Phreak Fun — Creative & Research Uses of the C5 Wireless Subsystem
Companion to: Phreak — Wireless AT Command Reference
Device: ESP32-C5 (Phreak) on Ant64 / DeMon
Philosophy: Everything here is receive-only, observation-based, or targeted at equipment you own. The C5 has no frame-injection, no jamming, and no rogue-AP hosting capability by design. "Hacking" here means understanding the invisible world around you — not breaking into someone else's network.
1. The philosophy of ethical RF fun
Phreak is a sensor, not a weapon. It can hear Wi-Fi, BLE, LoRa, and GPS signals, but it cannot shout over them. That constraint is a feature: it forces creativity. Every technique in this document is built from the same observation-only primitives in §12–§15 of the main reference.
The rules:
- Only listen — if it requires transmitting a frame you didn't craft yourself, the C5 can't do it (and this document won't teach it).
- Only your networks — active probing (
AT+PING,AT+CIPSTART) is fine on hardware you own. Never point it at a café, airport, or neighbour. - Share what you learn — RF is a commons; documenting weird behaviour helps everyone.
2. RF Cartography — mapping the invisible city
2.1 Wardriving with AT+CWLAP and AT+GNSSINF
The classic: drive (or walk) around with Ant64, scan Wi-Fi at intervals, and log GPS coordinates. You build a map of every AP in your neighbourhood — SSID, BSSID, channel, RSSI, security, and exact location.
AntOS script: wardrive.lua
-- wardrive.lua — log every AP with its GPS fix.
local phreak = require("phreak")
local gps = require("phreak.gps")
local log = io.open("/sd/wardrive.csv", "a")
log:write("timestamp,lat,lon,ssid,bssid,channel,rssi,security\n")
phreak.wifi_scan(function(ap)
local fix = gps.get_loc() -- polls AT+GNSSLOC
if fix.quality > 0 then
log:write(string.format("%d,%.6f,%.6f,"%s",%s,%d,%d,%s\n",
os.time(), fix.lat, fix.lon,
ap.ssid, ap.bssid, ap.channel, ap.rssi, ap.security))
log:flush()
end
end, 5000) -- scan every 5 seconds
Visualise: Import the CSV into WiGLE or plot it with Python/matplotlib. Colour-code by channel to see how congested 2.4 GHz is in your area.
Why it's fun: You discover APs with hilarious default names, find open networks (on your own property), and see how far your home Wi-Fi really leaks.
2.2 BLE wardriving with AT+BLERECON
Wi-Fi is only half the story. BLE devices are everywhere: fitness trackers, headphones, smart locks, TVs, cars, and those tiny beacons stores use for indoor positioning.
The game: Leave AT+BLERECON=1 running for an hour while you walk through a shopping centre (or your own house). Then dump the log and count:
- How many devices don't randomise their MAC?
- Which manufacturer IDs appear most? (Decode the first 3 bytes of
mfg_data_hex) - Can you spot the same device following you? (That's
AT+MONBLETAGterritory.)
AntOS one-liner:
phreak.ble_recon_log("/sd/ble_safari.log", 3600) -- 1 hour
2.3 Channel heatmap art with AT+WIFIHEATMAP
AT+WIFIHEATMAP isn't just for engineering — it's a way to see radio. Run a 10-minute heatmap in your home, then render the per-channel occupancy as a bar chart or even convert it to audio (sonification: busy channels = higher pitch).
Creative twist: Place Ant64 next to a microwave oven and run AT+WIFIHEATMAP=1,60 while it runs. Watch channel 11 (2.45 GHz) spike as the magnetron leaks into the ISM band. It's a cheap spectrum analyser.
2.4 Dual-band spectrum sweep with AT+LORASCAN
Wi-Fi and BLE only show you the crowded 2.4/5 GHz corners. The LR2021's spectral scan sweeps whole bands — Sub-GHz (868/915 MHz) and 2.4 GHz — and reports RSSI at each step, so you can see the traffic Wi-Fi tools never touch: LoRa nodes, smart meters (W-MBUS), 433/868 MHz remotes and sensors, weather stations, car key fobs, the lot.
