Tools & Resources

A practical toolbox for IoT & hardware security - our open-source tools and the gear we reach for. Search it, filter it, use it.

103 items

Bluetooth / BLE

(2)
nRF52840 Dongle

nRF52840 Dongle

by Nordic Semiconductor

A small, low-cost USB dongle (nRF52840 SoC) - a programmable BLE 5.4, Thread, Zigbee, 802.15.4, and 2.4 GHz radio widely used for BLE sniffing and wireless protocol research.

BLEZigbee802.15.4Sniffing
Visit site
Parani-UD100

Parani-UD100

by Sena Networks

A long-range Class 1 Bluetooth USB adapter (300 m, up to ~1 km with the exchangeable antenna) - extends BLE/Bluetooth recon, sniffing, and MITM range for wireless security testing.

BluetoothBLEReconLong-range
Visit site

EMFI

(1)
Faulty Cat

Faulty Cat

by Electronic Cats

An Electromagnetic Fault Injection (EMFI) and voltage glitching tool generating up to ~240V pulses for disrupting embedded system execution and bypassing secure boot. Also features automatic SWD/JTAG pin detection for discovering debug interfaces on unknown targets.

EMFIFault InjectionJTAGSWDGlitching
Buy on OzHack

Hardware Hacking

(15)
Bus Pirate 5

Bus Pirate 5

by Dangerous Prototypes

The upgraded universal hardware-hacking multi-tool - 8 buffered bidirectional I/Os, programmable 1-5V power supply, and support for UART, SPI, I2C, JTAG and more. VT100 terminal interface for direct device interaction with no custom code required.

UARTSPII2CJTAG
Buy on Lab401
CH341A + SOIC-8 Clip

CH341A + SOIC-8 Clip

Clip onto an SPI flash chip in-circuit and dump the firmware without desoldering - the fastest path to a device's code.

SPI FlashDumpingFirmware
Flipper Add-On CANBus

Flipper Add-On CANBus

by Electronic Cats

A Flipper Zero add-on for interacting with CAN bus networks via MCP2515 - monitors, captures, and replays network messages including OBDII automotive frames. Supports both standard and extended data frames for vehicle and industrial IoT security research.

CAN BusAutomotiveOBDIIIoTFlipper Zero
Buy on OzHack
Flipper Add-On Modbus

Flipper Add-On Modbus

by Electronic Cats

A Flipper Zero expansion with SP3485EN transceiver for interacting with industrial RS485/Modbus RTU networks - sniffing, packet injection, traffic analysis, and peripheral configuration. Critical for ICS/SCADA security assessments on industrial control systems.

ModbusICSSCADARS485IoT
Buy on OzHack
GreatFET One

GreatFET One

by Great Scott Gadgets

An open-source USB hardware hacking tool with 100 expansion pins supporting SPI, I2C, UART, and JTAG for interfacing with and analyzing external chips. Python API-driven with extensible neighbor expansion boards for logic analysis, hardware debugging, and protocol reverse engineering.

JTAGSPIUARTUSBHardware Audit
Buy on OzHack
Hot Air Rework Station

Hot Air Rework Station

Desolder eMMC/BGA packages for off-chip dumping and reballing when in-circuit reads aren't an option.

ReworkeMMCReballing

ICEBite

by IoTSRG

A hardware probing toolkit for identifying and interfacing with debug ports - JTAG, UART, and SWD - on embedded devices. Designed for IoT security assessors who need to quickly locate and exploit hardware-level access points.

JTAGUARTSWDHardware ProbingIoT
View on GitHub
JTAGulator (or DIY build)

JTAGulator (or DIY build)

Identify JTAG/UART pinouts on unknown headers by brute-forcing pin combinations - build your own for under $75.

JTAGPinoutDIY
Logic Analyzer

Logic Analyzer

Capture and decode UART, SPI, and I2C traffic to locate debug interfaces and sniff data on the wire - the first tool out of the bag on any new board.

UARTSPISniffing
MACOBOX

MACOBOX

by Mindstorm Security

An all-in-one hardware pentest platform automating firmware extraction across UART, JTAG, SPI, I2C, and SWD interfaces. Built-in level shifters (1.8V-5V), touchscreen UI, cloud vulnerability scanning, and AI-assisted analysis for repeatable engagements.

JTAGUARTFirmwareSPI
Buy on Lab401
Saleae Logic 8

Saleae Logic 8

by Saleae

A professional USB logic analyzer with 8 digital and 8 analog channels at 100 MS/s, decoding JTAG, SPI, I2C, CAN, 1-Wire, and 24+ protocols. Essential for firmware extraction, bus sniffing, and embedded system analysis during IoT security audits.

Logic AnalyzerJTAGSPII2CHardware Audit
Buy on OzHack
Saleae Logic Pro 16

Saleae Logic Pro 16

by Saleae

A professional 16-channel logic analyzer with 500 MS/s digital and 50 MS/s analog (12-bit) capture, supporting 20+ protocols including JTAG, SPI, I2C, USB, CAN, and UART. The go-to instrument for complex multi-bus hardware reverse engineering and firmware extraction.

