Tawank/BruceOS

Predatory ESP32 Firmware

β˜… 0Forks 0CGitHub β†—Compare

Project website β†—

README

Bruce Main Menu

🦈 Bruce

Bruce is a versatile ESP32 firmware packed with offensive-security tools, built to make Red Team operations fast and portable.

It also supports M5Stack, LILYGO , RockBase IoT and Elecrow products, and works great with the Cardputer, Sticks, M5Cores, T-Decks and T-Embeds.

⚑ Get Our Official DevKit!

RF REAPER

RF REAPER is our custom PCB devkit, purpose-built for Bruce!

Every major feature works natively, right out of the box. Sub-GHz, NFC/RFID, IR, 2.4GHz(NRF), GPS-ready, and a microSD, all driven by a beefy ESP32-S3 (16MB Flash / 8MB PSRAM). Tons of GPIOs via the AW9523 expander plus Flipper Zero & iButton header compatibility mean you can hack, mod, and build on it endlessly. Want a specific function? Ask us with an issue, we'll check it.

πŸ‘‰ Buy the RF REAPER and official boards

Check our fully open-source hardware too: https://bruce.computer/boards

More custom devkit boards coming soon! Stay across our communities!

πŸ—οΈ How to install

source ~/.espressif/v6.0.2/esp-idf/export.sh
idf.py -p PORT flash

πŸ› οΈ How to build

Install ESP-IDF and follow the instructions to build Bruce.

then build by sourcing the ESP-IDF environment and running:

source ~/.espressif/v6.0.2/esp-idf/export.sh
idf.py build

This builds the default board (M5 Cardputer). To build for a specific board, use tools/board.py instead, which picks the right chip target and board-specific sdkconfig.defaults (see boards/<board>/) and puts the build output in its own build-board/<board>/ directory:

source ~/.espressif/v6.0.2/esp-idf/export.sh
python tools/board.py --list                 # show available board ids
python tools/board.py m5stack-cplus2 build
python tools/board.py m5stack-cplus2 flash monitor -p PORT

πŸ§ͺ How to run tests

Perequisites:

source ~/.espressif/v6.0.2/esp-idf/export.sh
python -m pip install pytest pytest-embedded pytest-embedded-idf pytest-embedded-qemu
python $IDF_PATH/tools/idf_tools.py install qemu-xtensa qemu-riscv32

Then run the tests with:

source ~/.espressif/v6.0.2/esp-idf/export.sh
idf.py -B build-qemu build
python -m pytest tests/pytest_firmware.py

The QEMU image boots to the same interactive shell a real serial console would, then launches selftest on it (this is the one bit of test-running behavior baked into a QEMU test-mode boot -- QEMU's emulated serial link only carries firmware output back to the host in this setup, not typed input to the firmware, so the test can't just type the command itself once the shell's up). Pass --selftest-filter (repeatable) to run only cases whose name contains the given text, instead of the full suite -- this reconfigures and rebuilds build-qemu/ with the matching boot command before the image boots, so expect a rebuild the first time you use it (or switch back):

python -m pytest tests/pytest_firmware.py --selftest-filter=notification

docs/COMMANDS.md is generated the same way, from the firmware's own man --gen-md:

python tools/gen_commands_doc.py

⌨️ Discord Server

Contact us in our Discord Server!

πŸ“‘ Wiki

For more information on each function supported by Bruce, read our wiki here. Also, read our FAQ

πŸ’» List of Features BrucePIO supports

WiFi

BLE

  • BLE Scan
  • Bad BLE - Run Ducky scripts, similar to BadUsb
  • BLE Keyboard - Cardputer and T-Deck Only
  • iOS Spam
  • Windows Spam
  • Samsung Spam
  • Android Spam
  • Spam All

RF

  • Scan/Copy
  • Custom SubGhz
  • Spectrum
  • Jammer Full (sends a full squared wave into output)
  • Jammer Intermittent (sends PWM signal into output)
  • Config
  • Replay

RFID

  • Read tag
  • Read 125kHz
  • Clone tag
  • Write NDEF records
  • Amiibolink
  • Chameleon
  • Write data
  • Erase data
  • Save file
  • Load file
  • Config
  • Emulate tag

IR

FM

NRF24

Scripts

Others

Clock

  • RTC Support
  • NTP time adjust
  • Manual adjust

Connect (ESPNOW)

  • Send File
  • Receive File
  • Send Commands
  • Receive Commands

Config

  • Brightness
  • Dim Time
  • Orientation
  • UI Color
  • Boot Sound on/off
  • Clock
  • Sleep
  • Restart

Specific functions per Device, the ones not mentioned here are available to all.

