Releases: JesseCHale/HaleHound-CYD
Release list
HaleHound-CYD v3.6.2
_ _
.k$$$$$g, ,g$$$$$k.
.k$$$$$$$$$$$a. .a$$$$$$$$$$$k.
.J$$$$$?' `?$?^?, ,?^?$?` `?$$$$$L.
JS$$SI!a, _.JS$ ?, ,? $SL._ ,a$!IS$$SL
k$$$SI!:?$$$$$$$$$xu$$j j$$ux$$$$$$$$$?:!IS$$$k
:I$$SI:J$$?*"$$$$4^?*?: :?*?^4$$$$"*?$$L:iIS$$I:
:IS$$SiJ?` _.'$?`/' ': :' '/'?$'._ `?LiS$$SI:
?ISSik? _ ', ` . ,' _ ?kiSSI?
?i$?` _ k$ . :. $k _ `?$i?
'?I:-?z$$I _._.' ._._ I$$z?-:I?'
'*?- '?$$a louSxuS? ?xuSxuol a$$?' -?*'
i$$$$$$$$$$$S S$$$$$$$$$$$i
?$$$?- -?$$$?
██░ ██ ▄▄▄ ██▓ ▓█████ ██░ ██ ▒█████ █ ██ ███▄ █ ▓█████▄
▓██░ ██▒▒████▄ ▓██▒ ▓█ ▀ ▓██░ ██▒▒██▒ ██▒ ██ ▓██▒ ██ ▀█ █ ▒██▀ ██▌
▒██▀▀██░▒██ ▀█▄ ▒██░ ▒███ ▒██▀▀██░▒██░ ██▒▓██ ▒██░▓██ ▀█ ██▒░██ █▌
░▓█ ░██ ░██▄▄▄▄██ ▒██░ ▒▓█ ▄ ░▓█ ░██ ▒██ ██░▓▓█ ░██░▓██▒ ▐▌██▒░▓█▄ ▌
░▓█▒░██▓ ▓█ ▓██▒░██████▒░▒████▒░▓█▒░██▓░ ████▓▒░▒▒█████▓ ▒██░ ▓██░░▒████▓
▒ ░░▒░▒ ▒▒ ▓▒█░░ ▒░▓ ░░░ ▒░ ░ ▒ ░░▒░▒░ ▒░▒░▒░ ░▒▓▒ ▒ ▒ ░ ▒░ ▒ ▒ ▒▒▓ ▒
▒ ░▒░ ░ ▒ ▒▒ ░░ ░ ▒ ░ ░ ░ ░ ▒ ░▒░ ░ ░ ▒ ▒░ ░░▒░ ░ ░ ░ ░░ ░ ▒░ ░ ▒ ▒
░ ░░ ░ ░ ▒ ░ ░ ░ ░ ░░ ░░ ░ ░ ▒ ░░░ ░ ░ ░ ░ ░ ░ ░ ░
░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░
_ _
.k$$$$$g, ,g$$$$$k.
.k$$$$$$$$$$$a. .a$$$$$$$$$$$k.
.J$$$$$?' `?$?^?, ,?^?$?` `?$$$$$L.
JS$$SI!a, _.JS$ ?, ,? $SL._ ,a$!IS$$SL
k$$$SI!:?$$$$$$$$$xu$$j j$$ux$$$$$$$$$?:!IS$$$k
:I$$SI:J$$?*"$$$$4^?*?: :?*?^4$$$$"*?$$L:iIS$$I:
:IS$$SiJ?` _.'$?`/' ': :' '/'?$'._ `?LiS$$SI:
?ISSik? _ ', . . ,' _ ?kiSSI?
?i$?` _ k$ .: :. $k _ `?$i?
'?I:-?z$$I _._.' ._._ I$$z?-:I?'
'*?- '?$$a louSxuS? ?xuSxuol a$$?' -?*'
i$$$$$$$$$$$S S$$$$$$$$$$$i
?$$$?- -?$$$?
HaleHound-CYD v3.6.2
A stability pass — several white-screen crashes squashed across Deauth, Wardriving, and Packet Monitor, plus a leaner build.
What's New
Lighter build — de-duplicated the skull artwork, fonts, and icons, reclaiming ~180 KB of flash for headroom.
Tidier menu — removed a redundant "Saved Captures" shortcut; your captures still live under Loot.
Fixes
Deauth no longer white-screens under load — a heavy transmit burst could crash Deauth to a white screen while it tried to restart its radio. The transmit-buffer backpressure that set off the restart loop is handled cleanly now, so it powers through.
Deauth keeps running after other modules — launching Deauth right after a BLE or 2.4 GHz tool used to make it quit on its own a few seconds later. It was short on memory; that's freed up, and it stays alive.
Wardriving survives BLE scanning — the combined WiFi + BLE wardrive could white-screen a dozen networks in. The BLE scanner now sets up once and tears down cleanly instead of leaking memory each pass.
Packet Monitor arrows are back — the channel up/down arrows were getting buried by the background skull graphic. The skull now renders behind them.
Boards
Four targets in the flash package. Each gets an app bin (update over an existing install) and a -FULL bin (bootloader + partitions + app, for a fresh flash):
- HaleHound-CYD — 2.8" CYD (ESP32-2432S028, CH340 USB)