-- spectrum.lua — sweep 863–870 MHz in 25 kHz steps
phreak.lora_scan(863000000, 870000000, 25000, function(freq, rssi)
local bar = string.rep("█", math.max(0, rssi + 130))
print(string.format("%.3f MHz %4d %s", freq/1e6, rssi, bar))
end)
Fun with it: leave it sweeping and watch your neighbourhood's Sub-GHz life light up — the doorbell, the weather station, the energy meter phoning home every few seconds. Log it over a day and you have a spectral fingerprint of the street. It's completely receive-only — the same passive-observation ethic as the Wi-Fi survey, on the bands Wi-Fi can't reach.
Sense vs. decode. The LR2021 is a narrowband packet radio, not a wideband SDR — so there are two levels of listening. It can sense energy ("something is transmitting here") anywhere it tunes: 150–960 MHz, 2.4 GHz, and S/L-band. It can only decode its own modulations — LoRa, LR-FHSS, FLRC, (G)FSK, OOK, O-QPSK (802.15.4), BLE PHY, and the built-in Z-Wave / Wireless M-Bus / Wi-SUN framings. Wi-Fi, cellular, DECT and analog FM voice show up as energy but can't be read.
What's out there — D = decodable, S = sense-only:
| Band | What lives there | |
|---|---|---|
| 433 / 315 MHz | key fobs, garage & doorbell remotes, TPMS, weather stations, thermometers | D |
| 868 / 915 MHz | LoRa / LoRaWAN, Meshtastic, smart meters (W-MBUS), Z-Wave home automation | D |
| 138–470 / 929 MHz | pagers (POCSAG / FLEX) | D |
| 2.4 GHz | BLE, Zigbee / Thread, 2.4 GHz LoRa | D |
| 1.5–2.5 GHz | direct-to-satellite LoRa (licensed service) | D |
| ~162 MHz | marine AIS (ship transponders) | S |
| 865–928 MHz | UHF RFID tags | S |
| 150–470 MHz | business / marine / amateur FM voice | S |
| 935–960 MHz | cellular downlink | S |
| 2.4 GHz | Wi-Fi (the C5's job), microwave-oven noise | S |
| 1.88–1.90 GHz | DECT cordless phones | S |
The sweet spot for actually reading things is the 433/868/915 MHz world (the "rtl_433" gadgets) plus the native packet protocols — sweep the band to see what's alive, then decode the ones it speaks.
Stay legal. Ambient ISM beacons — your own gear, the neighbourhood doorbell / weather-station chatter — are fair game to receive. Intercepting cellular, licensed, or encrypted traffic is restricted in most places, which is exactly why this stays receive-only and pointed at open, public transmissions.
3. The Ghost Spectrum — hunting anomalies
3.1 Deauth flood detection as a game
AT+MONDEAUTH turns the C5 into a lightning detector for Wi-Fi attacks. Set it up at home and wait. Most residential areas are quiet, but when someone runs a deauth tool (even accidentally), you'll catch it.
The challenge: Can you correlate a +MONDEAUTH alarm with a real event? e.g.:
- Your neighbour's cheap security camera rebooting (some cameras spam deauths when they lose the AP)
- A misconfigured IoT plug
- A actual attacker (rare, but you'll know immediately)
Script:
-- deauth_watchdog.lua
phreak.on("+MONDEAUTH", function(evt)
local t = os.date("%H:%M:%S", os.time())
print(string.format("[ALERT %s] %d deauths from %s -> %s on ch %d",
t, evt.count, evt.src_addr, evt.dst_addr, evt.channel))
-- snapshot the RF environment for forensics
phreak.channel_score(0)
phreak.rf_logger_snapshot("/sd/deauth_" .. os.time() .. ".log")
end)
phreak.mon_deauth(1, 20, 10) -- threshold 20 in 10s window
3.2 Evil-twin spotting with AT+MONROGUE
After you teach AT+MONROGUECFG your home SSID+BSSID, AT+MONROGUE becomes a burglar alarm for your Wi-Fi identity. If someone clones your SSID (to phish your family), the alarm fires.
