Scanning
Discover and analyze nearby Bluetooth Low Energy devices
On this page
Discover nearby BLE devices and gather information about them. You need a Bluetooth-capable GhostESP; BLE scanning is not available on ESP32-S2.
Wi-Fi impact: Starting any BLE scan temporarily suspends the GhostNet access point. Wi-Fi services resume automatically once you stop scanning (for example by running
stopor pressing Back in the UI).
Scanning for Devices
On-Device UI
- Open BLE from the main menu.
- Choose a scan: Detect Devices, Advertiser Scan, OUI Device Scan, GATT Scan, Aerial Detector, Spam, or Raw. The device will start scanning. Leave it running until you have enough data.
- Press Back to stop scanning. Use List Detected Devices or List Advertisers to review results.
CLI
- Open the GhostESP terminal.
- Run
bledetectto start the tracker/skimmer/beacon scan, orblescan [OPTION]for one of the lower-level scans below. The device will start scanning. - Run
bledetect -sorblescan -swhen you’re done. The device will stop scanning and show a summary.
Starting a BLE scan suspends the GhostNet AP; Wi-Fi resumes when you stop.
Detecting Devices (bledetect)
bledetect is the current on-device Detect Devices scan. It watches advertisements and classifies trackers, skimmers, and beacons. Running bledetect with no argument starts the scan.
| Flag | Description |
|---|---|
-s | Stop the scan, keeping discovered devices |
-l | List discovered devices (index, type, name/MAC, RSSI) |
-c | Clear results (scan must be stopped first) |
-i | Show scan state, device count, and tracking info |
-t <idx> | Track a device and log its live RSSI |
-u | Stop tracking |
-sp <idx> | Spoof a detected AirTag; stopspoof ends it |
-h | Show usage |
Recognized signatures: AirTag, Flipper, Skimmer Suspect, Tile, SmartTag, Chipolo, AirPods, Apple Watch, FindMy, Fast Pair, Hearing Aid (ASHA), Exposure Beacon (GAEN), and Chameleon (ChameleonUltra).
BLE Spam Detector
- CLI:
blescan -ds - Detects active BLE spam attacks from nearby devices. Useful for testing whether your own spam is visible or detecting hostile spam.
BLE Skimmer Detection
- CLI:
capture -skimmer - Scans for payment terminal skimmers that use BLE to exfiltrate card data.
- Logs detected skimmers to a PCAP file for analysis.
- There is no skimmer entry in the BLE menu;
bledetectalso flags suspected skimmers as Skimmer Suspect.
GATT Service Enumeration
- UI: BLE → GATT Scan
- CLI:
blescan -g - Connect to BLE devices and discover what services they offer (e.g., heart rate, battery level, custom services).
- Track devices by signal strength to physically locate them.
See the dedicated GATT Discovery page for a full walkthrough, command reference, and service UUID tables.
BLE Advertiser Scan
- UI: BLE → Advertiser Scan
- CLI:
blescan -adv - Passively scans all BLE advertisements, including non-connectable beacons.
- Parses common advertisement fields and iBeacon UUID, major, minor, and measured power when present.
- Use List Advertisers or CLI
listadvto browse parsed results.
See the dedicated Advertiser Scan page for details.
Raw BLE Packet Capture
- UI: BLE → Raw → Raw BLE Scanner
- CLI:
blescan -r - Captures raw BLE packets for offline analysis. Useful for debugging BLE protocol issues.
Lower-Level CLI Scans
blescan -oui <prefix>- advertiser scan filtered to an OUI prefix (for exampleblescan -oui 00:1A:2B). UI: BLE → OUI Device Scan → Enter OUI Prefix.blescan -vendor <vendor>- advertiser scan filtered to a vendor name. UI: BLE → OUI Device Scan → Search Vendors.blescan -f- scans for nearby Flipper Zero devices; list withlistflippers.blescan -a- AirTag scanner using active scanning; list withlistairtags.capture -ble/capture -wiresharkble- BLE packet capture for offline and Wireshark analysis.
BLE Bridge and Wardriving
blebridge [start|stop|status|pair <peer_name>]- BLE bridge to a paired GhostESP peer.blewardriving(stop withblewardriving -s) - log BLE observations to the wardriving CSV.dualwd [start|-s]- Wi-Fi and BLE wardriving together; requires a PSRAM device.
Auto-Saving Results
When auto_save_scans is enabled (the default), list commands write their results to /mnt/ghostesp/scans/<mode>_<n>.txt on the SD card, auto-incrementing <n>. For example listadv writes ble_advertisers_<n>.txt and listgatt writes gatt_scan_<n>.txt.
Listing and Selecting Devices
After scanning, you can interact with discovered devices:
List Discovered Devices
- Detected devices: BLE → List Detected Devices or CLI
bledetect -l - Advertisers: BLE → List Advertisers or CLI
listadv - GATT devices: CLI
listgatt(also available as List GATT Devices) - Flippers: CLI
listflippers - AirTags: CLI
listairtags
Select a Device for Further Action
- Detected device: track with
bledetect -t <index>(stop withbledetect -u), or spoof a detected AirTag withbledetect -sp <index>. - Flipper: CLI
selectflipper <index>continuously tracks and displays the Flipper’s RSSI (signal strength). Use this to locate the Flipper by moving around and watching the signal strength change. - AirTag: CLI
selectairtag <index>(prepares for spoofing). - GATT device: CLI
selectgatt <index>, thenenumgattto discover its GATT services, ortrackgattto locate it using real-time signal strength updates.
Flipper and AirTag items are not part of the BLE menu; on-device they live under the GhostLink BLE submenu.
Notes
- BLE scans share one radio: starting a new scan retargets the radio, but other modes’ active flags and handlers are not fully reset, so stop the current scan (
blescan -s/bledetect -s) before starting a different one. - Signal strength (RSSI) is displayed in dBm; higher values (closer to 0) indicate stronger signals.
- Advertiser scan stores up to 64 advertisers when PSRAM is available, otherwise 32.
- GATT scan stores up to 20 devices, each with up to 8 services.
- Some devices may not respond to all scanning modes depending on their BLE implementation.
Troubleshooting
- No devices found: Move closer to BLE devices and try scanning again.
- Scanning stops immediately: Check that your device has Bluetooth enabled.
- Device not responding: Some devices may be in sleep mode or have BLE disabled. Try scanning again or move closer.