Logic AnalyzerJTAGHardware AuditReverse EngineeringProtocol Analysis
Buy on OzHack
Saleae Logic Pro 8

Saleae Logic Pro 8

by Saleae

A professional USB 3.0 logic analyzer with 8 digital channels at 500 MS/s and 8 analog channels at 50 MS/s (12-bit), supporting 30+ protocols including JTAG, SPI, I2C, UART, and CAN. Deep inspection of embedded system communications for IoT security audits.

Logic AnalyzerJTAGUARTEmbedded SecurityProtocol Analysis
Buy on OzHack
Screen Crab

Screen Crab

by Hak5

A covert HDMI MITM implant that passively captures full HD 1080p screenshots and video from any HDMI connection with zero lag via an onboard signal splitter. Stores captures to MicroSD and supports remote exfiltration over WiFi through Hak5 Cloud C2.

HDMIVideo CaptureHardware ImplantWiFiPhysical Pentest
Buy on OzHack
WHIDBoard Pro

WHIDBoard Pro

by Lab401

A complete hardware auditing toolkit with 24-channel pin enumerator, 8-channel logic analyzer, and native UART/SPI/I2C/JTAG/SWD support. Pre-integrated with TSURUGI Linux, flashrom, OpenOCD, Ghidra, and binwalk for full embedded device analysis.

JTAGUARTSWDFirmwareExtraction
Buy on Lab401

Lock Picking

(17)
Clear Acrylic Practice Lock

Clear Acrylic Practice Lock

by Sparrows Lock Picks

A transparent acrylic practice lock revealing pin and spring movement in real time, with interchangeable standard, spool, and serrated pin sets to simulate beginner through high-security lock internals. Essential for learning lock picking mechanics hands-on during physical security training.

LockPickingPhysical SecurityTrainingCutaway
Buy on OzHack
Double Door Bypass Tool (DDT)

Double Door Bypass Tool (DDT)

by KSec

A physical bypass tool that simultaneously engages latches or panic bars on both doors of a double-door setup with a single push, enabling rapid entry without separately manipulating each mechanism. Demonstrates double-door installation vulnerabilities during red team engagements.

LockPickingPhysical SecurityRed TeamBypassAccess Control
Buy on OzHack
Entry Wedge - Quick Access Tool

Entry Wedge - Quick Access Tool

by KSec

An inflatable entry wedge with a stiff plastic shim that slides into door or window gaps and expands to create clearance for latch bypass tools. Used by physical penetration testers to gain access during authorized assessments without damaging doors or frames.

LockPickingPhysical PentestEntry ToolBypassPhysical Security
Buy on OzHack
HUK 12-in-1 Lock Disassembly Kit

HUK 12-in-1 Lock Disassembly Kit

by HUK

A comprehensive 12-piece professional toolkit for disassembling and reassembling cylinder locks - plug followers, circlip remover, pliers, tweezers, G clamp, and carry case. Essential for analyzing lock internals, studying pin configurations, and performing detailed lock audits.

LockPickingPhysical SecurityLock DisassemblyHardware Audit
Buy on OzHack
HUK 7-Pin Tubular Lock Pick Set

HUK 7-Pin Tubular Lock Pick Set

by HUK

A 3-piece tubular lock pick set (7.0mm, 7.5mm, 7.8mm) with tempered stainless steel picking fingers, adjustable friction collar, and decoder key for 7-pin tubular locks in vending machines, safes, and coin-operated equipment. Audits IoT devices and coin-operated systems using tubular lock mechanisms.

LockPickingPhysical SecurityHardware AuditTubular Lock
Buy on OzHack
Lishi LW5 2-in-1 Pick & Decoder

Lishi LW5 2-in-1 Pick & Decoder

by Lishi

A professional 2-in-1 lock pick and decoder for Lockwood 5-pin (LW5/C4) residential locks common in Australia, the US, and UK. Non-destructively picks and decodes key bitting values directly from the cylinder for physical security assessments of residential and commercial entry points.

LockPickingPhysical SecurityLockDecoderResidential
Buy on OzHack
Master Lock Picking Training Kit

Master Lock Picking Training Kit

by KSec

A comprehensive physical security training kit with practice locks (standard, serrated, spool pins), tension wrenches, cutaway euro cylinder locks, and carrying case. For security researchers and penetration testers learning to assess and bypass physical access controls.

LockPickingPhysical SecurityPenetration TestingTraining
Buy on OzHack
Mini Jim EDC Latch Bypass (V2)

Mini Jim EDC Latch Bypass (V2)

by KSec

A compact, non-destructive latch bypass tool for quickly defeating spring latch locks without leaving damage. Used by security researchers and red teamers for physical penetration testing and access control assessments during authorized engagements.

LockPickingPhysical PentestLatch BypassEDC
Buy on OzHack
Sparrows Mini Jim

Sparrows Mini Jim

by Sparrows

A compact breaching tool for bypassing door latches, small enough to fit in a Sherman or tuxedo case. Useful for physical security researchers and red teamers conducting access control assessments and entry-point testing.

LockPickingPhysical SecurityBypassBreachingRed Team
Buy on OzHack
Sparrows Quick Jim

Sparrows Quick Jim

by Sparrows Lock Picks

A stainless steel bypass tool that retracts a door latch by sliding behind it, enabling rapid non-destructive entry. Demonstrates physical access vulnerabilities in commercial and institutional door hardware without damaging the lock mechanism.

