Phreak Fun — Creative & Research Uses of the C5 Wireless Subsystem

Companion to: Phreak — Wireless AT Command Reference
Device: ESP32-C5 (Phreak) on Ant64 / DeMon
Philosophy: Everything here is receive-only, observation-based, or targeted at equipment you own. The C5 has no frame-injection, no jamming, and no rogue-AP hosting capability by design. "Hacking" here means understanding the invisible world around you — not breaking into someone else's network.


1. The philosophy of ethical RF fun

Phreak is a sensor, not a weapon. It can hear Wi-Fi, BLE, LoRa, and GPS signals, but it cannot shout over them. That constraint is a feature: it forces creativity. Every technique in this document is built from the same observation-only primitives in §12–§15 of the main reference.

The rules:

  1. Only listen — if it requires transmitting a frame you didn't craft yourself, the C5 can't do it (and this document won't teach it).
  2. Only your networks — active probing (AT+PING, AT+CIPSTART) is fine on hardware you own. Never point it at a café, airport, or neighbour.
  3. Share what you learn — RF is a commons; documenting weird behaviour helps everyone.

2. RF Cartography — mapping the invisible city

2.1 Wardriving with AT+CWLAP and AT+GNSSINF

The classic: drive (or walk) around with Ant64, scan Wi-Fi at intervals, and log GPS coordinates. You build a map of every AP in your neighbourhood — SSID, BSSID, channel, RSSI, security, and exact location.

AntOS script: wardrive.lua

-- wardrive.lua  —  log every AP with its GPS fix.
local phreak = require("phreak")
local gps    = require("phreak.gps")
local log    = io.open("/sd/wardrive.csv", "a")

log:write("timestamp,lat,lon,ssid,bssid,channel,rssi,security\n")

phreak.wifi_scan(function(ap)
    local fix = gps.get_loc()   -- polls AT+GNSSLOC
    if fix.quality > 0 then
        log:write(string.format("%d,%.6f,%.6f,"%s",%s,%d,%d,%s\n",
            os.time(), fix.lat, fix.lon,
            ap.ssid, ap.bssid, ap.channel, ap.rssi, ap.security))
        log:flush()
    end
end, 5000)   -- scan every 5 seconds

Visualise: Import the CSV into WiGLE or plot it with Python/matplotlib. Colour-code by channel to see how congested 2.4 GHz is in your area.

Why it's fun: You discover APs with hilarious default names, find open networks (on your own property), and see how far your home Wi-Fi really leaks.


2.2 BLE wardriving with AT+BLERECON

Wi-Fi is only half the story. BLE devices are everywhere: fitness trackers, headphones, smart locks, TVs, cars, and those tiny beacons stores use for indoor positioning.

The game: Leave AT+BLERECON=1 running for an hour while you walk through a shopping centre (or your own house). Then dump the log and count:

  • How many devices don't randomise their MAC?
  • Which manufacturer IDs appear most? (Decode the first 3 bytes of mfg_data_hex)
  • Can you spot the same device following you? (That's AT+MONBLETAG territory.)

AntOS one-liner:

phreak.ble_recon_log("/sd/ble_safari.log", 3600)  -- 1 hour

2.3 Channel heatmap art with AT+WIFIHEATMAP

AT+WIFIHEATMAP isn't just for engineering — it's a way to see radio. Run a 10-minute heatmap in your home, then render the per-channel occupancy as a bar chart or even convert it to audio (sonification: busy channels = higher pitch).

Creative twist: Place Ant64 next to a microwave oven and run AT+WIFIHEATMAP=1,60 while it runs. Watch channel 11 (2.45 GHz) spike as the magnetron leaks into the ISM band. It's a cheap spectrum analyser.


2.4 Dual-band spectrum sweep with AT+LORASCAN

Wi-Fi and BLE only show you the crowded 2.4/5 GHz corners. The LR2021's spectral scan sweeps whole bands — Sub-GHz (868/915 MHz) and 2.4 GHz — and reports RSSI at each step, so you can see the traffic Wi-Fi tools never touch: LoRa nodes, smart meters (W-MBUS), 433/868 MHz remotes and sensors, weather stations, car key fobs, the lot.

