| name | detecting-bluetooth-low-energy-attacks |
| description | Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840 sniffers for packet capture, the bleak Python library for GATT service enumeration, and crackle for BLE encryption cracking. Use when assessing IoT device BLE security, monitoring for BLE-based attacks on wireless infrastructure, or performing authorized BLE penetration testing. Activates for requests involving BLE security assessment, Ubertooth sniffing, GATT enumeration, or BLE replay detection.
|
| domain | cybersecurity |
| subdomain | wireless-security |
| author | mukul975 |
| tags | ["ble","bluetooth","ubertooth","nrf-sniffer","gatt","wireless-security","iot-security","replay-attack"] |
| version | 1.0.0 |
| license | Apache-2.0 |
| nist_csf | ["PR.IR-01","DE.CM-01","ID.AM-03"] |
| mitre_attack | ["T1011.001","T1557","T1040","T1200"] |
Detecting Bluetooth Low Energy Attacks
Disclaimer
This skill is intended for authorized security testing, penetration testing engagements, CTF competitions, and educational purposes only. Sniffing, intercepting, or manipulating Bluetooth communications without authorization may violate federal wiretapping laws and local regulations. Always obtain explicit written permission before conducting any wireless security assessment.
When to Use
Use this skill when:
- Performing authorized BLE security assessments of IoT devices, medical devices, or smart locks
- Monitoring a wireless environment for BLE-based replay attacks, spoofing, or unauthorized enumeration
- Analyzing BLE packet captures to detect Man-in-the-Middle attacks or pairing exploitation
- Enumerating GATT services and characteristics to identify insecure read/write permissions on BLE peripherals
- Assessing BLE encryption strength and testing for crackable pairing exchanges
- Building BLE intrusion detection capabilities for wireless security monitoring
Do not use for intercepting BLE communications without explicit authorization. Do not deploy BLE scanning tools in environments where wireless monitoring is prohibited.
Prerequisites
- Ubertooth One hardware for passive BLE sniffing, or Nordic nRF52840 USB Dongle with nRF Sniffer firmware
- Python 3.10+ with pip
- bleak library:
pip install bleak (cross-platform BLE GATT client)
- Wireshark with BLE dissector plugins for packet analysis
- crackle tool for BLE encryption analysis: built from source at github.com/mikeryan/crackle
- ubertooth-btle CLI tools:
apt install ubertooth (Linux) or build from source
- Bluetooth 4.0+ adapter on the host system for bleak-based scanning
- Linux recommended for full Ubertooth/nRF sniffer support
Workflow
Step 1: BLE Environment Discovery and Device Scanning
Scan the environment to identify BLE devices and their advertising data:
python -c "
import asyncio
from bleak import BleakScanner
async def scan():
devices = await BleakScanner.discover(timeout=10.0)
for d in devices:
print(f'{d.address} | RSSI: {d.rssi} | Name: {d.name or \"Unknown\"}')
for uuid in d.metadata.get('uuids', []):
print(f' Service: {uuid}')
asyncio.run(scan())
"
ubertooth-btle -p -r capture.pcapng
ubertooth-btle -f -t AA:BB:CC:DD:EE:FF -r connection.pcapng
wireshark -i nRF_Sniffer -k