WprowadzenieOverview
ESP32 Marauder to wielofunkcyjne urządzenie do testowania bezpieczeństwa sieci WiFi i Bluetooth, działające na platformie mikrokontrolera ESP32. Oferuje szeroki zestaw narzędzi — od pasywnego nasłuchu i analizy protokołów, po aktywne testy penetracyjne.ESP32 Marauder is a multifunctional device for WiFi and Bluetooth security testing, running on the ESP32 microcontroller platform. It offers a wide range of tools — from passive sniffing and protocol analysis to active penetration testing.
Dostępne jest w wersji z ekranem dotykowym (interfejs GUI) oraz bez ekranu (tryb CLI przez port szeregowy UART).Available with a touchscreen (GUI interface) or without a screen (CLI mode via UART serial port).
Ustawienia MarauderaMarauder Settings
Zachowanie urządzenia można dostosować przez menu Device → Settings (GUI) lub komendę settings (CLI). Ustawienia w GUI są teraz kodowane kolorem — łatwiej odróżnić opcje aktywne od nieaktywnych.Device behavior can be customized via the Device → Settings menu (GUI) or the settings command (CLI). Settings in GUI are now color-coded — easier to distinguish active from inactive options.
sniffpmkid, wymuszając przechwycenie handshake PMKID bez czekania na naturalne rozłączenie klienta.Automatically sends deauth frames to detected APs during sniffpmkid, forcing PMKID handshake capture without waiting for natural client disconnection.
sniffprobe, stymulując urządzenia do ponownego wysyłania probe request.Automatically sends deauth frames during sniffprobe, stimulating devices to re-send probe requests.
Fox Hunt i Flock Sniff.Automatic WiFi channel switching during sniffing. Enables capturing traffic from all 2.4 GHz channels simultaneously. Also supported by Fox Hunt and Flock Sniff.
Przegląd aplikacjiApp Overview
Marauder z ekranem posiada menu podzielone na pięć kategorii. Wersja bez ekranu korzysta z tych samych funkcji przez CLI.Marauder with a screen has a menu divided into five categories. The screenless version uses the same functions via CLI.
WiFi – SnifferySniffers
Narzędzia do pasywnego i aktywnego przechwytywania ruchu sieciowego 802.11. Większość zapisuje dane PCAP na kartę SD (SavePCAP=true).Tools for passive and active 802.11 network traffic capture. Most save PCAP data to the SD card (SavePCAP=true).
SavePCAP=true.Visualizes WiFi packet traffic intensity in real time. Packet Rate automatically saves PCAP files to SD card when SavePCAP=true.ForcePMKID przyspiesza przechwycenie.Captures EAPOL/PMKID frames from WPA2 handshakes. PCAP files can be used for offline password cracking. The ForcePMKID option speeds up capture.Wymagają aktywnego połączenia z siecią WiFi (Join WiFi).Require an active WiFi connection (Join WiFi).
⚠ Funkcje aktywne — używaj wyłącznie w środowiskach testowych z pisemnym upoważnieniem właściciela sieci.Active functions — use only in test environments with written authorization from the network owner.
EPDeauth wymusza rozłączenie klientów z prawdziwymi AP.Fake WiFi network with a captive portal based on an HTML file from the SD card. The EPDeauth option forces client disconnection from real APs.Bluetooth / BLE – SnifferySniffers
foxhunt -b.New! Hunt for BT/BLE transmitter by RSSI signal strength — analogous to WiFi Fox Hunt. CLI: foxhunt -b.findmysound.New! Triggers Apple FindMy devices to emit a sound ping. CLI: findmysound.⚠ Ataki BLE spam mogą zakłócać pracę urządzeń medycznych i innej krytycznej infrastruktury. Zachowaj szczególną ostrożność w miejscach publicznych.BLE spam attacks may interfere with medical devices and other critical infrastructure. Exercise extreme caution in public places.
