Bruce

Pentest View the repo

Bruce is an ESP32‑based firmware that delivers a comprehensive suite of offensive security tools—including Wi‑Fi, Bluetooth, RF, RFID, IR, FM, and scripting capabilities—for fast, portable Red Team operations, and it runs on many ESP32 devices such as M5Stack, Lilygo, and the custom RF REAPER board.

auto-summary

6789 stars · 2266 forks

Maintainer
brucedevices
License
AGPL-3.0
Distribution
releasesweb-flasheresp-web-toolsm5burner
Capabilities
wifiblesub-ghzrfid-nfcirbadusb
Chip families
esp32esp32-s3esp32-c5

Runs on these boards

Known good

  • ESP32-C5-DevKitC-1Known goodEspressifrelease .bin
    Flash ESP32-C5-DevKitC-1in-browserknown-good

    Known good esp-atlas asserts this board↔firmware link at the shown trust tier — it does not guarantee your specific unit or the current firmware version. Flashing can erase keys/config and can brick the device. At your own risk.

  • T-DeckKnown goodLILYGOweb flasher
    Flash T-Deckweb flasherknown-good

    Known good esp-atlas asserts this board↔firmware link at the shown trust tier — it does not guarantee your specific unit or the current firmware version. Flashing can erase keys/config and can brick the device. At your own risk.

  • T-Display-S3Known goodLILYGOweb flasher
    Flash T-Display-S3web flasherknown-good

    Known good esp-atlas asserts this board↔firmware link at the shown trust tier — it does not guarantee your specific unit or the current firmware version. Flashing can erase keys/config and can brick the device. At your own risk.

  • T-EmbedKnown goodLILYGOweb flasher
    Flash T-Embedweb flasherknown-good

    Known good esp-atlas asserts this board↔firmware link at the shown trust tier — it does not guarantee your specific unit or the current firmware version. Flashing can erase keys/config and can brick the device. At your own risk.

  • T-Watch S3Known goodLILYGOweb flasher
    Flash T-Watch S3web flasherknown-good

    Known good esp-atlas asserts this board↔firmware link at the shown trust tier — it does not guarantee your specific unit or the current firmware version. Flashing can erase keys/config and can brick the device. At your own risk.

  • CardputerKnown goodM5Stackweb flasher
    Flash Cardputerweb flasherknown-good

    Known good esp-atlas asserts this board↔firmware link at the shown trust tier — it does not guarantee your specific unit or the current firmware version. Flashing can erase keys/config and can brick the device. At your own risk.

  • Core2Known goodM5Stackweb flasher
    Flash Core2web flasherknown-good

    Known good esp-atlas asserts this board↔firmware link at the shown trust tier — it does not guarantee your specific unit or the current firmware version. Flashing can erase keys/config and can brick the device. At your own risk.

  • CoreS3Known goodM5Stackweb flasher
    Flash CoreS3web flasherknown-good

    Known good esp-atlas asserts this board↔firmware link at the shown trust tier — it does not guarantee your specific unit or the current firmware version. Flashing can erase keys/config and can brick the device. At your own risk.

  • StickC-Plus2Known goodM5Stackweb flasher
    Flash StickC-Plus2web flasherknown-good

    Known good esp-atlas asserts this board↔firmware link at the shown trust tier — it does not guarantee your specific unit or the current firmware version. Flashing can erase keys/config and can brick the device. At your own risk.

  • M5StickS3Known goodM5Stackweb flasher
    Flash M5StickS3web flasherknown-good

    Known good esp-atlas asserts this board↔firmware link at the shown trust tier — it does not guarantee your specific unit or the current firmware version. Flashing can erase keys/config and can brick the device. At your own risk.

Unverified

  • CoreUnverifiedM5Stack
    Flash Coreguided

    Unverified esp-atlas asserts this board↔firmware link at the shown trust tier — it does not guarantee your specific unit or the current firmware version. Flashing can erase keys/config and can brick the device. At your own risk.

README

:shark: Bruce

Bruce is a versatile ESP32 firmware packed with offensive-security tools, built to make Red Team operations fast and portable.

It also supports M5Stack, LILYGO , RockBase IoT and Elecrow products, and works great with the Cardputer, Sticks, M5Cores, T-Decks and T-Embeds.