Fun experiment: Set it up, then deliberately create a hotspot on your phone with the same SSID as your home router (but different BSSID). Watch the +MONROGUE URC fire within seconds. Now imagine catching a real attacker.
3.3 BLE stalker-tag hunting
AirTags and similar trackers are designed to be stealthy, but they have a tell: they don't randomise their MAC address (or they rotate slowly). AT+MONBLETAG looks for BLE devices that follow you across multiple locations.
The game: Hide a BLE beacon (or an old phone broadcasting iBeacon) in a friend's bag. Walk around with Ant64 for 15 minutes. Can AT+MONBLETAG flag it? Adjust the <threshold_min> down to 5 for faster detection.
Responsible note: Only do this with consent. The same technique protects you from actual stalking devices in the wild.
4. LoRa Playground — long-range whisper net
The LR2021 that Phreak now uses is a LoRa Plus radio — still the classic long-range whisper for the projects below, but also dual-band (it reaches 2.4 GHz), with a high-speed FLRC mode and a real satellite path. The mesh, fox-hunt and tracker ideas work exactly as before on Sub-GHz LoRa; FLRC and satellite open two new playgrounds at the end (§4.4–§4.5).
4.1 LoRa mesh chat
Two (or more) Ant64 units, each with an LR2021 (Wio-LR2021), can form a messaging network with no infrastructure. No towers, no SIM cards, no subscriptions. On plain Sub-GHz LoRa it's a text whisper-net; switch the radio to FLRC (§4.4) and the same mesh can pass small images or voice clips.
Protocol (built on §12 P2P):
- Address
0= broadcast to all - Addresses
1–65534= unicast - Payload = JSON-ish text (hex-encoded):
{"from":"callsign","msg":"hello"}
AntOS chat client:
-- lorachat.lua
local my_addr = 42 -- my node address
local phreak = require("phreak")
phreak.lora_init({band=868000000, sf=9, bw=125, cr=5, addr=my_addr})
-- receive loop
phreak.on("+LORARCV", function(pkt)
local text = hex.decode(pkt.data_hex)
print(string.format("<%04X> %s", pkt.src_addr, text))
end)
-- send loop
while true do
local line = io.read()
if line then
local payload = hex.encode(string.format("{\"from\":\"%04X\",\"msg\":\"%s\"}", my_addr, line))
phreak.lora_send(0, #payload/2, payload) -- broadcast
end
end
Range test: In open countryside with SF12 and +22 dBm, you can reach 5–10 km. In a city with buildings, expect 500 m–2 km. The fun is finding the limits.
4.2 LoRa fox hunting (radio direction finding)
Hide a LoRa beacon (an Ant64 broadcasting +LORARCV every 10 seconds) in a park. Hunters carry another Ant64 running a signal-strength meter:
-- foxhunt.lua
phreak.lora_init({band=868000000, sf=9, bw=125, cr=5, addr=99})
phreak.on("+LORARCV", function(pkt)
if pkt.src_addr == 0xBEEF then -- the fox
local bar = string.rep("█", math.min(20, math.abs(pkt.rssi)))
print(string.format("RSSI %4d %s SNR %2d", pkt.rssi, bar, pkt.snr))
end
end)
Walk around. The RSSI bar grows as you approach. Add a directional antenna (yagi or patch) for serious hunting.
4.3 LoRa weather balloon tracker
Attach an Ant64 + GPS to a high-altitude balloon. It broadcasts its position every 30 seconds via LoRa. A ground station logs the packets and plots altitude vs. time.
Payload format (compact binary, hex-encoded):
<lat_f32><lon_f32><alt_u16><sats_u8>
The ground station decodes +LORARCV data and feeds it to a map. You now have a $50 near-space telemetry tracker. (For reach beyond line-of-sight to your ground station, see the real satellite path in §4.5.)