- HaleHound-CYD-HAT — 2.8" CYD wired for the NM RF Hat
- HaleHound-E32R28T — QDtech E32R28T (2.8", Type-C, battery)
- HaleHound-E32R35T — QDtech E32R35T (3.5")
⣀⡀⣀⢀⡀⢀⡀⣀ ⣀⢀⡀ ⡀⢀ ⣀⢀⡀⢀⡀
⢀⡀⣛⠘⠿⢦⠤⣽⢟⣿⢻⡟⣾⡏⣹⣿⣿⢻⡟⣿⣾⣿⣿⡿⣿⢿⣿⣌⣿⢸⡷⢤⡄⢚⢀⡀
⣀⢀⣀⣀⣀⢀⣀⣈⣁⣉⣀⣀⣀⣀⣉⣈⣁⣀⣀⣀⣀⣉⣀⣁⣀⣁⣉⣉⣀⣈⣀⣀⣀⣉⣈⣉⣀⣀⣀⣀⣈⣈⣁⣀⣀⣀ ⣀
⣤⠐⢶⢻⡟⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡟⢠⡇
⢀⣀⣠⣄⣤⣀⣤⣤⣤⣤⣤⣤⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣍⣭⣭⣭⣭⣥⣭⣭⣭⣭⣥⣭⣭⣭⣬⣭⣭⣥⣤⣤⣤⣤⣤⣤⣄⣤⣀⣄⣀⡀
⣴⠸⠟⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⢿⠿⠿⠉⠉
⢀⡀⣶⣦⣶⣴⣶⣴⣤⣴⣶⣶⣼⣦⣿⣶⣾⣶⣶⣾⣧⣿⣾⣷⣾⣷⣿⣶⣶⣶⣶⣶⣦⣶⣶⣶⣶⣷⣿⣶⣶⣶⣶⣶⣶⣿⣾⣷⣴⣦⣶⣦⣤⣤⣦⣴⣦⣴⢠⣦⣤⡆⣴⣤⣤⣤⣤⣤⣄
⠸⠇⠿⠻⢿⠿⠿⠿⠿⡿⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠿⠿⠿⠿⠿⠿⠿⠿⠿⠿⠟⠛⠃
⡤⢰⣶⣶⣶⣾⣷⣿⣶⣿⣾⣷⣿⣶⣿⣶⣷⣿⣿⣿⣿⣿⣿⣷⣿⣿⣿⣿⣷⣿⣿⣿⣾⣿⣿⣷⣿⣾⣿⣿⣷⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣿⣿⣿⣾⣷⣿⣧⣶⣰⣶⣤⣤⣤⣴⣶⣴⣶⣶⣶⣤⣶⣶
⠛⠘⠛⠛⠛⢿⠿⣿⠿⠿⠿⠿⠿⠿⠿⠿⠿⢿⠿⠿⠿⠿⣿⣿⣿⣿⣿⣿⡿⣿⣿⣿⣿⣿⣿⣿⣿⢿⣿⣿⣿⣿⣿⣿⣿⡿⣿⣿⣿⢿⣿⣿⡿⣿⠿⠿⠛⠛⠛⠛⠛⠛⠛⠛⠋⠛⠛⠛⠛⠛⠛⠁⠛⠘⠃⠐⠂
⢠⠶⣾⣶⣶⣶⣶⣶⣶⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣾⣿⣿⣿⣿⣷⣿⣿⣿⣿⣿⣿⣿⣿⣾⣿⣿⣾⣿⣿⣷⣿⣷⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣿⣶⣿⣾⣷⣿⣷⣾⣶⣶⣶⣶⣶⣶⣶⣶⣶⣶⣶⣶⠶⣶⣶⣦⣤⣀
⠉⠉⠛⠈⠛⠙⠋⠙⠛⠛⠛⠛⣿⠿⢿⣻⣿⢿⡟⢿⠿⠿⠿⠿⢿⡿⣿⠿⠿⢿⡿⣿⠿⣿⢿⡿⢿⡟⠿⠿⣿⣿⡿⣿⠿⣿⢿⡟⠿⠿⠿⠻⡿⢿⡟⠛⠛⠛⠛⠛⠛⠛⠋⠙⠋⠛⠋⠛⠉⠛⠋ ⠘⠁⠉ ⠋⠉⠁⠈⠉⠉
⢰⢿⣷⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⢿⡿⣿⣿⡾⢻⡟⣿⠿⣿ ⡆
⣀⢀⡀⣀⡘⢋⣀ ⣉⣉⣉⣈⣁⣙⡛⣁⣉⣉⣉⣉⣛⢛⣛⣛⣋⣛⣛⣛⣻⣿⣿⡟⣿⣿⣿⣿⡟⣿⣿⣿⣻⣟⣻⣛⣛⢛⣻⣿⣟⣛⣿⣿⣻⡟⣿⣟⣿⢛⣛⢛⣛⣛⣛⣛⣛⣛⣛⣛⣛⣛⣛⣉⡋⣛⡙⣛⠉⡀⠘⠁⠉⡈⠁⣈⡁⢉ ⠁⠈⠃
⠋⠠⠏⠘⠁⡿⢹⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⣿⡿⣿⢻⡿⣹⡇⣿ ⣓ ⡀
⢀⣀⣀⣈⣉⣩⣅⣄⣀⣭⣉⣍⣁⣈⣉⣩⣍⣩⣉⣭⣭⣿⣩⣍⣽⣭⣩⣭⣭⣭⣍⣭⣉⣍⣩⣍⣭⣉⣭⣩⣍⣩⣉⣭⣩⣍⣩⣍⣩⣉⣉⣉⣍⣉⣉⣭⣉⣉⣉⣍⣉⣉⣉⣩⣁⣉⢉⣉⢈⡁⣉⣀⣉⣉⣉⣁⣀⣈⣀⣈⣀⣁⣉⡁⠈ ⠁ ⠁
⠂⠚⠉⠛⠩⠟⠟⠻⣿⢿⣿⢿⣿⣿⣿⣿⣿⣿⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⣿⣿⣿⢿⣿⡿⠿⣿⢿⣿⣿⡿⣿⣿⣿⢹⣿⠿⠏⣿⢩⣿⣿⣿⣿⣿⣿⢿⡟⢹⡟⣤
⣠⣤⣤⣤⣤⣤⣤⣴⣤⣤⣤⣤⣤⣤⣤⣤⣤⣤⣤⣭⣼⣿⣿⣿⣿⣭⣭⣭⣭⣭⣭⣭⣤⣤⣤⣤⣤⣬⣥⣤⣄⣬⣭⣥⣬⣥⣭⣅⣤⣤⣬⣤⣄⣠⣄⣤ ⣤⣠⣤⣤⣴⣮⣤⣤⣤⣤⣤⣤⣤⣤⣤⣄⡀⣠⢀⣄⣤⣤⣤⣠⣤⣤⣀
⠈⠉⠛⠛⠿⠿⠛⠿⠿⠿⠿⠿⢿⠿⣿⠟⠿⠸⠟⢹⡇⢿⠘⠿⠻⠿⠟⠻⠿⠿⠿⠿⠿⠿⠿⠿⠿⠿⠿⠿⣿⢿⡿⢿⠿⠿⠿⠿⠿⠿⠿⠿⠿⢻⡟⠛⠃⠛ ⠚⠘⠏⠛⠙⠛⠻⠿⠿⠿⠛⠹⠟⠙⠃⣿⠰⡾⠛⠋⠿⠣⣿⠻⡿⠻⠇⠰
⢴⣤⣶⣶⣶⣶⣦⣶⣤⣤⣴⣤⢤⡄ ⣤⢠⣶⣶⣶⣶⣶⣶⣶⣶⣶⣶⣦⣶⣤⣤⣴⣶⣶⣶⣶⣶⣶⣦⣤⣠⣄ ⣤⠠⡆⠠⣤⣤⢠⣶⣶⡶⣤⡤⢤ ⣠⡄⣀
⠘⠋⠛⠛⠉⠋⠉⠿⠉⠿ ⠁ ⠉⠈⠁⠉⠉⠉⠉⠉⠉⠉⠋⠹⠿⠻⠏⠻⠿⠿⠻⠿⠿⠿⠟⠛⠛⠃ ⠈⠁⠘⠁⠉⠉⠛⠙⠃⠛ ⠋ ⠰⠆⠈ ⠴
⢀⡶⣶⡐⢶ ⠆ ⠠⠤⣦ ⣤⢲⣶⣶⣶⣶⣤⣤⢴⣦⢶⣶⣤⣶⣶ ⡴⢐⡆⢶⣰⣶
⠈⠁⠋ ⠂ ⠛ ⠋⠘⠛⠘⠋⠛⠛⠋⠙⠛⠛⠋⠚⠋⠛⠘⠃ ⠈⠁⠈⠁ ⠚
⢰⣷⣦⣴⣿⣾⣷⣶⣦ ⢰⡆⢲⡆
⠛ ⠉⠁⠉⠉⠋⠙⠋⠁ ⠈⠁⠈⠁ ⠛
⣀ ⣀ ⢀ ⣸⠹⣿⣿⡟⣿⢿⣿⢿⡽⠿⠞⢿⠃ ⣹⡟⣿⠇⣀ ⢀⡀⣀
⣉ ⠉ ⢀ ⡀⢀⣀⢈⡁⣉ ⠉⠈⠁ ⢀ ⡀ ⠉ ⠈ ⡉ ⡀ ⠈⠁⢉
⢘⡃⣿ ⣛⢀⡀ ⠈⣧⢸⡿⢿⣷⣹⡇ ⠘⠈⠃ ⠠⠶⢶⡿⢹⡟⣀ ⢀⡀⢘⡇⣿ ⣟⢀⡀⢀⡀
⣀⣀⣀⣀⣁⢈⠁ ⢠⣄⣀⣀⣉⣈⣀⣈⣁⠉ ⡀ ⡀ ⢀⡀⣈⣀⣄⢀⡀⢀⡀ ⢀⣁⣀⣁⣈⣀⣁ ⡁⠈
⢠⡤⢼⣿⣿⣯⡿⠸⡇⣤⠄⢤ ⣤⢠⡄⢿⠶⠿⢾⡟⣿⡏⣿⢫⣿⠹⡏⣤ ⠐⠃⠠ ⣤⠐⠶⠸⡇⢿⠻⠿⠸⡇⠙⠃⣤⠠⡤ ⢤⡄⣤⠈⠛⢽⠏⢿⠛⠿⠠⡇⢤⠄
⣠⣄⣤⣤⣤⣤⣤⣤⣄ ⣠⡄⣤⣀⣤⢀⣄⣠⣤⣄⢀⣄⡀ ⡀ ⢀ ⣠⡄⢀ ⣤⣀⣤ ⡀⢀ ⡀ ⡀⣠⣤⣤⣤⣤⣤⣤⣀⣤⣤
⠐ ⠒ ⣶⠰⠦⠉⠹⠟⢹⡿⠿⠋⠾⠛⠿⠛⠿⠉⠉⠉⠉⠉⠙⠛⢿⠟⢿⠸⡟⠻⠟⠛⠿⠟⠘⠇ ⠉⠁⠈ ⠈ ⠂ ⠶ ⠆⠘⠏⠉⠉⠉⠰⠆⠰⠆⠴⠈⠇⠘⠇⠿ ⡿⠘⠇⠉⠁⠿⠹⡿⠿⠋⠿⠉⠉⠰⠆⠰⠂
⣶⣴⣶⢶⡄⣀ ⢀⡀ ⢀⡀ ⢤⢠⣦⣤⡴⠲⡦⢤ ⣀ ⢀ ⣤⢀⡄⣠⡄⣠ ⡄ ⠴⠄⣶⣦⡴⢦ ⢠⣦⣶⣦⣴⣄⣀ ⣀⡀
⠉⠛⠛⠿⠆⠿⠰⠇⠰⠟⠛⠛⠛⠰⠆⠶⠆ ⠛⠈⠁⠘⠃⠈ ⠰⠆⠴ ⠦⠰⠆ ⠈ ⠉⠈⠁ ⠉⠰⠷⠰⠇⠶ ⠶ ⠁ ⠾ ⠁⠸⠏ ⠶⠰⠆⠰ ⠶
⠰⢶⣶⣿⣷⣶⣶⢶⣶⣶⣄⣀⡠⠦⠰⠦⠶⠄⠄ ⣀⡀ ⠠⡄⣤ ⠰⠦⠶⢤⣶⣤⡤⠠⡄⢤ ⠠⠶⣺⡷⣶⣶⣶⢶⡶⠶⠄ ⠠⣤⡤
⠉⠉⠙⠛⠛⠚⠛⠉⠈⠛ ⠘⠃⠘⠃⠛⠐⠓⠘⠃⠛ ⠙⠛⠘⠃⠛ ⠛⠘⠃ ⠈ ⠘⠉⠁ ⠁ ⠐⠛ ⠛⠂
⠤⠤⢤⠄ ⢀⠰⣶⠴⠦⣶⡆⣶⢠⡄ ⢀ ⡀ ⣀ ⡀⣶⡆⣶⣦⣤⢰⡦⢶⠆⣠ ⣒⢂⣶⢐⡒⠂
⠘⠁⠉ ⠉ ⠉⠈⠁⠈⠁⠉⠈⠉⠈⠃ ⠙⠈⠃⠈⠃⠉ ⠉⠈⠁ ⠉ ⠉⠈⠛⠈⠃
⢀⡀⢀⡀⣀ ⢀⡀⣿⢈⣿⠸⣇⣴⣴⣦⣴⣦⣹⡇⣶ ⣶⠆⣿⣶⣦⣶⡄⣿⢈⣿⣿⡿⢿⡿⠿ ⢀⡀
⠈⠁⠈⠁⠉ ⣀ ⢀⢀⡀⢈⡁⣈⣈⣁⣈⣁⣀ ⠉ ⢉ ⡀⣉ ⢉ ⢀⣀⠉⢈⣁⣈⡀⣉⠁⣀ ⠈⠁
⢀⡀⢀⡀ ⠉⠃⠉⠘⠋⢻⣿⣿⣿⣿⣻⡟⣿⠰⠶⠶⠶⣶⡶⠿⢻⣄⢀⡟⠿⠿⠿⠾⠷⣿⡟⣿⢻⡿⣿⣿⣿⣟⣿⢀⡄
⠈⠁ ⡀⣠⡄⣠⢀⡀⣀⡅⣈⣩⣭⢀⡀⢀ ⠠⡀ ⠈⠉ ⡅⢠⣤⣤⣠⡄⣈⡀⣀ ⣄⣈⡀⣈⡉⠁ ⡁
⠁⠿⠁⠼⢸⡿⠻⡿⢿⢿⠟⠛⠛⣿⠤⣤ ⠁⠚⠛⠓ ⠁⠛⠹⣿⢩⡗⢤⡜⠋⠻⠟⢽⠇⢼⠟⠻⠺⡇
⣤⣄⢠⡄⣤⢀⡄ ⠄ ⢠⡄ ⢀⡀⣤⣴⣦⣤⣤⣴⣆⢰⡄ ⢀⡀
⠛⠛⠚⠳⣿⠸⡇⠺⠏⠈⠁ ⠰⠆ ⠻⠏⢿⠈⠁⠈⠋⠛⠙⢿⠻⡿⠒⠁⠶⠈⠻⠠⠆ ⠶ ⠰⠆
⢰⡆⣴⡆⠤ ⢰⣦⣴⡶⣶⢶⡦⣄ ⣀
⠈⠁ ⠸⠇⠺⠇⠾ ⠿ ⠉ ⠛⠘⠋⠈⠁⠿ ⠶ ⠶ ⠶
⣀⡀
⡀⢀⡀
⠈⠉⠈⠁
⢀⡀⢀⡀ ⡶⢰⡆
⠈⠁⠈⠁ ⠈⠉⠈⠁
⠠⡤ ⠠⡤⠠⡄⢤
⠰⠆⠰⠆⠶⠐⠶⠰⠆⠶
⣄
...