:zap: Get Our Official DevKit!

RF REAPER

RF REAPER is our custom PCB devkit, purpose-built for Bruce!

Every major feature works natively, right out of the box. Sub-GHz, NFC/RFID, IR, 2.4GHz(NRF), GPS-ready, and a microSD, all driven by a beefy ESP32-S3 (16MB Flash / 8MB PSRAM). Tons of GPIOs via the AW9523 expander plus Flipper Zero & iButton header compatibility mean you can hack, mod, and build on it endlessly. Want a specific function? Ask us with an issue, we'll check it.

👉 Buy the RF REAPER and official boards

Check our fully open-source hardware too: https://bruce.computer/boards

More custom devkit boards coming soon! Stay across our communities!

:building_construction: How to install

The easiest way to install Bruce is using our official Web Flasher!

Check out: https://bruce.computer/flasher

Alternatively, you can download the latest binary from releases or actions and flash locally using esptool.py

esptool.py --port /dev/ttyACM0 write_flash 0x00000 Bruce-<device>.bin

For m5stack devices

If you already use M5Launcher to manage your m5stack device, you can install it with OTA

Or you can burn it directly from the m5burner tool, just search for 'Bruce' (My official builds will be uploaded by "owner" and have photos.) on the device category you want to and click on burn

:keyboard: Discord Server

Contact us in our Discord Server!

:bookmark_tabs: Wiki

For more information on each function supported by Bruce, read our wiki here. Also, read our FAQ

:computer: List of Features

WiFi

BLE

  • [x] BLE Scan
  • [x] Bad BLE - Run Ducky scripts, similar to BadUsb
  • [x] BLE Keyboard - Cardputer and T-Deck Only
  • [x] iOS Spam
  • [x] Windows Spam
  • [x] Samsung Spam
  • [x] Android Spam
  • [x] Spam All

RF

  • [x] Scan/Copy
  • [x] Custom SubGhz
  • [x] Spectrum
  • [x] Jammer Full (sends a full squared wave into output)
  • [x] Jammer Intermittent (sends PWM signal into output)
  • [x] Config
    • [x] RF TX Pin
    • [x] RF RX Pin
    • [x] RF Module
    • [x] RF Frequency
  • [x] Replay

RFID

  • [x] Read tag
  • [x] Read 125kHz
  • [x] Clone tag
  • [x] Write NDEF records
  • [x] Amiibolink
  • [x] Chameleon
  • [x] Write data
  • [x] Erase data
  • [x] Save file
  • [x] Load file
  • [x] Config
  • [ ] Emulate tag

IR

FM

NRF24

Scripts

Others

Clock

  • [x] RTC Support
  • [x] NTP time adjust
  • [x] Manual adjust

Connect (ESPNOW)

  • [x] Send File
  • [x] Receive File
  • [x] Send Commands
  • [x] Receive Commands

Config

  • [x] Brightness
  • [x] Dim Time
  • [x] Orientation
  • [x] UI Color
  • [x] Boot Sound on/off
  • [x] Clock
  • [x] Sleep
  • [x] Restart

Specific functions per Device, the ones not mentioned here are available to all.

