What actually runs on what
Every cell is checked against the firmware project's own device table or install docs — not community hope. ✓ means the upstream project officially documents support for that exact hardware; ✗ means it does not. Each cell cites the project page it was verified against.
| Device | Bruce | Marauder | ESPHome | GrapheneOS | CalyxOS | Kali NetHunter | postmarketOS | LineageOS |
|---|---|---|---|---|---|---|---|---|
| StealthDeck Lite ESP32-2432S028 CYD + CC1101 + nRF24L01+PA/LNA + PN532 |
✓ flashable
project docs ↗ CYD-2432S028 is a supported port (device table): CC1101, nRF24, PN532. |
✓ flashable
project docs ↗ CYD 2432S028 binary in the official release table; also in the Marauder Installer. |
✓ flashable
project docs ↗ ESP32 (WROOM) is an ESPHome-supported variant; custom YAML firmware. |
— | — | — | — | — |
| StealthPuter M5Stack Cardputer Adv (ESP32-S3, keyboard, battery, IR) |
✓ flashable
project docs ↗ M5Stack Cardputer (and ADV) is a first-class port with full peripheral support. |
✓ flashable
project docs ↗ Dedicated _m5cardputer_adv.bin in the official release table. |
✓ flashable
project docs ↗ ESP32-S3 is supported; usable as a smart-home display/keypad. |
— | — | — | — | — |
| StealthDeck Pro LILYGO T-Embed CC1101 (ESP32-S3, LCD, PN532, battery) + nRF24 shield |
✓ flashable
project docs ↗ Lilygo T-Embed CC1101 fully supported (CC1101 + PN532 rows). |
✗ unsupported
project docs ↗ No T-Embed binary in the official release table or installer device list — not supported. |
✓ flashable
project docs ↗ ESP32-S3 is supported by ESPHome. |
— | — | — | — | — |
| StealthDeck Micro (M5StickC Plus2) M5StickC Plus2 + CC1101 + nRF24L01+PA/LNA |
✓ flashable
project docs ↗ M5StickC PLUS2 supported in the Bruce device table (CC1101 + nRF24). |
✓ flashable
project docs ↗ M5StickC Plus 2 is in the official Marauder Installer device list. |
✓ flashable
project docs ↗ Original ESP32 is an ESPHome-supported variant. |
— | — | — | — | — |
| Pixel 9a · GrapheneOS Build Google Pixel 9a, 128 GB, refurbished |
— | — | — |
✓ flashable
project docs ↗ Pixel 9a (tegu): official production target, verified boot re-locked. |
✓ flashable
project docs ↗ Pixel 9a is also a current CalyxOS device. |
✗ unsupported
project docs ↗ No Pixel 9a kernel listed in the NetHunter device-kernel table. |
— |
✗ unsupported
project docs ↗ Not an officially supported LineageOS device at wiki.lineageos.org. |
| Pixel 8a · GrapheneOS Build Pixel 8a, 128 GB, refurbished |
— | — | — |
✓ flashable
project docs ↗ Pixel 8a (akita): official production target. |
✓ flashable
project docs ↗ Pixel 8a is a current CalyxOS device. |
✗ unsupported
project docs ↗ No Pixel 8a kernel listed in the NetHunter device-kernel table. |
— | — |
| Pixel 9 · GrapheneOS Build Pixel 9, 128 GB, refurbished |
— | — | — |
✓ flashable
project docs ↗ Pixel 9 (tokay): official production target, strongest security posture of the line. |
✓ flashable
project docs ↗ Pixel 9 is a current CalyxOS device. |
✗ unsupported
project docs ↗ No Pixel 9 kernel listed in the NetHunter device-kernel table. |
— | — |
| Pixel 9 Pro · GrapheneOS Build Pixel 9 Pro, 256 GB, refurbished |
— | — | — |
✓ flashable
project docs ↗ Pixel 9 Pro (caiman): official production target. |
✓ flashable
project docs ↗ Pixel 9 Pro is a current CalyxOS device. |
✗ unsupported
project docs ↗ No Pixel 9 Pro kernel listed in the NetHunter device-kernel table. |
— | — |
| Pixel 7a · CalyxOS Build Pixel 7a, 128 GB, refurbished |
— | — | — |
✓ flashable
project docs ↗ Pixel 7a (lynx): GrapheneOS officially supports this hardware. |
✓ flashable
project docs ↗ Pixel 7a: OS/security updates to May 2028 per CalyxOS device-support table. |
✗ unsupported
project docs ↗ No Pixel 7a kernel listed in the NetHunter device-kernel table. |
— | — |