-- spectrum.lua — sweep 863–870 MHz in 25 kHz steps
phreak.lora_scan(863000000, 870000000, 25000, function(freq, rssi)
    local bar = string.rep("█", math.max(0, rssi + 130))
    print(string.format("%.3f MHz %4d %s", freq/1e6, rssi, bar))
end)

Fun with it: leave it sweeping and watch your neighbourhood's Sub-GHz life light up — the doorbell, the weather station, the energy meter phoning home every few seconds. Log it over a day and you have a spectral fingerprint of the street. It's completely receive-only — the same passive-observation ethic as the Wi-Fi survey, on the bands Wi-Fi can't reach.

Sense vs. decode. The LR2021 is a narrowband packet radio, not a wideband SDR — so there are two levels of listening. It can sense energy ("something is transmitting here") anywhere it tunes: 150–960 MHz, 2.4 GHz, and S/L-band. It can only decode its own modulations — LoRa, LR-FHSS, FLRC, (G)FSK, OOK, O-QPSK (802.15.4), BLE PHY, and the built-in Z-Wave / Wireless M-Bus / Wi-SUN framings. Wi-Fi, cellular, DECT and analog FM voice show up as energy but can't be read.

What's out there — D = decodable, S = sense-only:

Band What lives there
433 / 315 MHz key fobs, garage & doorbell remotes, TPMS, weather stations, thermometers D
868 / 915 MHz LoRa / LoRaWAN, Meshtastic, smart meters (W-MBUS), Z-Wave home automation D
138–470 / 929 MHz pagers (POCSAG / FLEX) D
2.4 GHz BLE, Zigbee / Thread, 2.4 GHz LoRa D
1.5–2.5 GHz direct-to-satellite LoRa (licensed service) D
~162 MHz marine AIS (ship transponders) S
865–928 MHz UHF RFID tags S
150–470 MHz business / marine / amateur FM voice S
935–960 MHz cellular downlink S
2.4 GHz Wi-Fi (the C5's job), microwave-oven noise S
1.88–1.90 GHz DECT cordless phones S

The sweet spot for actually reading things is the 433/868/915 MHz world (the "rtl_433" gadgets) plus the native packet protocols — sweep the band to see what's alive, then decode the ones it speaks.

Stay legal. Ambient ISM beacons — your own gear, the neighbourhood doorbell / weather-station chatter — are fair game to receive. Intercepting cellular, licensed, or encrypted traffic is restricted in most places, which is exactly why this stays receive-only and pointed at open, public transmissions.


3. The Ghost Spectrum — hunting anomalies

3.1 Deauth flood detection as a game

AT+MONDEAUTH turns the C5 into a lightning detector for Wi-Fi attacks. Set it up at home and wait. Most residential areas are quiet, but when someone runs a deauth tool (even accidentally), you'll catch it.

The challenge: Can you correlate a +MONDEAUTH alarm with a real event? e.g.:

  • Your neighbour's cheap security camera rebooting (some cameras spam deauths when they lose the AP)
  • A misconfigured IoT plug
  • A actual attacker (rare, but you'll know immediately)

Script:

-- deauth_watchdog.lua
phreak.on("+MONDEAUTH", function(evt)
    local t = os.date("%H:%M:%S", os.time())
    print(string.format("[ALERT %s] %d deauths from %s -> %s on ch %d",
        t, evt.count, evt.src_addr, evt.dst_addr, evt.channel))
    -- snapshot the RF environment for forensics
    phreak.channel_score(0)
    phreak.rf_logger_snapshot("/sd/deauth_" .. os.time() .. ".log")
end)
phreak.mon_deauth(1, 20, 10)  -- threshold 20 in 10s window

3.2 Evil-twin spotting with AT+MONROGUE

After you teach AT+MONROGUECFG your home SSID+BSSID, AT+MONROGUE becomes a burglar alarm for your Wi-Fi identity. If someone clones your SSID (to phish your family), the alarm fires.

