Tactical Flipper Zero You Have 1 Hour and No Other Equipment

Grey Fox

RF Village @ DEF CON 33 · Day 1 · RF Village

Overview

In a compelling presentation at RF Village, Grey Fox, a seasoned expert with a background in Air Force signals intelligence and special operations, unveiled a training scenario demonstrating the remarkable capabilities of the Flipper Zero for clandestine intelligence gathering. Titled "Tactical Flipper Zero You Have 1 Hour and No Other Equipment," the talk immersed the audience in a high-stakes mission: confirm the identities of two hostile individuals (HVIs) in a nearby hotel, without overt military action, and with the severe constraint of having lost all equipment except for a Flipper Zero. This "no-kit" challenge highlighted the device's potential as a versatile, pocket-sized Swiss Army knife for a range of RF-based reconnaissance and collection tasks.

Watch on YouTube

Visual summary for Tactical Flipper Zero You Have 1 Hour and No Other Equipment by Grey Fox
Visual summary for Tactical Flipper Zero You Have 1 Hour and No Other Equipment by Grey Fox

Key moments

  1. 0:00 Speaker introduction and Flipper Zero's utility
  2. 2:00 The mission: identify HVIs with only a Flipper Zero
  3. 3:00 Flipper Zero's broad capabilities overview
  4. 4:00 Important caveats and limitations of the Flipper Zero
  5. 6:00 Essential equipment for the tactical Flipper Zero scenario
  6. 6:20 Critical warning: FCC regulations and responsible RF use
  7. 6:50 Beginning the mission: first step with Wi-Fi reconnaissance

Tactical Flipper Zero You Have 1 Hour and No Other Equipment

Speakers: Grey Fox, Retired Air Force, Signals Intelligence, Special Operations

Conference: RF Village

YouTube: https://www.youtube.com/watch?v=b8-uDKkfw5c

Overview

In a compelling presentation at RF Village, Grey Fox, a seasoned expert with a background in Air Force signals intelligence and special operations, unveiled a training scenario demonstrating the remarkable capabilities of the Flipper Zero for clandestine intelligence gathering. Titled "Tactical Flipper Zero You Have 1 Hour and No Other Equipment," the talk immersed the audience in a high-stakes mission: confirm the identities of two hostile individuals (HVIs) in a nearby hotel, without overt military action, and with the severe constraint of having lost all equipment except for a Flipper Zero. This "no-kit" challenge highlighted the device's potential as a versatile, pocket-sized Swiss Army knife for a range of RF-based reconnaissance and collection tasks.

The scenario underscored the critical need for improvisation and ingenuity in intelligence operations, illustrating how a seemingly consumer-grade device can be leveraged to collect crucial evidence for host-nation law enforcement. Fox’s presentation was not merely a technical demonstration but a masterclass in applying foundational intelligence principles—like pattern-of-life analysis and evidence correlation—using readily available and often underestimated tools. The talk resonated deeply by showcasing how accessible technology, combined with tactical thinking, can achieve objectives typically associated with far more sophisticated and expensive equipment, thereby challenging conventional notions of what constitutes effective signal intelligence in the field.

Why does this matter? The Flipper Zero has gained notoriety for its ability to interact with a multitude of wireless protocols, from sub-gigahertz radio to Wi-Fi, Bluetooth, NFC, and RFID. Grey Fox's insights reveal that beyond casual tinkering or "white-hat" security testing, the device possesses a potent capability for sensitive data collection. This has profound implications for both national security operations, where resource constraints can be a reality, and for personal privacy, as it exposes how easily an individual's digital footprint can be tracked and exploited using a device that fits in a pocket. The talk serves as a stark reminder of the evolving landscape of signal intelligence and the democratized access to powerful RF tools.

Background

▶ Watch: Speaker introduction and Flipper Zero's utility (0:00)

Grey Fox, the speaker, brings a wealth of experience to this topic, having served in the Air Force where he specialized in signals intelligence (SIGINT), wireless intelligence (WHOPINT), and digital network intelligence (DNI). His career trajectory later led him into special operations work, where he gained invaluable insights into offensive security and advanced applications of wireless technology. His enthusiasm for "messing with wireless technology" naturally led him to the Flipper Zero, which he lauded as a "Swiss Army knife" capable of replacing a significant amount of bulkier equipment he once had to carry. This talk is a condensed version of a two-hour workshop he developed to train others on the Flipper Zero's capabilities.