4.4 FLRC — the fast lane
Plain LoRa trades speed for range: perfect for a text whisper, too slow for much else. The LR2021 adds FLRC (Fast Long-Range Communication) at up to 2.6 Mbps — still long-range and robust, but fast enough to move real payloads. Same mesh, richer traffic:
- Photo drop — snap a low-res JPEG on one node and FLRC it to another a kilometre away. No Wi-Fi, no cell.
- Voice-memo net — a few seconds of compressed audio per message: a walkie-talkie that works past line-of-sight.
- Off-grid file sync — push a firmware image or a DBFS export between two machines over the air.
FLRC is a per-link mode (see Phreak §12.6), so a mesh can stay on slow-and-far LoRa for beacons and drop into FLRC only when two nodes have a good enough link for the fast payload.
4.5 Satellite whisper — off-grid, over the horizon
The LR2021's S-band port gives Phreak something the SX1262 never could: a path to low-earth-orbit satellites (non-terrestrial network / direct-to-satellite). A short status message from the middle of an ocean, a desert, or a dead valley — anywhere with sky but no ground network.
The honest version of this idea:
- It's a licensed-service capability, not free spectrum. S-band satellite links go through licensed satellite-IoT networks (the LoRaWAN-over-satellite operators), not by blasting skyward on your own. Use an appropriate service and follow its rules — the same "only your own links, don't step on anyone else's" ethic the rest of this document runs on, applied to spectrum that's very much spoken for.
- What it's brilliant for: an off-grid check-in beacon — a hiker, a boat, or a remote sensor firing one tiny "I'm here, I'm OK, here's my GPS fix" packet on a schedule, logged when a satellite passes overhead.
- Pair it with the GPS clock (§6.1) and the tracker (§4.3) and you have a genuinely autonomous off-grid node: it knows where it is, knows the time, and can say so to orbit.
4.6 RF trilateration — positioning without GPS
The LR2021 adds RTToF ranging (AT+LORARANGE): it measures the round-trip flight time to another node and turns it into a distance. One measurement gives you a radius; three fixed anchor nodes give you a position — indoors, underground, anywhere GPS can't reach.
The setup: three Ant64 units at known, fixed positions (the anchors). A fourth (the tag) ranges against each in turn and solves for where it is:
-- trilaterate.lua (tag side)
local anchors = { [1]={x=0,y=0}, [2]={x=10,y=0}, [3]={x=5,y=8} }
local d = {}
for id in pairs(anchors) do
d[id] = phreak.lora_range(id) -- metres to that anchor
end
local pos = trilaterate(anchors, d) -- least-squares solve
print(string.format("You are at (%.1f, %.1f) m", pos.x, pos.y))
Where it shines: asset tracking in a workshop, a museum-style "which room am I in" guide, a warehouse robot that knows its aisle, or a treasure hunt where the prize's position is computed, not hidden. Accuracy depends on bandwidth and multipath, but even a few metres is enough for room-level location. It also upgrades §4.2's fox hunt from "warmer / colder" to an actual coordinate.
4.7 Personal LoRa-to-BLE gateway
The Ant64's two radios meet inside one controller, so it can bridge them: a sensor a kilometre away talks to the LR2021 over LoRa, and the Ant64 re-broadcasts each reading over BLE to your phone in the room. Off-grid range on one side, everyday convenience on the other.
Because the bridge lives in the C5 firmware (see Phreak §16), you set it up with a couple of AT commands and it then runs itself — no polling loop, no script in the hot path:
AT+BRIDGEADD=LORA,LRBLE, -> +BRIDGEADD: 1
AT+BRIDGEMAP=1,PASS
AT+BRIDGE=1,1 -> now forwarding LoRa -> BLE
Any LoRa packet the LR2021 hears is re-advertised over BLE; point a phone's BLE scanner at it and your distant sensor shows up like a local beacon. Flip the endpoints (AT+BRIDGEADD=BLE,LORA,…) and you can push a phone's message out over long-range LoRa instead.
