Home > Features > Bluetooth Scanning & Detection

Bluetooth Scanning & Detection

Biscuit includes a suite of specialized Bluetooth scanners, each tuned to detect specific types of devices. All scanning modes are found under the Bluetooth tab in the Scanning section.

To start any scan: open the app, navigate to Bluetooth > Scanning, and select the mode you want.


Bluetooth Scan

General-purpose BLE device discovery. This mode scans for all nearby Bluetooth Low Energy devices and displays everything it finds.

How to start: Bluetooth > Scanning > Bluetooth Scan

What you see: A scrollable list of detected devices. Each entry shows:

  • Device name (if the device is broadcasting one, otherwise shown as “Unknown”)
  • MAC address
  • Signal strength (RSSI) in dBm
  • Device type based on advertised services (e.g., audio, wearable, computer, phone)
  • Vendor – The manufacturer identified from the MAC address OUI database

Filtering and sorting: You can sort results by signal strength, name, or device type. A search bar lets you filter by name or MAC address.

This is the broadest scan mode and a good starting point when you want to see what BLE devices are active in your area. Results update in real time as devices appear, disappear, or change signal strength.

Tips:

  • Tap a device card to open its action menu for Advertisement Details, Foxhunt, and address tools. When the app is connected to supported Pro/Ultra firmware, the same menu includes active GATT inspection and emulation. Bluetooth results do not enter a selection mode.
  • The vendor name (shown below the MAC address) can help you identify what a device is even when it does not broadcast a name.
  • BLE devices rotate their MAC addresses periodically for privacy. You may see the same physical device appear with different addresses over time.

Find My Sniff

A specialized scanner for the whole Find My family: Apple AirTags, third-party Find My (FMNA) accessories, and DULT-compliant trackers.

How to start: Bluetooth > Scanning > Find My Sniff

What you see: A list of detected trackers, each showing:

  • Type — AirTag, FMNA, or DULT
  • MAC address
  • Signal strength (RSSI)

Tips:

  • You can save any detected AirTag with a custom name for ongoing tracking and later use with the AirTag Spoof attack.
  • This is particularly useful for detecting unwanted tracking devices. If you suspect someone has placed a tracker on your belongings, vehicle, or bag, this scanner will reveal it.
  • Trackers rotate their MAC address roughly every 15 minutes, so a device may reappear under a new address; watch the signal strength to home in on it.
  • Because it detects the broad Find My network, some nearby Apple phones and accessories may appear alongside actual trackers.

Flipper Zero Detection

Detects nearby Flipper Zero multi-tool devices. The Flipper Zero broadcasts characteristic BLE advertisements that this scanner identifies and flags.

How to start: Bluetooth > Scanning > Flipper Zero

What you see: A list of detected Flipper devices, each showing:

  • Device name
  • MAC address
  • Signal strength (RSSI)

Tips:

  • The Flipper Zero uses a distinctive BLE advertisement pattern that makes it identifiable even when its Bluetooth name has been changed.
  • This is useful for security awareness in environments where Flipper devices may be used for unauthorized testing.

Flock Camera Detection

Looks for wireless signatures associated with Flock Safety automated license plate reader (ALPR) equipment. These cameras are commonly mounted on poles, signs, or vehicles and are used to capture and log license plates.

How to start: Bluetooth > Scanning > Flock Camera

What you see: A list of detected cameras, each showing:

  • Device name (or the camera’s serial number if no name is advertised)
  • MAC address
  • Signal strength (RSSI)
  • Serial number
  • Detection method – a short tag showing which wireless clue produced the result

On iOS, Detection defaults to Legacy. Choose IE Fingerprint to run the isolated Wi-Fi probe-profile scan on supported firmware. Its additional controls let you require a known Flock-associated prefix, choose 2.4 GHz, 5 GHz, or both, and enable Full Sweep. Pro/Ultra require WROOM 1.5.7 and C5 1.5.8; direct single-C5 models require firmware 1.5.8. Android and external Biscuit Nodes remain on Legacy detection.