HaleHound-CYD v3.6.1
Flash in your browser — no install needed: https://flash.halehound.com
_ _
.k$$$$$g, ,g$$$$$k.
.k$$$$$$$$$$$a. .a$$$$$$$$$$$k.
.J$$$$$?' `?$?^?, ,?^?$?` `?$$$$$L.
JS$$SI!a, _.JS$ ?, ,? $SL._ ,a$!IS$$SL
k$$$SI!:?$$$$$$$$$xu$$j j$$ux$$$$$$$$$?:!IS$$$k
:I$$SI:J$$?*"$$$$4^?*?: :?*?^4$$$$"*?$$L:iIS$$I:
:IS$$SiJ?` _.'$?`/' ': :' '/'?$'._ `?LiS$$SI:
?ISSik? _ ', ` . ,' _ ?kiSSI?
?i$?` _ k$ . :. $k _ `?$i?
'?I:-?z$$I _._.' ._._ I$$z?-:I?'
'*?- '?$$a louSxuS? ?xuSxuol a$$?' -?*'
i$$$$$$$$$$$S S$$$$$$$$$$$i
?$$$?- -?$$$?
██░ ██ ▄▄▄ ██▓ ▓█████ ██░ ██ ▒█████ █ ██ ███▄ █ ▓█████▄
▓██░ ██▒▒████▄ ▓██▒ ▓█ ▀ ▓██░ ██▒▒██▒ ██▒ ██ ▓██▒ ██ ▀█ █ ▒██▀ ██▌
▒██▀▀██░▒██ ▀█▄ ▒██░ ▒███ ▒██▀▀██░▒██░ ██▒▓██ ▒██░▓██ ▀█ ██▒░██ █▌
░▓█ ░██ ░██▄▄▄▄██ ▒██░ ▒▓█ ▄ ░▓█ ░██ ▒██ ██░▓▓█ ░██░▓██▒ ▐▌██▒░▓█▄ ▌
░▓█▒░██▓ ▓█ ▓██▒░██████▒░▒████▒░▓█▒░██▓░ ████▓▒░▒▒█████▓ ▒██░ ▓██░░▒████▓
▒ ░░▒░▒ ▒▒ ▓▒█░░ ▒░▓ ░░░ ▒░ ░ ▒ ░░▒░▒░ ▒░▒░▒░ ░▒▓▒ ▒ ▒ ░ ▒░ ▒ ▒ ▒▒▓ ▒
▒ ░▒░ ░ ▒ ▒▒ ░░ ░ ▒ ░ ░ ░ ░ ▒ ░▒░ ░ ░ ▒ ▒░ ░░▒░ ░ ░ ░ ░░ ░ ▒░ ░ ▒ ▒
░ ░░ ░ ░ ▒ ░ ░ ░ ░ ░░ ░░ ░ ░ ▒ ░░░ ░ ░ ░ ░ ░ ░ ░ ░
░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░
_ _
.k$$$$$g, ,g$$$$$k.
.k$$$$$$$$$$$a. .a$$$$$$$$$$$k.
.J$$$$$?' `?$?^?, ,?^?$?` `?$$$$$L.
JS$$SI!a, _.JS$ ?, ,? $SL._ ,a$!IS$$SL
k$$$SI!:?$$$$$$$$$xu$$j j$$ux$$$$$$$$$?:!IS$$$k
:I$$SI:J$$?*"$$$$4^?*?: :?*?^4$$$$"*?$$L:iIS$$I:
:IS$$SiJ?` _.'$?`/' ': :' '/'?$'._ `?LiS$$SI:
?ISSik? _ ', . . ,' _ ?kiSSI?
?i$?` _ k$ .: :. $k _ `?$i?
'?I:-?z$$I _._.' ._._ I$$z?-:I?'
'*?- '?$$a louSxuS? ?xuSxuol a$$?' -?*'
i$$$$$$$$$$$S S$$$$$$$$$$$i
?$$$?- -?$$$?
HaleHound-CYD v3.6.1
Maintenance fix for v3.6.0. Two bugs down, fresh HALEHOUND art, and your saved RFID dumps now show up in Loot.
What's New
HALEHOUND artwork — the graffiti skull watermark now rides on every CYD board.
RFID dumps in Loot — saved tag dumps (NTAG, page dumps, keys) land in a new RFID category under Loot and open right on the device in the text viewer. No more pulling the card to read them.
Fixes
RFID no longer drops the SD card — reading or saving a tag used to leave the SD card unreadable for the rest of the session (Loot and Wardriving would come up empty until a reboot). The shared SPI bus is now handed back cleanly, so RFID, SD logging, and saved dumps all work in one session.
Evil Portal broadcasts your SSID — the portal was coming up under the ESP32's default name (ESP_xxxxxx) no matter what SSID you set. It now broadcasts the name you choose.
Boards
Four targets in the flash package. Each gets an app bin (update over an existing install) and a -FULL bin (bootloader + partitions + app, for a fresh flash):
- HaleHound-CYD — 2.8" CYD (ESP32-2432S028, CH340 USB)
- HaleHound-CYD-HAT — 2.8" CYD wired for the NM RF Hat
- HaleHound-E32R28T — QDtech E32R28T (2.8", Type-C, battery)
- HaleHound-E32R35T — QDtech E32R35T (3.5")
⣀⡀⣀⢀⡀⢀⡀⣀ ⣀⢀⡀ ⡀⢀ ⣀⢀⡀⢀⡀
⢀⡀⣛⠘⠿⢦⠤⣽⢟⣿⢻⡟⣾⡏⣹⣿⣿⢻⡟⣿⣾⣿⣿⡿⣿⢿⣿⣌⣿⢸⡷⢤⡄⢚⢀⡀
⣀⢀⣀⣀⣀⢀⣀⣈⣁⣉⣀⣀⣀⣀⣉⣈⣁⣀⣀⣀⣀⣉⣀⣁⣀⣁⣉⣉⣀⣈⣀⣀⣀⣉⣈⣉⣀⣀⣀⣀⣈⣈⣁⣀⣀⣀ ⣀
⣤⠐⢶⢻⡟⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡟⢠⡇
⢀⣀⣠⣄⣤⣀⣤⣤⣤⣤⣤⣤⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣍⣭⣭⣭⣭⣥⣭⣭⣭⣭⣥⣭⣭⣭⣬⣭⣭⣥⣤⣤⣤⣤⣤⣤⣄⣤⣀⣄⣀⡀
