Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
07-wireless/07-bluetooth-zigbee.md — BLE GATT, pairing abuse, Zigbee key sniff.
How to operate
Adapter check: monitor mode + injection on 2.4 / 5 / 6 GHz before any capture (01-recon-monitoring.md).
WPA/WPA2 capture path is hcxdumptool → hashcat (PMKID, then 4-way handshake fallback).
Enterprise: capture PEAP-MSCHAPv2 inner-auth via Evil Twin with hostapd-mana / eaphammer; submit MSCHAPv2 to crack.sh for guaranteed ≤24h crack when in scope.
BLE/Zigbee at consumer-Wi-Fi engagement level: pair sniffing (Sniffle) + GATT enumeration. For sub-GHz / LoRa / Z-Wave / NFC use pentest-iot-ot/03-radio-rf.md.
When NOT to use
Cellular / 4G / 5G (regulated tooling, out of typical scope).
IoT-device-RF specifically → pentest-iot-ot.
Pre-conditions
Wi-Fi adapter with monitor + injection (Alfa AWUS036ACS/ACH/ACM, AR9271, MT76).