Skip to content

skid-finder

Passive BLE-spam and Wi-Fi-attack detector with foxhunting, live alerts and a sensor-net collector

  • Version recorded: 0.6.0-alpha.1
  • Categories: bluetooth, capture-analysis, wifi
  • Upstream: https://github.com/ChiefGyk3D/Skid-Finder
  • Needs first: bluez, python3, rfkill, tmux, whiptail, iw, tshark, python3-paho-mqtt

What it does

Listens passively for the scripted radio attacks that turn up at conferences and in enterprises and tells you where they come from. On Bluetooth it detects Flipper- and Marauder-style advertising floods, Fast Pair lure floods and address-churn spam, fingerprints devices with an honest identity tier (a rotating address identifies a product, not a unit), and foxhunts a source by median RSSI. On Wi-Fi it detects deauthentication and disassociation floods, beacon floods, evil twins and KARMA-style responders from a monitor-mode capture. Every capture leaves JSON Lines records a SIEM ingests, several sensors can feed one collector that estimates a source's location with its error stated, and a whiptail menu runs the common paths from a small screen.

Why you would want it

A venue or security team wants a timeline and a rough location, not a hunch, when phones start throwing pairing pop-ups or clients start dropping off the Wi-Fi. Kismet and Wireshark show you the frames; this judges them against measured thresholds and says which family of tool is likely running, while refusing to claim more than the data supports. It is the maintainer's own field tool for the uConsole + AIO v2 and it runs unchanged on a laptop with a BlueZ adapter and a monitor-capable Wi-Fi card.

Before it will work

A BlueZ-visible Bluetooth adapter for the BLE side; a monitor-mode capable Wi-Fi adapter (the MT7921 in the AC1200 is one) for the Wi-Fi side. Root for anything that touches a radio; the menu adds sudo to exactly those actions. Copy config/interfaces.conf.example to config/interfaces.conf in the installed tree (the menu offers to on first run) and set the adapter names, SENSOR_ID and, for a fixed sensor, its position. An MQTT broker only if you run more than one sensor.

How it installs

  • prebuilt tarball from https://github.com/ChiefGyk3D/Skid-Finder/archive/refs/tags/v0.6.0-alpha.1.tar.gz
  • Upstream is at 0.6.0-alpha.1 (2026-09-19): the whole BLE workflow runs without root on a laptop in the wireshark group (exercised on real hardware); incidents with a foxhunt handoff, an evidence bundle, Wi-Fi fingerprinting and systemd units ship in the tree; the uConsole checklist is still open. Alpha means green in its own CI against synthetic captures and stubbed radios and not yet validated on the uConsole hardware; its docs/ROADMAP.md defines the stages. Re-pin URL and digest together at every tag. This unit has not yet been installed through the engine on any target container or VM; the first dry run and install are the open item on its PR.

What it changes on your machine

  • installed tree — /usr/local/share/hammunition/skid-finder is created and handed to the operator who ran the install by an explicit chown step in the plan (D-043): the software keeps settings, logs or data beside its executable, so the tree has to be writable by whoever runs it. On a shared machine that means anyone who can act as that user can change what the launcher runs.
  • /usr/local/share/hammunition stays root-owned; the tree itself is replaced whole on every install, so anything the software wrote inside it is lost then
  • undo: hammunition uninstall skid-finder removes the tree

Known problems

Alpha: the detector thresholds were measured on a hacker-conference floor and against synthetic traffic, not yet against a quiet baseline on the uConsole; a match is a lead, not a verdict, until you record your own baseline as its docs describe. The tree writes config/ and logs/ beside itself, so it must be owned by the operator, which the install's chown step does; running the scripts with sudo leaves root-owned files under logs/ that the analysis tools then cannot update. The menu's whiptail screens have not been sized on the uConsole's 1280x480 display.

Keeping it current

  • probe: github release (ChiefGyk3D/Skid-Finder)
  • strategy: reinstall
  • Tagged pre-releases per milestone (docs/ROADMAP.md upstream); each is a new tarball digest. Re-pin from the tag, never from a branch.

Where to get help with the software itself

GitHub issues on the project; the README lists what to attach.

Source: catalog/packages/skid-finder.yaml