⣴⠸⠟⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⢿⠿⠿⠉⠉
⢀⡀⣶⣦⣶⣴⣶⣴⣤⣴⣶⣶⣼⣦⣿⣶⣾⣶⣶⣾⣧⣿⣾⣷⣾⣷⣿⣶⣶⣶⣶⣶⣦⣶⣶⣶⣶⣷⣿⣶⣶⣶⣶⣶⣶⣿⣾⣷⣴⣦⣶⣦⣤⣤⣦⣴⣦⣴⢠⣦⣤⡆⣴⣤⣤⣤⣤⣤⣄
⠸⠇⠿⠻⢿⠿⠿⠿⠿⡿⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠿⠿⠿⠿⠿⠿⠿⠿⠿⠿⠟⠛⠃
⡤⢰⣶⣶⣶⣾⣷⣿⣶⣿⣾⣷⣿⣶⣿⣶⣷⣿⣿⣿⣿⣿⣿⣷⣿⣿⣿⣿⣷⣿⣿⣿⣾⣿⣿⣷⣿⣾⣿⣿⣷⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣿⣿⣿⣾⣷⣿⣧⣶⣰⣶⣤⣤⣤⣴⣶⣴⣶⣶⣶⣤⣶⣶
⠛⠘⠛⠛⠛⢿⠿⣿⠿⠿⠿⠿⠿⠿⠿⠿⠿⢿⠿⠿⠿⠿⣿⣿⣿⣿⣿⣿⡿⣿⣿⣿⣿⣿⣿⣿⣿⢿⣿⣿⣿⣿⣿⣿⣿⡿⣿⣿⣿⢿⣿⣿⡿⣿⠿⠿⠛⠛⠛⠛⠛⠛⠛⠛⠋⠛⠛⠛⠛⠛⠛⠁⠛⠘⠃⠐⠂
⢠⠶⣾⣶⣶⣶⣶⣶⣶⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣾⣿⣿⣿⣿⣷⣿⣿⣿⣿⣿⣿⣿⣿⣾⣿⣿⣾⣿⣿⣷⣿⣷⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣿⣶⣿⣾⣷⣿⣷⣾⣶⣶⣶⣶⣶⣶⣶⣶⣶⣶⣶⣶⠶⣶⣶⣦⣤⣀
⠉⠉⠛⠈⠛⠙⠋⠙⠛⠛⠛⠛⣿⠿⢿⣻⣿⢿⡟⢿⠿⠿⠿⠿⢿⡿⣿⠿⠿⢿⡿⣿⠿⣿⢿⡿⢿⡟⠿⠿⣿⣿⡿⣿⠿⣿⢿⡟⠿⠿⠿⠻⡿⢿⡟⠛⠛⠛⠛⠛⠛⠛⠋⠙⠋⠛⠋⠛⠉⠛⠋ ⠘⠁⠉ ⠋⠉⠁⠈⠉⠉
⢰⢿⣷⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⢿⡿⣿⣿⡾⢻⡟⣿⠿⣿ ⡆
⣀⢀⡀⣀⡘⢋⣀ ⣉⣉⣉⣈⣁⣙⡛⣁⣉⣉⣉⣉⣛⢛⣛⣛⣋⣛⣛⣛⣻⣿⣿⡟⣿⣿⣿⣿⡟⣿⣿⣿⣻⣟⣻⣛⣛⢛⣻⣿⣟⣛⣿⣿⣻⡟⣿⣟⣿⢛⣛⢛⣛⣛⣛⣛⣛⣛⣛⣛⣛⣛⣛⣉⡋⣛⡙⣛⠉⡀⠘⠁⠉⡈⠁⣈⡁⢉ ⠁⠈⠃
⠋⠠⠏⠘⠁⡿⢹⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⣿⡿⣿⢻⡿⣹⡇⣿ ⣓ ⡀
⢀⣀⣀⣈⣉⣩⣅⣄⣀⣭⣉⣍⣁⣈⣉⣩⣍⣩⣉⣭⣭⣿⣩⣍⣽⣭⣩⣭⣭⣭⣍⣭⣉⣍⣩⣍⣭⣉⣭⣩⣍⣩⣉⣭⣩⣍⣩⣍⣩⣉⣉⣉⣍⣉⣉⣭⣉⣉⣉⣍⣉⣉⣉⣩⣁⣉⢉⣉⢈⡁⣉⣀⣉⣉⣉⣁⣀⣈⣀⣈⣀⣁⣉⡁⠈ ⠁ ⠁
⠂⠚⠉⠛⠩⠟⠟⠻⣿⢿⣿⢿⣿⣿⣿⣿⣿⣿⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⣿⣿⣿⢿⣿⡿⠿⣿⢿⣿⣿⡿⣿⣿⣿⢹⣿⠿⠏⣿⢩⣿⣿⣿⣿⣿⣿⢿⡟⢹⡟⣤
⣠⣤⣤⣤⣤⣤⣤⣴⣤⣤⣤⣤⣤⣤⣤⣤⣤⣤⣤⣭⣼⣿⣿⣿⣿⣭⣭⣭⣭⣭⣭⣭⣤⣤⣤⣤⣤⣬⣥⣤⣄⣬⣭⣥⣬⣥⣭⣅⣤⣤⣬⣤⣄⣠⣄⣤ ⣤⣠⣤⣤⣴⣮⣤⣤⣤⣤⣤⣤⣤⣤⣤⣄⡀⣠⢀⣄⣤⣤⣤⣠⣤⣤⣀
⠈⠉⠛⠛⠿⠿⠛⠿⠿⠿⠿⠿⢿⠿⣿⠟⠿⠸⠟⢹⡇⢿⠘⠿⠻⠿⠟⠻⠿⠿⠿⠿⠿⠿⠿⠿⠿⠿⠿⠿⣿⢿⡿⢿⠿⠿⠿⠿⠿⠿⠿⠿⠿⢻⡟⠛⠃⠛ ⠚⠘⠏⠛⠙⠛⠻⠿⠿⠿⠛⠹⠟⠙⠃⣿⠰⡾⠛⠋⠿⠣⣿⠻⡿⠻⠇⠰
⢴⣤⣶⣶⣶⣶⣦⣶⣤⣤⣴⣤⢤⡄ ⣤⢠⣶⣶⣶⣶⣶⣶⣶⣶⣶⣶⣦⣶⣤⣤⣴⣶⣶⣶⣶⣶⣶⣦⣤⣠⣄ ⣤⠠⡆⠠⣤⣤⢠⣶⣶⡶⣤⡤⢤ ⣠⡄⣀
⠘⠋⠛⠛⠉⠋⠉⠿⠉⠿ ⠁ ⠉⠈⠁⠉⠉⠉⠉⠉⠉⠉⠋⠹⠿⠻⠏⠻⠿⠿⠻⠿⠿⠿⠟⠛⠛⠃ ⠈⠁⠘⠁⠉⠉⠛⠙⠃⠛ ⠋ ⠰⠆⠈ ⠴
⢀⡶⣶⡐⢶ ⠆ ⠠⠤⣦ ⣤⢲⣶⣶⣶⣶⣤⣤⢴⣦⢶⣶⣤⣶⣶ ⡴⢐⡆⢶⣰⣶
⠈⠁⠋ ⠂ ⠛ ⠋⠘⠛⠘⠋⠛⠛⠋⠙⠛⠛⠋⠚⠋⠛⠘⠃ ⠈⠁⠈⠁ ⠚
⢰⣷⣦⣴⣿⣾⣷⣶⣦ ⢰⡆⢲⡆
⠛ ⠉⠁⠉⠉⠋⠙⠋⠁ ⠈⠁⠈⠁ ⠛
⣀ ⣀ ⢀ ⣸⠹⣿⣿⡟⣿⢿⣿⢿⡽⠿⠞⢿⠃ ⣹⡟⣿⠇⣀ ⢀⡀⣀
⣉ ⠉ ⢀ ⡀⢀⣀⢈⡁⣉ ⠉⠈⠁ ⢀ ⡀ ⠉ ⠈ ⡉ ⡀ ⠈⠁⢉
⢘⡃⣿ ⣛⢀⡀ ⠈⣧⢸⡿⢿⣷⣹⡇ ⠘⠈⠃ ⠠⠶⢶⡿⢹⡟⣀ ⢀⡀⢘⡇⣿ ⣟⢀⡀⢀⡀
⣀⣀⣀⣀⣁⢈⠁ ⢠⣄⣀⣀⣉⣈⣀⣈⣁⠉ ⡀ ⡀ ⢀⡀⣈⣀⣄⢀⡀⢀⡀ ⢀⣁⣀⣁⣈⣀⣁ ⡁⠈
⢠⡤⢼⣿⣿⣯⡿⠸⡇⣤⠄⢤ ⣤⢠⡄⢿⠶⠿⢾⡟⣿⡏⣿⢫⣿⠹⡏⣤ ⠐⠃⠠ ⣤⠐⠶⠸⡇⢿⠻⠿⠸⡇⠙⠃⣤⠠⡤ ⢤⡄⣤⠈⠛⢽⠏⢿⠛⠿⠠⡇⢤⠄
⣠⣄⣤⣤⣤⣤⣤⣤⣄ ⣠⡄⣤⣀⣤⢀⣄⣠⣤⣄⢀⣄⡀ ⡀ ⢀ ⣠⡄⢀ ⣤⣀⣤ ⡀⢀ ⡀ ⡀⣠⣤⣤⣤⣤⣤⣤⣀⣤⣤
⠐ ⠒ ⣶⠰⠦⠉⠹⠟⢹⡿⠿⠋⠾⠛⠿⠛⠿⠉⠉⠉⠉⠉⠙⠛⢿⠟⢿⠸⡟⠻⠟⠛⠿⠟⠘⠇ ⠉⠁⠈ ⠈ ⠂ ⠶ ⠆⠘⠏⠉⠉⠉⠰⠆⠰⠆⠴⠈⠇⠘⠇⠿ ⡿⠘⠇⠉⠁⠿⠹⡿⠿⠋⠿⠉⠉⠰⠆⠰⠂
⣶⣴⣶⢶⡄⣀ ⢀⡀ ⢀⡀ ⢤⢠⣦⣤⡴⠲⡦⢤ ⣀ ⢀ ⣤⢀⡄⣠⡄⣠ ⡄ ⠴⠄⣶⣦⡴⢦ ⢠⣦⣶⣦⣴⣄⣀ ⣀⡀
⠉⠛⠛⠿⠆⠿⠰⠇⠰⠟⠛⠛⠛⠰⠆⠶⠆ ⠛⠈⠁⠘⠃⠈ ⠰⠆⠴ ⠦⠰⠆ ⠈ ⠉⠈⠁ ⠉⠰⠷⠰⠇⠶ ⠶ ⠁ ⠾ ⠁⠸⠏ ⠶⠰⠆⠰ ⠶
⠰⢶⣶⣿⣷⣶⣶⢶⣶⣶⣄⣀⡠⠦⠰⠦⠶⠄⠄ ⣀⡀ ⠠⡄⣤ ⠰⠦⠶⢤⣶⣤⡤⠠⡄⢤ ⠠⠶⣺⡷⣶⣶⣶⢶⡶⠶⠄ ⠠⣤⡤
⠉⠉⠙⠛⠛⠚⠛⠉⠈⠛ ⠘⠃⠘⠃⠛⠐⠓⠘⠃⠛ ⠙⠛⠘⠃⠛ ⠛⠘⠃ ⠈ ⠘⠉⠁ ⠁ ⠐⠛ ⠛⠂
⠤⠤⢤⠄ ⢀⠰⣶⠴⠦⣶⡆⣶⢠⡄ ⢀ ⡀ ⣀ ⡀⣶⡆⣶⣦⣤⢰⡦⢶⠆⣠ ⣒⢂⣶⢐⡒⠂
⠘⠁⠉ ⠉ ⠉⠈⠁⠈⠁⠉⠈⠉⠈⠃ ⠙⠈⠃⠈⠃⠉ ⠉⠈⠁ ⠉ ⠉⠈⠛⠈⠃
⢀⡀⢀⡀⣀ ⢀⡀⣿⢈⣿⠸⣇⣴⣴⣦⣴⣦⣹⡇⣶ ⣶⠆⣿⣶⣦⣶⡄⣿⢈⣿⣿⡿⢿⡿⠿ ⢀⡀
⠈⠁⠈⠁⠉ ⣀ ⢀⢀⡀⢈⡁⣈⣈⣁⣈⣁⣀ ⠉ ⢉ ⡀⣉ ⢉ ⢀⣀⠉⢈⣁⣈⡀⣉⠁⣀ ⠈⠁
⢀⡀⢀⡀ ⠉⠃⠉⠘⠋⢻⣿⣿⣿⣿⣻⡟⣿⠰⠶⠶⠶⣶⡶⠿⢻⣄⢀⡟⠿⠿⠿⠾⠷⣿⡟⣿⢻⡿⣿⣿⣿⣟⣿⢀⡄
⠈⠁ ⡀⣠⡄⣠⢀⡀⣀⡅⣈⣩⣭⢀⡀⢀ ⠠⡀ ⠈⠉ ⡅⢠⣤⣤⣠⡄⣈⡀⣀ ⣄⣈⡀⣈⡉⠁ ⡁
⠁⠿⠁⠼⢸⡿⠻⡿⢿⢿⠟⠛⠛⣿⠤⣤ ⠁⠚⠛⠓ ⠁⠛⠹⣿⢩⡗⢤⡜⠋⠻⠟⢽⠇⢼⠟⠻⠺⡇
⣤⣄⢠⡄⣤⢀⡄ ⠄ ⢠⡄ ⢀⡀⣤⣴⣦⣤⣤⣴⣆⢰⡄ ⢀⡀
⠛⠛⠚⠳⣿⠸⡇⠺⠏⠈⠁ ⠰⠆ ⠻⠏⢿⠈⠁⠈⠋⠛⠙⢿⠻⡿⠒⠁⠶⠈⠻⠠⠆ ⠶ ⠰⠆
⢰⡆⣴⡆⠤ ⢰⣦⣴⡶⣶⢶⡦⣄ ⣀
⠈⠁ ⠸⠇⠺⠇⠾ ⠿ ⠉ ⠛⠘⠋⠈⠁⠿ ⠶ ⠶ ⠶
⣀⡀
⡀⢀⡀
⠈⠉⠈⠁
⢀⡀⢀⡀ ⡶⢰⡆
⠈⠁⠈⠁ ⠈⠉⠈⠁
⠠⡤ ⠠⡤⠠⡄⢤
⠰⠆⠰⠆⠶⠐⠶⠰⠆⠶
⣄
⠺⠐⠇⠐⠆⠲ ⠶⠐⠇⠰⠂⠲ ⠇⠐⠇⠲ ⠲⠐⠆⠸⠂⠾ ⠖
⠘⠛⠘⠃⠛ ⠛⠘⠃⠘⠃⠛⠐⠓⠘⠃⠛ ⠛⠘⠃⠘⠃⠛⠐⠛⠐⠃
HaleHound-CYD v3.6.0
_ _
.k$$$$$g, ,g$$$$$k.
.k$$$$$$$$$$$a. .a$$$$$$$$$$$k.
.J$$$$$?' `?$?^?, ,?^?$?` `?$$$$$L.
JS$$SI!a, _.JS$ ?, ,? $SL._ ,a$!IS$$SL
k$$$SI!:?$$$$$$$$$xu$$j j$$ux$$$$$$$$$?:!IS$$$k
:I$$SI:J$$?*"$$$$4^?*?: :?*?^4$$$$"*?$$L:iIS$$I:
:IS$$SiJ?` _.'$?`/' ': :' '/'?$'._ `?LiS$$SI:
?ISSik? _ ', ` . ,' _ ?kiSSI?
?i$?` _ k$ . :. $k _ `?$i?
'?I:-?z$$I _._.' ._._ I$$z?-:I?'
'*?- '?$$a louSxuS? ?xuSxuol a$$?' -?*'
i$$$$$$$$$$$S S$$$$$$$$$$$i
?$$$?- -?$$$?
██░ ██ ▄▄▄ ██▓ ▓█████ ██░ ██ ▒█████ █ ██ ███▄ █ ▓█████▄
▓██░ ██▒▒████▄ ▓██▒ ▓█ ▀ ▓██░ ██▒▒██▒ ██▒ ██ ▓██▒ ██ ▀█ █ ▒██▀ ██▌
▒██▀▀██░▒██ ▀█▄ ▒██░ ▒███ ▒██▀▀██░▒██░ ██▒▓██ ▒██░▓██ ▀█ ██▒░██ █▌
░▓█ ░██ ░██▄▄▄▄██ ▒██░ ▒▓█ ▄ ░▓█ ░██ ▒██ ██░▓▓█ ░██░▓██▒ ▐▌██▒░▓█▄ ▌
░▓█▒░██▓ ▓█ ▓██▒░██████▒░▒████▒░▓█▒░██▓░ ████▓▒░▒▒█████▓ ▒██░ ▓██░░▒████▓
▒ ░░▒░▒ ▒▒ ▓▒█░░ ▒░▓ ░░░ ▒░ ░ ▒ ░░▒░▒░ ▒░▒░▒░ ░▒▓▒ ▒ ▒ ░ ▒░ ▒ ▒ ▒▒▓ ▒
▒ ░▒░ ░ ▒ ▒▒ ░░ ░ ▒ ░ ░ ░ ░ ▒ ░▒░ ░ ░ ▒ ▒░ ░░▒░ ░ ░ ░ ░░ ░ ▒░ ░ ▒ ▒
░ ░░ ░ ░ ▒ ░ ░ ░ ░ ░░ ░░ ░ ░ ▒ ░░░ ░ ░ ░ ░ ░ ░ ░ ░
░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░
_ _
.k$$$$$g, ,g$$$$$k.
.k$$$$$$$$$$$a. .a$$$$$$$$$$$k.
.J$$$$$?' `?$?^?, ,?^?$?` `?$$$$$L.
JS$$SI!a, _.JS$ ?, ,? $SL._ ,a$!IS$$SL
k$$$SI!:?$$$$$$$$$xu$$j j$$ux$$$$$$$$$?:!IS$$$k
:I$$SI:J$$?*"$$$$4^?*?: :?*?^4$$$$"*?$$L:iIS$$I:
:IS$$SiJ?` _.'$?`/' ': :' '/'?$'._ `?LiS$$SI:
?ISSik? _ ', . . ,' _ ?kiSSI?
?i$?` _ k$ .: :. $k _ `?$i?
'?I:-?z$$I _._.' ._._ I$$z?-:I?'
'*?- '?$$a louSxuS? ?xuSxuol a$$?' -?*'
i$$$$$$$$$$$S S$$$$$$$$$$$i
?$$$?- -?$$$?
HaleHound-CYD v3.6.0
This one's stacked. A four-tool drone toolkit, a real SubGHz spectrum analyzer, NFC Tools-grade NTAG writing, the new Skimmer Hunter, and a rebuilt WiFi jammer.
What's New
New Modules
Drone Toolkit — a full anti-drone menu with four tools:
- Drone Detect — runs two radios at once: the NRF24 sniffs for drone BLE presence while the ESP32 sweeps WiFi in promiscuous mode, on a dual-core engine so neither side blocks the other. Flags drones by ASTM F3411 Remote ID plus SSID and BLE fingerprint.
- Drone Jelly — full-screen jam with a live equalizer readout.
- Drone Deauth — targeted deauth against a drone's control link.
- RID Spoof — broadcasts an ASTM F3411 Remote ID beacon over WiFi (Beacon and NaN) and BLE.
SubGHz Spectrum Analyzer — a 33-bar live spectrum across the 433 front-end with peak-hold dots and a waveform graph under it. Band focus (433.92 / 315 / WIDE) narrows the sweep and the RX bandwidth together, so the noise floor drops and close signals separate instead of smearing. Noise-floor calibration measures each channel's floor and then shows only what rises above it, and a GAIN dial pulls weak signals up the bars. Full controls under How to Use.
RFID NTAG Tools — an NFC Tools-style tag suite for NTAG213 / 215 / 216. Model ID, full page dump, NDEF decode (URL and Text), a multi-record composer, and the write side: erase, permanent read-only lock, password set and remove, and auth-on-write. Full controls under How to Use.
Skimmer Hunter (beta) — a Bluetooth credit-card-skimmer hunter. Multi-signal scoring plus an active confirmation pass to cut false positives. It's built and ships in this release for field testing — treat it as beta until the hardware validation pass is done.
Overhauls
WLAN Jammer — rebuilt on GFSK noise output with a PA-level toggle and a tight 1/6/11 pattern, plus an all-channels mode with tuned per-channel dwell. The approaches that didn't pan out are documented in the source so they don't get retried.
Captive Portal — six new templates, real brand logos, and a fix for the SSID getting overwritten when you switch templates.
How to Use
SubGHz Spectrum Analyzer
SubGHz > Spectrum Analyzer. Live sweep of the 433 front-end — 33 spectrum bars with peak-hold dots, a waveform graph under them, and a peak-frequency readout at the bottom.
Top icons: power = start/stop the sweep, undo = clear the display, antenna = CAL on/off (the ON/OFF label sits right next to it, lit pink = on), back arrow on the far left = exit. The physical BOOT button also exits.
Bottom strip — three tap zones: left third < = previous band, right third > = next band, center = GAIN. Each GAIN tap steps 1x -> 2x -> 3x -> 4x -> back to 1x (shown in yellow) and lifts weak signals higher up the bars.
Bands: 433.92 (426-442 MHz, the default and the radio's matched home), 315 (307-323 MHz, US car/garage fobs — weaker since it's off the 433 match, but it'll hear a strong fob held close), and WIDE (300-464 MHz, the whole usable range in one sweep). The front-end is matched for 433, so 868/915 are deaf and aren't offered.
CAL (noise-floor calibration): off by default — bars show raw RSSI. Tap the antenna to turn it on, keep the band quiet for the ~0.3s it spends measuring each channel's floor ("CALIBRATING... keep the band quiet"), and from then on the bars show only signal above that floor — empty channels sit flat and a real transmission jumps out. Changing bands drops CAL back to off (the old floor doesn't apply to a new band), so re-arm it after you switch. Run RAW to eyeball a whole band, flip to CAL to make one fob or sensor pop out of the noise.
Reading it: tallest bar = strongest channel. The bottom line gives the peak frequency, how far it stands above the floor (d: in dB), the noise floor, raw RSSI, and SCAN/PAUSE.
RFID NTAG Tools
RFID > NTAG Tools. Works on NTAG213 / 215 / 216 (and Ultralight EV1). It's a nine-item touch menu, and the flow is stage-then-write — you build the records first, then flash them to the tag in one pass. Write Tag and Clear Records stay dimmed until you've staged at least one record.
- Read / Info + Dump — hold a tag to the reader; shows the model, how much user memory it has, its lock/password state, and a full page dump (saved to SD if a card is in). If the tag carries NDEF records, a later Write Tag can re-clone them.
- Add URL — type a URL; it's staged as an NDEF record (common prefixes like
https://get packed short automatically). - Add Text — type a text record; staged the same way.
- Write Tag [N rec] — hold a tag; writes the N staged records onto it. If the tag is password-protected, it tells you it needs the password.
- Clear Records — empties the staging buffer. Does not touch the tag.
- Erase — wipes the NDEF message off the tag. Re-writable afterward. Asks you to confirm.
- Make Read-Only — permanently locks the tag against any future write. No undo — it confirms first. A locked tag still reads, it just never writes again.
- Set Password — sets a 4-byte write password (PWD_AUTH). Write it down; you need it to remove the password or to write the tag later.
- Remove Password — clears the password. You enter the current one to do it.
Text, URL, and password entry all use the on-screen keyboard (lower / upper / symbols).
Boards
Four targets in the flash package. Each board gets an app bin (to update over an existing install) and a -FULL bin (bootloader + partitions + app, for a fresh flash):
- HaleHound-CYD — 2.8" CYD (ESP32-2432S028, CH340 USB)
- HaleHound-CYD-HAT — 2.8" CYD wired for the NM RF Hat
- HaleHound-E32R28T — QDtech E32R28T (2.8", Type-C, battery)
- HaleHound-E32R35T — QDtech E32R35T (3.5")
Credits
- ToxxikHalo — for proposing the SubGHz Spectrum Analyzer. The concept came from his idea.
- JboHack — the Drone Toolkit's drone spoofing is built on his Nyan drone-spoofing project.
⣀⡀⣀⢀⡀⢀⡀⣀ ⣀⢀⡀ ⡀⢀ ⣀⢀⡀⢀⡀
⢀⡀⣛⠘⠿⢦⠤⣽⢟⣿⢻⡟⣾⡏⣹⣿⣿⢻⡟⣿⣾⣿⣿⡿⣿⢿⣿⣌⣿⢸⡷⢤⡄⢚⢀⡀
⣀⢀⣀⣀⣀⢀⣀⣈⣁⣉⣀⣀⣀⣀⣉⣈⣁⣀⣀⣀⣀⣉⣀⣁⣀⣁⣉⣉⣀⣈⣀⣀⣀⣉⣈⣉⣀⣀⣀⣀⣈⣈⣁⣀⣀⣀ ⣀
⣤⠐⢶⢻⡟⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡟⢠⡇
⢀⣀⣠⣄⣤⣀⣤⣤⣤⣤⣤⣤⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣭⣍⣭⣭⣭⣭⣥⣭⣭⣭⣭⣥⣭⣭⣭⣬⣭⣭⣥⣤⣤⣤⣤⣤⣤⣄⣤⣀⣄⣀⡀
⣴⠸⠟⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⢿⠿⠿⠉⠉
⢀⡀⣶⣦⣶⣴⣶⣴⣤⣴⣶⣶⣼⣦⣿⣶⣾⣶⣶⣾⣧⣿⣾⣷⣾⣷⣿⣶⣶⣶⣶⣶⣦⣶⣶⣶⣶⣷⣿⣶⣶⣶⣶⣶⣶⣿⣾⣷⣴⣦⣶⣦⣤⣤⣦⣴⣦⣴⢠⣦⣤⡆⣴⣤⣤⣤⣤⣤⣄
⠸⠇⠿⠻⢿⠿⠿⠿⠿⡿⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠿⠿⠿⠿⠿⠿⠿⠿⠿⠿⠟⠛⠃
⡤⢰⣶⣶⣶⣾⣷⣿⣶⣿⣾⣷⣿⣶⣿⣶⣷⣿⣿⣿⣿⣿⣿⣷⣿⣿⣿⣿⣷⣿⣿⣿⣾⣿⣿⣷⣿⣾⣿⣿⣷⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣿⣿⣿⣾⣷⣿⣧⣶⣰⣶⣤⣤⣤⣴⣶⣴⣶⣶⣶⣤⣶⣶
⠛⠘⠛⠛⠛⢿⠿⣿⠿⠿⠿⠿⠿⠿⠿⠿⠿⢿⠿⠿⠿⠿⣿⣿⣿⣿⣿⣿⡿⣿⣿⣿⣿⣿⣿⣿⣿⢿⣿⣿⣿⣿⣿⣿⣿⡿⣿⣿⣿⢿⣿⣿⡿⣿⠿⠿⠛⠛⠛⠛⠛⠛⠛⠛⠋⠛⠛⠛⠛⠛⠛⠁⠛⠘⠃⠐⠂
⢠⠶⣾⣶⣶⣶⣶⣶⣶⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣾⣿⣿⣿⣿⣷⣿⣿⣿⣿⣿⣿⣿⣿⣾⣿⣿⣾⣿⣿⣷⣿⣷⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣿⣶⣿⣾...
HaleHound-CYD v3.5.5
What's New
New Modules
Airoha RACE — CVE-2025-20700/20701/20702
Unauthenticated BLE GATT exploit for Airoha-based Bluetooth audio devices. Targets Sony XM4/XM5/XM6, Marshall, JBL, Jabra, Beyerdynamic — anything running an Airoha chipset. Extracts link keys, BD_ADDR, firmware version, and flash memory without pairing. Two-phase scan: BLE discovery then GATT service probe. Attack report with SD card loot save.
Tesla Charge Port Opener
Opens the charge port on any Tesla. Static 43-byte OOK payload, zero authentication, zero rolling code. Region selector: US (315 MHz), EU (433.92 MHz), or both.
.Sub Read — Flipper .sub File Browser + Transmitter
Browse and transmit Flipper Zero .sub files from the SD card. Supports RAW, Princeton, CAME, Nice FLO across the full CC1101 frequency range (300-348, 387-464, 779-928 MHz). Nested folder navigation. No .sub files required — drop them in /subghz/ on the SD when you have them.
Battery Monitor
LiPo battery voltage and percentage monitoring for boards with TP4854 charge IC (E32R28T, E32R35T). ADC on GPIO 34.
SubGHz Replay — Major Overhaul
- Complete UI revamp: Nosifer glitch title, 6-icon bar, skull watermark, transparent capture panel
- RSSI gating — noise floor frames rejected, real remotes only
- Drain loop — RMT RX buffer no longer floods with garbage
- Repeat validation — requires signal decoded twice before accepting
- CLEAR button — tap to discard capture and resume listening
- On-screen QWERTY keyboard for custom profile naming
- Auto-scan ON by default
SubGHz Brute Force — De Bruijn Fix
De Bruijn sequence generator was wired up but never called. Now active — overlapping code windows exhaust N-bit keyspace efficiently.
Proto Kill — GFSK Noise Mode
New toggle: CW carrier (original narrowband spike) or GFSK modulated noise (random 32-byte packets at 2Mbps filling ~2MHz bandwidth per channel). Toggle with SELECT when not jamming.
Bug Fixes
- EEPROM address collision — Three modules used different EEPROM sizes and overlapping addresses. Settings commit with begin(512) was nuking all SubGHz saved profiles. Unified to 5120 bytes, moved WiFi portal addresses above SubGHz range.
- SPI bus leak — Added SPI.end() to all NRF24 init failure paths (BLE Jammer, WLAN Jammer, Proto Kill, MouseJack). Prevents SPI bus lock when radio init fails on Core 0.
- SubGHz Replay RMT restart — resumeRmtRx() wasn't uninstalling RX driver before re-init, causing capture to silently stop after clearing a signal.
- SPI speed optimizations — Flash SPI 40→80 MHz, display SPI 40→55 MHz, NRF24 raw SPI 8→10 MHz.
Other
- README complete rewrite — trimmed, all 40+ modules documented, community credits
- Ebyte PA module independent 3.3V buck converter requirement documented
- Supported boards consolidated to 4 targets
- Version bump to v3.5.5
Firmware Downloads
| File | Board |
|---|---|
| HaleHound-CYD-FULL.bin | CYD 2.8" (ESP32-2432S028) |
| HaleHound-E32R35T-FULL.bin | QDtech E32R35T 3.5" |
| HaleHound-E32R28T-FULL.bin | QDtech E32R28T 2.8" |
| HaleHound-CYD-HAT-FULL.bin | NM-RF-Hat |
Flash at address 0x0 with ESP Web Flasher or esptool.
Four-file method also available — download all assets below.
HaleHound-CYD v3.5.1 — CYD35C Pin Fix
v3.5.1 Patch Release
CYD35C (3248S035C) Pin Mapping Fix
Fixed incorrect pin assignments on the 3.5" capacitive touch build target that caused CC1101 SubGHz radio to fail. If you're running a 3248S035C board, update immediately.
Changes
- CC1101 chip select corrected from GPIO 21 to GPIO 26 on 3248S035C (GPIO 27 is backlight, GPIO 26 is speaker pad — speaker disabled for SubGHz)
- NRF24 chip select moved from GPIO 4 to GPIO 21 to avoid conflict with CC1101 TX enable
- E32R35T gets its own splash screen watermark
- Flash instructions updated with CYD35C board and correct version
- All version references updated to v3.5.1
Firmware Downloads
- HaleHound-CYD.bin — CYD 2.8" (ESP32-2432S028)
- HaleHound-CYD-HAT.bin — NM-RF-Hat
- HaleHound-E32R28T.bin — QDtech E32R28T 2.8"
- HaleHound-E32R35T.bin — QDtech E32R35T 3.5" Resistive
- HaleHound-CYD35C.bin — ESP32-3248S035C 3.5" Capacitive
Ref: issue #5
Full flash instructions included in the repo.
HaleHound-CYD v3.5.0
What's New
New Modules
BLE Predator — GATT Reconnaissance + Honeypot Credential Trap
Three-phase BLE attack. SCAN discovers nearby devices and classifies them by threat tier (RED/YELLOW). RECON connects via GATT client, enumerates all services and characteristics, caches read values. HONEYPOT clones the target as a connectable GATTS server — logs every CONNECT/READ/WRITE/DISCONNECT event. WRITE captures contain credential data (PINs, tokens, passwords). 3-mode on-screen keyboard for device name filtering. Pulsing LIVE indicator, color-coded event log, SD card loot save.
Flock You — Flock Safety Surveillance Camera Detector
Passive SIGINT module that detects Flock Safety ALPR cameras, Raven/ShotSpotter gunshot sensors, and associated infrastructure via BLE advertisement fingerprinting. 22 OUI prefixes, 4 BLE name patterns, XUNTONG manufacturer ID, 8 Raven GATT service UUIDs with firmware version estimation. Dual-core BLE scan. SD card save with GPS coordinates.
Upgrades
Radio Test Overhaul
- NRF24: 126-channel spectrum scan (30 sweeps via testRPD()) + TX test
- CC1101: RSSI baseline on 315/433.92 MHz, 3-second signal detection
- GPS: inline test with gradient progress bar
- 4-button layout: NRF24 / CC1101 / GPS / WIRING
Radio Test upgrade source code by Duggie
AP-Locked 2.4GHz Spectrum Analyzer
- Tap AP Select to WiFi scan, pick an AP, locks analyzer to that channel's NRF24 range (~22 channels)
- Zoomed view with wider bar spacing, channel + SSID in title bar
Fast Touch Engine
- Bypasses TFT_eSPI getTouch() 5x validation loop with direct raw reads cached per frame
- 100-200x faster touch response — quick taps register instantly
Jammer Flicker Fix
- Draw-once standby pattern on all 4 jammer screens (BLE, WLAN, ProtoKill, SubGHz)
- Idle refresh reduced from 30ms to 200ms when not jamming
BLE Database — 94 company IDs, 73 service UUIDs, 52 GAP appearances for device identification
New Hardware Support
ESP32-3248S035C (CYD35C) — 3.5" Capacitive Touch
- GT911 capacitive touch controller (I2C) — same ST7796 display as E32R35T
- Edge-triggered debounce tuned for capacitive panels
- Build:
pio run -e esp32-cyd35c
3.5" UI Scaling — BLE Spoofer, Beacon, Sniffer + SubGHz Jammer/Brute Force touch zones properly scaled for 320x480
Removed
BLE Ducky — T-vK/ESP32-BLE-Keyboard library is abandoned (240+ open issues, broken Windows reconnect). Replaced by BLE Predator honeypot.
Menu Changes
- BLE Predator replaces BLE Scanner + Sniffer in Bluetooth menu
- AirTag hub renamed to Lunatic Fringe hub (Tracker Scan, AirTag Detect, Phantom Flood, AirTag Replay)
- Flock You added to SIGINT menu
Supported Boards
| Board | Build Target | Status |
|---|---|---|
| ESP32-2432S028 (2.8") | esp32-cyd |
Fully Tested |
| QDtech E32R35T (3.5") | esp32-e32r35t |
Fully Tested |
| ESP32-3248S035C (3.5" Cap Touch) | esp32-cyd35c |
Fully Tested |
| QDtech/Hosyond E32R28T (2.8") | esp32-e32r28t |
Fully Tested |
| NM-RF-Hat (2.8") | esp32-cyd-hat |
Supported |
Credits
Duggie — Radio Test upgrade source code (spectrum scan, TX test, signal detection)
HaleHound-CYD v3.4.0
HaleHound-CYD v3.4.0
New Board: QDtech E32R35T (3.5")
The E32R35T replaces the old ESP32-3248S035C as the supported 3.5" board. XPT2046 resistive touch, exposed SPI breakout, battery charging via TP4854, and onboard amp — all the hardware a HaleHound needs.
What's New
- E32R35T support — New build target
esp32-e32r35twith full pin mapping: CC1101 CS on GPIO 21, NRF24 on GPIO 26/16, battery ADC on GPIO 34, amp enable on GPIO 4 - XPT2046 resistive touch — Replaces GT911 capacitive. Shares HSPI with the LCD via TFT_eSPI's built-in driver. No extra library needed.
- Touch calibration — Save/load from NVS. Auto-recalibrates on rotation change. Calibrate from Settings > Touch Calibration.
- GPS screen scaled for 3.5" — Compass, speed arc, satellite bars, crosshairs, and all layout elements properly fill the 320x480 display
- PA module support — TX_EN (GPIO 4) and RX_EN (GPIO 0) for CC1101 power amplifier on E32R35T
- Battery monitoring — ADC on GPIO 34 for TP4854 charge IC
Bug Fixes
- Fixed touch blocking loot file selection — Edge-trigger flag was consuming every touch before menu selection could see it
- Tuned touch sensitivity — Threshold set to 100 for responsive light taps on XPT2046 panels
Removed
- GT911 capacitive touch driver (TAMC_GT911 library)
- ESP32-3248S035C (old CYD 3.5") board support
Supported Boards
| Board | Build Target | Flash File |
|---|---|---|
| CYD 2.8" (ESP32-2432S028) | esp32-cyd |
HaleHound-CYD |
| QDtech E32R35T (3.5") | esp32-e32r35t |
HaleHound-E32R35T |
| QDtech E32R28T (2.8") | esp32-e32r28t |
HaleHound-E32R28T |
| NM-RF-Hat | esp32-cyd-hat |
HaleHound-CYD-HAT |
Flashing
Single file: Flash HaleHound-<board>-FULL.bin at address 0x0
Four file: bootloader.bin (0x1000) + partitions.bin (0x8000) + boot_app0.bin (0xe000) + HaleHound-<board>.bin (0x10000)
HaleHound-CYD v3.3.2 — Bug Fixes
What's Fixed
- NRF24 Jammer cleanup — Scanner/Analyzer no longer dies after WLAN Jammer or ProtoKill (RF24 library CRC bug workaround)
- Evil Twin hotspot — Deauth failure recovery no longer kills the AP (#12)
- Valhalla SD wipe — Files in subdirectories now actually get deleted
- RFID Brute Force — Fixed crash + added scroll to Reader and Brute screens
- WhisperPair — Fixed attack chain (connection reuse, SD save, touch navigation)
- BLE Ducky — Fixed screen flicker (dirty-flag redraw)
What's Changed
- MouseJack — UI redesign with target frame, action button, device type display
- Find You — Removed (replaced by AirTag Detect)
- BLE-to-NRF24 handoff — Improved exit checks, heap diagnostics, SPI cleanup
Flash Package
Pre-built binaries for all supported boards:
- CYD 2.8" — HaleHound-CYD.bin / HaleHound-CYD-FULL.bin
- CYD HAT — HaleHound-CYD-HAT.bin / HaleHound-CYD-HAT-FULL.bin
- E32R28T — HaleHound-E32R28T.bin / HaleHound-E32R28T-FULL.bin
See FLASH_INSTRUCTIONS.txt in the repo for flashing guide.