Device CC1101 NRF24 FM Radio PN532 Mic BadUSB RGB Led Speaker Fuel Gauge LITE_VERSION
M5Stack Cardputer (and ADV) πŸ†— πŸ†— πŸ†— πŸ†— πŸ†— πŸ†— πŸ†— NS4168 ❌ ❌
M5Stack M5StickC PLUS2 πŸ†— πŸ†— πŸ†— πŸ†— πŸ†— πŸ†—ΒΉ ❌ Tone ❌ ❌
M5Stack M5StickC PLUS πŸ†— πŸ†— πŸ†— πŸ†— πŸ†— πŸ†—ΒΉ ❌ Tone ❌ ❌²
M5Stack M5Core BASIC πŸ†— πŸ†— πŸ†— πŸ†— πŸ†— πŸ†—ΒΉ ❌ Tone ❌ ❌
M5Stack M5Core2 πŸ†— πŸ†— πŸ†— πŸ†— πŸ†— πŸ†—ΒΉ ❌ ❌ ❌ ❌
M5Stack M5CoreS3/SE πŸ†— πŸ†— πŸ†— πŸ†— ❌ πŸ†— ❌ ❌ ❌ ❌
JCZN CYD‑2432S028 πŸ†— πŸ†— πŸ†— πŸ†— ❌ πŸ†—ΒΉ ❌ ❌ ❌ ❌²
Lilygo T‑Embed CC1101 πŸ†— πŸ†— πŸ†— πŸ†— πŸ†— πŸ†— πŸ†— πŸ†— πŸ†— ❌
Lilygo T‑Embed πŸ†— πŸ†— πŸ†— πŸ†— πŸ†— πŸ†— πŸ†— πŸ†— ❌ ❌
Lilygo T-Display-S3 πŸ†— πŸ†— ❌ ❌ ❌ πŸ†— ❌ ❌ ❌ ❌
Lilygo T‑Deck (and pro) πŸ†— ❌ ❌ ❌ ❌ πŸ†— ❌ ❌ ❌ ❌
Lilygo T-Watch-S3 ❌ ❌ ❌ ❌ ❌ πŸ†— ❌ ❌ ❌ ❌
Lilygo T-LoRa Pager ❌ ❌ ❌ ❌ ❌ πŸ†— ❌ ❌ ❌ ❌
Smoochiee V2 πŸ†— πŸ†— ❌ πŸ†— ❌ πŸ†— ❌ ❌ ❌ ❌
ESP32-C5 πŸ†— πŸ†— ❌ πŸ†— ❌ ❌ ❌ ❌ ❌ ❌
Bruce RF Reaper πŸ†— πŸ†— ❌ πŸ†— but w/ ST25R3916 ❌ πŸ†— πŸ†— ❌ πŸ†— ❌
Elecrow 24B πŸ†— πŸ†— πŸ†— πŸ†— ❌ πŸ†—ΒΉ ❌ ❌ ❌ ❌²
Elecrow 3.5" πŸ†— πŸ†— πŸ†— πŸ†— ❌ πŸ†—ΒΉ ❌ ❌ ❌ ❌²
NM-CYD-C5 + RF HAT πŸ†— πŸ†— ❌ πŸ†— ❌ πŸ†— πŸ†— ❌ πŸ†— ❌
Β² CYD have a LITE_VERSION version for Launcher Compatibility
ΒΉ Core, CYD and StickCs Bad-USB: here

LITE_VERSION: TelNet, SSH, WireGuard, ScanHosts, RawSniffer, Brucegotchi, BLEBacon, BLEScan and Interpreter are NOT available for M5Launcher Compatibility

✨ Why and how does it look?

Bruce stems from a keen observation within the community focused on devices like Flipper Zero. While these devices offered a glimpse into the world of offensive security, there was a palpable sense that something more could be achieved without being that overpriced, particularly with the robust and modular hardware ecosystem provided by ESP32 Devices, Lilygo and M5Stack products.

Bruce Main Menu Bruce on M5Core Bruce on Stick Bruce on CYD Bruce on CYD with NM-RF-HAT

Other media can be found here.

πŸ‘ Acknowledgements

  • @bmorcelli for new core and a bunch of new features, also porting to many devices!
  • @IncursioHack for adding RF and RFID modules features.
  • @Luidiblu for logo and UI design assistance.
  • @eadmaster for adding a lot of features.
  • @rennancockles for a lot of RFID code, refactoring and others features.
  • @7h30th3r0n3 refactoring and a lot of help with WiFi attacks.
  • @Tawank refactoring interpreter among many other things
  • @pablonymous RF functions to read RAW Data
  • Smoochiee for Bruce PCB design.
  • TH3_KR4K3N for Stick cplus extender PCB design.
  • Everyone who contributed in some way to the project, thanks ❀️

Bruce also stands on the shoulders of other great open-source firmware projects, which inspired features and code across the project:

Bruce builds on many free-software libraries, and parts of the RF and NFC/RFID modules are derived from other projects. See THIRD_PARTY.md for third-party attribution and copyleft-compliance details.

🚧 Disclaimer

Bruce is a tool for cyber offensive and red team operations, distributed under the terms of the Affero General Public License (AGPL). It is intended for legal and authorized security testing purposes only. Use of this software for any malicious or unauthorized activities is strictly prohibited. By downloading, installing, or using Bruce, you agree to comply with all applicable laws and regulations. This software is provided free of charge, and we do not accept payments for copies or modifications. The developers of Bruce assume no liability for any misuse of the software. Use at your own risk.

Contributors

bmorcelliTawankpr3yrennancocklesvalentin8709emericklaweadmasterrouingPabloOrtizVibiawhywilsonNinja-jrsmoochieeSenape3000LamnxzpGabriWarandreockGosheto12349dlIncursioHackDevEclipse1AlekseiGorwcd6Doominator1gato001k1tatuleamarin7wp81xWrackerTonylshafshnmorimotoThoxy67

Issues