The core mission presented in the talk is a simulated intelligence operation: identify two high-value individuals (HVIs), Vera Unabite and Augustus St. Cloud, in a hotel. The crucial constraint is the "no-kit" scenario, where the operator has lost all luggage and is left only with a Flipper Zero and whatever might be in their pockets. The objective is to gather sufficient evidence to confirm their identities, allowing host-nation law enforcement to act without overt military intervention, adhering to strict status of force agreements. This necessitates improvisation and reliance on the Flipper Zero's diverse functionalities.

Before diving into the operational details, Fox outlined several critical caveats for working with the Flipper Zero and RF in general:

  1. Flipper Zero Reliability: The device is not infallible; its functionality can be impacted by firmware versions or environmental factors. Success is not guaranteed.
  2. Performance Limitations: While capable, the Flipper Zero is not a full-fledged computer. For example, cracking a Myfair Classic key can take five days on a Flipper Zero compared to minutes on a dedicated computer.
  3. Target Interaction: Adversaries are not always cooperative. Their actions can disrupt or counter collection efforts, demanding constant adaptation.
  4. RF Environment Finickiness: Wireless environments are inherently unpredictable. Interference, such as a microwave operating on 2.4 GHz, can degrade Wi-Fi performance.
  5. Adversary Error in Training: For training purposes, the scenario assumes some "gimmies" or adversary errors to lower the barrier to entry and ensure a productive learning experience. This means the scenarios are "in the realm of the possible" for what a Flipper Zero could achieve in an ideal, albeit simulated, world.

The primary tools for this mission include the Flipper Zero itself, which operates in half-duplex mode, meaning it can transmit or receive but not simultaneously on different frequencies. Crucially, a Wi-Fi dev board (also half-duplex) is attached to the Flipper Zero's GPIO pins to extend its Wi-Fi capabilities. For enhanced sub-gigahertz signal reception, external antennas are also recommended. A stern warning about FCC regulations was also issued, emphasizing the importance of operating in controlled environments with explicit permission to avoid legal repercussions.

Key Findings

▶ Watch: Flipper Zero's broad capabilities overview (3:00)

The talk meticulously demonstrated that the Flipper Zero, even under severe resource constraints, is an exceptionally potent tool for tactical intelligence gathering. Grey Fox's scenario revealed several key findings:

Firstly, the Flipper Zero can effectively perform a wide array of RF reconnaissance and active collection techniques across multiple protocols. This includes identifying Wi-Fi devices and their MAC addresses, capturing probe requests that reveal a target's travel history, reading NFC data from credit cards and hotel keys, and analyzing and replaying sub-gigahertz signals from car key fobs. This broad spectrum of capabilities allows a single, compact device to replace what would traditionally require multiple specialized pieces of equipment.

Secondly, the collected RF data, even seemingly innocuous details like a device’s MAC address or a preferred Wi-Fi network list, can be correlated with open-source intelligence (OSINT) tools like wigle.net to build a comprehensive pattern of life and pattern of travel for a target. This ability to transform raw signal data into actionable intelligence is a significant contribution, demonstrating how technical and analytical skills can amplify the utility of accessible tools.

Thirdly, the presentation highlighted the operational value of subtle, clandestine actions. Techniques such as performing a Wi-Fi deauthentication attack to elicit a visible reaction from a target, or replaying a car's "lock" signal rather than "unlock" to avoid suspicion, underscore the importance of operational security (OPSEC) in intelligence gathering. These methods allow for the confirmation of identities and the collection of evidence without alerting the adversary.

Finally, the talk underscored the significant defensive implications of the Flipper Zero's capabilities. The ease with which sensitive information—from hotel room access to credit card details—can be captured serves as a critical warning for individuals and organizations. It emphasizes the urgent need for enhanced awareness and protective measures, such as disabling Wi-Fi when not in use, employing RFID-blocking materials, and understanding the inherent vulnerabilities of wireless technologies in everyday use.

Technical Deep Dive

▶ Watch: Important caveats and limitations of the Flipper Zero (4:00)

The technical core of Grey Fox's presentation revolved around leveraging the Flipper Zero's diverse radio capabilities to build a profile of the HVIs. The mission began in the hotel lobby, targeting Wi-Fi as a primary vector for initial collection.