LockPickingPhysical BypassLatch BypassPenetration Testing
Buy on OzHack
Standard Pin Cut Away Lock

Standard Pin Cut Away Lock

by Sparrows Lock Picks

A five-pin cut-away practice lock exposing the internal pin mechanism so researchers can observe and learn pin manipulation techniques in real time. Ideal for physical security assessors building lock-picking proficiency with a Schlage keyway cylinder.

LockPickingPhysical SecurityPractice LockTraining
Buy on OzHack
The EOD - Full Pick Set

The EOD - Full Pick Set

by Sparrows Lock Picks

A professional-grade lock pick set heavy on raking tools with a mini Door Jim and wafer picks, designed for rapid non-destructive entry into doors, cabinets, and luggage. Suits physical penetration testers needing fast, quiet access under operational conditions.

LockPickingPhysical PentestRed TeamCovert EntryRaking
Buy on OzHack
The Escort

The Escort

by Sparrows Lock Picks

A folding lock pick set with hooks, rakes, and tension wrench in a compact EDC-friendly form factor - all picks lock in place and a trap-door gives access to the tension wrench for discreet carry. For field lock picking assessments and covert entry during physical pentests.

LockPickingEDCPhysical PentestFolding Pick Set
Buy on OzHack
The Vorax

The Vorax

by Sparrows Lock Picks

A 15-piece professional lock picking kit with .025 stainless steel picks and thermal handles - rakes, SSDeV hooks, and Sandman pick in a Multicam Black tactical case. Covers raking, single pin picking, and high-security deep access picking for physical penetration testers.

LockPickingPhysical PentestHardware AuditRed Team
Buy on OzHack
Tuxedo Set

Tuxedo Set

by Sparrows Lock Picks

A professional everyday-carry lock picking kit with 7 picks (including thin pick for narrow keyways) and 6 tension wrenches in a compact case. Ideal for physical penetration testing and lock vulnerability assessments during red team engagements.

LockPickingPhysical SecurityRed TeamEDC
Buy on OzHack
Ultimate Multi-Tool & Bypass Set

Ultimate Multi-Tool & Bypass Set

by KSec

A compact 20-piece lock picking and bypass kit with tension wrenches, comb rakes, and specialized bypass implements in a pocket-sized EDC form factor. For physical penetration testers conducting lock vulnerability assessments and covert entry scenario evaluations.

LockPickingPhysical PentestEDCBypass Tools
Buy on OzHack
Ultimate Wafer Lock Entry Set

Ultimate Wafer Lock Entry Set

by KSec

A comprehensive 35-piece jiggler and skeleton key set for opening wafer locks commonly found in cabinets, lockers, and automotive applications. Ideal for physical penetration testers assessing lock vulnerabilities in low-security environments.

LockPickingPhysical SecurityJigglersWafer Lock
Buy on OzHack

Multi-Tool

(2)
Flipper Zero

Flipper Zero

by Flipper Devices Inc.

A pocket-sized multi-tool for pentesters combining RFID/NFC read/write/emulate, Sub-GHz transceiver, IR, iButton, and HID emulation in a single open-source device. Operates standalone - ideal for field assessments of access control systems and IoT radio protocols.

RFIDSubGHzNFCBLEHardwareAudit
Buy on Lab401
Minino IoT Multitool

Minino IoT Multitool

by Electronic Cats

The first multi-protocol IoT security tool - detects, sniffs, and manipulates BLE, Zigbee, Thread, WiFi, and Matter protocols. Outputs PCAP to SD card for Wireshark, supports WiFi deauth, AirTag jamming, and GPS-tagged wardrive operations.

BLEZigbeeWiFiIoTMatter
Buy on Lab401

RFID / NFC

(19)
BlueShark

BlueShark

by ProxGrind

A wireless kit adding Bluetooth 2.0 EDR and a 400mAh battery to the Proxmark3 RDV4, enabling untethered RFID attacks in the field. Supports standalone mode, offline sniffing, and offline card reading/simulation for covert access control assessments.

RFIDBluetoothProxmark3NFCStandalone
Buy on OzHack
BomberCat

BomberCat

by Electronic Cats

Combines NFC and magnetic stripe card technologies (RP2040 + PN7150 NFC + ESP32) for auditing banking terminals, reading/writing NFC cards, and emulating magstripe data. Supports card emulation, read/write, and Magspoof modes with WiFi remote testing via HTTP or MQTT.

NFCRFIDBLEMagSpoofHardware Audit
Buy on OzHack
Chameleon Ultra

Chameleon Ultra

by RfidResearchGroup

A keychain-sized RFID emulator supporting LF (125kHz) and HF (13.56MHz) - clone, read, write, and emulate RFID/NFC credentials on the go. Performs active MIFARE Classic key cracking via Darkside and Nested algorithms.

RFIDNFCEmulationClone
Buy on Lab401
DESFire Card (4B & 7B UID Changeable)

DESFire Card (4B & 7B UID Changeable)

by ProxGrind

A fully emulatable DESFire smart card with changeable UID, SAK, ATQA, and ATS for both 4-byte and 7-byte UID modes. Enables cloning, spoofing, and testing of access control systems that rely on MIFARE DESFire credential verification.

