Tagged: wifi

FliteGrid: A Crowdsourced Drone Detection Network That Pays Feeders US$50 A Month

Thank you, Chris, for writing in and sharing news about the recent launch of FliteGrid's hex claiming scheme. FlightGrid is a crowdsourced drone-tracking network that will pay feeders in an eligible hex grid $50 a month to run a drone-detection sensor. Chris explains:

The US government is building out Unmanned Traffic Management (UTM), which will be the equivalent of air traffic control for drones. This will make it possible to automate things like shipping, emergency response, infrastructure inspections, and more all over the country. To do that, they'll need awareness of every drone in the sky just like they have for every plane today, and FliteGrid is our solution to providing it.

The devices themselves are custom sensors that receive Remote ID transmissions. That's the standard the FAA created for drones to transmit identifying information, which it now requires all drones in America to broadcast. Serial number, location, altitude, operator location, etc. Remote ID can be broadcast on four different protocols, so we've got four receivers in each piece of hardware; two WiFi and two Bluetooth. That data is then uploaded onto the SkySafe platform, which provides a realtime map of every drone in the sky.

The catch to getting paid is that you need to 1) pay a $100 refundable deposit to receive their hardware, and 2) place and run it in a hex grid that offers to pay. The paying hex grids are mostly around US airports and critical infrastructure right now, so you'd need to live in, or have access to a roof in those areas to host the device. Payment is given in USDC, a stablecoin cryptocurrency pegged to the US dollar.

FliteGrid Hexes: Red - Claimed, Green - Available to claim with $50 p/m payout, Purple - Requested by community, Black - Requestable.
FliteGrid Hexes: Red - Claimed, Green - Available to claim with $50 p/m payout, Purple - Requested by community, Black - Requestable.

FliteGrid/SkySafe is able to pay users because operators of critical infrastructure and large facilities such as airports, universities, energy infrastructure, the US military, DHS, and the DOD will pay for real-time awareness of the airspace above them. SkySafe has been around since 2015, has raised around $50M in funding, and has contracts with many of the previously listed organizations. Chris notes that the service has already been used successfully in operations like busting gangs smuggling drugs into prisons via drones. 

The FliteGrid sensor appears to be a computing device with WiFi and Bluetooth radios repurposed to detect Remote ID, with each radio connected to a higher-gain external antenna. Recently, on the blog, we have seen DIY Remote ID detectors made from ESP32s and other commodity Bluetooth hardware.

Since a 2024 mandate, drones over 249 g in the USA must transmit Remote ID signals for tracking and identification purposes, similar to how ADS-B is used for larger aircraft. For ADS-B, flight aggregation services such as FlightAware/FlightRadar24/ADS-B Exchange etc. already exist, with volunteer feeders setting up stations that can cover up to 400km. However, unlike ADS-B, Remote ID is transmitted with single-digit milliwatts of power, compared to a minimum of 70W for ADS-B, so its reception range is limited, making a dense distributed reception network like SkySafe for Remote ID very important. Individual SkySafe hex grids cover just under 1km of area. 

FliteGrid cannot detect drones that are not transmitting Remote ID, though Chris mentions that government infrastructure and facilities may use normal radar to detect these. A radar detection that does not correlate with a SkySafe detection would confirm that a drone is a potential threat.

The FliteGrid Sensor
The FliteGrid Sensor

ESPsoup: Turn an ESP32-C5 into a 2.4 & 5 GHz Pocket Scanner with a Connected Phone or PC

Thank you to Peter Holzhauser for writing in and sharing with us his latest open-source project, 'ESPsoup'. Peter has written in previously to share his Android app, V2X2MAP, which detects and plots vehicle V2X (car-to-car) communications used by some modern cars. His new project, ESPsoup, combines an ESP32-C5 and a connected PC or phone into a fully featured scanner for the 2.4 GHz and 5 GHz bands.

ESPsoup has various features including a live spectrum view up to 80 MHz wide, a sweep mode to monitor larger bandwidths, a GPS-enabled heatmapping tool, Bluetooth analysis tools, an AirTag detector, WiFI analysis tools, a car-to-car V2X monitor, a smart home sensor reader, a drone remote ID detector, a microwave oven detector, and an analog FPV video demodulator and display.

The website notes that if you want to monitor multiple FPV drone video channels, up to eight ESP32-C5s have been tested to work together on a single USB hub connected to a PC.

Peter notes that he is planning to add RTL-SDR support to ESPsoup in approximately two weeks, so keep an eye out on their website for updates.

ESPsoup screenshots from a mobile device.
ESPsoup screenshots from a mobile device.

Automating Indoor RF Heatmapping with a PlutoSDR, Raspberry Pi 5 and LiDAR SLAM

Researchers at Tokyo City University in Japan recently showed in an academic paper how indoor mapping via LiDAR SLAM (simultaneous localization and mapping) and SDR can be combined to generate accurate indoor RF heatmaps. Mapping WiFi reception in indoor spaces can be challenging because accurate indoor localization is often lacking (GPS doesn't work), so it is usually done through manual measurements.