Fun experiment: Set it up, then deliberately create a hotspot on your phone with the same SSID as your home router (but different BSSID). Watch the +MONROGUE URC fire within seconds. Now imagine catching a real attacker.


3.3 BLE stalker-tag hunting

AirTags and similar trackers are designed to be stealthy, but they have a tell: they don't randomise their MAC address (or they rotate slowly). AT+MONBLETAG looks for BLE devices that follow you across multiple locations.

The game: Hide a BLE beacon (or an old phone broadcasting iBeacon) in a friend's bag. Walk around with Ant64 for 15 minutes. Can AT+MONBLETAG flag it? Adjust the <threshold_min> down to 5 for faster detection.

Responsible note: Only do this with consent. The same technique protects you from actual stalking devices in the wild.


4. LoRa Playground — long-range whisper net

The LR2021 that Phreak now uses is a LoRa Plus radio — still the classic long-range whisper for the projects below, but also dual-band (it reaches 2.4 GHz), with a high-speed FLRC mode and a real satellite path. The mesh, fox-hunt and tracker ideas work exactly as before on Sub-GHz LoRa; FLRC and satellite open two new playgrounds at the end (§4.4–§4.5).

4.1 LoRa mesh chat

Two (or more) Ant64 units, each with an LR2021 (Wio-LR2021), can form a messaging network with no infrastructure. No towers, no SIM cards, no subscriptions. On plain Sub-GHz LoRa it's a text whisper-net; switch the radio to FLRC (§4.4) and the same mesh can pass small images or voice clips.

Protocol (built on §12 P2P):

  • Address 0 = broadcast to all
  • Addresses 1–65534 = unicast
  • Payload = JSON-ish text (hex-encoded): {"from":"callsign","msg":"hello"}

AntOS chat client:

-- lorachat.lua
local my_addr = 42   -- my node address
local phreak = require("phreak")

phreak.lora_init({band=868000000, sf=9, bw=125, cr=5, addr=my_addr})

-- receive loop
phreak.on("+LORARCV", function(pkt)
    local text = hex.decode(pkt.data_hex)
    print(string.format("<%04X> %s", pkt.src_addr, text))
end)

-- send loop
while true do
    local line = io.read()
    if line then
        local payload = hex.encode(string.format("{\"from\":\"%04X\",\"msg\":\"%s\"}", my_addr, line))
        phreak.lora_send(0, #payload/2, payload)  -- broadcast
    end
end

Range test: In open countryside with SF12 and +22 dBm, you can reach 5–10 km. In a city with buildings, expect 500 m–2 km. The fun is finding the limits.


4.2 LoRa fox hunting (radio direction finding)

Hide a LoRa beacon (an Ant64 broadcasting +LORARCV every 10 seconds) in a park. Hunters carry another Ant64 running a signal-strength meter:

-- foxhunt.lua
phreak.lora_init({band=868000000, sf=9, bw=125, cr=5, addr=99})
phreak.on("+LORARCV", function(pkt)
    if pkt.src_addr == 0xBEEF then   -- the fox
        local bar = string.rep("█", math.min(20, math.abs(pkt.rssi)))
        print(string.format("RSSI %4d %s  SNR %2d", pkt.rssi, bar, pkt.snr))
    end
end)

Walk around. The RSSI bar grows as you approach. Add a directional antenna (yagi or patch) for serious hunting.


4.3 LoRa weather balloon tracker

Attach an Ant64 + GPS to a high-altitude balloon. It broadcasts its position every 30 seconds via LoRa. A ground station logs the packets and plots altitude vs. time.

Payload format (compact binary, hex-encoded):

<lat_f32><lon_f32><alt_u16><sats_u8>

The ground station decodes +LORARCV data and feeds it to a map. You now have a $50 near-space telemetry tracker. (For reach beyond line-of-sight to your ground station, see the real satellite path in §4.5.)