With Full Sweep off, Biscuit revisits a focused set of 3 channels (2.4 GHz), 4 channels (5 GHz), or 7 channels (both). Full Sweep covers 14, 28, or 42 channels and takes approximately 3.5, 7, or 10.5 seconds per pass. Broader sweeps revisit each channel less often. Full Sweep remains passive; it only selects channels already supported by Biscuit and does not transmit. This mode has no signal-strength floor, so it can examine distant candidate traffic as well as nearby traffic.

IE Fingerprint results are shown separately:

  • Tier 4 (WIE4) means an exact FY1 wildcard-probe profile plus a curated Flock-associated prefix.
  • IE-only candidate (WIEC) means the same exact profile without a curated prefix and appears only when Require known Flock prefix is off.

The IE profile can identify a Wi-Fi stack or device class; it is not a uniquely Flock-controlled identifier. A locally administered address does not by itself prove that the address is rotating. Counts are unique observed addresses, not estimates of physical cameras. These experimental rows are not saved to history or reports, do not trigger notifications or rewards, and cannot launch BLE Foxhunt or WiGLE lookup.

Understanding Flock Detection Methods

The methods belong to different evidence families:

Evidence family Method tags What it means
Manufacturer data MFR The strongest, confirmed classification: the BLE advertisement carried the recognized manufacturer data used by Flock equipment.
Characteristic name or behavior NAME, WPROBE High evidence. NAME matches a characteristic advertised Flock product name. WPROBE combines a known prefix with characteristic WiFi probe behavior; it is more than an OUI-only match.
Serial-like name SNAME Suspected. A 10-digit advertised name is common on Flock hardware but is not unique to it.
OUI-only OUI, SOUI, COUI, WADDR2, WADDR1 Suspected and the least-confident family. The result came from a built-in, unpublished, user-supplied, transmitter, or receiver MAC prefix without stronger identifying content.

An OUI identifies the organization associated with a MAC-address prefix; it does not prove that the physical object at the mapped location is a Flock camera. Custom prefixes are especially dependent on the accuracy of the user’s entry. Treat every OUI-only result as a lead to inspect, not a confirmed camera.

The first time you open the wardrive Notable list or tap a Flock marker on the map, Biscuit explains these method families and reminds you how to verify a result. You can revisit the same explanation from Help.

Tips:

  • Flock cameras are often found in residential neighborhoods, commercial areas, and along major roads.
  • Detection range is typically shorter than for other BLE devices, as Flock cameras use low-power BLE advertisements.
  • Before reporting a location to any third-party website, visit the mapped location safely and visually verify the physical camera. Do not report an OUI-only result as a confirmed Flock camera unless you have laid eyes on the hardware.
  • Treat an IE-only candidate as experimental evidence and use a negative-control survey before drawing conclusions about false positives in your environment.

Skimmer Detection

Scans for Bluetooth-enabled credit card skimmers. Criminals attach skimming devices to ATMs, gas pumps, and point-of-sale terminals to steal card data. Many of these skimmers use HC-05 or HC-06 Bluetooth modules to wirelessly transmit stolen information.

How to start: Bluetooth > Scanning > Skimmer Detection

What you see: A list of suspected skimmer devices, each showing:

  • Device name (typically generic module names like “HC-05” or “HC-06”)
  • MAC address
  • Signal strength (RSSI)

Tips:

  • If you detect a suspected skimmer, do not attempt to remove it yourself. Report it to the establishment’s management and contact local authorities.
  • Common locations for skimmers include gas station pumps, standalone ATMs, and self-checkout kiosks.
  • Not all HC-05/HC-06 modules are skimmers – they are also used in legitimate hobbyist and IoT projects. The context of where you find them matters.

Axon Body Camera Detection

Detects Axon (formerly TASER) body-worn cameras used by law enforcement. These cameras broadcast identifiable BLE signatures that this scanner picks up.