applejuice.New Apple BLE attack. Sends precise BLE frames causing intrusive system notifications on Apple devices. More effective than Sour Apple. CLI: applejuice.GPS
Wymagają podłączonego modułu GPS (np. NEO-6M przez UART). Dane GPS używane są przez funkcje Wardrive do geolokalizacji wykrytych sieci i urządzeń.Require a connected GPS module (e.g. NEO-6M via UART). GPS data is used by Wardrive functions for geolocation of detected networks and devices.
gpsdata.Displays current module data: latitude and longitude, altitude, speed, course, number of satellites. CLI: gpsdata.Device
Join WiFi.Downloads the latest firmware over WiFi. Marauder must be connected to the internet via Join WiFi..bin na karcie SD. Przydatne przy braku dostępu do internetu.Updates firmware from a .bin file on the SD card. Useful when internet access is unavailable.reboot.Immediate ESP32 restart. CLI: reboot.CLI – Interfejs linii poleceńCommand Line Interface
Sterowanie przez port szeregowy. Parametry połączenia: 115200 baud, 8N1.Control via serial port. Connection parameters: 115200 baud, 8N1.
| KomendaCommand | OpisDescription |
|---|---|
| help | Lista dostępnych komend z opisemList of available commands |
| info | Informacje o urządzeniuDevice info |
| reboot | Restart urządzeniaDevice restart |
| settings -s [name] -v [value] | Zmiana ustawieńChange settings |
| scanap | Skanuje pobliskie APScans nearby APs |
| scansta | Skanuje stacje klienckieScans client stations |
| sniffbeacon | Nasłuch ramek beaconBeacon frame sniffing |
| sniffprobe | Nasłuch ramek probe requestProbe request sniffing |
| sniffdeauth | Nasłuch ramek deauthDeauth frame sniffing |
| sniffpmkid | Przechwytywanie PMKID handshakePMKID handshake capture |
| sniffraw | Surowe ramki 802.11 do PCAPRaw 802.11 frames to PCAP |
| sniffbt | Skanowanie urządzeń BT/BLEBT/BLE device scanning |
| attack -t [type] | Uruchamia atak: deauth, beacon, probe...Launches attack: deauth, beacon, probe... |
| evilportal | Uruchamia Evil PortalLaunches Evil Portal |
| karma | Uruchamia atak KarmaLaunches Karma attack |
| applejuice | Apple Juice BLE spam |
| sourapple | Sour Apple BLE spam |
| swiftpair | Swift Pair BLE spam (Windows) |
| samsungblespam | Samsung BLE spam |
| btspamall | Wszystkie BLE spam jednocześnieAll BLE spam simultaneously |
| spoofat | Emulacja AirTag przez BLEAirTag emulation via BLE |
| findmysound | Ping dźwiękowy Apple FindMyApple FindMy sound ping |
| wardrive | Wardrive WiFi z GPSWiFi Wardrive with GPS |
| foxhunt | Polowanie na nadajnik po RSSITransmitter hunting by RSSI |
| pingscan | Skanowanie hostów ICMP pingICMP ping host scanning |
| packetcount | Zliczanie pakietów na kanalePacket count on channel |
| join -s [ssid] -p [pass] | Łączy z siecią WiFiConnects to WiFi network |
| list / listbt | Wyświetla listy AP / BTDisplays AP / BT lists |
| save / load | Zapis/wczyt z karty SDSave/load from SD card |
| gpsdata | Wyświetla dane GPSDisplays GPS data |
| update | Aktualizacja firmware OTAOTA firmware update |
Przykładowe scenariusze użyciaUsage Scenarios
Poniższe workflow pokazują jak łączyć funkcje Maraudera. Wszystkie wymagają pisemnego upoważnienia do testowanej infrastruktury.The following workflows show how to combine Marauder functions. All require written authorization for the tested infrastructure.
