Open Source · Free to Use





BLESPloit: BLE Security Research Framework
Open-source toolkit for Bluetooth Low Energy research consisting of mobile application, Device Library and optional ESP32. Capture, understand, simulate, and script BLE devices without writing native firmware or mobile code.
What BLESPloit does

Discover and fingerprint nearby BLE devices, display vendor, decode proprietary advertisements.

Test known BLE vulnerabilities and misconfigurations on real or simulated hardware targets.

BLE GATT manual browser - annotated proprietary services/characteristics, hints on format and sample payloads.

Create a simple GUI or quick-actions to interact with devices.

Dynamically scripted scanning (Observer), simulation (Peripheral) and control (Central) roles.

Simulate any BLE device on ESP32 for testing and development.
Short demo
Other demos:
Documentation
Reference:
scan and fingerprint BLE devices, connect as a GATT client, run Central and Observer Lua scripts, remotely control ESP32.
JSON-based device entries describing GATT profiles, advertising data, UI, optionally extended with dynamic LUA scripts.
simulate, remotely interact with BLE devices. Possible to flash directly from phone, controlled via web api.
Howto instructions:
WhisperPair and Airoha
From the original device to simulated copy in < 60 seconds
Reverse-engineer Android application to understand the protocol
Trainings & workshops
Hands-on BLE security workshops at security conferences and private engagements.
Responsible use
g BLESPloit is designed for authorized security research and educational purposes. Always obtain permission before testing against devices you do not own.