In this system, the researchers used a Raspberry Pi with a LiDAR sensor and Google Cartographer SLAM running on a connected PC to automatically locate and map out the indoor space. At the same time, a PlutoSDR measures the WiFi SNR. The result is a relative SNR WiFi heatmap.

They then derive a 3D model from the collected LiDAR SLAM data and put it into an RF ray-tracing simulation. Finally, they compared their real-world results with the ray-tracing simulation and found the results matched.

Combining LiDAR SLAM + WiFi SNR Measurements for Indoor Signal Strength Mapping
Combining LiDAR SLAM + WiFi SNR Measurements for Indoor Signal Strength Mapping

ESP32 Bit Pirate Updates: New LoRa and Meshtastic Analysis Features

Back in September 2025, we posted about the "ESP32 Bus Pirate" firmware, which transforms an ESP32-S3 into a multi-protocol debugging and hacking tool. We later covered an update in March 2026 that added waterfall displays, cellular modem support, and an external radio expander.

Although the ESP32 does not have true SDR capabilities, it can leverage its numerous built-in radio hardware components to achieve a range of interesting SDR-like features. Recently, "Geo," the creator of the ESP32 Bus Pirate, wrote in to share some recent firmware updates with us.

Geo notes that the project is now called "ESP32 Bit Pirate" and now includes LoRa/SX1262 support and Meshtastic analysis features.

ESP32 Bit Pirate can now transmit and receive LoRa packets, monitor RSSI, scan frequency activity, display a simple waterfall view and perform Channel Activity Detection. Radio parameters including frequency, bandwidth, spreading factor, coding rate, transmit power, preamble and sync word can be configured directly from the interface.

Packets can also be recorded to the ESP32 filesystem and replayed later together with their original radio configuration.

A dedicated Meshtastic analysis shell has also been added, allowing users to send, receive and inspect Meshtastic packets. The goal is not to replace a Meshtastic node, but to provide a debugging and experimentation interface for understanding and interacting with LoRa/Meshtastic traffic.

The latest update has also added new LoRa hardware support for the Heltec Vision Master T190 and Heltec WiFi LoRa 32 V4, a browser-based debugging ecosystem, a Python scripting lab, and a BPIO2 USB adapter mode.

The project is entirely open source, and the code can be found on their GitHub page.

ESP32 Bit Pirate LoRa Support Added
ESP32 Bit Pirate LoRa Support Added

ESP32 Bus Pirate: Update Brings Waterfall Displays, Cellular Modem Support and External Radio Expander

Back in September 2025, we posted about the "ESP32 Bus Pirate" firmware, which transforms an ESP32-S3 into a multi-protocol debugging and hacking tool. Although the ESP32 does not have true SDR capabilities, it can leverage its numerous built-in radio hardware components to achieve a range of interesting feats. Recently, "Geo," the creator of the ESP32 Bus Pirate, wrote in to share some recent firmware updates with us. He writes:

The ESP32-Bus-Pirate project is an open-source firmware that transforms inexpensive ESP32-S3 boards into versatile hardware hacking and debugging tools. Inspired by tools like the Bus Pirate and Flipper Zero, the firmware allows a single ESP32 device to interact with a wide range of digital buses, radios, and hardware interfaces.

Because ESP32 boards include integrated WiFi and Bluetooth radios and can interface with many external modules, the firmware makes it possible to experiment with both hardware protocols and RF systems using very low-cost hardware.

The firmware currently supports a wide range of protocols and devices including:

I²C, SPI, UART, CAN, 1-Wire, infrared, smartcards, Sub-GHz radios, RF24 modules, WiFi, Bluetooth and cellular modems.

Major New Features in v1.5

The latest release adds several major capabilities useful for hardware analysis and RF experimentation.

Waterfall Spectrum Displays

Multiple RF modules can now display real-time waterfall visualizations, showing signal peaks and activity across frequencies. This is available for:

• Sub-GHz radios
• RF24 modules
• FM radio modules
• WiFi channel activity

This makes it easier to visually monitor RF environments directly from the device.

Sub-GHz Improvements

The Sub-GHz subsystem has been completely reworked for improved reliability when recording, replaying and receiving RF frames. Raw payload transmission is also supported.

Cellular Modem Support

ESP32-Bus-Pirate can now interact with cellular modem modules, allowing users to inspect modem and network information and perform operations such as:

• Dumping SIM card data
• sending SMS
• dialing calls

External Radio Expander

The firmware now supports an **external UART radio expansion module** called the **ESP32 Bus Expander**, which allows adding additional RF hardware modules to the system, notably for the WiFi 5GHz.