RFIDDESFireUID CloningAccess ControlNFC
Buy on OzHack
ESP Key - Wiegand Interceptor

ESP Key - Wiegand Interceptor

by April Brother

A WiFi-enabled passive logger that intercepts and captures Wiegand protocol credentials from RFID card readers via a covert 4-wire tap, supporting 26-37 bit HID cards. Provides web-based log access and experimental replay/fuzzing mode for access control system audits.

RFIDWiegandAccessControlWiFiInterception
Buy on OzHack
Flipper Add-On MagSpoof

Flipper Add-On MagSpoof

by Electronic Cats

A MagSpoof add-on for Flipper Zero enabling magnetic stripe card emulation by generating electromagnetic fields that mimic all three tracks of traditional magstripe cards on standard readers. Tests access control systems, payment terminals, and ID card readers without physical card contact.

MagStripeRFIDCard EmulationAccess ControlFlipper Zero
Buy on OzHack
GDMIC Rewritable Keyfob

GDMIC Rewritable Keyfob

by GDMIC

A rewritable keyfob using scrolling (rolling) code technology to clone and emulate access control cards and elevator cards with anti-copy protections. Compatible with ICOPY-X10 and Honey Badger for capturing and replaying rolling-code credentials.

RFIDRolling CodeAccess ControlCard Cloning
Buy on OzHack
ICopy-X

ICopy-X

by Lab401

A standalone RFID cloning device built on Proxmark 3 - reads, cracks, and clones LF/HF badges in the field without a laptop. Supports MIFARE Classic, NTAG, iCLASS, EM410x, and HID Prox with 16GB storage and built-in battery.

RFIDNFCBadgeCloningProxmark
Buy on Lab401
iCS Decoder (iCLASS SE & SEOS)

iCS Decoder (iCLASS SE & SEOS)

by ProxGrind

A USB-C accessory for the iCopy-XS that reads and clones iCLASS SE and SEOS credential cards, covering ~85% of compatible readers. Extracts CSN, Facility Code, and Card Number for auditing HID-based physical access control systems.

RFIDiCLASSSEOSAccess ControlCard Cloning
Buy on OzHack
Magic NTAG215 (UID Changeable Gen3)

Magic NTAG215 (UID Changeable Gen3)

by Electronic Cats

A Gen3 UID-changeable NTAG215 card with 504 bytes of NDEF memory - clone and emulate NFC tags by modifying the UID using Proxmark commands. Used for RFID cloning, access control bypass research, and NFC replay attack testing.

RFIDNFCUID-CloningProxmarkAccessControl
Buy on OzHack
MagSpoof v5

MagSpoof v5

by Electronic Cats

A compact device that wirelessly emulates magnetic stripe data across all three tracks, letting researchers test magstripe readers in credit cards, hotel keys, parking systems, and driver licenses without physical card contact. USB-C with integrated LiPo charger and Arduino-compatible.

MagStripeCard EmulationRFIDHardware AuditUSB
Buy on OzHack
NFC Kill

NFC Kill

by NFCKill

The world's only RFID fuzzing tool - permanently disables RFID/NFC cards across 125KHz to 950MHz via high-voltage pulses up to ~1600V. Used for access control audits, RFID hardware testing, and GDPR-compliant data destruction on contactless credentials.

RFIDNFCFuzzingAccess ControlHardwareAudit
Buy on OzHack
Proxmark 3 RDV4.01

Proxmark 3 RDV4.01

by RRG / Proxmark

The gold-standard RFID platform - reads, writes, sniffs, replays, and emulates LF (125kHz) and HF (13.56MHz) RFID/NFC systems. Used for access control audits, credential cloning, and MITM attacks on contactless protocols.

RFIDNFCEmulationAccessControl
Buy on Lab401
RFID Field Detector Ultra

RFID Field Detector Ultra

by Lab401

A passive, battery-free tri-band tool identifying RFID fields across LF (125kHz), HF (13.56MHz), and UHF (860-960MHz) with color-coded LEDs. No firmware or RF signature - ideal for covert recon of access control infrastructure.

RFIDNFCPassiveReconDetection
Buy on Lab401
Super Sniffer Card (MiFare)

Super Sniffer Card (MiFare)

by ProxGrind

A passive sniffing card that captures random numbers exchanged between MiFare M1/M4 cards and readers during legitimate transactions, storing up to 7 sets for offline MfKey32 key recovery attacks. Audits RFID access control by recovering secret keys without active cloning equipment.

RFIDMiFareNFCCardSnifferKeyRecovery
Buy on OzHack
T5577 125KHz Writable Keyfob

T5577 125KHz Writable Keyfob

by ProxGrind

A writable 125KHz RFID keyfob with changeable UID, compatible with EM4305 and a wide range of 125KHz access control readers. Clone, emulate, and test low-frequency RFID badges and proximity card systems during physical penetration tests.

