Title: Scanning Description: Discover and analyze nearby Bluetooth Low Energy devices URL: /latest/ble/scanning/ Version: latest Section: BLE Search index: /search-index.json # Scanning > Discover and analyze nearby Bluetooth Low Energy devices ## On this page - [Scanning for Devices](#scanning-for-devices) - [On-Device UI](#on-device-ui) - [CLI](#cli) - [Detecting Devices (<code>bledetect</code>)](#detecting-devices-bledetect) - [BLE Spam Detector](#ble-spam-detector) - [BLE Skimmer Detection](#ble-skimmer-detection) - [GATT Service Enumeration](#gatt-service-enumeration) - [BLE Advertiser Scan](#ble-advertiser-scan) - [Raw BLE Packet Capture](#raw-ble-packet-capture) - [Lower-Level CLI Scans](#lower-level-cli-scans) - [BLE Bridge and Wardriving](#ble-bridge-and-wardriving) - [Auto-Saving Results](#auto-saving-results) - [Listing and Selecting Devices](#listing-and-selecting-devices) - [List Discovered Devices](#list-discovered-devices) - [Select a Device for Further Action](#select-a-device-for-further-action) - [Notes](#notes) - [Troubleshooting](#troubleshooting) --- Discover nearby BLE devices and gather information about them. You need a Bluetooth-capable GhostESP; BLE scanning is not available on ESP32-S2. Wi-Fi impact: Starting any BLE scan temporarily suspends the GhostNet access point. Wi-Fi services resume automatically once you stop scanning (for example by running stop or pressing Back in the UI). ## Scanning for Devices ### On-Device UI - Open BLE from the main menu. - Choose a scan: Detect Devices, Advertiser Scan, OUI Device Scan, GATT Scan, Aerial Detector, Spam, or Raw. The device will start scanning. Leave it running until you have enough data. - Press Back to stop scanning. Use List Detected Devices or List Advertisers to review results. ### CLI - Open the GhostESP terminal. - Run bledetect to start the tracker/skimmer/beacon scan, or blescan [OPTION] for one of the lower-level scans below. The device will start scanning. - Run bledetect -s or blescan -s when you’re done. The device will stop scanning and show a summary. How a BLE scan works 1 Start scanning`bledetect` for trackers, or `blescan <mode>` for a lower-level scan 2 Capture advertising packetsLegacy advertising plus scan responses 3 Classify and store matchesTracker type, vendor OUI, and service data 4 List or track results`-l` to list, `-t <idx>` to track RSSI 5 Stop`-s` keeps results and the AP returns Starting a BLE scan suspends the GhostNet AP; Wi-Fi resumes when you stop. ## Detecting Devices (bledetect) bledetect is the current on-device Detect Devices scan. It watches advertisements and classifies trackers, skimmers, and beacons. Running bledetect with no argument starts the scan. Flag | Description | -s | Stop the scan, keeping discovered devices | -l | List discovered devices (index, type, name/MAC, RSSI) | -c | Clear results (scan must be stopped first) | -i | Show scan state, device count, and tracking info | -t <idx> | Track a device and log its live RSSI | -u | Stop tracking | -sp <idx> | Spoof a detected AirTag; stopspoof ends it | -h | Show usage | Recognized signatures: AirTag, Flipper, Skimmer Suspect, Tile, SmartTag, Chipolo, AirPods, Apple Watch, FindMy, Fast Pair, Hearing Aid (ASHA), Exposure Beacon (GAEN), and Chameleon (ChameleonUltra). ### BLE Spam Detector - CLI: blescan -ds - Detects active BLE spam attacks from nearby devices. Useful for testing whether your own spam is visible or detecting hostile spam. ### BLE Skimmer Detection - CLI: capture -skimmer - Scans for payment terminal skimmers that use BLE to exfiltrate card data. - Logs detected skimmers to a PCAP file for analysis. - There is no skimmer entry in the BLE menu; bledetect also flags suspected skimmers as Skimmer Suspect. ### GATT Service Enumeration - UI: BLE → GATT Scan - CLI: blescan -g - Connect to BLE devices