Home > 3rd-Party Integration > Wardrive Integration

Wardrive Integration

Wardriving is the most common 3rd-party integration target: a long-running session that streams Wi-Fi access points, Bluetooth devices, and Flock surveillance hits to your client as the device moves. This page documents the command surface, the expected reply stream, and the data record formats so you can build a wardrive recorder, analyzer, or live dashboard.


One command does everything

CMD:wardriveall:

A single wardriveall command starts a combined 2.4 GHz Wi-Fi + 5 GHz Wi-Fi + Classic/BLE devices + Flock detection session, interleaved on a single notification stream. The command works identically on Biscuit Pro, Biscuit Ultra, and Biscuit DIY. The device handles the radio split internally, and the wire protocol you observe is the same on every variant.

Sample exchange:

-> CMD:wardriveall:
<- RSP:wardriveall:OK
<- STATUS:2:Scan started: wardriveall
<- DATA:AP:MyWiFi,AA:BB:CC:DD:EE:FF,6,-58,[WPA2_PSK]
<- DATA:BT:MyHeadphones,11:22:33:44:55:66,-72,BLE
<- DATA:FLOCK:B4:1E:52:11:22:33,Penguin-1234567890,-65,1234567890,OUI
   ...

RSP:wardriveall:OK lands within 100 ms; the DATA: lines arrive continuously until you stop the session.


Stopping

CMD:stopscan:

Reply sequence:

<- RSP:stopscan:OK
<- STATUS:1:Ready

RSP:stopscan:OK is the acknowledgment that the stop command was accepted. STATUS:1:Ready arrives a few hundred milliseconds later, once the scan task has actually halted. Treat STATUS:1 as the signal that no more DATA: records will arrive. Queued records may still flush in between the two messages.


Live data formats

Every DATA: line is comma-separated:

Frame Fields
DATA:AP SSID,BSSID,Channel,RSSI,Security
DATA:NODEAP SSID,BSSID,Channel,RSSI,Security,NodeMAC
DATA:BT Name,MAC,RSSI,Type[,Payload][,SF=XX]
DATA:NODEBT Name,MAC,RSSI,Type,NodeMAC[,SF=XX]
DATA:FLOCK MAC,Name,RSSI,Serial,Method[,Radio]
DATA:STATS Beacons,Probes,Deauths,Data,EAPOL,MinRSSI,MaxRSSI

Parser notes:

  • AP SSIDs and their Flock companion names are sanitized: embedded NUL, commas, carriage returns, and line feeds become _, keeping each observation on one protocol line.
  • RSSI is signed dBm in the wire range -128 through 127. The field is always present. Reject missing or malformed numbers instead of substituting zero. AP channels must be in the supported set: 1–14, 36–64 in steps of four, 100–144 in steps of four, or 149–177 in steps of four.
  • Security is required: expect five AP fields, or six for a Node AP. Open networks use [OPEN]. Reject missing, empty, or incomplete bracketed security; preserve complete unfamiliar bracketed tokens. OWE is encrypted, password-free Wi-Fi and uses [OWE].
  • Canonical security tokens are [OPEN], [WEP], [WPA_PSK], [WPA_ENTERPRISE], [WPA2_PSK], [WPA_WPA2_PSK], [WPA2_ENTERPRISE], [WPA3_PSK], [WPA3_ENTERPRISE], [WPA2_WPA3_PSK], [WPA2_WPA3_ENTERPRISE], [OWE], [WAPI_PSK], and [UNDEFINED]. Legacy [UNKNOWN] is also accepted as a complete token; it does not replace a missing security field.
  • AirTag and other manufacturer-payload BLE devices append a fifth field with hex-encoded manufacturer data.
  • SF=XX is an optional BLE-family hint. It is appended only when nonzero. If a hint is present without a payload, the fifth field is empty: DATA:BT:Name,MAC,RSSI,BLE,,SF=XX. XX is a hexadecimal bitmask: 01 Apple Continuity, 02 Google Fast Pair, 04 Samsung EasySetup, 08 Microsoft Swift Pair, 10 HID plus local-name beacon, and 20 a known spam-only preset, model, or name. Preserve unknown bits. A family bit alone is not a spam verdict.
  • Node BLE sightings use the same hint after NodeMAC. Older Nodes omit it; current parsers should treat absence as zero.