RFID125KHzT5577CloningAccessControl
Buy on OzHack
Ultimate Magic Card Gen4

Ultimate Magic Card Gen4

by ProxGrind

A fully configurable RFID/NFC card emulation platform supporting MIFARE Mini/1k/4k, Ultralight, and NTAG types with customizable UID (4/7/10-byte), SAK, ATQA, and ATS parameters. Compatible with Proxmark3 RDV4, iCopy-XS, and LibNFC, with Shadow Mode for field-safe temporary modifications.

RFIDNFCCardEmulationMIFAREProxmark3
Buy on OzHack
Ultimate Magic Keyfob Gen4

Ultimate Magic Keyfob Gen4

by ProxGrind

A multi-purpose RFID emulation keyfob supporting MIFARE variants and NTAG specifications with adjustable UID, SAK, ATQA, and ATS for access control research. Features Shadow Mode for temporary field modifications and Recovery Mode to prevent bricking.

RFIDNFCCard EmulationAccess ControlProxmark3
Buy on OzHack
USB RFID Reader/Writer DL533N

USB RFID Reader/Writer DL533N

by Lab401

A USB stick-form 13.56MHz LibNFC-compatible reader/writer for MIFARE Classic, Ultralight, FeliCa, and ISO 14443B cards. Integrates with mfoc and mfcuk for offline dictionary and nested attacks against access control systems.

RFIDNFCMIFAREUSB
Buy on Lab401

SDR

(9)
ANT500 Telescopic Antenna

ANT500 Telescopic Antenna

by Great Scott Gadgets

A 50-ohm telescopic antenna covering 75 MHz to 1 GHz for SDR platforms like HackRF One. Used for RF spectrum analysis, signal capture, and wireless protocol investigations across SubGHz and lower UHF bands.

SDRAntennaSubGHzRFHackRF
Buy on OzHack
ANT700 Telescopic Antenna

ANT700 Telescopic Antenna

by Great Scott Gadgets

A stainless steel telescopic antenna covering 300 MHz to 1100 MHz with SMA male connector, rotating shaft, and adjustable elbow - compatible with HackRF One and YARD Stick One. Versatile general-purpose antenna for signal capture and RF experimentation.

SDRSubGHzAntennaRFHackRF
Buy on OzHack
BladeRF 2.0 Micro xA4

BladeRF 2.0 Micro xA4

by Nuand

A wide-band 2x2 MIMO full-duplex SDR transceiver (47MHz-6GHz) for GSM traffic interception, GPS signal manipulation, and IoT RF protocol analysis. USB 3.0 SuperSpeed with onboard FPGA, compatible with GNU Radio and MATLAB.

SDRMIMORFGSM
Buy on Lab401
HackRF Pro

HackRF Pro

by GreatScott Gadgets

A wide-band half-duplex SDR transceiver (100kHz-6GHz) for capturing, decoding, and replaying wireless signals - Bluetooth sniffing, GPS research, GSM monitoring, and RFID analysis. TCXO precision, 16-bit sampling, and USB-C over the original HackRF One.

SDRSubGHzBluetoothRF
Buy on Lab401
KrakenSDR

KrakenSDR

by KrakenRF

A 5-channel coherent SDR for radio direction finding (RDF) - triangulates and tracks IoT devices, rogue APs, and covert RF beacons across 24MHz-1766MHz. Open-source with GPS-based mobile app for field spectrum reconnaissance and unauthorized transmitter hunting.

SDRRDFRFSpectrumAnalysis
Buy on Lab401
PortaPack H4M + HackRF

PortaPack H4M + HackRF

by OpenSource SDR Lab

A self-contained portable SDR on HackRF pre-flashed with MAYHEM firmware - GPS spoofing, Bluetooth sniffing, TPMS decoding, spectrum analysis, and signal jamming from a touchscreen handheld. No computer required for on-site wireless assessments.

SDRSubGHzBluetoothRF
Buy on Lab401
RTL-SDR R820T2+RTL2832U

RTL-SDR R820T2+RTL2832U

by RTL-SDR Blog

An entry-level SDR USB dongle (24 MHz - 1.7 GHz, up to 3.2 MHz instantaneous bandwidth) for passively capturing and analyzing radio signals. Covers sub-GHz IoT protocols, ADS-B aircraft transponders, weather satellites, and other wireless communications.

SDRSubGHzRFRadioScanningIoT
Buy on OzHack
RTL-SDR V4

RTL-SDR V4

by RTL-SDR Blog

A wideband SDR receiver tuning from 500 kHz to 1.7 GHz for passively monitoring and analyzing RF signals including ADS-B, AIS, weather satellites, and SubGHz IoT protocols. Built-in HF up-converter, 1PPM TCXO for frequency accuracy, and software-activatable bias-tee.

SDRSubGHzRFIoTWireless
Buy on OzHack
SignalSDR Pro

SignalSDR Pro

by SignalLens

An industry-grade SDR (70MHz-6GHz, 56MHz bandwidth, 12-bit at 61.44 MSPS) purpose-built for 5G pentesting and cellular network auditing. Emulates USRP and ADALM-PLUTO frameworks with Open5GS and 5ghoul integration in a Raspberry Pi form factor.

