acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration
$ npx -y skills add Mikaru0Mystic/sectinel --skill detecting-bluetooth-low-energy-attacks --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/detecting-bluetooth-low-energy-attacksContext preview
The summary Claude sees to decide when to auto-load this skill.
Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration
name: detecting-bluetooth-low-energy-attacks description: 'Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840 sniffers for packet capture, the bleak Python library for GATT service enumeration, and crackle for BLE encryption cracking. Use when assessing IoT device BLE security, monitoring for BLE-based attacks on wireless infrastructure, or performing authorized BLE penetration testing. Activates for requests involving BLE security assessment, Ubertooth sniffing, GATT enumeration, or BLE replay detection. ' domain: cybersecurity subdomain: wireless-security author: mukul975 tags: - ble - bluetooth - ubertooth - nrf-sniffer - gatt - wireless-security - iot-security - replay-attack version: 1.0.0 license: Apache-2.0 nist_csf: - PR.IR-01 - DE.CM-01 - ID.AM-03
This skill is intended for authorized security testing, penetration testing engagements, CTF competitions, and educational purposes only. Sniffing, intercepting, or manipulating Bluetooth communications without authorization may violate federal wiretapping laws and local regulations. Always obtain explicit written permission before conducting any wireless security assessment.
Use this skill when:
**Do not use** for intercepting BLE communications without explicit authorization. Do not deploy BLE scanning tools in environments where wireless monitoring is prohibited.
Scan the environment to identify BLE devices and their advertising data:
# Scan for BLE devices using bleak (cross-platform)
python -c "
import asyncio
from bleak import BleakScanner
async def scan():
devices = await BleakScanner.discover(timeout=10.0)
for d in devices:
print(f'{d.address} | RSSI: {d.rssi} | Name: {d.name or \"Unknown\"}')
for uuid in d.metadata.get('uuids', []):
print(f' Service: {uuid}')
asyncio.run(scan())
"
# Passive BLE sniffing with Ubertooth One (promiscuous mode)
ubertooth-btle -p -r capture.pcapng
# Follow a specific BLE connection
ubertooth-btle -f -t AA:BB:CC:DD:EE:FF -r connection.pcapng
# Use nRF Sniffer with Wireshark (via extcap interface)
wireshark -i nRF_Sniffer -kConnect to target BLE peripherals and enumerate their GATT profile:
# Enumerate all services, characteristics, and descriptors
python -c "
import asyncio
from bleak import BleakClient
async def enum_gatt(address):
async with BleakClient(address) as client:
print(f'Connected: {client.is_connected}')
for service in client.services:
print(f'Service: {service.uuid} - {service.description}')
for char in service.characteristics:
props = ','.join(char.properties)
print(f' Char: {char.uuid} | Props: {props}')
for desc in char.descriptors:
val = await client.read_gatt_descriptor(desc.handle)
print(f' Desc: {desc.uuid} = {val}')
asyncio.run(enum_gatt('AA:BB:CC:DD:EE:FF'))
"Security-relevant findings during GATT enumeration:
Capture BLE traffic for offline analysis:
# Capture with Ubertooth in PcapNG format (recommended) ubertooth-btle -f -r capture.pcapng # Capture in PCAP/PPI format for crackle compatibility ubertooth-btle -f -c capture_ppi.pcap # Analyze capture in Wireshark wireshark capture.pcapng # Apply display filter: btle # Filter connection requests: btle.advertising_header.pdu_type == 0x05 # Filter data packets: btle.data_header # Extract pairing information with tshark tshark -r capture.pcapng -Y "btle.control_opcode == 0x01" -T fields \ -e btle.master_bd_addr -e btle.slave_bd_addr
Analyze captured pairing exchanges to test encryption strength:
# Crack BLE Legacy Pairing (Just Works / passkey) crackle -i capture_ppi.pcap -o decrypted.pcap # Crack with known Temporary Key (TK) crackle -i capture_ppi.pcap -o decrypted.pcap -l 000000 # Analyze decrypted traffic wireshark decrypted.pcap
BLE Legacy Pairing with Just Works mode uses a TK of all zeros, making it trivially crackable. Passkey entry uses a 6-digit PIN (000000-999999) that can be brute-forced in under a second. Only BLE Secure Conn
Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative