
"ESP32 Marauder project roundup: what the community actually builds"
ESP32 Marauder project roundup: what the community actually builds
ESP32 Marauder has quietly become the default WiFi/Bluetooth toolkit for people who'd rather flash an A$30 board than buy a A$400 gadget. The firmware started as JustCallMeKoko's ESP32Marauder project on GitHub — a suite of WiFi and Bluetooth scanning, sniffing and assessment tools inspired by Spacehuhn's ESP8266 deauther — and it now runs on a long list of boards, from bare devkits to the Flipper Zero WiFi devboard. This post rounds up the builds people are actually making with it, including with Bruce firmware, and where each one fits a lawful security-research workflow.
What Marauder does
Marauder covers passive scanning and sniffing — access point enumeration, client detection, probe request capture, BLE scanning — plus wardriving with GPS, all aimed at assessing networks you own or are authorised to test. The project wiki's Flipper Zero page documents pairing the firmware with a Flipper over GPIO using the companion app by 0xchocolate, which turns the Flipper's screen into the control interface for the ESP32's radio work. If you want a browser-based install instead of a build toolchain, the official Marauder web installer flashes supported boards over USB without touching PlatformIO.
Project roundup
1. The Flipper Zero wardriver. The most copied build in the community: a Flipper Zero, a Marauder-flashed WiFi devboard, and a small GPS module soldered to the devboard so every scanned access point gets coordinates and a WiGLE-ready CSV. The Hacked Existence wardriving tutorial walks through the whole assembly — devboard teardown, GPS wiring, enclosure rebuild — and the resulting setup logs wardrive CSVs straight to the devboard's SD card. Our Flipper Marauder WiFi Devboard is the same ESP32 + nRF24 + CC1101 combination this build is based on.
2. The standalone mini wardriver. Not everyone wants a Flipper in the loop. The Sil333033 flipperzero-wardriver project is an ESP32-plus-GPS scanner that streams scan data and NMEA GPS over UART to a Flipper, which joins the streams and writes the CSV — but the same architecture works with any serial terminal as the receiver. It's the build we'd point a first-timer at, because every part is individually debuggable.
3. Bruce firmware multi-tools. The second firmware people keep installing on the same hardware is Bruce, an open-source ESP32 firmware focused on red-team workflows: WiFi scanning and deauth detection, sub-GHz radio work via CC1101, NFC/RFID, bad-BLE, and wardriving. Bruce supports the Cheap Yellow Display boards, M5Stack Sticks and Cardputers, and LILYGO T-Decks — which is exactly the hardware stack in our StealthDeck Lite and StealthDeck Micro builds. The Marauder README itself cross-references Bruce and the other community firmware (Evil-M5Project, M5Stick-Nemo), so many builders keep two SD cards and switch firmware per job.
4. The PMKID sniffing rig. ChrisFiola's ESP32-Marauder-for-Flipper-Zero fork shows the deeper end of the pool: a Marauder build tuned for sniffing PMKID captures against your own lab access points, useful for learning how WPA handshakes actually work without touching anyone else's network.
Skill level and what to buy first
Every build above is beginner-soldering at worst — the wardriver needs four wires between GPS and devboard; everything else is plug-in and flash. Start with the Marauder devboard (A$44) if you own a Flipper, or a display board like the ESP32-S3 touch display board if you want a standalone unit. Add the GT-U7 GPS module (A$36.48) when you're ready to geotag scans. A real USB data cable matters more than any accessory — charge-only cables are the number one first-weekend failure.
Lawful use, as always
Scanning and sniffing your own networks, or ones you have written permission to assess, is standard security research. Deauthing, portal-cloning or jamming networks you don't own is not — in Australia that's unauthorised interference with communications, and we've covered the legal line in detail in WiFi testing law in Australia. Keep your captures scoped to your own SSIDs and the hobby stays legal and genuinely educational.