// the find
cifertech/ESP32-DIV
ESP32DIV is a multi-purpose wireless offensive and defensive toolkit powered by an ESP32
ESP32-DIV is an open-source handheld toolkit built on an ESP32-S3, with a 2.8 inch TFT touchscreen and a companion shield carrying NRF24, CC1101 Sub-GHz and IR modules. It covers Wi-Fi, BLE, 2.4GHz, Sub-GHz, IR, RFID/NFC and GPS, and most of its tools are offensive, including deauth, beacon spam, jamming, card cloning and AirTag spoofing. It is aimed at security researchers and hobbyists who own the hardware and the networks they test.
The defensive counterparts sit next to the offensive tools: Deauth Detector beside the deauth attack, Jamming Detector beside the Sub-GHz jammer, and AirTag Sniffer beside the AirTag spoofer. That pairing is useful for anyone studying both sides of an attack. The hardware is in the repo too, with Gerbers, schematics and BOMs for both board revisions, so the design can be rebuilt without asking the author. Flashing is low-friction, with a browser flasher, merged firmware images for each board variant, and a Python flasher that bundles the bootloader and partition tables.
The repo carries a lot of committed binaries: two copies of the TFT_eSPI and CC1101 library zips, ELF and map files under tools/, a stack of pre-compiled .bin images, and a leftover Touchscreen.h.bak beside the source. That makes clones heavy and firmware diffs hard to review. Setup detail is pushed to an external wiki, and the visible part of the tree has no tests and no CI workflow, so changes are checked by hand on hardware. The legal framing is one warning line. Jamming is illegal to operate in most countries, and deauthing or spoofing devices you do not own usually falls under computer misuse or radio rules, whatever the research intent. The README does not address that beyond the warning. The 2.4GHz, Sub-GHz and IR sections need the shield's NRF24, CC1101 and IR parts, so a bare ESP32-S3 covers mostly the Wi-Fi and BLE tools.