AntiHunter: The Secret Weapon for Wireless Perimeter Defense
What if your wireless network was already compromised—and you had no idea? Every day, rogue devices, deauth attacks, and unauthorized drones slip past traditional security tools. Firewalls can't see them. SIEMs don't log them. And by the time you notice the breach, the damage is done.
But what if you could build an invisible sensor net that watches every corner of your airspace? A system so distributed, so intelligent, that it learns what's normal—and screams when something's wrong?
Enter AntiHunter, the open-source perimeter defense platform that's making professional security teams rethink their entire wireless strategy. Built on ESP32-S3 hardware and coordinated through LoRa mesh networking, AntiHunter transforms cheap microcontrollers into a military-grade detection grid. Whether you're securing a data center, auditing event WiFi, or hunting rogue devices in the field, this is the tool that changes everything.
And here's the kicker: it's completely open-source. No licenses. No subscriptions. Just raw, distributed intelligence you can deploy today.
What is AntiHunter?
AntiHunter is an open-source wireless sensor node firmware designed for perimeter defense and spectrum awareness. Created by Luke Switzer with the original concept and hardware design from @TheRealSirHaXalot, it transforms ESP32-S3 development boards into autonomous detection nodes capable of scanning WiFi, Bluetooth Low Energy (BLE), and even drone Remote ID broadcasts.
The project emerged from a critical gap in wireless security tooling. Traditional solutions—expensive spectrum analyzers, proprietary hardware, or software-defined radio setups—require significant investment and expertise. AntiHunter democratizes this capability, putting professional-grade detection into a sub-$100 build that anyone with basic soldering skills can assemble.
The firmware runs on Seeed XIAO ESP32-S3 boards with 8MB minimum flash, paired with Meshtastic-compatible LoRa boards like the Heltec WiFi LoRa 32 V3.2. Each node operates independently, scanning 2.4GHz spectrum for suspicious activity, then coordinates findings across a Meshtastic mesh network for distributed awareness. The system was recently featured in Seeed Studio's Best 20 XIAO Projects in 2025, validating its technical innovation and practical impact.
What makes AntiHunter genuinely disruptive is its dual-mode architecture: deploy nodes as standalone Access Points with full web dashboards, or run them headless for covert, low-power operation. Every detection—MAC addresses, RSSI values, GPS coordinates, timestamps—gets logged to SD card and broadcast over mesh, creating an immutable record of wireless activity across your entire perimeter.
Key Features That Make AntiHunter Insane
AntiHunter packs capabilities that rival commercial systems costing thousands of dollars. Here's what each node brings to your defense grid:
Target Scan with Watchlist Intelligence — Maintain dynamic lists of MAC addresses, OUI prefixes, SSIDs, or identity IDs (T-XXXX). The moment a watched target enters range, every node within detection radius fires alerts via mesh, web UI, and command center integration. Combined WiFi/BLE scanning ensures no device slips through, while the global allowlist prevents false positives from known-good equipment.
Behavioral MAC Randomization Correlation — This is where AntiHunter gets scary-smart. Modern devices randomize MAC addresses every few minutes to evade tracking. AntiHunter defeats this using behavioral fingerprinting: Information Element patterns, channel sequencing, timing analysis, RSSI stability, and sequence number correlation. It links randomized MACs to persistent T-XXXX identities with adaptive confidence thresholds, detecting up to 30 simultaneous identities with 50 linked MACs each. Even dual-signature devices (full and minimal IE patterns) get tracked across randomization cycles.
Ghost SSID Detection — Probe requests reveal where devices have been—home networks, corporate SSIDs, hotel WiFi from last week's conference. AntiHunter's three-field correlation engine (source address, destination address, BSSID matching) flags ghost SSIDs with no responding AP nearby, surfacing location history and travel patterns. These appear prefixed with ~ in logs: ~"HomeNetwork" versus "CoffeeShop".
Deauth Attack Detection — Real-time promiscuous monitoring catches 802.11 deauthentication and disassociation frames, identifying attack sources even through MAC randomization. Integration with the correlation engine means you don't just see an attack—you see who launched it.
Drone Remote ID Detection — With FAA and EASA mandating broadcast Remote ID for most drones, AntiHunter monitors for ODID/ASTM F3411 frames (WiFi NAN action frames and beacon frames) plus French drone ID (OUI 0x6a5c35). Extract UAV identification, pilot GPS location, and flight telemetry—critical for counter-UAV operations and airspace monitoring.