Where it goes next: the C5 buffers readings in its own PSRAM so a burst or a briefly-absent phone doesn't drop anything (DBFS on DeMon only comes in when you want them to survive a power-cut), or fan one LoRa feed out to BLE and an MQTT topic over Wi-Fi at once — a little off-grid-to-internet bridge. It's only as broad as the stacks underneath (LoRa↔BLE first; Zigbee and friends follow), but even LoRa↔BLE is genuinely useful on day one.
5. BLE Safari — the zoo of invisible devices
5.1 iBeacon treasure hunt
Place iBeacon transmitters (or phones running beacon apps) around a building. Players use AT+BLEIBEACONSCAN=1 and hunt for specific UUIDs. When the UUID matches a clue, the player gets the next coordinate.
Educational twist: Each beacon broadcasts a different URL via Eddystone-URL. Players collect URLs to build a scavenger-hunt story.
5.2 BLE device fingerprinting
Every BLE chip has quirks: advertisement interval, manufacturer data format, service UUIDs, TX power. AT+BLERECON logs enough to fingerprint devices.
Challenge: Got two identical devices — say your headphones and a friend's same model, with their say-so? Can you tell them apart from the BLE advertisement pattern alone? Plot RSSI over time — the set you're wearing shows a strong, consistent signal; the other stays weak and intermittent.
5.3 Contact-tracing research (your own devices)
Apple/Google exposure-notification beacons rotate their RPI (Rolling Proximity Identifier) every 15 minutes, but the MAC address also rotates. However, the timing and payload structure are distinctive. AT+BLERECON can log these frames (anonymised) to study how many exposure-notification devices are nearby.
Important: Do not attempt to deanonymise or correlate RPIs. This is purely a "how many beacons are in the room?" counting exercise.
6. GPS & Positioning — time and space
6.1 GPS disciplined clock
The NEO-M10 emits a PPS (pulse-per-second) signal on a GPIO. While the AT bridge carries the NMEA timestamp (good to ~1 second), the PPS edge gives you nanosecond-level alignment.
The project: Use AT+GNSSINF to get the UTC second, and wire the PPS pin to a DeMon timer-capture input. You now have a GPS-disciplined oscillator accurate enough for SDR timestamping, LoRa TDOA (time-difference-of-arrival), or just a very precise wall clock.
Lua snippet:
local gps = require("phreak.gps")
gps.on_fix(function(fix)
-- sync local RTC to GPS time
os.settime(fix.utc_time)
print("RTC synced to GPS:", fix.utc_time)
end)
6.2 Geofencing with AT+GNSSURC
Set AT+GNSSURC=5 (5-second updates) and define a geofence in Lua:
local fence = {lat=51.5074, lon=-0.1278, radius_m=100}
phreak.on("+GNSS", function(fix)
local d = haversine(fix.lat, fix.lon, fence.lat, fence.lon)
if d < fence.radius_m then
print("Inside fence! Playing sound...")
antos.beep()
end
end)
Use case: "Where did I park?" — walk away from your car; when you return within 10 m, Ant64 beeps.
6.3 Speedometer / odometer
AT+GNSSINF gives speed in km/h. Mount Ant64 on a bike or car dashboard, log speed every second, and compute total distance. Add a MAX7219 LED matrix and you have a custom digital speedo.
7. CSI & Presence — art from radio waves
7.1 Motion-reactive LED wall
AT+CSISTREAM captures Channel State Information — the way Wi-Fi signals bounce off objects and people. The amplitude and phase of each subcarrier change when someone moves.
The art piece: Place Ant64 in a room with a static Wi-Fi router (the router is the transmitter; Ant64 is the receiver in monitor mode on that channel). Stream CSI to AntOS, compute variance across subcarriers, and map that to RGB LED colours.
-- csi_art.lua
local leds = require("antos.ws2812")
phreak.csi_stream(1, 50) -- 50 ms interval
phreak.on("+CSI", function(csi)
local variance = csi.std_amp -- from AT+CSISTATS logic
local hue = (variance * 10) % 360
leds.fill_hsv(hue, 255, math.min(255, variance * 5))
end)
Walk in front of the antenna: the lights flare. Stand still: they calm. It's a room that breathes with you.