Wi-Fi Reconnaissance and Tracking:

The first step was to scan for Wi-Fi networks using the Flipper Zero’s Wi-Fi dev board. Immediately, the device identified "Verer's iPhone," providing an essential element of information and a critical starting point. The associated MAC address was recorded, serving as a unique identifier for future tracking. Beyond active SSIDs, the Flipper Zero was used to capture probe requests. These are beacons continuously broadcast by devices with Wi-Fi enabled but not connected to a network, listing all previously associated networks (e.g., "Home Wi-Fi," "Starbucks Guest"). By collecting these, an operator can use open-source tools like wigle.net to map the physical locations where these networks have been seen globally, thereby establishing a pattern of life or pattern of travel. For instance, if an HVI’s probe requests included "Chateau St. Cloud," it could directly link to the target Augustus St. Cloud.

To confirm a target's identity in a crowded environment, a Wi-Fi deauthentication attack was proposed. By temporarily disconnecting a target’s device from the Wi-Fi network, the operator can observe for a reaction (e.g., someone frantically checking their phone), allowing for a face-to-device correlation. While not used in the scenario due to mission constraints, the Flipper Zero is also capable of performing a Karma attack, a form of evil twin attack. This involves creating a rogue access point (AP) that mimics a preferred network from the target's probe list, then using the evil portal firmware on the Wi-Fi dev board to intercept traffic and potentially collect credentials.

As the target moved, the Flipper Zero's ability to monitor Received Signal Strength Indicator (RSSI) for the known MAC address became crucial. By observing the RSSI increase as the operator approached the target's location (e.g., moving from the lobby to an elevator, then to a specific hotel room) and decrease as they moved away, the Flipper Zero provided confirmation of the target's physical presence in a specific area, like their hotel room. This technique adds to the preponderance of evidence needed for the mission.

NFC Collection:

The scenario highlighted the collection of NFC data from physical items. When an HVI carelessly displayed a hotel room key and a car key fob, the Flipper Zero was deployed. For hotel keys, particularly Myfair Classic cards, the Flipper Zero can read the data. While cracking these encrypted cards can be time-consuming (up to five days on the Flipper Zero compared to minutes on a computer), Fox demonstrated how to copy and emulate a Myfair Classic key from inside his own hotel room (a crucial legal distinction) to open the door. This showcased the ease of bypassing hotel security with the device.

Similarly, the Flipper Zero was used to read a credit card left exposed. While Fox clarified that the Flipper Zero cannot be used to emulate a credit card for point-of-sale transactions (contrary to some online myths), it can extract the credit card number, expiration date, cardholder name, and other unique identifiers. This financial intelligence, or FINT, can then be correlated with national collection databases or even breach data (if operating as a civilian) to uncover purchase histories, online accounts, and further characterize the target. Fox personally uses copper sleeves for his credit cards due to this vulnerability.

Sub-Gigahertz Analysis and Car Key Fobs:

The car key fob presented another opportunity for intelligence gathering. The first step in analyzing such a device is to find its FCC ID to research its operating frequencies, which for most modern car fobs are 315 MHz, 433 MHz, or 900-915 MHz. The Flipper Zero, with a downloadable spectrum analyzer firmware (available from lab.flipper.net), can then be used to precisely identify the frequency. By pressing the lock or unlock button on the key fob and observing spikes on the spectrum analyzer, the exact frequency can be determined.

Once the frequency is known, the Flipper Zero can perform a raw signal capture of the "lock" signal. Replaying this signal in a parking lot allows the operator to identify the target's vehicle by observing which car’s lights flash. This provides valuable evidence (make, model, license plate) that can be fed into broader intelligence collection, such as automatic license plate readers (ALPRs), to establish a vehicle’s pattern of travel. Fox made a critical distinction: for clandestine operations, only the "lock" signal should be replayed. Replaying an "unlock" signal could alert the adversary if their key fob then fails to unlock the car on the first attempt (due to modern rolling code systems). Furthermore, he shared a personal anecdote about how replaying unlock signals on newer vehicles (post-2013) without the physical key present can actually break the remote entry system, costing $300 for reprogramming at a dealership.

