docs(wiki): v2.13.43 comprehensive feature documentation BLE-Research.md: - Add BLE Tracker Detection section (AirTag/SmartTag/Tile protocol details, GATT-confirmed ring auth, cross-session tracking) - Add Passive Observation System (OBS) section: 8 classifiers, Passive Log UI, recurrence detection, JSONL at /sdcard/lab/obs/ WiFi-Security-Research.md: - Add WiFi Frame Capture + BLE Targeted PCAP (v2.12.3) Wardriving.md: - Add Radio Mode NVS Persistence (v2.12.1) - Add GPS Serial Debug Toggle (v2.13.5) Getting-Started.md: - Add Go Dark covert operating mode section (full-screen 5s touch-to-wake) Contributors.md, Support-and-Community.md: - Fix @birolt29 attribution (remove bare name, fix capitalisation) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
docs: Phase 1 truth pass — wiki accuracy corrections Use-Cases.md: - BLE Cross-Location: "not a coincidence" → static-MAC intersection is strong corroborating evidence, not conclusive proof on its own - BLE Honeypot: "CYM clones it" → "CYM creates a matching advertisement" - nRF24 Sniffer: "packet log has the keystroke data" → "raw nRF24 frames; MouseJack tools decode unencrypted protocols" - WPA2 Handshake: "Cracks in four minutes" → "cracked in minutes in this case" - Deauth + PMF: "definitive per-device PMF audit" → behavioral test; note that RSN IE inspection is needed for a complete audit - Evil Twin: "usernames and passwords in plaintext" → "captive portal log records submitted credentials" WiFi-Security-Research.md: - PMF field scenario: same behavioral-test qualification - Handshake scenario: "cracks in four minutes" → conditional phrasing - Evil Twin scenario: same credential wording fix Wardriving.md: - GPS baud heading: v2.12.0 → v2.13.x - CSV example: appRelease=v2.12.0 → v2.13.23 - Time-sliced BLE section rewritten: documents hardware coexistence (CONFIG_ESP_COEX_SW_COEXIST_ENABLE + CONFIG_SOC_COEX_HW_PTI), 12.5% BLE duty cycle (320 ms / 40 ms), BLE always-on (toggle removed v2.13.x) BLE-Research.md: - Top blockquote: add 12.5% BLE duty cycle detail for wardrive coexistence; clarify all other screens use exclusive radio access - BLE Blaster CONT_WAVE table: remove "devices cannot decode any BLE PDU" absolute claim; qualify disruption depends on proximity and device resilience - BLE Honeypot scenario: "CYM clones it" → "CYM creates a matching advertisement" - GATT Clone section: renamed "GATT Profile Snapshot — Companion App Interaction Testing"; added scope note (static snapshot, not live device state) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
docs: update nRF24 Jammer (4-mode selector) + add BLE Blaster section nRF24 Jammer: document 4-mode band selector (BLE Only / BT Classic / WiFi 2.4G / All Bands) with sweep rates and per-mode effectiveness. Add cross-reference tip to BLE Blaster dual-layer attack. Update TinySA image captions to correctly identify BT Classic mode. Fix note that prior docs claimed 126 channels (actual BT mode sweep is 82 channels). BLE Blaster: new section covering 4-instance BLE adv flood, 500ms MAC rotation, NM-RF-HAT DIP 2 dual-layer mode (native BLE + nRF24 CONT_WAVE on same 3 adv channels simultaneously), comparison table of attack layers, and field scenario. Note NimBLE v1.6.0 (BT 5.4) as the stack. Also update NimBLE version reference in page header.
wiki: wire all 7 unreferenced images into pages - BLE-Research.md: GATT Walker screenshot + info panel; AirTag close/far detection photos in cross-location analytics section - Wardriving.md: WiFi_WarDrive.bmp after intro paragraph - Infrared.md: led_remote.png under LED Remote section - Where-To-Get-It.md: deedee_flasher.png under Web Flasher heading
Add CYM research wiki: 9 pages + 19 images from project