Single-radio variants

If you need to scope a session to a single radio, the following commands return only that subset:

Command Stream
CMD:wardrive: 2.4 GHz Wi-Fi APs only
CMD:wardrive5g: 5 GHz Wi-Fi APs only
CMD:btwardrive: Classic and BLE devices, no Flock filtering
CMD:flockwardrive: Flock devices only
CMD:btflockwardrive: Bluetooth and Flock combined

Use wardriveall unless you have a specific reason to narrow the stream. Packed notifications mean there is no bandwidth penalty for collecting everything at once.


Flock classification

wardriveall includes Flock automatically. Hits arrive as DATA:FLOCK: records on the same stream as Wi-Fi and Bluetooth. Each hit’s Method field indicates the rule that produced the result:

The optional sixth field, Radio, is WIFI, BLE, or UNKNOWN. It identifies the capture radio without changing the detection method or confidence. An AP that matches a Flock rule still produces its normal AP record. Keep the notable companion for alerts; use the AP record for Wi-Fi export, and never turn the companion into a Bluetooth row. Export Flock observations as Bluetooth only when their radio is known to be BLE.

For older records, WPROBE, WADDR1, and WADDR2 identify Wi-Fi; MFR, NAME, and SNAME identify BLE. Bare OUI, SOUI, COUI, and unknown methods resolve to UNKNOWN. Retain these detections in saved results and alerts, but omit them from radio-specific exports. Explicit UNKNOWN, or a conflict between a radio-specific method and Radio, also stays unknown. Store sightings separately when the same MAC appears on both radios. Older clients that ignore the sixth field need an update to apply these export rules.

Method What it matched Evidence
MFR Manufacturer ID 0x09C8 in advertisement data Strongest; confirmed classification
NAME Pattern: Penguin-..., Flock-..., pigvision, or FS Ext Battery High
WPROBE 802.11 probe request with wildcard SSID from a Flock OUI High; combines prefix and characteristic behavior
SNAME 10-digit-serial-only BLE name with no other signal Suspected
OUI Flock IEEE-registered OUI B4:1E:52 Suspected; OUI-only
SOUI Suspected (unpublished) Flock OUI Suspected; OUI-only
WADDR2 Wi-Fi management-frame transmitter MAC matched a Flock OUI Suspected; OUI-only
WADDR1 Wi-Fi frame receiver MAC matched a Flock OUI Suspected; OUI-only

The method is an investigative clue, not proof of the physical device type. An OUI identifies the organization associated with a MAC-address prefix, so every OUI-only method belongs to the least-confident evidence family. Visually verify the hardware before reporting a location to a third-party website. Interpret the code by evidence family rather than as a probability or a complete account of every matching clue.

Example records:

DATA:FLOCK:B4:1E:52:AA:BB:CC,Penguin-9876543210,-58,9876543210,OUI
DATA:FLOCK:11:22:33:44:55:66,FS Ext Battery,-71,,NAME

Isolated IE-fingerprint stream

C5 v1.5.8+ offers a separate opt-in scan; it is not included in wardriveall and does not change DATA:FLOCK.

CMD:flocksig:require_oui=true,band=2.4,full_sweep=false
RSP:flocksig:OK
DATA:FLOCKSIG:B4:1E:52:AA:BB:CC,-88,6,WIE4,FY1

All three arguments are required. Invalid input returns RSP:flocksig:ERROR,<reason> without interrupting the active operation. Stop with CMD:stopscan:. WIE4 is an exact FY1 wildcard-probe profile plus a curated prefix. With require_oui=false, exact-profile hits from other prefixes arrive as experimental WIEC candidates. There is no RSSI floor.

Focused schedules are channels 1,6,11 for 2.4 GHz and 36,44,149,157 for 5 GHz. Full Sweep uses every channel in Biscuit’s passive table: 1-14 and/or 28 supported 5 GHz channels. At 250 ms dwell, full sweeps take approximately 3.5, 7, or 10.5 seconds. DATA:FLOCKSIG must remain separate from legacy Flock history, notifications, rewards, reports, exports, and Node routing. A local-address bit does not prove rotation, and address counts are not physical-camera counts.


Attribution

The combined dual-band wardrive design draws on justcallmekoko’s upstream work on the ESP32 Marauder project. The FY1 signature and curated-prefix research is derived from the MIT-licensed colonelpanichacks/flock-you source pinned at 7e969663eade07833603bad86cb156338e895583. Credit is due wherever these protocol surfaces are reused.