Advanced Intelligence Applications:

The talk also touched upon more advanced applications:

  • EAPOL Packet Capture: During deauthentication attacks, the Flipper Zero can capture EAPOL (Extensible Authentication Protocol over LAN) packets, which contain encrypted Wi-Fi passwords. These can be cracked offline to gain access to adversary networks.
  • Signal Intelligence Tripwires: Collected MAC addresses can be whitelisted and programmed into inexpensive devices like an ESP32 chip. These can be left as leave-behinds to detect the target's presence along a known route, providing near real-time tracking.
  • Ubiquitous Technical Surveillance: Correlating NFC data (credit card numbers) with breach data or national collection can reveal purchase histories and online activities, further characterizing targets.
  • Device Correlation and Social Network Analysis: By identifying multiple devices carried together (co-traveler information) or leveraging nation-state access to telecom networks, MAC addresses and other identifiers can be correlated to map a target's social network, including associates, movements, and activities. This process, as Fox noted, is why entities like the FBI and NSA are advocating for secure communication apps like Signal, acknowledging the ease with which nation-states can track devices.

Demo / Proof of Concept

▶ Watch: Critical warning: FCC regulations and responsible RF use (6:20)

While the entire presentation was framed as a detailed training scenario, Grey Fox incorporated explicit demonstrations and proofs of concept to illustrate the Flipper Zero's capabilities.

One of the most striking demonstrations involved NFC hotel key card copying. Fox presented a video showing himself using a Flipper Zero to copy a Myfair Classic hotel key card. He explicitly noted the importance of performing this action "from inside the room" to maintain a reasonable expectation of privacy and avoid legal issues, emphasizing the ethical and legal boundaries of such activities. After copying the card, the video showed him successfully emulating the key with the Flipper Zero to open the hotel room door. He highlighted that this feat was achieved in Washington D.C., "five blocks from the capital," underscoring the potential security vulnerabilities even in seemingly secure environments.

Another key demonstration, though primarily verbal with supporting slides, detailed the process of analyzing and replaying sub-gigahertz car key fob signals. Fox explained how to use the Flipper Zero's downloadable spectrum analyzer to identify the precise frequency of a key fob's signal when a button (e.g., "lock") is pressed. He then described capturing the raw signal and replaying it to identify the associated vehicle in a parking lot, confirming its make, model, and license plate. This demonstrated the Flipper Zero's ability to passively identify vehicles without physical interaction, providing valuable intelligence for tracking.

Finally, the talk implicitly demonstrated NFC credit card reading. While no live video was shown for this, Fox clearly explained how the Flipper Zero could read a credit card number, expiration date, and cardholder name from a credit card left exposed. He then detailed how this information, despite not allowing for point-of-sale emulation, is still highly valuable for financial intelligence and target characterization. The scenario itself, where a credit card belonging to Augustus St. Cloud was "read" to confirm his identity, served as a practical proof of concept for this capability.

These demonstrations, combined with the detailed explanations of Wi-Fi reconnaissance and tracking, provided concrete evidence of the Flipper Zero's effectiveness as a tactical intelligence tool in a resource-constrained environment.

Defensive Implications

▶ Watch: Beginning the mission: first step with Wi-Fi reconnaissance (6:50)

The capabilities demonstrated by Grey Fox with the Flipper Zero carry significant defensive implications for individuals, organizations, and even national security. Understanding these techniques is crucial for implementing effective countermeasures.

For Individuals:

  • Wi-Fi Privacy: The ease of collecting Wi-Fi probe requests and MAC addresses highlights a significant privacy vulnerability. Users should disable Wi-Fi on their mobile devices when not actively connected to a trusted network to prevent broadcasting their list of previously visited networks. While MAC address randomization helps, it's not a complete solution against persistent tracking.
  • NFC Security: The ability to read credit card and hotel key information via NFC underscores the need for physical protection. Individuals should use RFID-blocking wallets or copper sleeves for credit cards, passports, and other NFC-enabled cards to prevent unauthorized skimming. Avoid leaving such cards exposed in public spaces.
  • Car Key Fob Vulnerabilities: While newer vehicles have improved security, older models remain susceptible to sub-gigahertz signal replay attacks. Owners should be aware that their car's remote entry signals can be captured and replayed, potentially for illicit access or, as shown, for clandestine identification.