4.4 FLRC — the fast lane

Plain LoRa trades speed for range: perfect for a text whisper, too slow for much else. The LR2021 adds FLRC (Fast Long-Range Communication) at up to 2.6 Mbps — still long-range and robust, but fast enough to move real payloads. Same mesh, richer traffic:

  • Photo drop — snap a low-res JPEG on one node and FLRC it to another a kilometre away. No Wi-Fi, no cell.
  • Voice-memo net — a few seconds of compressed audio per message: a walkie-talkie that works past line-of-sight.
  • Off-grid file sync — push a firmware image or a DBFS export between two machines over the air.

FLRC is a per-link mode (see Phreak §12.6), so a mesh can stay on slow-and-far LoRa for beacons and drop into FLRC only when two nodes have a good enough link for the fast payload.


4.5 Satellite whisper — off-grid, over the horizon

The LR2021's S-band port gives Phreak something the SX1262 never could: a path to low-earth-orbit satellites (non-terrestrial network / direct-to-satellite). A short status message from the middle of an ocean, a desert, or a dead valley — anywhere with sky but no ground network.

The honest version of this idea:

  • It's a licensed-service capability, not free spectrum. S-band satellite links go through licensed satellite-IoT networks (the LoRaWAN-over-satellite operators), not by blasting skyward on your own. Use an appropriate service and follow its rules — the same "only your own links, don't step on anyone else's" ethic the rest of this document runs on, applied to spectrum that's very much spoken for.
  • What it's brilliant for: an off-grid check-in beacon — a hiker, a boat, or a remote sensor firing one tiny "I'm here, I'm OK, here's my GPS fix" packet on a schedule, logged when a satellite passes overhead.
  • Pair it with the GPS clock (§6.1) and the tracker (§4.3) and you have a genuinely autonomous off-grid node: it knows where it is, knows the time, and can say so to orbit.

4.6 RF trilateration — positioning without GPS

The LR2021 adds RTToF ranging (AT+LORARANGE): it measures the round-trip flight time to another node and turns it into a distance. One measurement gives you a radius; three fixed anchor nodes give you a position — indoors, underground, anywhere GPS can't reach.

The setup: three Ant64 units at known, fixed positions (the anchors). A fourth (the tag) ranges against each in turn and solves for where it is:

-- trilaterate.lua (tag side)
local anchors = { [1]={x=0,y=0}, [2]={x=10,y=0}, [3]={x=5,y=8} }
local d = {}
for id in pairs(anchors) do
    d[id] = phreak.lora_range(id)      -- metres to that anchor
end
local pos = trilaterate(anchors, d)     -- least-squares solve
print(string.format("You are at (%.1f, %.1f) m", pos.x, pos.y))

Where it shines: asset tracking in a workshop, a museum-style "which room am I in" guide, a warehouse robot that knows its aisle, or a treasure hunt where the prize's position is computed, not hidden. Accuracy depends on bandwidth and multipath, but even a few metres is enough for room-level location. It also upgrades §4.2's fox hunt from "warmer / colder" to an actual coordinate.


4.7 Personal LoRa-to-BLE gateway

The Ant64's two radios meet inside one controller, so it can bridge them: a sensor a kilometre away talks to the LR2021 over LoRa, and the Ant64 re-broadcasts each reading over BLE to your phone in the room. Off-grid range on one side, everyday convenience on the other.

Because the bridge lives in the C5 firmware (see Phreak §16), you set it up with a couple of AT commands and it then runs itself — no polling loop, no script in the hot path:

AT+BRIDGEADD=LORA,LRBLE,       -> +BRIDGEADD: 1
AT+BRIDGEMAP=1,PASS
AT+BRIDGE=1,1                    -> now forwarding LoRa -> BLE

Any LoRa packet the LR2021 hears is re-advertised over BLE; point a phone's BLE scanner at it and your distant sensor shows up like a local beacon. Flip the endpoints (AT+BRIDGEADD=BLE,LORA,…) and you can push a phone's message out over long-range LoRa instead.