Triangulation with Kalman Filtering — Deploy multiple nodes for RSSI-based weighted trilateration. Each node records signal strength and GPS coordinates; mesh aggregation produces location estimates with confidence intervals and uncertainty metrics. The system outputs Google Maps links directly to your command center. Per-target distance tuning (0.1x–5.0x multipliers) adapts to environmental path loss models from open sky to dense industrial settings.
Secure Data Destruction — Tamper detection via vibration sensor triggers configurable auto-erase sequences. Remote wipe commands use token-authenticated mesh messages with 5-minute expiry. Post-wipe obfuscation plants dummy IoT weather configurations to mislead forensic analysis. This isn't just deletion—it's plausible deniability engineering.
Privacy Mode — One-click MAC/GPS/SSID redaction for screenshots and shared reports. SSIDs hash to net#XXXX format, preserving correlation capability without exposing sensitive network names.
Real-World Use Cases Where AntiHunter Dominates
Corporate Perimeter & Data Center Security
Deploy nodes at fence lines, loading docks, and parking structures. Baseline anomaly detection learns your facility's normal wireless landscape over days, then alerts on new devices, disappeared equipment, or RSSI shifts indicating closer proximity. The MAC randomization correlation defeats employee privacy attempts and contractor evasion—track who brings unauthorized devices into restricted zones without relying on enterprise WiFi logs that attackers already bypassed.
Penetration Testing & Red Team Exercises
Professional pentesters use AntiHunter to audit their own operational security. Deploy during engagements to detect if the target's blue team has deployed wireless IDS, identify surveillance detection attempts, or map defensive sensor coverage. Probe request analysis reveals which networks the target's devices prefer—valuable intelligence for evil twin and credential harvesting attacks. Post-engagement, verify no rogue access points were left behind by the red team itself.
Event Security & Executive Protection
At conferences, political events, or high-profile gatherings, AntiHunter nodes create an invisible detection bubble. Drone RID detection identifies unauthorized UAVs before they reach camera range. Deauth attack detection catches WiFi jammers and evil twins targeting VIP communications. The battery saver mode extends runtime to 12+ hours for all-day operations, with mesh coordination ensuring no gap in coverage.
Counter-UAV & Critical Infrastructure Protection
Power plants, water treatment facilities, and transportation hubs face increasing drone threats. AntiHunter's Remote ID detection provides regulatory-compliant identification without military-grade radar. Multiple nodes create overlapping detection zones; triangulation pinches location to within meters. Integration with the AntiHunter Command Center Pro enables real-time mapping and automated response triggers.
Surveillance Detection & OPSEC Audits
Journalists, diplomats, and executives in hostile environments use AntiHunter for technical surveillance countermeasures (TSCM). Ghost SSID detection reveals if tracking devices have connected to foreign networks. MAC randomization correlation identifies persistent trackers despite address rotation. The privacy mode ensures your own operational data doesn't leak during collaborative analysis.
Step-by-Step Installation & Setup Guide
Hardware Assembly
Before flashing, assemble your detection node. Required components:
| Component | Specification |
|---|---|
| Main Controller | Seeed XIAO ESP32-S3 (8MB+ flash) |
| Mesh Radio | Heltec WiFi LoRa 32 V3.2 (recommended) or T114 |
| GPS Module | ATGM336H |
| Storage | Micro SD SDHC TF Card Adapter + 16GB FAT32 SD |
| Tamper Detection | SW-420 Vibration Sensor |
| Timekeeping | DS3231 RTC Module |
| Thermal Protection | KSD9700 Normally Open Thermal Sensor (30-40°C) |
| Power | Type-C 15W 3A 5V UPS with 2S 18650 |
| Cooling | 30mm 5V JST Fan |
| Enclosure | Weatherproof 3D-printed case (STL files in repo) |
Follow the illustrated assembly manual for PCB mounting, antenna routing, and weatherproofing. Critical: use regulated 5V power only—unregulated battery sources cause voltage instability and random crashes.