7.2 Presence-based room automation
AT+PRESENCE=1 detects occupancy without cameras (privacy-preserving). Use it to:
- Turn on lights when someone enters
- Pause music when everyone leaves
- Log room usage for "which room is busiest?" heatmaps
No cameras, no microphones — just Wi-Fi echoes.
7.3 Sleep stage detection (experimental)
CSI variance correlates with large motion (walking) but also with micro-motion (breathing, heartbeats). With enough averaging and a very quiet room, you can detect the ~0.2–0.3 Hz rhythm of breathing.
Disclaimer: This is research-grade, not medical-grade. But it's a fascinating demo of what passive Wi-Fi can infer.
8. Network Archaeology — digging through PCAP
8.1 Retro device hunting with AT+PCAPSTART
Start a capture in your home network and look for ancient protocols:
- NetBIOS broadcasts from old Windows machines
- UPnP/SSDP from smart TVs and printers
- mDNS from Apple devices
- ARP storms from misconfigured IoT
Use AT+NETDISCOVER=0,"_http._tcp" to find web servers you forgot existed. That old NAS from 2012? It's still broadcasting.
8.2 IoT exfiltration detection
Log +SNIFF or +CLIENTWATCH over 24 hours. Which devices talk when? A smart plug that uploads 50 MB at 3 AM every night is worth investigating. Is it a firmware update — or something else?
Script:
-- iot_watch.lua
phreak.client_watch(1, "AA:BB:CC:DD:EE:FF", 6) -- watch my IoT subnet
phreak.on("+CLIENTWATCH", function(dev)
print(dev.mac, "seen", dev.pkts, "packets")
end)
8.3 Protocol archaeology with AT+WIFISNIFF
Some old devices (Nintendo DS, PSP, original Xbox) only speak 802.11b. Set AT+WIFISNIFF=1,6,7 on channel 6 and watch for management frames with ancient capability bits. It's like finding a fossil.
9. Capture The Flag & Training Labs
9.1 Build your own Wi-Fi CTF
Set up a test network with deliberate misconfigurations and challenge players to find them using only Phreak's observation tools:
| Challenge | Technique | Command(s) |
|---|---|---|
| Find the hidden SSID | Look for probe responses | AT+WIFISNIFF=1,6,1 |
| Spot the rogue AP | Evil-twin detection | AT+MONROGUECFG + AT+MONROGUE |
| Count the clients | Station inventory | AT+CLIENTWATCH |
| Find the deauth attacker | Flood detection | AT+MONDEAUTH |
| Map the building | BLE + Wi-Fi fusion | AT+BLERECON + AT+CWLAP |
| Crack the weak cipher | Identify WEP/TKIF | AT+BEACONMON security field |
No attacking required — the flags are in the observations.