SDR5GRFCellularAudit
Buy on Lab401

SubGHz / RF

(10)
CatSniffer V3

CatSniffer V3

by Electronic Cats

A multi-protocol multi-band USB sniffer and attack tool for IoT security research, supporting SubGHz, LoRa/LoRaWAN, Zigbee, Thread, BLE 5.2, and IEEE 802.15.4g across Sub-1GHz and 2.4GHz. TI CC1352 + RP2040 in a compact USB-C stick for capturing and interacting with a wide range of IoT protocols.

SubGHzBLELoRaZigbeeIoT
Buy on OzHack
Evil Crow RF V2

Evil Crow RF V2

by Evil Crow

A multi-band RF security testing device with two CC1101 modules (300-928MHz) and NRF24L01 (2.4GHz) enabling simultaneous transmission and reception across different frequencies. Supports replay attacks, signal analysis, brute-force, MouseJacking, and WiFi-based configuration.

SubGHzRFReplay AttackMouseJacking433MHz
Buy on OzHack
Feberis Pro

Feberis Pro

by SAPSAN

A Flipper Zero expansion covering Sub-GHz (433/868/900MHz) and 2.4GHz with MouseJacker, WiFi deauth, BLE wardriving + GPS, and multi-protocol packet capture. Signal capture, replay, and RF remote cloning at 100m+ range - no external power needed.

SubGHzWiFiBLERFIoT
Buy on Lab401
FlatSat 1

FlatSat 1

by Electronic Cats

An intentionally vulnerable hardware training platform for aerospace cybersecurity, featuring dual LoRa transceivers, RP2040 MCU, and environmental/motion sensors. Practice binary exploitation, reverse engineering, RF signal testing in ISM bands, and space-themed CTF challenges.

LoRaSubGHzCTFIoTRF
Buy on OzHack
Flipper Add-On SubGHz (CC1101+LoRa)

Flipper Add-On SubGHz (CC1101+LoRa)

by Electronic Cats

A Flipper Zero expansion with dual CC1101 and LoRa SX1262 transceivers covering 150-960 MHz Sub-GHz spectrum for monitoring, analyzing, and replaying IoT wireless signals. Supports long-range LoRa communication and sub-1GHz protocols used in smart home and industrial sensors.

SubGHzLoRaSDRIoTFlipper Zero
Buy on OzHack
PandwaRF Rogue Pro

PandwaRF Rogue Pro

by Comthings

A pocket-sized RF capture, decrypt, and transmit device covering 300-950MHz for auditing wireless remote control systems. Supports automated scanning, rolling-code decryption (30x accelerated via Kaiju platform), demodulation, and SubGHz jamming.

SubGHz433MHzRollingCodeRF
Buy on Lab401
T-Deck Plus 915 MHz

T-Deck Plus 915 MHz

by LilyGo

An ESP32-S3 handheld combining WiFi, BLE 5, SX1262 LoRa (915 MHz), GPS, 2.8" display, keyboard, and 2000mAh battery - ideal for wireless protocol research and LoRa network auditing in the field. Supports custom firmware via Arduino or MicroPython.

LoRaSubGHzWiFiBLEESP32
Buy on OzHack
T-Deck Pro Voice 915 MHz

T-Deck Pro Voice 915 MHz

by LilyGo

A compact ESP32-S3 handheld with keyboard, 3.1" touchscreen, LoRa SX1262 (915 MHz), GPS, WiFi, BLE 5 plus audio (PCM5102A, mic, speaker) for SubGHz communications research and portable IoT security tooling. Ideal for off-grid mesh protocols and LoRaWAN network auditing.

SubGHzLoRaWiFiBLEIoT
Buy on OzHack
WiFi LoRa 32 v4 (915 MHz)

WiFi LoRa 32 v4 (915 MHz)

by Heltec Automation

A compact ESP32-S3 board integrating SX1262 LoRa (902-928 MHz), WiFi, and Bluetooth with 28 dBm TX power and integrated OLED display - versatile for IoT security research, LoRaWAN network testing, and Meshtastic field deployments.

LoRaWiFiBLESubGHzIoT
Buy on OzHack
YARD Stick One

YARD Stick One

by Great Scott Gadgets

A sub-1 GHz wireless transceiver (281-961 MHz) that ships with RfCat firmware for transmitting and receiving signals from an interactive Python shell. Widely used for analyzing, replaying, and fuzzing SubGHz protocols in automotive key fobs, garage door openers, and IoT sensors.

SubGHzSDRRFWirelessIoT
Buy on OzHack

USB Attack

(14)
Bash Bunny Mark II

Bash Bunny Mark II

by Hak5

A multi-function USB attack platform emulating HID, storage, and network devices simultaneously for credential harvesting and network infiltration. Full Linux OS with Bluetooth remote triggering, geofencing, and microSD exfiltration.

USBHIDKeystrokeInjectionRedTeam
Buy on Lab401
Cynthion

Cynthion

by GreatScott Gadgets

A USB reverse engineering platform for passive capture and protocol analysis of USB Low/Full/High-Speed traffic. Enables real-time MITM interception via USBProxy and custom USB device emulation through Python or FPGA.

USBMITMFPGAFirmware
Buy on Lab401
Evil Crow Wind

Evil Crow Wind

by Evil Crow

An ESP32-S3-based BadUSB device with USB-C form factor that mimics a phone charging cable while delivering wireless-controlled HID payloads via a web panel interface. Tests endpoint defenses against rogue USB devices with WiFi-based attack delivery.