Pinout Configuration
| Function | GPIO | Description |
|---|---|---|
| Vibration Sensor | 2 | SW-420 tamper interrupt |
| RTC SDA | 6 | DS3231 I2C data |
| RTC SCL | 3 | DS3231 I2C clock |
| GPS RX | 44 | NMEA data receive |
| SD CS | 1 | SD card chip select |
| SD SCK | 7 | SPI clock |
| SD MISO | 8 | SPI MISO |
| SD MOSI | 9 | SPI MOSI |
| Mesh RX | 4 | Meshtastic UART receive |
| Mesh TX | 5 | Meshtastic UART transmit |
Firmware Installation (Web Flasher - Recommended)
The zero-installation method using Chrome or Edge:
- Navigate to https://lukeswitz.github.io/AntiHunter/
- Select Full (web UI + AP mode) or Headless (mesh/serial only)
- Connect your ESP32-S3 via USB, click Connect & Flash
- Choose "Erase Device" if upgrading from pre-v0.9.2 or clearing corrupted settings
- After flashing, optionally push configuration without physical access
CLI Flash Method
For automation and batch deployment:
# Download and execute the flash script
curl -fsSL -o flashAntihunter.sh https://raw.githubusercontent.com/lukeswitz/AntiHunter/main/Dist/flashAntihunter.sh
chmod +x flashAntihunter.sh
./flashAntihunter.sh
Use -c flag to configure parameters during flash, -e to erase first:
./flashAntihunter.sh -e -c # Full erase with configuration prompt
Build from Source (PlatformIO)
For customization and development:
# Clone the repository
git clone https://github.com/lukeswitz/AntiHunter.git
cd AntiHunter
# List connected devices
pio device list
# Flash full firmware with web UI
pio run -e AntiHunter-full -t upload
# Flash headless firmware (minimal, no web server)
pio run -e AntiHunter-headless -t upload
# Monitor serial output
pio device monitor -e AntiHunter-full
# Clean flash: erase all then upload
pio run -e AntiHunter-full -t erase -t upload
Post-flash configuration:
- Full firmware: Connect to
AntihunterAP (password:antihunt3r123), browse tohttp://192.168.4.1, immediately change default credentials in RF Settings - Headless firmware: Use serial monitor or mesh commands exclusively
Meshtastic Mesh Integration
Configure your LoRa radio for TEXTMSG mode at 115200 baud:
| Board | Mesh RX | Mesh TX |
|---|---|---|
| T114 | GPIO 10 | GPIO 9 |
| Heltec V3 | GPIO 19 | GPIO 20 |
Join public or encrypted Meshtastic channels. Nodes auto-discover and coordinate with 3-second rate-limited mesh broadcasts.
REAL Code Examples from AntiHunter
Example 1: Starting a Target Scan via Mesh Command
AntiHunter's mesh command protocol enables remote orchestration of entire sensor grids. Here's how to initiate a combined WiFi/BLE target scan across all nodes:
@ALL SCAN_START:2:300:1,6,11
Command breakdown:
@ALL— Broadcast to all nodes (replace withAH01for single-node targeting)SCAN_START— Initiate target watchlist scan2— Mode: 0=WiFi only, 1=BLE only, 2=both300— Duration in seconds (5 minutes)1,6,11— WiFi channels to scan (comma-separated or1..14for range)
The FOREVER flag (append as fourth parameter) creates persistent scanning until STOP command. Nodes report hits in real-time:
AH01: Target: WIFI AA:BB:CC:DD:EE:FF RSSI:-62dBm [Name:SuspiciousAP] GPS=40.7128,-74.0060
This distributed command structure means one operator can coordinate dozens of nodes across kilometers of terrain, with each node filtering against its local watchlist and aggregating results through mesh.
Example 2: Configuring Baseline Anomaly Detection
Baseline mode learns "normal" wireless environment, then alerts on deviations. Critical for facilities with dynamic but predictable device populations:
@ALL BASELINE_START:300
This 5-minute baseline establishment captures all visible devices to RAM (200-500 devices) with SD overflow to 1,000-100,000 entries. After baseline completes, subsequent scans trigger alerts:
AH02: ANOMALY-NEW: WIFI 11:22:33:44:55:66 RSSI:-71dBm [Not in baseline]
AH02: ANOMALY-RETURN: BLE AA:BB:CC:11:22:33 RSSI:-54dBm [Absent 3600s]
AH02: ANOMALY-RSSI: WIFI CC:DD:EE:FF:00:11 RSSI:-45dBm [Delta +23dBm, closer?]
The three anomaly types—NEW, RETURN, and RSSI—cover infiltration, sleeper activation, and physical proximity changes. Persistent SD storage survives reboots; reset via @ALL BASELINE_RESET or API call.