| Fairphone 5 · CalyxOS Build Fairphone 5, 128/256 GB, refurbished |
— | — | — |
✗ unsupported
project docs ↗ GrapheneOS supports Google Pixel hardware only — non-Pixel devices are explicitly unsupported. |
✓ flashable
project docs ↗ Fairphone 5 (FP5): official CalyxOS support, security updates to September 2031. |
✗ unsupported
project docs ↗ No Fairphone 5 kernel listed in the NetHunter device-kernel table. |
✗ unsupported
project docs ↗ Fairphone 5 is not in the postmarketOS community device set we build. |
— |
| Pixel 6a · Kali NetHunter Build Pixel 6a, 128 GB, refurbished |
— | — | — |
✓ flashable
project docs ↗ Pixel 6a (bluejay): GrapheneOS officially supports this hardware (but not while rooted/unlocked). |
— |
✓ flashable
project docs ↗ Pixel 6a has an official community kernel + pre-created image (bluejay-los, LineageOS base). |
— |
✓ flashable
project docs ↗ Pixel 6a (bluejay) is an officially supported LineageOS device. |
| OnePlus 7T · Kali NetHunter Build OnePlus 7T, 256 GB, refurbished |
— | — | — |
✗ unsupported
project docs ↗ GrapheneOS supports Google Pixel hardware only. |
✗ unsupported
project docs ↗ OnePlus 7T is not in the current CalyxOS device-support table. |
✓ flashable
project docs ↗ OnePlus 7/7 Pro/7T/7T Pro: official pre-created images and install docs at kali.org. |
— | — |
| OnePlus 6 · postmarketOS Build OnePlus 6, 256 GB, refurbished |
— | — | — |
✗ unsupported
project docs ↗ GrapheneOS supports Google Pixel hardware only. |
— | — |
✓ flashable
project docs ↗ OnePlus 6 (enchilada): supported community device, mainline-adjacent kernel, full Alpine Linux. |
— |
| Pocophone F1 · postmarketOS Build Pocophone F1, 6/128 GB, refurbished |
— | — | — |
✗ unsupported
project docs ↗ GrapheneOS supports Google Pixel hardware only. |
— | — |
✓ flashable
project docs ↗ Pocophone F1 (beryllium): supported community device. |
— |
| Pixel 6a · LineageOS Build Pixel 6a, 128 GB, refurbished |
— | — | — |
✓ flashable
project docs ↗ GrapheneOS also supports this hardware; we flash it as an alternative build. |
— | — | — |
✓ flashable
project docs ↗ Pixel 6a (bluejay) is an officially supported LineageOS device. |
Honest limitations — read before you order
- GrapheneOS runs on Google Pixel hardware only. The project is explicit: non-Pixel devices are unsupported, and there is no microG path. Verified at grapheneos.org FAQ.
- CalyxOS on Fairphone 5 uses microG — a weaker security posture than GrapheneOS's sandboxed Play, but the only degoogled full-support option for non-Pixel hardware we stock. Verified at calyxos.org.
- Kali NetHunter requires an unlocked, rooted bootloader by design. Device support depends on a community kernel existing for your exact model — the NetHunter device-kernel table is the authority: nethunter.kali.org.
- postmarketOS is a Linux (Alpine) phone, not Android. No Android app ecosystem; telephony is functional rather than polished. Device support: postmarketOS wiki.
- LineageOS has no verified boot — the bootloader stays unlocked and patch cadence depends on the device maintainer. Official device list: wiki.lineageos.org.
- Marauder does not support the LilyGO T-Embed (StealthDeck Pro). There is no T-Embed binary in the project's release table, so we don't offer it — Bruce is the pentest firmware for that deck.
- Bruce / Marauder / ESPHome are interchangeable by reflash on every ESP32 deck we build — flash readout is never disabled, so you can verify or re-flash anything yourself. See firmware verification.
Lawful use only. Lawful use only: StealthOz devices are general-purpose security research tools for auditing networks and RF systems you own or are authorized to test. You are responsible for compliance with all applicable laws and radio regulations in your jurisdiction. Matrix verified against upstream project pages, October 2026.