USB AttackBadUSBWiFiESP32HID Injection
Buy on OzHack
EvilCrow Keylogger

EvilCrow Keylogger

by EvilCrow

A covert hardware keylogger (Atmega32U4 + ESP32-PICO WiFi) that sits inline between a USB keyboard and host to silently capture keystrokes. Retrieved wirelessly via web interface or physically from the onboard MicroSD slot - useful for physical penetration testing.

USB AttackWiFiHardware AuditKeyloggerPhysical Pentest
Buy on OzHack
Key Croc

Key Croc

by Hak5

A keylogging pentest implant inline on USB keyboards - records keystrokes and triggers DuckyScript payloads when typed patterns match keywords/regex. Emulates multiple USB personas, clones hardware IDs for evasion, and runs Debian Linux with Cloud C2 support.

USB AttackKeyloggerHIDPentest ImplantHardware Audit
Buy on OzHack
O.MG Adapter Elite

O.MG Adapter Elite

by O.MG

A USB adapter with an advanced implant supporting DuckyScript 3 at up to 890 keys/sec with encrypted WiFi C2, hardware keylogger (650,000 keystrokes), geo-fencing, and self-destruct. USB 2.0 data passthrough makes it indistinguishable from a legitimate adapter.

USB AttackKeyloggerRed TeamC2DuckyScript
Buy on OzHack
O.MG Cable

O.MG Cable

by Hak5

A USB exploit cable disguised as a charging or data cable - emulates HID keyboard/mouse and executes payloads locally or remotely via built-in WiFi. Elite variants add keystroke logging, covert exfiltration, and air-gap communications.

USBHIDWiFiRedTeam
Buy on Lab401
O.MG Malicious Cable Detector

O.MG Malicious Cable Detector

by O.MG

Uses side-channel power analysis at 200,000 samples/sec to identify malicious USB cables including stealthy variants that hide activity until triggered. Also functions as a data blocker during charging - dual-purpose for hardware security audits and supply chain cable inspection.

USBHardware AuditSide-ChannelData BlockerSupply Chain
Buy on OzHack
O.MG Plug Elite

O.MG Plug Elite

by O.MG

A compact USB keystroke and mouse injection tool supporting DuckyScript 3 at up to 890 keystrokes/sec with WiFi C2, geo-fencing, self-destruct, and 300 payload slots. Remote payload delivery and port stealthing from any browser-connected device.

USB AttackKeystroke InjectionWiFiRed TeamPayload Delivery
Buy on OzHack
O.MG Programmer USB A+C

O.MG Programmer USB A+C

by O.MG

A universal programming and management tool for the full O.MG ecosystem - initial setup, firmware upgrades, recovery from self-destruct, and forensic dumps of any O.MG device. Essential for deploying and maintaining USB implant hardware in bulk during red team engagements.

USBRed TeamFirmwareHardware AuditO.MG
Buy on OzHack
O.MG UnBlocker Elite

O.MG UnBlocker Elite

by O.MG

A USB data blocker disguised form containing a covert wireless implant with keystroke injection at 890 keys/sec, USB spoofing, bidirectional tunneling, and encrypted C2. 300 payload slots, geo-fencing, and self-destruct for assessing endpoint defenses against hardware-based attacks.

USB AttackKeystroke InjectionWiFiRed TeamHardware Implant
Buy on OzHack
Paw Detector

Paw Detector

by Electronic Cats

Identifies malicious USB cables and keyloggers by detecting keystroke injection, mouse injection, payload injection, and hardware keylogging attacks in real time - no software required. Connect a suspect cable, plug into a computer, and an LED instantly indicates whether the cable is malicious.

USBHardware AuditKeylogger DetectionBadUSBInjection Attack
Buy on OzHack
Rubber Ducky

Rubber Ducky

by Hak5

A USB keystroke injection platform emulating a trusted HID keyboard to deliver DuckyScript payloads at over 1000 words/min. Automates credential harvesting, backdoor installation, and data exfiltration across Windows, macOS, Linux, and Android.

USBHIDKeystrokeInjectionRedTeam
Buy on Lab401
USBNinja Pro Remote

USBNinja Pro Remote

by ProxGrind

A BLE-based wireless trigger for the USBNinja Pro exploit framework, enabling remote payload execution at ranges of 30-50 meters (up to 80m with bi-directional antenna). Extends USB attack delivery beyond smartphone app range for covert physical penetration testing.

USB AttackBLEWireless TriggerPhysical PentestHID Attack
Buy on OzHack

WiFi / Network

(14)
ALFA AWUS036AXML WiFi 6E

ALFA AWUS036AXML WiFi 6E

by Alfa Wireless

A tri-band WiFi 6E (802.11axe) USB adapter covering 2.4/5/6 GHz with Bluetooth 5.2, designed for high-performance wireless assessments and Kali Linux-compatible. Replaceable RP-SMA antenna connector allows swapping in higher-gain antennas for extended-range WiFi reconnaissance.