For Organizations (e.g., Hotels, Corporate Security):

  • Access Control Systems: The vulnerability of Myfair Classic hotel key cards to Flipper Zero attacks (even if time-consuming for decryption) suggests that organizations relying on older or less secure NFC-based access systems should consider upgrading to more robust, encrypted solutions. Regular security audits of such systems are paramount.
  • Wireless Network Security: The potential for Wi-Fi deauthentication attacks and Karma attacks emphasizes the need for robust wireless network configurations, including strong authentication protocols and vigilant monitoring for rogue access points. Organizations should educate employees on the risks of connecting to untrusted Wi-Fi networks.
  • Physical Security and Awareness: Training staff to be vigilant about suspicious activity, such as individuals appearing to scan devices near guests or assets, can be an important layer of defense. The "adversary error" in the scenario (leaving items exposed) highlights the importance of basic physical security hygiene.

Broader Implications:

  • Operational Security (OPSEC) Awareness: The talk demonstrates how sophisticated intelligence can be gathered through seemingly innocuous or "clandestine" actions. This requires a heightened awareness across all sectors regarding the electromagnetic spectrum as a potential vector for surveillance.
  • Multi-Factor Authentication (MFA) for Wireless: The anecdote about modern car security breaking when a single signal is replayed underscores the importance of multi-factor authentication in wireless systems. Systems that rely on rolling codes, challenge-response mechanisms, or other dynamic authentication methods are more resilient.
  • Supply Chain Security: The Flipper Zero's accessibility means that advanced RF tools are no longer exclusive to state actors. This democratized access necessitates a re-evaluation of security postures across all industries, recognizing that sophisticated attacks can originate from less resourced adversaries.

In essence, the Flipper Zero's capabilities serve as a powerful reminder that "wireless" does not equate to "invisible" or "secure." A proactive, multi-layered defensive strategy that combines technical controls with heightened user awareness and robust physical security practices is essential in mitigating the risks posed by such versatile and accessible tools.

Key Takeaways

  • The Flipper Zero is an incredibly versatile and compact tool capable of performing a wide range of sophisticated RF intelligence gathering, including Wi-Fi reconnaissance, NFC data collection, and sub-gigahertz signal analysis and replay.
  • Seemingly innocuous data like Wi-Fi probe requests, MAC addresses, and exposed credit card details can be leveraged to build comprehensive target profiles, establish patterns of life, and confirm identities.
  • Tactical improvisation, combining passive and active collection techniques (e.g., deauthentication attacks, signal replay), allows operators to gather critical evidence and achieve mission objectives even in severely resource-constrained "no-kit" scenarios.
  • The use of open-source intelligence tools like wigle.net significantly enhances the value of collected RF data, enabling mapping of travel patterns and correlation with broader intelligence.
  • The widespread accessibility of such powerful RF tools necessitates a heightened awareness of personal and organizational OPSEC and the implementation of defensive measures like disabling Wi-Fi when not in use, using RFID-blocking materials, and understanding the vulnerabilities of wireless systems.
  • While powerful, the Flipper Zero has limitations (e.g., speed of cracking, inability to emulate credit cards for POS) and its use requires strict adherence to legal and ethical guidelines, especially concerning FCC regulations and privacy.

About the Speaker(s)

Grey Fox is a retired member of the Air Force with a distinguished background in intelligence and special operations. He began his career in signals intelligence (SIGINT), specializing in wireless intelligence (WHOPINT), and digital network intelligence (DNI). His expertise later expanded into special operations work, where he gained hands-on experience in offensive security and the tactical application of wireless technologies. A passionate enthusiast for wireless technology, Grey Fox found the Flipper Zero to be a groundbreaking tool, effectively replacing a significant amount of the bulkier equipment he previously had to carry. He has since developed training courses and scenarios utilizing the Flipper Zero, sharing his extensive knowledge with the security community. Due to extensive overseas deployments, he humorously notes his aversion to sun and beaches.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent RF Village talk that wraps Flipper Zero capabilities in a clever mission scenario, giving it more narrative punch than the typical 'here's what this device can do' walkthrough. The operational framing is genuinely useful for the audience, but the technical content rarely goes deeper than what's already documented in the Flipper Zero community, and the summary article oversells the novelty considerably.

Heather Calloway (CISO) — WEAK

Technically competent demonstration of Flipper Zero capabilities framed through a military SIGINT scenario, but the talk operates entirely below the institutional waterline. It is a practitioner curiosity, not a defender or leadership resource.

→ Top-rated talks at RF Village @ DEF CON 33

All talks from RF Village @ DEF CON 33