v3.3.0 — NRF Sniffer, MouseJack, BLE Ducky
What's New
NRF Promiscuous Sniffer
- Travis Goodspeed promiscuous receive mode on NRF24L01+PA+LNA
- Captures raw 2.4GHz packets from wireless keyboards, mice, drones, IoT sensors
- Channel hopping across all 126 channels (Core 0 task)
- Tap any captured device address to auto-populate MouseJack target
- Nosifer UI with animated skull row, scrollable packet list, hex dump detail view
MouseJack Keystroke Injection
- Inject keystrokes into Logitech Unifying, Dell, Microsoft wireless keyboards
- Fixed Logitech HID++ packet format: 0xC1 frame type, LRC checksum, 16-bit CRC
- Full HID scancode keymap: a-z, 0-9, symbols, F1-F12, arrows, modifiers
- Pre-built payloads: reverse shell (PowerShell/bash), WiFi exfil, custom string
- Core 0 injection task with 10ms inter-keystroke timing
BLE Ducky — BLE HID Keyboard Injection
- ESP32 acts as BLE HID keyboard via ESP32-BLE-Keyboard library
- Target pairs with "HaleHound KB", then receives injected keystrokes
- Pre-built payloads: reverse shell, Rick Roll, custom string entry
- 50ms BLE keystroke timing, progress display, pairing status
AirTag Attack Suite (AirTag Hub)
- Phantom Flood — FindMy OF advertisement flood with random public keys
- AirTag Replay — Sniff & replay real AirTag BLE identity
- Find You — Stealth AirTag clone with P-224 EC key rotation (15-120s key rotation below Apple anti-stalking threshold)
WhisperPair — CVE-2025-36911 Exploit Chain
- Full attack phase added: scan, probe, and exploit Google Fast Pair devices
- GATT-based Key-Based Pairing characteristic probe for unauthorized pairing
- Loot Viewer for browsing discovered vulnerable devices
Unified Loot Manager
- Centralized loot storage and browsing across all attack modules
- WhisperPair Loot Viewer with full device detail display
- GPS coordinate tagging for wardriving loot
E32R28T Board Support
- Full support for QDtech E32R28T 2.8" board
- VALHALLA protocol for board identification
- Custom skull art and per-board skull watermarks (240x320 and 320x480 variants)
- GPIO 0 fix for E32R28T boot behavior
- Pre-compiled binaries now included in flash_package
BLE Database Integration
- 94 company IDs, 73 service UUIDs, 52 GAP appearances — all PROGMEM binary search
- Source: Nordic Semiconductor bluetooth-numbers-database v1.0.4
- BLE Sniffer now shows manufacturer names and device types
Dual-Core 2.4GHz Scanner + Analyzer
- NRF24 Scanner and Spectrum Analyzer now run scan on Core 0, draw on Core 1
- Significantly faster scan rates with smooth UI updates
CC1101 E07-PA Module Support
- PA module control added to all SubGHz operations
- E07-PA wiring diagram added to Radio Test pages
- Proper power amplifier enable/disable for E07 modules
EAPOL Capture — AP List Pagination
- Scrollable AP list for networks with many access points
- No more truncated scan results on busy networks
Bug Fixes
- Fixed WiFi/BLE radio handoff — proper teardown for cross-module transitions
- Fixed residual touch exits + GPIO0 bug across all modules
- Fixed BLE Sniffer instant-exit on E32R28T + Classic BT memory release
- Fixed NRF24 SETUP_AW register persistence across ESP32 reset (promiscuous sniffer cleanup)
- Fixed boot NRF24 detection false positive after sniffer use
- Fixed 3.5" CYD bugs: attack popup touch zones, RFID brute crash, wardriving layout
- SubGHz analyzer speed improvements + replay noise filter
- DRAM optimization: reduced BLE sniffer device array, const-qualified icon arrays
UI Polish
- NRF Sniffer and MouseJack screens: Nosifer headers, rounded frames, skull rows
- Per-board skull watermarks for CYD 2.8", CYD 3.5", and E32R28T
- E07-PA wiring diagram in Radio Test
- Improved boot mismatch warning — mentions E32R28T and HAT by name
Supported Boards
| Board | Build Target |
|---|---|
| CYD 2.8" (ESP32-2432S028) | esp32-cyd |
| QDtech E32R28T | esp32-e32r28t |
| NM-RF-Hat | esp32-cyd-hat |
Note: CYD 3.5" (ESP32-3248S035C) is temporarily excluded from this release due to a DRAM overflow caused by the GT911 touch driver. Will be fixed in a follow-up release.
Pre-Compiled Binaries
| File | Board | Flash Address |
|---|---|---|
| HaleHound-CYD-FULL.bin | CYD 2.8" | 0x0 (single file) |
| HaleHound-CYD.bin | CYD 2.8" | 0x10000 (4-file method) |
| HaleHound-CYD-HAT-FULL.bin | NM-RF-Hat | 0x0 |
| HaleHound-CYD-HAT.bin | NM-RF-Hat | 0x10000 |
| HaleHound-E32R28T-FULL.bin | QDtech E32R28T | 0x0 |
| HaleHound-E32R28T.bin | QDtech E32R28T | 0x10000 |
Flash instructions: see FLASH_INSTRUCTIONS.txt in the release.
Requirements
- NRF24L01+PA+LNA module required for NRF Sniffer, MouseJack, WLAN Jammer, Proto Kill
- CC1101 module required for SubGHz attacks (standard HW-863 or E07-PA supported)
- BLE Ducky uses ESP32's built-in Bluetooth — no external hardware needed
- GPS module on GPIO 3 (P1 connector) required for wardriving
HaleHound-CYD v3.2.0 — VALHALLA Protocol, IoT Recon, RFID/NFC, Jam Detect
HaleHound-CYD v3.2.0 — VALHALLA Protocol + 4 New Modules
The biggest single release in HaleHound history. Four entirely new attack modules, a full defensive panic system, device PIN lock, and over 9,000 new lines of code.
VALHALLA Protocol — Scorched Earth Panic System
One-tap emergency response. Tap the VALHALLA banner on the home screen and hold to confirm:
- Wipes SD card — recursive delete, everything gone
- Locks all offensive tools — 17 offensive functions gated
- Enters Blue Team mode — device switches to defensive-only operation
- Legal disclaimer — EEPROM-persisted liability screen with scrollable text. Must accept before any offensive function will run. Cites 47 U.S.C. § 333 and 18 U.S.C. § 1030.
- Blue Team mode persists across reboots until you actively re-accept the disclaimer
New Modules
-
IoT Recon — Automated LAN attack suite. WiFi connect via on-screen keyboard, full network scan, service fingerprinting (HTTP, Telnet, SSH, MQTT, RTSP, FTP), credential brute forcing with 40+ default password combos, harvested credential storage. Core 0 scan task for responsive UI during deep scans. (Shoutout: @CircuitZ for reminding me to add IoT)
-
PN532 RFID/NFC — Five attack modes: Card Scanner (UID + type detection), Card Reader (full sector dump with default keys), Card Clone (copy UID to magic Gen1a cards), Key Brute Force (dictionary + sequential attack on all sectors), Card Emulate (replay captured UID). Software SPI to avoid bus conflicts. (Shoutout: @duggie162-cpu for the RFID recommendation)
-
Jam Detect — Defensive RF jamming detection across all 3 radios. (Shoutout: @valleytechsolutions for bringing up the idea)
- WiFi Guardian — 2.4 GHz deauth/disassoc frame counter with per-channel heatmap
- SubGHz Sentinel — CC1101 wideband energy monitoring across 315/433/868/915 MHz
- 2.4 GHz Watchdog — NRF24 spectrum-analyzer-style continuous sweep with threshold alerts
- Full Spectrum — All radios simultaneously, split-screen dashboard
-
Captive Portal Upgrade — PSK capture templates + Core 0 deauth task for continuous client disruption while serving portal pages. (Shoutout: @muffduncan for bringing it to my attention)
Renamed
- Stalkerware Detect has been renamed to Lunatic Fringe
Security
- PIN Lock — 4-digit device lock with configurable auto-lock timeout (30s to 10min or never). Skull animation on lock screen. Persisted in EEPROM.
Fixes & Improvements
- NRF24 SPI clock reduced to 4 MHz for reliability on noisy power sources
- IoT Recon timeout tuning + harvested credential persistence
- Jam Detect flicker elimination + WiFi Guardian full layout redesign
- PN532 software SPI fix for CYD GPIO conflicts
- IoT max devices reduced 64→48 to fix 3.5" CYD DRAM overflow
Community
Credit to the people who made this release happen:
- @muffduncan — For bringing the Captive Portal update to my attention
- @CircuitZ — For reminding me to add IoT
- @valleytechsolutions — For bringing up the Jam Detect idea
- @duggie162-cpu — For the RFID recommendation, Lunatic Fringe concept, and EAPOL bug reports
- @duggie162-cpu, @valleytechsolutions, @ TalkingSasquach, @Notorious-Squirrel, @Man-In-The-Mayhem, @Hamspiced — For the efforts and ideas that created the OPSEC of the HaleHound
Downloads
Easiest method: Flash the FULL.bin at offset 0x0
| File | Board | Size |
|---|---|---|
HaleHound-CYD-FULL.bin |
2.8" CYD (ESP32-2432S028) | 2.3 MB |
HaleHound-CYD-35-FULL.bin |
3.5" CYD (ESP32-3248S035) | 2.4 MB |
HaleHound-CYD-HAT-FULL.bin |
2.8" CYD + NM-RF-Hat | 2.3 MB |
Four-file method (if single-file gives black screen):
| File | Flash Address |
|---|---|
bootloader.bin |
0x1000 |
partitions.bin |
0x8000 |
boot_app0.bin |
0xe000 |
HaleHound-CYD.bin / HaleHound-CYD-35.bin / HaleHound-CYD-HAT.bin |
0x10000 |
Flash with ESP Web Flasher (Chrome/Edge/Opera) or esptool.
See flash_package/FLASH_INSTRUCTIONS.txt for step-by-step guide.