WiFiWiFi6EBluetoothPacketCaptureKaliLinux
Buy on OzHack
AWOK Dual C5 Touch

AWOK Dual C5 Touch

by AWOK Dynamics

A Flipper Zero add-on with dual ESP32-C5 for simultaneous 2.4GHz/5GHz WiFi 6 and BLE operations plus onboard GPS for georeferenced wardriving. Supports beacon spam, deauth, Evil Portal, and BLE spoofing across multiple firmware profiles.

WiFiBLEWiFi6Wardriving
Buy on Lab401
Flipper Add-On Ethernet

Flipper Add-On Ethernet

by Electronic Cats

An Ethernet add-on for Flipper Zero using ENC28J60 over GPIO/SPI - enables ARP scanning, ARP poisoning/spoofing, device detection, ping, and PCAP packet capture. For wired network audits and traffic monitoring in environments without WiFi.

NetworkEthernetPacket CaptureARP SpoofingFlipper Zero
Buy on OzHack
Flipper Add-On Marauder+Spoof

Flipper Add-On Marauder+Spoof

by Electronic Cats

A Flipper Zero module combining ESP32-S3 WiFi Marauder with MagSpoof - supports deauth attacks, beacon spam, active packet injection, and wireless magstripe emulation. One board for both WiFi/Bluetooth offensive testing and physical card emulation.

WiFiBluetoothMagSpoofESP32Flipper Zero
Buy on OzHack
Flipper Multi-in-One (WiFi+RF+GPS)

Flipper Multi-in-One (WiFi+RF+GPS)

by Electronic Cats

A single Flipper Zero add-on combining ESP32C5 dual-band WiFi (Marauder 5G firmware), 433MHz RF transceiver, and GPS - WiFi attacks, SubGHz RF analysis, and GPS positioning in one board. Versatile for comprehensive IoT and hardware security field work.

WiFiSubGHzESP32GPSFlipper Zero
Buy on OzHack
Flipper Zero WiFi Devboard

Flipper Zero WiFi Devboard

by Flipper Zero

An ESP32-S2 expansion for Flipper Zero adding WiFi pentesting - deauth attacks, PMKID capture, and passive network monitoring in promiscuous mode. Doubles as a Black Magic Probe for in-circuit USB/WiFi debugging and OTA firmware updates.

WiFiESP32FirmwareIoT
Buy on Lab401
GhostBoard

GhostBoard

by Lab401

A WiFi 6 + BLE 5 audit board for Flipper Zero running GhostESP - WiFi deauth, evil portal, karma, handshake capture, wardriving, AirTag spoofing, and skimmer detection. Includes Ethernet mode and web screen mirroring via GhostLink.

WiFiBLEBluetoothWardriving
Buy on Lab401
LAN Turtle

LAN Turtle

by Hak5

A covert network implant disguised as a USB-to-Ethernet adapter for MITM attacks, traffic capture, DNS poisoning, and internal network mapping. Supports reverse shells and VPN tunneling for authorized red-team operations.

NetworkMITMUSBLAN
Buy on Lab401
Packet Squirrel Mark II

Packet Squirrel Mark II

by Hak5

A compact Linux-based MITM network implant with dual RJ45 ports, DNS spoofing, packet sniffing, and reverse shell deployment. Scriptable in DuckyScript, Bash, or Python - plug it in-line between devices during authorized network audits.

NetworkMITMPacketSniffingDNS
Buy on Lab401
Plunder Bug LAN Tap

Plunder Bug LAN Tap

by Hak5

A pocket-sized USB-C Ethernet tap that passively intercepts and records 10/100 Base-T traffic between two endpoints without disrupting the connection. Enables passive network reconnaissance and active scanning using Wireshark across Windows, Mac, and Linux.

NetworkLAN TapPacket CaptureMITMUSB
Buy on OzHack
Shark Jack

Shark Jack

by Hak5

A keyring-sized network auditing tool for rapid network reconnaissance - automated nmap scans and data exfiltration with fully customizable DuckyScript payloads. Compact and ideal for covert network intelligence during IoT/hardware pentesting.

NetworkReconnaissanceAutomation
Buy on Lab401
Throwing Star LAN Tap Kit

Throwing Star LAN Tap Kit

by Hak5

A passive Ethernet tap requiring no power that inserts inline as a transparent cable segment, splitting receive lines to two monitoring ports for silent network traffic capture. Essential for 10/100BASE-TX MITM analysis and packet inspection.

NetworkPassive TapEthernetPacket CaptureMITM
Buy on OzHack
Throwing Star LAN Tap Pro

Throwing Star LAN Tap Pro

by Hak5

A passive Ethernet tap monitoring 10/100BASE-TX traffic inline between target equipment with receive-only monitoring ports for a truly transparent, undetectable tap. Works with Wireshark and tcpdump, no power required.

NetworkPassive TapPacket CaptureEthernetUndetectable
Buy on OzHack
WiFi Pineapple Mark VII

WiFi Pineapple Mark VII

by Hak5

Hak5's advanced WiFi auditing platform with PineAP suite - rogue AP, deauth, WPA/WPA-Enterprise credential capture, DNS spoofing, and packet capture. The go-to tool for assessing wireless infrastructure resilience during network security engagements.

WiFiMITMNetworkAuditWPA
Buy on Lab401