David Kennedy (@HackingDave) Empresa: TrustedSec
-o -)El etiquetado de ubicación GPS requiere que el daemon gpsd esté en ejecución con un receptor GPS conectado. Si gpsd no está en ejecución, btrpa-scan continúa con normalidad sin GPS.
| Plataforma | Instalación | Inicio |
|---|---|---|
| macOS | brew install gpsd | gpsd -n /dev/tty.usbserial-* |
| Debian/Ubuntu | sudo apt install gpsd gpsd-clients | sudo systemctl start gpsd |
| Fedora/RHEL | sudo dnf install gpsd gpsd-clients | sudo systemctl start gpsd |
| Arch | sudo pacman -S gpsd | sudo systemctl start gpsd |
| Windows | Usa gpsd mediante WSL o MSYS2 | Consulta las instrucciones de WSL anteriores |
Para verificar que gpsd funciona:
# Check that gpsd is listening
gpspipe -w -n 5
# Or use the curses monitor
cgps
| Plataforma | Notas |
|---|---|
| macOS | Usa CoreBluetooth. El modo IRK aprovecha una API no documentada para obtener direcciones Bluetooth reales en lugar de UUIDs. --active no tiene efecto — CoreBluetooth siempre escanea de forma activa. |
| Linux | Puede requerir root o la capacidad CAP_NET_ADMIN para escanear. |
| Windows | API Bluetooth WinRT nativa — direcciones MAC reales disponibles de forma nativa. La TUI requiere pip install windows-curses. |
Este proyecto usa pyproject.toml (PEP 621), el estándar moderno de empaquetado de Python. Define el proyecto como un paquete instalable con un comando CLI registrado — no es necesario ejecutar archivos .py directamente.
uvx btrpa-scan --all
uvx --from git+https://github.com/hackingdave/btrpa-scan.git btrpa-scan --all
uv tool install btrpa-scan
O directamente desde GitHub:
uv tool install git+https://github.com/hackingdave/btrpa-scan.git
pip install btrpa-scan
Para soporte de GUI (interfaz de radar basada en Flask):
pip install btrpa-scan[gui]
git clone https://github.com/hackingdave/btrpa-scan.git
cd btrpa-scan
pip install .
usage: btrpa-scan [-h] [-a] [--irk HEX] [--irk-file PATH] [-t TIMEOUT]
[--output {csv,json,jsonl}] [-o FILE] [--log FILE]
[-v | -q] [--min-rssi DBM] [--rssi-window N] [--active]
[--environment {free_space,indoor,outdoor}]
[--ref-rssi DBM] [--name-filter PATTERN]
[--alert-within METERS] [--tui] [--gui] [--gui-port PORT]
[--no-gps] [--adapters LIST] [mac]
BLE Scanner — discover all devices or hunt for a specific one
positional arguments:
mac Target MAC address to search for (omit to scan all)
optional arguments:
-h, --help show this help message and exit
-a, --all Scan for all broadcasting devices
--irk HEX Resolve RPAs using this Identity Resolving Key (32 hex chars)
--irk-file PATH Read IRK(s) from a file (one per line, hex format)
-t, --timeout TIMEOUT Scan timeout in seconds (default: 30, or infinite for --irk)
--output {csv,json,jsonl}
Batch output format written at end of scan
-o, --output-file FILE
Output file path (default: btrpa-scan-results.<format>;
use - for stdout)
--log FILE Stream detections to a CSV file in real time
-v, --verbose Verbose mode — show additional details
-q, --quiet Quiet mode — suppress per-device output, show summary only
--min-rssi DBM Minimum RSSI threshold (e.g. -70) — ignore weaker signals
--rssi-window N RSSI sliding window size for averaging (default: 1 = no averaging)
--active Use active scanning (sends SCAN_REQ for additional data)
--environment {free_space,indoor,outdoor}
Distance estimation path-loss model (default: free_space)
--ref-rssi DBM Calibrated RSSI at 1 metre for distance estimation
--name-filter PATTERN Filter devices by name (case-insensitive substring match)
--alert-within METERS Proximity alert when device is within this distance
--tui Live-updating terminal table instead of scrolling output
--gui Launch web-based radar interface in the browser
--gui-port PORT Port for GUI web server (default: 5000)
--no-gps Disable GPS location stamping (GPS is on by default via gpsd)
--adapters LIST Comma-separated Bluetooth adapter names (e.g. hci0,hci1)