Links

Project:
https://github.com/geo-tp/ESP32-Bus-Pirate

Web Flasher:
https://geo-tp.github.io/ESP32-Bus-Pirate/webflasher/

Documentation:
https://github.com/geo-tp/ESP32-Bus-Pirate/wiki

Scripts collection:
https://github.com/geo-tp/ESP32-Bus-Pirate-Scripts

ESP32 Bus Expander:
https://github.com/geo-tp/ESP32-Bus-Expander

ESP32 Bus Pirate. Left - Running on COTS ESP32-S3 based devices. Right - ESP32 Bus Pirate Interface
ESP32 Bus Pirate. Left - Running on COTS ESP32-S3 based devices. Right - ESP32 Bus Pirate Web Interface

A Discussion on How WiFi Can Be Used To See Through Walls

Earlier in the year on YouTube, Yaniv Hoffman and Occupy The Web haved discussed research showing how Wi-Fi signals can be used to detect and track people through walls. The idea is simple from an RF point of view. Wi-Fi is just radio, and when those signals pass through a room they reflect and scatter off walls, furniture, and human bodies. By analyzing these reflections, it is possible to infer movement and even rough human outlines without placing any hardware inside the room.

Using low-cost SDRs, a standard PC, an NVIDIA GPU, and open-source AI tools like DensePose, researchers can reconstruct basic 3D human shapes in real time. In some cases, the system does not even need to transmit its own signal. It can passively analyze reflections from an existing Wi-Fi router already operating in the home.

The speakers note that this raises obvious privacy concerns. While there are some benign uses like motion-based home security or monitoring breathing in elderly care, the same techniques could be misused. Countermeasures are limited, as Wi-Fi uses spread spectrum techniques that make jamming difficult. 

If you're interested, we posted about something similar in 2015, where USRP radios were being used to detect the presence of people behind walls.

They’re Watching You Through Wi-Fi… And You Have No Idea

halow_scanner: An RTL-SDR Based 802.11aH HaLow Channel Scanner

Over on GitHub we've recently noticed the release of halow_scanner, a Python script that uses an RTL-SDR to scan the 802.11ah (WiFi HaLow) channels in the sub-GHz spectrum to determined which channels have the least noise/interference.

Unlike standard WiFi, which operates outside of the RTL-SDRs range at 2.4 GHz+, 802.11ah operates in the sub-GHz ISM bands, which RTL-SDRs can easily receive.

Use of these lower frequencies gives 802.11ah HaLow excellent signal penetration, making it useful for long-range, low-power IoT devices. With 802.11ah HaLow links, several kilometers can be achieved.

The software's features include:

  • 🔍 Scans all 802.11ah HaLow channels in the US 902-928 MHz band
  • 📊 Supports multiple channel bandwidths: 1, 2, 4, and 8 MHz
  • 📡 Uses RTL-SDR for spectrum analysis
  • 🎯 Identifies the cleanest channel with lowest noise floor
  • 📈 Provides detailed power spectrum measurements
  • ⚡ Fast scanning with averaging for accuracy
Comparison Between regular WiFi and 802.11ah HaLow. Source: https://www.gateworks.com/802-11ah-halow-long-range-low-power-wireless-for-iot/
Comparison Between regular WiFi and 802.11ah HaLow. Source: https://www.gateworks.com/802-11ah-halow-long-range-low-power-wireless-for-iot
 

ESP32 Bus Pirate: Turn your ESP32 into a Multi-Purpose Hacker Tool

Thank you to "Geo" for writing in and sharing with us his open source project called "ESP32-Bus-Pirate" which he thinks might be of interest to those in the RTL-SDR community. The ESP32 is a popular low-cost microcontroller due to the fact that it has WiFi and Bluetooth capabilities built in. Although the ESP32 does not have true SDR capabilities, it can leverage its numerous built-in hardware radio components to achieve various interesting feats. Geo writes:

This firmware turns an inexpensive ESP32-S3 board into a multi-protocol debugging and hacking tool, inspired by the original Bus Pirate and the Flipper Zero.

It currently supports a wide range of protocols and devices, including I²C, SPI, UART, 1-Wire, CAN, infrared, smartcards, and more. It also communicates with radio protocols as Subghz, RFID, RF24, WiFi, Bluetooth.

Compared to existing solutions, the focus is on:

Accessibility — runs on cheap ESP32-S3 hardware (around $7–$10).

Versatility — one device can probe, sniff, and interact with multiple buses.

Extensibility — open-source and modular, making it easy to add new protocol support.

I believe this could be useful for hardware hackers, security researchers, and hobbyists looking for a low-cost, flexible alternative to commercial tools.

With the firmware installed on a compatible ESP32 device, it is possible to create WiFi, Bluetooth, and RF24 sniffers, scanners, and spoofers, as well as perform general sub-GHz and RFID sniffing, scanning, and replay attacks. It also has a host of non-RF capabilities useful for hacking devices.