Where it goes next: the C5 buffers readings in its own PSRAM so a burst or a briefly-absent phone doesn't drop anything (DBFS on DeMon only comes in when you want them to survive a power-cut), or fan one LoRa feed out to BLE and an MQTT topic over Wi-Fi at once — a little off-grid-to-internet bridge. It's only as broad as the stacks underneath (LoRa↔BLE first; Zigbee and friends follow), but even LoRa↔BLE is genuinely useful on day one.


5. BLE Safari — the zoo of invisible devices

5.1 iBeacon treasure hunt

Place iBeacon transmitters (or phones running beacon apps) around a building. Players use AT+BLEIBEACONSCAN=1 and hunt for specific UUIDs. When the UUID matches a clue, the player gets the next coordinate.

Educational twist: Each beacon broadcasts a different URL via Eddystone-URL. Players collect URLs to build a scavenger-hunt story.


5.2 BLE device fingerprinting

Every BLE chip has quirks: advertisement interval, manufacturer data format, service UUIDs, TX power. AT+BLERECON logs enough to fingerprint devices.

Challenge: Got two identical devices — say your headphones and a friend's same model, with their say-so? Can you tell them apart from the BLE advertisement pattern alone? Plot RSSI over time — the set you're wearing shows a strong, consistent signal; the other stays weak and intermittent.


5.3 Contact-tracing research (your own devices)

Apple/Google exposure-notification beacons rotate their RPI (Rolling Proximity Identifier) every 15 minutes, but the MAC address also rotates. However, the timing and payload structure are distinctive. AT+BLERECON can log these frames (anonymised) to study how many exposure-notification devices are nearby.

Important: Do not attempt to deanonymise or correlate RPIs. This is purely a "how many beacons are in the room?" counting exercise.


6. GPS & Positioning — time and space

6.1 GPS disciplined clock

The NEO-M10 emits a PPS (pulse-per-second) signal on a GPIO. While the AT bridge carries the NMEA timestamp (good to ~1 second), the PPS edge gives you nanosecond-level alignment.

The project: Use AT+GNSSINF to get the UTC second, and wire the PPS pin to a DeMon timer-capture input. You now have a GPS-disciplined oscillator accurate enough for SDR timestamping, LoRa TDOA (time-difference-of-arrival), or just a very precise wall clock.

Lua snippet:

local gps = require("phreak.gps")
gps.on_fix(function(fix)
    -- sync local RTC to GPS time
    os.settime(fix.utc_time)
    print("RTC synced to GPS:", fix.utc_time)
end)

6.2 Geofencing with AT+GNSSURC

Set AT+GNSSURC=5 (5-second updates) and define a geofence in Lua:

local fence = {lat=51.5074, lon=-0.1278, radius_m=100}

phreak.on("+GNSS", function(fix)
    local d = haversine(fix.lat, fix.lon, fence.lat, fence.lon)
    if d < fence.radius_m then
        print("Inside fence! Playing sound...")
        antos.beep()
    end
end)

Use case: "Where did I park?" — walk away from your car; when you return within 10 m, Ant64 beeps.


6.3 Speedometer / odometer

AT+GNSSINF gives speed in km/h. Mount Ant64 on a bike or car dashboard, log speed every second, and compute total distance. Add a MAX7219 LED matrix and you have a custom digital speedo.


7. CSI & Presence — art from radio waves

7.1 Motion-reactive LED wall

AT+CSISTREAM captures Channel State Information — the way Wi-Fi signals bounce off objects and people. The amplitude and phase of each subcarrier change when someone moves.

The art piece: Place Ant64 in a room with a static Wi-Fi router (the router is the transmitter; Ant64 is the receiver in monitor mode on that channel). Stream CSI to AntOS, compute variance across subcarriers, and map that to RGB LED colours.