How to start: Bluetooth > Scanning > Axon Camera

What you see: A list of detected cameras, each showing:

  • Device name
  • MAC address
  • Signal strength (RSSI)

Tips:

  • Axon body cameras are primarily used by law enforcement and security personnel.
  • Detection can help you identify the presence of body-worn recording devices in your vicinity.

Requires firmware v1.0.94 or later.


Meshtastic Detection

Detects Meshtastic long-range mesh radio devices. Meshtastic is a popular open-source project that uses LoRa radios to create off-grid mesh communication networks. This scanner identifies Meshtastic nodes broadcasting via BLE.

How to start: Bluetooth > Scanning > Meshtastic

What you see: A list of detected Meshtastic nodes, each showing:

  • Device name
  • MAC address
  • Signal strength (RSSI)

Tips:

  • Meshtastic nodes use BLE for local configuration and communication with a companion app, and LoRa for long-range mesh networking.
  • Detection of Meshtastic nodes can reveal the presence of an off-grid communication network in the area.

Requires firmware v1.0.94 or later.


Drone Detection (Remote ID)

Detects drones broadcasting FAA Remote ID signals. Since 2024, most drones sold in the United States are required to broadcast identification and location data. Biscuit captures these broadcasts over both WiFi and BLE.

How to start: Bluetooth > Scanning > Drone Detection

What you see: A list of detected drones with detailed information for each:

  • Drone identification – Unique ID or serial number of the drone
  • Type – The aircraft category: multirotor, airplane, helicopter, VTOL (vertical takeoff and landing), or glider
  • Status – Whether the drone is on the ground or airborne
  • GPS position – Latitude and longitude of the drone’s current location
  • Altitude – Height above ground level
  • Speed – Current flight speed
  • Heading – Direction of travel
  • Operator location – GPS coordinates of the drone operator (when broadcast by the drone)
  • Signal strength (RSSI)

Tips:

  • This is useful for identifying drones operating in your vicinity and understanding their flight patterns.
  • The operator location field reveals where the person controlling the drone is standing, which is valuable for security assessments.
  • Not all drones broadcast Remote ID. Older drones, custom-built drones, and some hobby drones may not transmit these signals.
  • Remote ID is broadcast over both WiFi beacon frames and BLE advertisements. Biscuit monitors both channels.

Requires firmware v1.2.0 or later.


Meta Glasses Detection

Detects Meta / Ray-Ban smart glasses. These devices broadcast recognizable Bluetooth signatures while powered on, and this scanner flags them so you can tell when camera-equipped smart glasses are nearby. Meta Quest headsets are excluded and remain ordinary Bluetooth devices rather than Meta detections or Notable map markers.

How to start: Bluetooth > Scanning > Meta Glasses

What you see: A list of detected smart-glasses candidates, each showing:

  • Device name (if broadcast, otherwise the MAC address)
  • MAC address
  • Signal strength (RSSI)

Tips:

  • Useful for spotting recording-capable smart glasses in spaces where they may not be obvious.
  • Meta devices, like other phones and wearables, rotate their Bluetooth address periodically, so the same pair of glasses may appear with different addresses over time.
  • Meta detections also appear automatically during a Wardrive with an All-mode session, mapped to GPS and counted under the Notable stat alongside Flock cameras and Axon devices.

nyanBOX Detection

Detects nyanBOX badges – a third-party ESP32 pentesting and wardriving device. A nyanBOX broadcasts its own identity beacon, and this scanner picks it up and reads what that beacon carries.

How to start: Bluetooth > Scanning > nyanBOX Detection

What you see: A list of detected nyanBOX units, each showing:

  • Device name, usually in the form nyanBOX-XXXX, though an owner can set their own
  • MAC address
  • Signal strength (RSSI)
  • Level and rank – nyanBOX has a built-in levelling system, and the unit broadcasts its current level. Ranks run from N00b through Skid, Wannabe, L33t, Hacker, Uber Hacker, Elite and Godlike up to Legend.
  • Firmware version
  • Dangerous – a red tag shown when the unit has unlocked its disruptive tools
  • Silent – shown when a unit you were tracking has stopped broadcasting

Understanding “Silent”:

A nyanBOX only broadcasts its beacon while it is sitting on its main menu. The moment its operator opens any tool, the beacon stops. So when a unit you were watching goes Silent, it means someone has left the main menu and gone into the toolset – it does not mean the device was switched off, and it does not tell you which tool was opened.