9.2 RF escape room
Design a puzzle room where players must:
- Use
AT+BLEIBEACONSCANto find a beacon under a floorboard - Decode the beacon's UUID to get a LoRa frequency
- Tune
AT+LORABANDto that frequency and receive a coordinates packet - Use
AT+GNSSLOCto verify they're at the right spot - The final door unlocks via
AT+BMESHONOFFto a BLE Mesh relay
10. Advanced AntOS Recipes
10.1 The "War Room" dashboard
Combine multiple AT commands into a single live status screen:
-- warroom.lua
while true do
local wifi = phreak.linkq()
local gps = phreak.gnss_loc()
local coex = phreak.coex_stat()
antos.clear_screen()
print(string.format("Wi-Fi: %s RSSI %d dBm %.1f Mbps",
wifi.band == 0 and "2.4G" or "5G", wifi.rssi, wifi.phy_rate))
print(string.format("GPS: %s %.4f %.4f",
gps.fix_quality > 0 and "FIX" or "NO FIX", gps.lat, gps.lon))
print(string.format("Radio: WiFi %d%% BLE %d%% LoRa %s",
coex.wifi_airtime_pct, coex.ble_airtime_pct,
({[0]="OFF", "IDLE", "TX", "RX"})[coex.lora_state]))
antos.sleep(1000)
end
10.2 Automated channel hopper
Cycle through all 2.4 GHz channels, sniff for 2 seconds each, and log any deauth frames:
-- hopper.lua
for ch = 1, 14 do
phreak.wifi_sniff(1, ch, 8) -- deauth-only filter
antos.sleep(2000)
phreak.wifi_sniff(0, ch)
end
10.3 LoRa + GPS logger (field recorder)
Log every LoRa packet received along with GPS coordinates and timestamp. Perfect for mapping LoRa coverage in your area:
-- lora_gps_logger.lua
local log = io.open("/sd/lora_gps.csv", "a")
log:write("time,lat,lon,src_addr,rssi,snr,data\n")
phreak.lora_init({band=868000000, sf=9, bw=125, cr=5, addr=1})
phreak.gnss_pwr(1)
phreak.on("+LORARCV", function(pkt)
local fix = phreak.gnss_loc()
local ts = os.date("%Y-%m-%dT%H:%M:%S")
local txt = hex.decode(pkt.data_hex):gsub(""", "\"")
log:write(string.format("%s,%.6f,%.6f,%d,%d,%d,"%s"\n",
ts, fix.lat or 0, fix.lon or 0,
pkt.src_addr, pkt.rssi, pkt.snr, txt))
log:flush()
end)
11. Responsible disclosure & ethics
If you discover something alarming while playing with these tools — an open industrial control system, a hospital BLE device leaking PHI, a widespread deauth attack in your neighbourhood — the right thing to do is:
- Document it — PCAPs, logs, timestamps.
- Don't exploit it — no probing deeper than necessary.
- Tell the owner — if it's a local business, talk to them. If it's a vendor, file a vulnerability report.
- Share responsibly — blog about the technique, not the target.
Phreak makes you a better defender by teaching you what the attackers see. Use that knowledge to harden your own networks and help others do the same.
Appendix: Quick command reference for fun mode
| What you want | Command(s) | Section |
|---|---|---|
| Wardriving (Wi-Fi + GPS) | AT+CWLAP + AT+GNSSINF |
§5, §13 |
| BLE safari | AT+BLERECON=1 |
§14.7 |
| Deauth alarm | AT+MONDEAUTH=1 |
§14.7 |
| Evil-twin watch | AT+MONROGUECFG → AT+MONROGUE=1 |
§14.7 |
| Stalker-tag hunt | AT+MONBLETAG=1 |
§14.7 |
| LoRa chat | AT+LORASEND / +LORARCV |
§12.4 |
| LoRa fox hunt | AT+LORASEND (beacon) + RSSI meter |
§12.4 |
| Spectrum sweep | AT+LORASCAN |
§12.6 |
| RF trilateration | AT+LORARANGE (×3 anchors) |
§12.6 |
| FLRC fast link | AT+LORAMOD=FLRC + AT+LORAFLRC |
§12.6 |
| Satellite check-in | AT+LORASAT |
§12.6 |
| LoRa→BLE gateway | AT+BRIDGEADD + AT+BRIDGE |
§16 |
| CSI art | AT+CSISTREAM=1 |
§14.2 |
| Presence automation | AT+PRESENCE=1 |
§14.2 |
| iBeacon treasure hunt | AT+BLEIBEACONSCAN=1 |
§14.3 |
| Capture everything | AT+PCAPSTART |
§14.2 |
| Channel survey | AT+CHANNELSCORE / AT+WIFIHEATMAP |
§14.1 |
| GPS sync | AT+GNSSINF + PPS wire |
§13.3 |
| Network audit | AT+PING + AT+CIPSTART (scan.lua) |
§6, §14.8 |
| IoT CTF | AT+WIFISNIFF + AT+CLIENTWATCH |
§14.7 |
| RF dashboard | AT+LINKQ + AT+COEXSTAT + AT+GNSSLOC |
§14.5, §14.6, §13 |