-- csi_art.lua
local leds = require("antos.ws2812")
phreak.csi_stream(1, 50)  -- 50 ms interval

phreak.on("+CSI", function(csi)
    local variance = csi.std_amp   -- from AT+CSISTATS logic
    local hue = (variance * 10) % 360
    leds.fill_hsv(hue, 255, math.min(255, variance * 5))
end)

Walk in front of the antenna: the lights flare. Stand still: they calm. It's a room that breathes with you.


7.2 Presence-based room automation

AT+PRESENCE=1 detects occupancy without cameras (privacy-preserving). Use it to:

  • Turn on lights when someone enters
  • Pause music when everyone leaves
  • Log room usage for "which room is busiest?" heatmaps

No cameras, no microphones — just Wi-Fi echoes.


7.3 Sleep stage detection (experimental)

CSI variance correlates with large motion (walking) but also with micro-motion (breathing, heartbeats). With enough averaging and a very quiet room, you can detect the ~0.2–0.3 Hz rhythm of breathing.

Disclaimer: This is research-grade, not medical-grade. But it's a fascinating demo of what passive Wi-Fi can infer.


8. Network Archaeology — digging through PCAP

8.1 Retro device hunting with AT+PCAPSTART

Start a capture in your home network and look for ancient protocols:

  • NetBIOS broadcasts from old Windows machines
  • UPnP/SSDP from smart TVs and printers
  • mDNS from Apple devices
  • ARP storms from misconfigured IoT

Use AT+NETDISCOVER=0,"_http._tcp" to find web servers you forgot existed. That old NAS from 2012? It's still broadcasting.


8.2 IoT exfiltration detection

Log +SNIFF or +CLIENTWATCH over 24 hours. Which devices talk when? A smart plug that uploads 50 MB at 3 AM every night is worth investigating. Is it a firmware update — or something else?

Script:

-- iot_watch.lua
phreak.client_watch(1, "AA:BB:CC:DD:EE:FF", 6)  -- watch my IoT subnet
phreak.on("+CLIENTWATCH", function(dev)
    print(dev.mac, "seen", dev.pkts, "packets")
end)

8.3 Protocol archaeology with AT+WIFISNIFF

Some old devices (Nintendo DS, PSP, original Xbox) only speak 802.11b. Set AT+WIFISNIFF=1,6,7 on channel 6 and watch for management frames with ancient capability bits. It's like finding a fossil.


9. Capture The Flag & Training Labs

9.1 Build your own Wi-Fi CTF

Set up a test network with deliberate misconfigurations and challenge players to find them using only Phreak's observation tools:

Challenge Technique Command(s)
Find the hidden SSID Look for probe responses AT+WIFISNIFF=1,6,1
Spot the rogue AP Evil-twin detection AT+MONROGUECFG + AT+MONROGUE
Count the clients Station inventory AT+CLIENTWATCH
Find the deauth attacker Flood detection AT+MONDEAUTH
Map the building BLE + Wi-Fi fusion AT+BLERECON + AT+CWLAP
Crack the weak cipher Identify WEP/TKIF AT+BEACONMON security field

No attacking required — the flags are in the observations.


9.2 RF escape room

Design a puzzle room where players must:

  1. Use AT+BLEIBEACONSCAN to find a beacon under a floorboard
  2. Decode the beacon's UUID to get a LoRa frequency
  3. Tune AT+LORABAND to that frequency and receive a coordinates packet
  4. Use AT+GNSSLOC to verify they're at the right spot
  5. The final door unlocks via AT+BMESHONOFF to a BLE Mesh relay

10. Advanced AntOS Recipes

10.1 The "War Room" dashboard

Combine multiple AT commands into a single live status screen:

-- warroom.lua
while true do
    local wifi = phreak.linkq()
    local gps  = phreak.gnss_loc()
    local coex = phreak.coex_stat()

    antos.clear_screen()
    print(string.format("Wi-Fi: %s  RSSI %d dBm  %.1f Mbps",
        wifi.band == 0 and "2.4G" or "5G", wifi.rssi, wifi.phy_rate))
    print(string.format("GPS:   %s  %.4f %.4f",
        gps.fix_quality > 0 and "FIX" or "NO FIX", gps.lat, gps.lon))
    print(string.format("Radio: WiFi %d%%  BLE %d%%  LoRa %s",
        coex.wifi_airtime_pct, coex.ble_airtime_pct,
        ({[0]="OFF", "IDLE", "TX", "RX"})[coex.lora_state]))

    antos.sleep(1000)
end

10.2 Automated channel hopper

Cycle through all 2.4 GHz channels, sniff for 2 seconds each, and log any deauth frames:

