
Сканер Bluetooth Low Energy (BLE) с разрешением Resolvable Private Address (RPA) с использованием Identity Resolving Keys (IRKs)
A Bluetooth Low Energy (BLE) scanner with advanced Resolvable Private Address (RPA) resolution. Discover nearby BLE devices, track a specific device by MAC address, or resolve privacy-randomized addresses using an Identity Resolving Key (IRK).
Written by: David Kennedy (@HackingDave) Company: TrustedSec
-o -)Для привязки GPS-координат требуется запущенный демон gpsd с подключённым GPS-приёмником. Если gpsd не запущен, btrpa-scan продолжает работу без GPS.
| Платформа | Установка | Запуск |
|---|---|---|
| macOS | brew install gpsd | gpsd -n /dev/tty.usbserial-* |
| Debian/Ubuntu | sudo apt install gpsd gpsd-clients | sudo systemctl start gpsd |
| Fedora/RHEL | sudo dnf install gpsd gpsd-clients | sudo systemctl start gpsd |
| Arch | sudo pacman -S gpsd | sudo systemctl start gpsd |
| Windows | Используйте gpsd через WSL или MSYS2 | См. инструкции для WSL выше |
Чтобы проверить, что gpsd работает:
# Check that gpsd is listening
gpspipe -w -n 5
# Or use the curses monitor
cgps
| Платформа | Примечания |
|---|---|
| macOS | Использует CoreBluetooth. Режим IRK использует недокументированный API для получения реальных Bluetooth-адресов вместо UUID. --active не действует — CoreBluetooth всегда выполняет активное сканирование. |
| Linux | Для сканирования могут потребоваться права root или возможность CAP_NET_ADMIN. |
| Windows | Собственный API Bluetooth WinRT — реальные MAC-адреса доступны изначально. Для TUI требуется pip install windows-curses. |
Этот проект использует pyproject.toml (PEP 621) — современный стандарт упаковки Python. Он определяет проект как устанавливаемый пакет с зарегистрированной CLI-командой — нет необходимости запускать .py-файлы напрямую.
uvx btrpa-scan --all
uvx --from git+https://github.com/hackingdave/btrpa-scan.git btrpa-scan --all
uv tool install btrpa-scan
Или напрямую с GitHub:
uv tool install git+https://github.com/hackingdave/btrpa-scan.git
pip install btrpa-scan
Для поддержки графического интерфейса (радар на основе Flask):
pip install btrpa-scan[gui]
git clone https://github.com/hackingdave/btrpa-scan.git
cd btrpa-scan
pip install .
usage: btrpa-scan [-h] [-a] [--irk HEX] [--irk-file PATH] [-t TIMEOUT]
[--output {csv,json,jsonl}] [-o FILE] [--log FILE]
[-v | -q] [--min-rssi DBM] [--rssi-window N] [--active]
[--environment {free_space,indoor,outdoor}]
[--ref-rssi DBM] [--name-filter PATTERN]
[--alert-within METERS] [--tui] [--gui] [--gui-port PORT]
[--no-gps] [--adapters LIST] [mac]
BLE Scanner — discover all devices or hunt for a specific one
positional arguments:
mac Target MAC address to search for (omit to scan all)
optional arguments:
-h, --help show this help message and exit
-a, --all Scan for all broadcasting devices
--irk HEX Resolve RPAs using this Identity Resolving Key (32 hex chars)
--irk-file PATH Read IRK(s) from a file (one per line, hex format)
-t, --timeout TIMEOUT Scan timeout in seconds (default: 30, or infinite for --irk)
--output {csv,json,jsonl}
Batch output format written at end of scan
-o, --output-file FILE
Output file path (default: btrpa-scan-results.<format>;
use - for stdout)
--log FILE Stream detections to a CSV file in real time
-v, --verbose Verbose mode — show additional details
-q, --quiet Quiet mode — suppress per-device output, show summary only
--min-rssi DBM Minimum RSSI threshold (e.g. -70) — ignore weaker signals
--rssi-window N RSSI sliding window size for averaging (default: 1 = no averaging)
--active Use active scanning (sends SCAN_REQ for additional data)
--environment {free_space,indoor,outdoor}
Distance estimation path-loss model (default: free_space)
--ref-rssi DBM Calibrated RSSI at 1 metre for distance estimation
--name-filter PATTERN Filter devices by name (case-insensitive substring match)
--alert-within METERS Proximity alert when device is within this distance
--tui Live-updating terminal table instead of scrolling output
--gui Launch web-based radar interface in the browser
--gui-port PORT Port for GUI web server (default: 5000)
--no-gps Disable GPS location stamping (GPS is on by default via gpsd)
--adapters LIST Comma-separated Bluetooth adapter names (e.g. hci0,hci1)
Сканирование всех передающих BLE-устройств (тайм-аут по умолчанию 30 секунд):
btrpa-scan --all
С собственным тайм-аутом:
btrpa-scan --all -t 60