Skip to content

catsniffer-v3

Electronic Cats CatSniffer v3 — multiprotocol sub-GHz, BLE and 802.15.4

Vendor: Electronic Cats

Status: supported — the identifiers and setup recipe are believed correct.

Maintainer-verified 2026-08-26 on Pop!_OS 22.04: Attached and enumerated; identifier, product string and serial captured with scripts/identify-device.sh. The radio side was not exercised and no firmware was flashed.

What it is

A multiprotocol RF board built around Texas Instruments radio silicon, covering sub-GHz ISM bands, Bluetooth Low Energy and IEEE 802.15.4 from one device.

What you can do with it

Sniff and analyse traffic across the three protocol families it supports, and load alternative firmware for specific capture tasks.

Setup

This board is an RP2040 (confirmed by capture, see below), not the ESP32 the badgelife class serves, so it joins no class. Its Linux-side needs are a serial console — tio /dev/ttyACM0 at 115200 8N1 — and, for firmware, the RP2040 UF2 bootloader: hold BOOTSEL while attaching and it mounts as a USB mass-storage device you copy a .uf2 onto. Confirm it appears under /dev before going further.

Known problems

Firmware and host tooling are versioned together and the board ships in several firmware variants; a capture tool that reports nothing is usually running against the wrong firmware rather than a quiet band. Kismet is not a host tool for it yet: Kismet's CatSniffer Zigbee helper (on its development branch since 2024-09-18) and its Sniffle BLE helper (since 2026-07-22) are in no Kismet release and in no packaging measured on 2026-09-30 -- not Kali's, Parrot's, or Kismet's own release or nightly repositories -- so kismet is not in this entry's packages until a release carries them. The USB identifier is confirmed by capture (2e8a:00c0), and it is the generic RP2040/Arduino identifier — shared with every Pico, which is why no rule here matches on it.

How it identifies itself

USB id What Confirmed Node
2e8a:00c0 RP2040 CDC serial, as presented by Arduino-core firmware yes serial

⚠ 2e8a:00c0 is not unique to this device (vendor_chip_default; also used by: any Raspberry Pi Pico or RP2040 board running Arduino-core firmware). Vendor 2e8a is Raspberry Pi and 00c0 with product string "RaspberryPi Pico" is what Arduino-core USB firmware presents on any RP2040. The board identifies its microcontroller and its build environment, not itself. Not on the generated ambiguity list: the device is claimed by cdc_acm on interface class rather than by identifier, so neither the kernel module table nor Debian's udev rules mention it -- a real limit of the sweep, found by attaching hardware.

What is not yet known

The host-side identifier is confirmed, and it identifies an RP2040 rather than a CatSniffer. What is NOT established is whether a differently flashed CatSniffer v3 presents something else -- the board's USB identity comes from its firmware, so a unit running the vendor image rather than an Arduino-core build may differ. Captures from other units, or from this one after reflashing, would settle it.

Who can close it: the maintainer owns this hardware; the gap closes at the next capture session.

Access and permissions

Group membership required: dialout, plugdev — added at install, applies at next login.

Software that makes it useful

tio, wireshark

Upstream: https://github.com/ElectronicCats/CatSniffer