| Device | CC1101 | NRF24 | FM Radio | PN532 | Mic | BadUSB | RGB Led | Speaker | Fuel Gauge | LITE_VERSION | | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :----: | :---: | :------: | :------------------: | :--: | :----: | :-----: | :-----: | :--------: | :----------: | | M5Stack Cardputer (and ADV) | :ok: | :ok: | :ok: | :ok: | :ok: | :ok: | :ok: | NS4168 | :x: | :x: | | M5Stack M5StickC PLUS2 | :ok: | :ok: | :ok: | :ok: | :ok: | :ok:¹ | :x: | Tone | :x: | :x: | | M5Stack M5StickC PLUS | :ok: | :ok: | :ok: | :ok: | :ok: | :ok:¹ | :x: | Tone | :x: | :x:² | | M5Stack M5Core BASIC | :ok: | :ok: | :ok: | :ok: | :ok: | :ok:¹ | :x: | Tone | :x: | :x: | | M5Stack M5Core2 | :ok: | :ok: | :ok: | :ok: | :ok: | :ok:¹ | :x: | :x: | :x: | :x: | | M5Stack M5CoreS3/SE | :ok: | :ok: | :ok: | :ok: | :x: | :ok: | :x: | :x: | :x: | :x: | | JCZN CYD‑2432S028 | :ok: | :ok: | :ok: | :ok: | :x: | :ok:¹ | :x: | :x: | :x: | :x:² | | Lilygo T‑Embed CC1101 | :ok: | :ok: | :ok: | :ok: | :ok: | :ok: | :ok: | :ok: | :ok: | :x: | | Lilygo T‑Embed | :ok: | :ok: | :ok: | :ok: | :ok: | :ok: | :ok: | :ok: | :x: | :x: | | Lilygo T-Display-S3 | :ok: | :ok: | :x: | :x: | :x: | :ok: | :x: | :x: | :x: | :x: | | Lilygo T‑Deck (and pro) | :ok: | :x: | :x: | :x: | :x: | :ok: | :x: | :x: | :x: | :x: | | Lilygo T-Watch-S3 | :x: | :x: | :x: | :x: | :x: | :ok: | :x: | :x: | :x: | :x: | | Lilygo T-LoRa Pager | :x: | :x: | :x: | :x: | :x: | :ok: | :x: | :x: | :x: | :x: | | Smoochiee V2 | :ok: | :ok: | :x: | :ok: | :x: | :ok: | :x: | :x: | :x: | :x: | | ESP32-C5 | :ok: | :ok: | :x: | :ok: | :x: | :x: | :x: | :x: | :x: | :x: | | Bruce RF Reaper | :ok: | :ok: | :x: | :ok: but w/ ST25R3916 | :x: | :ok: | :ok: | :x: | :ok: | :x: | | Elecrow 24B | :ok: | :ok: | :ok: | :ok: | :x: | :ok:¹ | :x: | :x: | :x: | :x:² | | Elecrow 3.5" | :ok: | :ok: | :ok: | :ok: | :x: | :ok:¹ | :x: | :x: | :x: | :x:² | | NM-CYD-C5 + RF HAT | :ok: | :ok: | :x: | :ok: | :x: | :ok: | :ok: | :x: | :ok: | :x: | ² CYD have a LITE_VERSION version for Launcher Compatibility ¹ Core, CYD and StickCs Bad-USB: here

LITE_VERSION: TelNet, SSH, WireGuard, ScanHosts, RawSniffer, Brucegotchi, BLEBacon, BLEScan and Interpreter are NOT available for M5Launcher Compatibility

:sparkles: Why and how does it look?

Bruce stems from a keen observation within the community focused on devices like Flipper Zero. While these devices offered a glimpse into the world of offensive security, there was a palpable sense that something more could be achieved without being that overpriced, particularly with the robust and modular hardware ecosystem provided by ESP32 Devices, Lilygo and M5Stack products.

Other media can be found here.

:clap: Acknowledgements

  • @bmorcelli for new core and a bunch of new features, also porting to many devices!
  • @IncursioHack for adding RF and RFID modules features.
  • @Luidiblu for logo and UI design assistance.
  • @eadmaster for adding a lot of features.
  • @rennancockles for a lot of RFID code, refactoring and others features.
  • @7h30th3r0n3 refactoring and a lot of help with WiFi attacks.
  • @Tawank refactoring interpreter among many other things
  • @pablonymous RF functions to read RAW Data
  • Smoochiee for Bruce PCB design.
  • TH3_KR4K3N for Stick cplus extender PCB design.
  • Everyone who contributed in some way to the project, thanks :heart:

Bruce also stands on the shoulders of other great open-source firmware projects, which inspired features and code across the project:

Bruce builds on many free-software libraries, and parts of the RF and NFC/RFID modules are derived from other projects. See THIRD_PARTY.md for third-party attribution and copyleft-compliance details.

:construction: Disclaimer

Bruce is a tool for cyber offensive and red team operations, distributed under the terms of the Affero General Public License (AGPL). It is intended for legal and authorized security testing purposes only. Use of this software for any malicious or unauthorized activities is strictly prohibited. By downloading, installing, or using Bruce, you agree to comply with all applicable laws and regulations. This software is provided free of charge, and we do not accept payments for copies or modifications. The developers of Bruce assume no liability for any misuse of the software. Use at your own risk.

Read the full README on GitHub

source github.com/BruceDevices/firmware