and discover what services they offer (e.g., heart rate, battery level, custom services). - Track devices by signal strength to physically locate them. See the dedicated [GATT Discovery](/latest/ble/gatt/) page for a full walkthrough, command reference, and service UUID tables. ### BLE Advertiser Scan - UI: BLE → Advertiser Scan - CLI: blescan -adv - Passively scans all BLE advertisements, including non-connectable beacons. - Parses common advertisement fields and iBeacon UUID, major, minor, and measured power when present. - Use List Advertisers or CLI listadv to browse parsed results. See the dedicated [Advertiser Scan](/latest/ble/advertisers/) page for details. ### Raw BLE Packet Capture - UI: BLE → Raw → Raw BLE Scanner - CLI: blescan -r - Captures raw BLE packets for offline analysis. Useful for debugging BLE protocol issues. ### Lower-Level CLI Scans - blescan -oui <prefix> - advertiser scan filtered to an OUI prefix (for example blescan -oui 00:1A:2B). UI: BLE → OUI Device Scan → Enter OUI Prefix. - blescan -vendor <vendor> - advertiser scan filtered to a vendor name. UI: BLE → OUI Device Scan → Search Vendors. - blescan -f - scans for nearby Flipper Zero devices; list with listflippers. - blescan -a - AirTag scanner using active scanning; list with listairtags. - capture -ble / capture -wiresharkble - BLE packet capture for offline and Wireshark analysis. ## BLE Bridge and Wardriving - blebridge [start|stop|status|pair <peer_name>] - BLE bridge to a paired GhostESP peer. - blewardriving (stop with blewardriving -s) - log BLE observations to the wardriving CSV. - dualwd [start|-s] - Wi-Fi and BLE wardriving together; requires a PSRAM device. ## Auto-Saving Results When auto_save_scans is enabled (the default), list commands write their results to /mnt/ghostesp/scans/<mode>_<n>.txt on the SD card, auto-incrementing <n>. For example listadv writes ble_advertisers_<n>.txt and listgatt writes gatt_scan_<n>.txt. ## Listing and Selecting Devices After scanning, you can interact with discovered devices: ### List Discovered Devices - Detected devices: BLE → List Detected Devices or CLI bledetect -l - Advertisers: BLE → List Advertisers or CLI listadv - GATT devices: CLI listgatt (also available as List GATT Devices) - Flippers: CLI listflippers - AirTags: CLI listairtags ### Select a Device for Further Action - Detected device: track with bledetect -t <index> (stop with bledetect -u), or spoof a detected AirTag with bledetect -sp <index>. - Flipper: CLI selectflipper <index> continuously tracks and displays the Flipper’s RSSI (signal strength). Use this to locate the Flipper by moving around and watching the signal strength change. - AirTag: CLI selectairtag <index> (prepares for spoofing). - GATT device: CLI selectgatt <index>, then enumgatt to discover its GATT services, or trackgatt to locate it using real-time signal strength updates. Flipper and AirTag items are not part of the BLE menu; on-device they live under the GhostLink BLE submenu. ## Notes - BLE scans share one radio: starting a new scan retargets the radio, but other modes’ active flags and handlers are not fully reset, so stop the current scan (blescan -s / bledetect -s) before starting a different one. - Signal strength (RSSI) is displayed in dBm; higher values (closer to 0) indicate stronger signals. - Advertiser scan stores up to 64 advertisers when PSRAM is available, otherwise 32. - GATT scan stores up to 20 devices, each with up to 8 services. - Some devices may not respond to all scanning modes depending on their BLE implementation. ## Troubleshooting - No devices found: Move closer to BLE devices and try scanning again. - Scanning stops immediately: Check that your device has Bluetooth enabled. - Device not responding: Some devices may be in sleep mode or have BLE disabled. Try scanning again or move closer.