-- hopper.lua
for ch = 1, 14 do
    phreak.wifi_sniff(1, ch, 8)   -- deauth-only filter
    antos.sleep(2000)
    phreak.wifi_sniff(0, ch)
end

10.3 LoRa + GPS logger (field recorder)

Log every LoRa packet received along with GPS coordinates and timestamp. Perfect for mapping LoRa coverage in your area:

-- lora_gps_logger.lua
local log = io.open("/sd/lora_gps.csv", "a")
log:write("time,lat,lon,src_addr,rssi,snr,data\n")

phreak.lora_init({band=868000000, sf=9, bw=125, cr=5, addr=1})
phreak.gnss_pwr(1)

phreak.on("+LORARCV", function(pkt)
    local fix = phreak.gnss_loc()
    local ts  = os.date("%Y-%m-%dT%H:%M:%S")
    local txt = hex.decode(pkt.data_hex):gsub(""", "\"")
    log:write(string.format("%s,%.6f,%.6f,%d,%d,%d,"%s"\n",
        ts, fix.lat or 0, fix.lon or 0,
        pkt.src_addr, pkt.rssi, pkt.snr, txt))
    log:flush()
end)

11. Responsible disclosure & ethics

If you discover something alarming while playing with these tools — an open industrial control system, a hospital BLE device leaking PHI, a widespread deauth attack in your neighbourhood — the right thing to do is:

  1. Document it — PCAPs, logs, timestamps.
  2. Don't exploit it — no probing deeper than necessary.
  3. Tell the owner — if it's a local business, talk to them. If it's a vendor, file a vulnerability report.
  4. Share responsibly — blog about the technique, not the target.

Phreak makes you a better defender by teaching you what the attackers see. Use that knowledge to harden your own networks and help others do the same.


Appendix: Quick command reference for fun mode

What you want Command(s) Section
Wardriving (Wi-Fi + GPS) AT+CWLAP + AT+GNSSINF §5, §13
BLE safari AT+BLERECON=1 §14.7
Deauth alarm AT+MONDEAUTH=1 §14.7
Evil-twin watch AT+MONROGUECFG → AT+MONROGUE=1 §14.7
Stalker-tag hunt AT+MONBLETAG=1 §14.7
LoRa chat AT+LORASEND / +LORARCV §12.4
LoRa fox hunt AT+LORASEND (beacon) + RSSI meter §12.4
Spectrum sweep AT+LORASCAN §12.6
RF trilateration AT+LORARANGE (×3 anchors) §12.6
FLRC fast link AT+LORAMOD=FLRC + AT+LORAFLRC §12.6
Satellite check-in AT+LORASAT §12.6
LoRa→BLE gateway AT+BRIDGEADD + AT+BRIDGE §16
CSI art AT+CSISTREAM=1 §14.2
Presence automation AT+PRESENCE=1 §14.2
iBeacon treasure hunt AT+BLEIBEACONSCAN=1 §14.3
Capture everything AT+PCAPSTART §14.2
Channel survey AT+CHANNELSCORE / AT+WIFIHEATMAP §14.1
GPS sync AT+GNSSINF + PPS wire §13.3
Network audit AT+PING + AT+CIPSTART (scan.lua) §6, §14.8
IoT CTF AT+WIFISNIFF + AT+CLIENTWATCH §14.7
RF dashboard AT+LINKQ + AT+COEXSTAT + AT+GNSSLOC §14.5, §14.6, §13

Important: The Ant64 family of home computers are at early design/prototype stage, everything you see here is subject to change.