Example 3: Triangulation with Environmental Calibration
Multi-node target location requires precise RF environment modeling. Here's a suburban triangulation command with custom power multipliers:
@AH01 TRIANGULATE_START:AA:BB:CC:DD:EE:FF:60:1:1.5:0.8
Parameter analysis:
AA:BB:CC:DD:EE:FF— Target MAC address60— Duration in seconds1— RF environment: 0=OpenSky, 1=Suburban, 2=Indoor, 3=IndoorDense, 4=Industrial1.5— WiFi power multiplier (adjusts path loss calculation)0.8— BLE power multiplier (fine-tunes for BLE's different propagation)
Nodes broadcast triangulation data during scan:
AH01: T_D: AA:BB:CC:DD:EE:FF RSSI:-67dBm Type:WiFi GPS=40.7128,-74.0060 HDOP=1.20
AH02: T_D: AA:BB:CC:DD:EE:FF RSSI:-82dBm Type:WiFi GPS=40.7135,-74.0072 HDOP=0.85
AH03: T_D: AA:BB:CC:DD:EE:FF RSSI:-71dBm Type:WiFi GPS=40.7121,-74.0055 HDOP=1.05
Final aggregation produces:
AH01: T_F: MAC=AA:BB:CC:DD:EE:FF GPS=40.7127,-74.0063 CONF=87.3 UNC=8.7
AH01: T_C: MAC=AA:BB:CC:DD:EE:FF Nodes=3 https://maps.google.com/?q=40.7127,-74.0063
The 87.3% confidence with 8.7 meter uncertainty demonstrates practical accuracy for physical response coordination. Per-target distance multipliers compensate for device-specific transmit power variations.
Example 4: Secure Erase with Token Authentication
Emergency data destruction uses time-bound token authentication to prevent spoofed wipe commands:
@AH01 ERASE_REQUEST
Node responds with device-specific token:
AH01: ERASE_TOKEN: AH_12345678_87654321_00001234
Execute within 5-minute expiry:
@AH01 ERASE_FORCE:AH_12345678_87654321_00001234
Post-wipe, the node broadcasts:
AH01: WIPE_COMPLETE: All data destroyed. Obfuscation active.
The obfuscation layer plants a dummy weather station configuration, misleading casual forensic examination into believing the device was always a harmless IoT sensor.
Example 5: API-Driven Probe Database Analysis
For integration with external analysis tools, stream the complete probe database:
# Fetch structured probe data with correlation intelligence
curl http://192.168.4.1/api/probedb
Response includes behavioral fingerprints:
{
"devices": [
{
"mac": "AA:BB:CC:11:22:33",
"vendor": "Apple, Inc.",
"ssids": ["CorpWiFi", "HomeNetwork", "Starbucks_Guest"],
"rssi_min": -82,
"rssi_max": -34,
"rssi_current": -67,
"randomization": true,
"identity_id": "T-0042",
"confidence": 0.94,
"first_seen": "2025-01-15T09:23:17Z",
"last_seen": "2025-01-15T14:56:03Z",
"probe_count": 247
}
]
}
The identity_id and confidence fields reveal AntiHunter's correlation engine at work—linking 247 probe requests across randomized MACs to persistent identity T-0042 with 94% confidence based on IE fingerprint and timing pattern matching.
Advanced Usage & Best Practices
Deploy in Overlapping Triads for Triangulation — Minimum three nodes with 30-50% coverage overlap enables reliable location estimation. Heltec V3 boards handle mesh buffer better than T114; use V3 for triangulation anchors.
Calibrate RF Environment Before Critical Operations — Default path loss models vary dramatically. Perform calibration walks with known-distance reference devices, then apply custom wifiPwr/blePwr multipliers. Document your environment's n and RSSI0 values for repeatable accuracy.
Layer Defenses: Baseline + Target + Anomaly — Don't rely on single detection mode. Run perpetual baseline with periodic target scans and continuous deauth monitoring. The intersection of alerts—new device in baseline and probe request hit for ghost SSID—produces highest-confidence threat indicators.
Secure Your Mesh — Default Meshtastic public channels are interceptable. Configure encrypted channels with rotated keys for sensitive deployments. Treat mesh traffic as you would any radio communication—assume adversaries are listening.
Automate with API Polling — The JSON/JSONL endpoints enable SIEM integration. Poll /api/probedb every 60 seconds, /deauth-results every 10 seconds during active operations. The headless firmware logs identical data without web UI attack surface.
Battery Saver for Extended Operations — @ALL BATTERY_SAVER_START:10 reduces CPU to 80MHz, enables light sleep, polls GPS once per minute. Mesh heartbeat format reveals status without full scan activation. Critical for 48+ hour unmanned deployments.
