Scanning

Discover and analyze nearby Bluetooth Low Energy devices

On this page

Discover nearby BLE devices and gather information about them. You need a Bluetooth-capable GhostESP; BLE scanning is not available on ESP32-S2.

Wi-Fi impact: Starting any BLE scan temporarily suspends the GhostNet access point. Wi-Fi services resume automatically once you stop scanning (for example by running stop or pressing Back in the UI).

Scanning for Devices

On-Device UI

  1. Open BLE from the main menu.
  2. Choose a scan: Detect Devices, Advertiser Scan, OUI Device Scan, GATT Scan, Aerial Detector, Spam, or Raw. The device will start scanning. Leave it running until you have enough data.
  3. Press Back to stop scanning. Use List Detected Devices or List Advertisers to review results.

CLI

  1. Open the GhostESP terminal.
  2. Run bledetect to start the tracker/skimmer/beacon scan, or blescan [OPTION] for one of the lower-level scans below. The device will start scanning.
  3. Run bledetect -s or blescan -s when you’re done. The device will stop scanning and show a summary.
How a BLE scan works
1 Start scanning`bledetect` for trackers, or `blescan <mode>` for a lower-level scan
2 Capture advertising packetsLegacy advertising plus scan responses
3 Classify and store matchesTracker type, vendor OUI, and service data
4 List or track results`-l` to list, `-t <idx>` to track RSSI
5 Stop`-s` keeps results and the AP returns

Starting a BLE scan suspends the GhostNet AP; Wi-Fi resumes when you stop.

Detecting Devices (bledetect)

bledetect is the current on-device Detect Devices scan. It watches advertisements and classifies trackers, skimmers, and beacons. Running bledetect with no argument starts the scan.

FlagDescription
-sStop the scan, keeping discovered devices
-lList discovered devices (index, type, name/MAC, RSSI)
-cClear results (scan must be stopped first)
-iShow scan state, device count, and tracking info
-t <idx>Track a device and log its live RSSI
-uStop tracking
-sp <idx>Spoof a detected AirTag; stopspoof ends it
-hShow usage

Recognized signatures: AirTag, Flipper, Skimmer Suspect, Tile, SmartTag, Chipolo, AirPods, Apple Watch, FindMy, Fast Pair, Hearing Aid (ASHA), Exposure Beacon (GAEN), and Chameleon (ChameleonUltra).

BLE Spam Detector

  • CLI: blescan -ds
  • Detects active BLE spam attacks from nearby devices. Useful for testing whether your own spam is visible or detecting hostile spam.

BLE Skimmer Detection

  • CLI: capture -skimmer
  • Scans for payment terminal skimmers that use BLE to exfiltrate card data.
  • Logs detected skimmers to a PCAP file for analysis.
  • There is no skimmer entry in the BLE menu; bledetect also flags suspected skimmers as Skimmer Suspect.

GATT Service Enumeration

  • UI: BLE → GATT Scan
  • CLI: blescan -g
  • Connect to BLE devices and discover what services they offer (e.g., heart rate, battery level, custom services).
  • Track devices by signal strength to physically locate them.

See the dedicated GATT Discovery page for a full walkthrough, command reference, and service UUID tables.

BLE Advertiser Scan

  • UI: BLE → Advertiser Scan
  • CLI: blescan -adv
  • Passively scans all BLE advertisements, including non-connectable beacons.
  • Parses common advertisement fields and iBeacon UUID, major, minor, and measured power when present.
  • Use List Advertisers or CLI listadv to browse parsed results.

See the dedicated Advertiser Scan page for details.

Raw BLE Packet Capture

  • UI: BLE → Raw → Raw BLE Scanner
  • CLI: blescan -r
  • Captures raw BLE packets for offline analysis. Useful for debugging BLE protocol issues.

Lower-Level CLI Scans

  • blescan -oui <prefix> - advertiser scan filtered to an OUI prefix (for example blescan -oui 00:1A:2B). UI: BLE → OUI Device Scan → Enter OUI Prefix.
  • blescan -vendor <vendor> - advertiser scan filtered to a vendor name. UI: BLE → OUI Device Scan → Search Vendors.
  • blescan -f - scans for nearby Flipper Zero devices; list with listflippers.
  • blescan -a - AirTag scanner using active scanning; list with listairtags.
  • capture -ble / capture -wiresharkble - BLE packet capture for offline and Wireshark analysis.

BLE Bridge and Wardriving

  • blebridge [start|stop|status|pair <peer_name>] - BLE bridge to a paired GhostESP peer.
  • blewardriving (stop with blewardriving -s) - log BLE observations to the wardriving CSV.
  • dualwd [start|-s] - Wi-Fi and BLE wardriving together; requires a PSRAM device.

Auto-Saving Results

When auto_save_scans is enabled (the default), list commands write their results to /mnt/ghostesp/scans/<mode>_<n>.txt on the SD card, auto-incrementing <n>. For example listadv writes ble_advertisers_<n>.txt and listgatt writes gatt_scan_<n>.txt.

Listing and Selecting Devices

After scanning, you can interact with discovered devices:

List Discovered Devices

  • Detected devices: BLE → List Detected Devices or CLI bledetect -l
  • Advertisers: BLE → List Advertisers or CLI listadv
  • GATT devices: CLI listgatt (also available as List GATT Devices)
  • Flippers: CLI listflippers
  • AirTags: CLI listairtags

Select a Device for Further Action

  • Detected device: track with bledetect -t <index> (stop with bledetect -u), or spoof a detected AirTag with bledetect -sp <index>.
  • Flipper: CLI selectflipper <index> continuously tracks and displays the Flipper’s RSSI (signal strength). Use this to locate the Flipper by moving around and watching the signal strength change.
  • AirTag: CLI selectairtag <index> (prepares for spoofing).
  • GATT device: CLI selectgatt <index>, then enumgatt to discover its GATT services, or trackgatt to locate it using real-time signal strength updates.

Flipper and AirTag items are not part of the BLE menu; on-device they live under the GhostLink BLE submenu.

Notes

  • BLE scans share one radio: starting a new scan retargets the radio, but other modes’ active flags and handlers are not fully reset, so stop the current scan (blescan -s / bledetect -s) before starting a different one.
  • Signal strength (RSSI) is displayed in dBm; higher values (closer to 0) indicate stronger signals.
  • Advertiser scan stores up to 64 advertisers when PSRAM is available, otherwise 32.
  • GATT scan stores up to 20 devices, each with up to 8 services.
  • Some devices may not respond to all scanning modes depending on their BLE implementation.

Troubleshooting

  • No devices found: Move closer to BLE devices and try scanning again.
  • Scanning stops immediately: Check that your device has Bluetooth enabled.
  • Device not responding: Some devices may be in sleep mode or have BLE disabled. Try scanning again or move closer.