Understanding “Dangerous”:

A Nyan keeps its most disruptive tool – a signal jammer – hidden until its owner turns on a setting that unlocks it. That setting is carried in the beacon, so a unit with it switched on is tagged Dangerous in red.

Two things to keep in mind:

  • The tag means the tool is unlocked and available, not that it is running.
  • The setting resets every time the Nyan restarts, so the tag describes it right now rather than anything lasting about the unit or its owner.

No tag means unknown, not safe – if a unit is not tagged, the scan simply could not read the setting.

Tips:

  • Level, rank, version and the Dangerous tag are only readable when the badge is broadcasting its full beacon. Units picked up faintly or at the edge of range may appear with just an address until more of the beacon is received.
  • Unlike phones and smart glasses, a nyanBOX uses a fixed Bluetooth address, so the same unit shows up with the same address every time you see it.

Biscuit Detection

Finds other Biscuit devices nearby.

How to start: Bluetooth > Scanning > Biscuit Detection

What you see: A list of detected devices, each showing name, address, signal strength, and which board it is – Crumb, Pro, Ultra, T-Dongle and so on.

Biscuits announce their model, so the scan can name the exact board without connecting to it. Renaming a Biscuit doesn’t affect this.

  • Confirmed – the device announced its model. The badge names the board.
  • Suspected – it looks like a Biscuit and has a name, but didn’t announce a model.
  • Unconfirmed – it looks like a Biscuit but announced neither a model nor a name.

Biscuits running firmware older than v1.4.34 don’t announce a model and will show as Suspected or Unconfirmed. Updating them fixes it.


Custom OUI

Biscuit recognises Flock cameras, Meta glasses, and Axon devices using built-in detection rules, including known manufacturer MAC prefixes (OUIs). Custom OUI lets you add prefixes of your own, so you can flag any manufacturer’s hardware the same way built-in detections work.

Where to find it: Settings → Custom OUI (both iOS and Android)

Adding an entry:

  1. Type the first three pairs of a MAC address in the OUI field – for example, AA:BB:CC. The app shows you which manufacturer that prefix belongs to as you type.
  2. Choose a Category: Flock, Meta, Axon, or Ignore (see below).
  3. Tap Add.

Once added, any device whose MAC address starts with that prefix is flagged in scan results and during wardriving – with the same alerts, map markers, and report entries as a built-in detection, labelled Custom OUI to indicate the match came from your list. This remains a suspected OUI-only match; a user-supplied prefix does not confirm the type of physical device.

Ignoring a prefix: Choose Ignore to stop a prefix being flagged. Devices whose MAC starts with an ignored prefix are no longer reported as Flock, Meta, or Axon – in live scans, dedicated scans, or wardriving – even if a built-in rule would normally flag them. They still show up as ordinary Bluetooth or WiFi devices; only the surveillance flag is removed. Use this to clear out a known false positive.

Removing an entry: tap the ✕ next to any entry in the list to delete it.

WiFi note: Flock and Meta custom prefixes also match WiFi access points whose BSSID starts with that prefix. Axon matches Bluetooth devices only.

Many consumer Bluetooth gadgets use randomized MAC addresses, which change regularly – a manufacturer prefix won’t catch those devices.


General Tips

  • Signal strength is color-coded across all scan modes: green for strong, yellow for fair, red for weak.
  • Per-device actions: Tap a Bluetooth device card to open its action menu and start Foxhunt or inspect its advertisement. Active GATT tools appear only while connected to supported Pro/Ultra firmware.
  • Wardriving integration: To map Bluetooth devices to GPS locations, use the Wardriving feature with a Bluetooth-enabled mode (BT Only or All).
  • Scan persistence: Scan results are cleared when you start a new scan of the same type. Switch between scan types without losing results from other modes.