Scan APs – zeskanuj pobliskie sieciscan nearby networksSelect APs – wybierz docelowe APselect target APSavePCAP=true i ForcePMKID=trueEAPOL PMKID Scan – uruchom nasłuchWiFi → Wardrive – uruchomupload) lub import CSVSelect EP HTML File – wskaż plikEPDeauth=trueWiFi Attacks → Evil Portal – uruchomBluetooth → Sniffers → Detect Card SkimmersBluetooth → Attacks → BT Spam AllReboot lub stopscanAtaki i Funkcje – Pełny przewodnikAttacks & Functions – Complete Guide
Poniższy przewodnik szczegółowo opisuje każdą funkcję ESP32 Maraudera — od skanowania i nasłuchu, przez aktywne ataki WiFi i BLE, po zaawansowane techniki. Każda sekcja zawiera:The following guide describes every ESP32 Marauder function in detail — from scanning and sniffing, through active WiFi and BLE attacks, to advanced techniques. Each section includes:
- ✅ Cel i mechanizm działania✅ Purpose and mechanism
- ✅ Instrukcje GUI (krok po kroku)✅ GUI instructions (step by step)
- ✅ Komendy CLI✅ CLI commands
- ✅ Wskazówki i ostrzeżenia✅ Tips and warnings
Aktywne ataki na sieci 802.11 — od rozłączania klientów, przez spamowanie beaconami, aż po zaawansowane ataki na WPA3. Wszystkie wymagają autoryzacji.Active 802.11 network attacks — from client disconnection, through beacon spamming, to advanced WPA3 attacks. All require authorization.
- Zeskanuj AP (
scanap) i wybierz cel (select)Scan APs (scanap) and select target (select) - Atak trwa do momentu ręcznego zatrzymania (
stopscan)Attack continues until manually stopped (stopscan) - Dla precyzyjnego ataku na konkretnego klienta: wybierz też stację (
selectsta)For targeted attack on a specific client: also select a station (selectsta) - Można ręcznie podać adresy MAC:
attack -t deauth -s [MAC_AP] -d [MAC_klienta]Manual MAC addresses:attack -t deauth -s [MAC_AP] -d [MAC_client]
- Dodaj SSID: CLI
ssid -a "NazwaSieci"lub GUIAdd SSIDAdd SSID: CLIssid -a "NetworkName"or GUIAdd SSID - Możesz wygenerować losowe SSID:
Generate SSIDsw GUIYou can generate random SSIDs:Generate SSIDsin GUI - Sprawdź listę:
listw CLICheck the list:listin CLI
EPDeauth rozłącza klientów z prawdziwymi AP, by skusić ich do połączenia z fałszywą siecią.Mechanism: Marauder creates its own WiFi network with a selected SSID. Upon connection, the victim's device gets an IP (DHCP), and all HTTP requests are redirected to an HTML page from the SD card. The EPDeauth option disconnects clients from real APs to lure them to the fake network.- Przygotuj plik HTML (formularz logowania) i zapisz na karcie SDPrepare an HTML file (login form) and save it on the SD card
WiFi General → Select EP HTML File— wskaż plikWiFi General → Select EP HTML File— select the file- Opcjonalnie: włącz
EPDeauth=truewDevice → SettingsOptionally: enableEPDeauth=trueinDevice → Settings - Uruchom atak i monitoruj dane logowania przez Serial/CLILaunch the attack and monitor login data via Serial/CLI
Ataki BLE polegają na emitowaniu fałszywych ramek reklamowych (Advertising Packets), które wywołują powiadomienia systemowe na urządzeniach mobilnych — iPhone, Android, Windows. Działają w zasięgu do ok. 10-30 metrów w zależności od mocy nadajnika i przeszkód. BLE attacks consist of emitting fake advertising frames that trigger system notifications on mobile devices — iPhone, Android, Windows. Effective range is about 10-30 meters depending on transmitter power and obstacles.
- Uruchom komendę
applejuicew CLI lub wybierz z menu GUIRunapplejuicein CLI or select from GUI menu - Atak działa natychmiast — iPhone'y w zasięgu zaczną otrzymywać powiadomieniaAttack works immediately — iPhones in range will start receiving notifications
- Aby zatrzymać:
stopscanlubrebootTo stop:stopscanorreboot - Wskazówka: zwiększ moc nadawania w ustawieniach NimBLE dla większego zasięguTip: increase NimBLE output power in settings for greater range
- Uruchom
sourapplez CLI lub z menu GUIRunsourapplefrom CLI or GUI menu - Efekty widoczne na urządzeniach Apple w zasięgu BLE (ok. 10-20m)Effects visible on Apple devices in BLE range (approx. 10-20m)
- Zatrzymanie:
stopscanStop:stopscan
- Uruchom
swiftpair— komputery Windows w zasięgu otrzymają powiadomieniaRunswiftpair— Windows computers in range will receive notifications - Działa na Windows 10 wersja 1803+ i Windows 11Works on Windows 10 version 1803+ and Windows 11
- Można zmieniać nazwy urządzeń przez CLIDevice names can be changed via CLI
- Uruchom
samsungblespam— telefony Samsung z One UI w zasięgu otrzymają spamRunsamsungblespam— Samsung phones with One UI in range will receive spam - Działa też na innych Androidach z Google Fast Pair, ale najlepiej na SamsungachAlso works on other Androids with Google Fast Pair, but best on Samsung devices
- Uruchom
googleblespamz CLIRungoogleblespamfrom CLI - Działa na wszystkich Androidach z Google Play Services 12.8+Works on all Androids with Google Play Services 12.8+
- Uruchom
btspamall— atak na wszystkie platformy jednocześnieRunbtspamall— attacks all platforms simultaneously - Obserwuj reakcje: iPhone (Apple), Samsung (Android), Windows (Swift Pair)Observe reactions: iPhone (Apple), Samsung (Android), Windows (Swift Pair)
- Zatrzymaj przez
rebootlubstopscanStop viarebootorstopscan - ⚠ Może znacząco obciążyć urządzenia w zasięgu — używaj w kontrolowanym środowisku⚠ May significantly impact devices in range — use in controlled environment
- Uruchom
spoofat— iPhone'y w zasięgu zobaczą alert AirTagRunspoofat— iPhones in range will see an AirTag alert - Alert zawiera informację, że AirTag porusza się z użytkownikiemThe alert informs that an AirTag is moving with the user
- Zatrzymanie:
stopscanStop:stopscan
- Uruchom
findmysound— AirTag/iDevice w zasięgu zacznie piszczećRunfindmysound— AirTag/iDevice in range will start beeping - Użyj do sprawdzenia, czy w twoim otoczeniu nie ma nieznanych AirTagówUse to check if there are unknown AirTags in your vicinity
- Zatrzymanie:
stopscanlub automatycznie po 15 sekundachStop:stopscanor automatically after 15 seconds
⚠ UWAGA:WARNING: Ataki BLE spam mogą zakłócać pracę urządzeń medycznych (rozruszniki, pompy insulinowe), systemów alarmowych i innej krytycznej infrastruktury. Nie używaj w szpitalach, na lotniskach ani w miejscach publicznych bez wyraźnej zgody administratora. W niektórych jurysdykcjach samo emitowanie ramek BLE może być traktowane jako zakłócanie pracy urządzeń radiowych. BLE spam attacks may interfere with medical devices (pacemakers, insulin pumps), alarm systems and other critical infrastructure. Do NOT use in hospitals, airports or public places without explicit administrator consent. In some jurisdictions, merely emitting BLE frames may be considered radio interference.
| AtakAttack | PlatformaPlatform | Komenda CLICLI Command | SkutecznośćEffectiveness |
|---|---|---|---|
| Apple Juice | iOS | applejuice | ⭐⭐⭐⭐⭐ |
| Sour Apple | iOS | sourapple | ⭐⭐⭐⭐ |
| Swift Pair | Windows | swiftpair | ⭐⭐⭐⭐⭐ |
| Samsung BLE | Samsung | samsungblespam | ⭐⭐⭐⭐⭐ |
| Google BLE | Android | googleblespam | ⭐⭐⭐⭐ |
| Flipper BLE | Cross | flipperblespam | ⭐⭐⭐ |
| BT Spam All | ALL | btspamall | ⭐⭐⭐⭐⭐ |
| Spoof AirTag | iOS | spoofat | ⭐⭐⭐⭐ |
| FindMy Sound | iOS | findmysound | ⭐⭐⭐⭐⭐ |