Comparison with Alternatives
| Capability | AntiHunter | WiFi Pineapple | ESP32 Marauder | Commercial RF Sensors |
|---|---|---|---|---|
| Cost per Node | ~$75 DIY | ~$200 | ~$25 | $2,000-$50,000 |
| Distributed Mesh | ✅ Native LoRa | ❌ USB tether | ❌ None | ⚠️ Proprietary |
| MAC Randomization Defeat | ✅ Behavioral | ❌ Basic OUI | ❌ None | ⚠️ Partial |
| Drone RID Detection | ✅ FAA/EASA | ❌ None | ❌ None | ⚠️ Limited models |
| Triangulation | ✅ RSSI + Kalman | ❌ None | ❌ None | ✅ Radar/TDOA |
| Secure Data Destruction | ✅ Tamper + Remote | ❌ None | ❌ None | ⚠️ Physical only |
| Open Source | ✅ Full | ⚠️ Partial | ✅ Full | ❌ Proprietary |
| Battery Operation | ✅ 12+ hours | ⚠️ Power bank | ✅ Hours | ⚠️ Vehicle/AC |
| Web Dashboard | ✅ Full + Headless | ✅ Extensive | ⚠️ Basic | ✅ Varies |
| API/SIEM Integration | ✅ REST + JSONL | ⚠️ Cloud | ❌ None | ✅ Often |
AntiHunter's unique position: professional-grade distributed detection at hobbyist cost, with open architecture preventing vendor lock-in. The Pineapple excels at active attacks; Marauder at portable simplicity; commercial sensors at plug-and-play reliability. AntiHunter dominates where you need coordinated, persistent, intelligent defense across wide areas.
Frequently Asked Questions
Is AntiHunter legal to use?
AntiHunter is legal for authorized security operations on your own networks and spectrum, or with explicit written permission. The legal disclaimer emphasizes lawful use only—research, training, and authorized assessments. Compliance with GDPR, local radio regulations (LoRa duty cycles), and privacy laws is your responsibility. Never use for unauthorized tracking or surveillance.
What's the detection range per node?
WiFi/BLE detection typically reaches 50-100 meters depending on antenna quality and environment. LoRa mesh communication extends 1-5+ kilometers line-of-sight with appropriate antennas. Triangulation accuracy improves with node density—three nodes within 200 meters of target area yields 5-15 meter precision.
Can AntiHunter detect AirTags or other trackers?
Yes—BLE scanning captures AirTags, Tile, Samsung SmartTags, and similar devices. MAC randomization correlation links rotating addresses to persistent identities, defeating Apple's privacy-preserving address rotation. The baseline anomaly mode specifically excels at detecting planted trackers that appear suddenly in your environment.
How does the mesh network avoid interference with detection?
AntiHunter uses UART serial connection to separate Meshtastic LoRa boards, keeping mesh traffic on sub-GHz ISM bands (868/915/923 MHz) while WiFi/BLE scanning operates at 2.4 GHz. This physical separation eliminates self-interference. Rate limiting (3-second default) prevents mesh saturation during high-activity periods.
What's the difference between Full and Headless firmware?
Full firmware includes ESPAsyncWebServer with complete web UI, AP mode for direct connection, and all API endpoints. Headless firmware removes web dependencies for minimal attack surface, reduced memory usage, and lower power consumption—ideal for covert deployment where only mesh coordination is needed. Both log identically to SD card.
How do I update firmware on deployed nodes?
Physical USB access required for flashing. For remote updates, the web flasher supports OTA-style reconfiguration of RF parameters, scan modes, and target lists via API—no reflashing needed. Mesh commands update all operational parameters dynamically. Plan deployment locations with maintenance access in mind.
Can I integrate with my existing security stack?
The JSON/JSONL API endpoints enable straightforward integration with Splunk, Elasticsearch, or custom SIEMs. The AntiHunter Command Center Pro provides dedicated visualization and aggregation. MQTT bridge scripts (community-contributed) connect to Home Assistant, Node-RED, and other automation platforms.
Conclusion
Wireless threats aren't coming—they're already here, invisible to traditional defenses, exploiting the blind spot between your firewall and the air. AntiHunter demolishes that blind spot with an open-source, distributed detection architecture that scales from single-node audits to multi-kilometer sensor grids.
The combination of behavioral MAC correlation, drone RID detection, RSSI triangulation, and tamper-resistant operation creates capabilities previously reserved for government and enterprise budgets. At roughly $75 per node and completely open firmware, this is the democratization of wireless security intelligence.
But the real power isn't any single feature—it's the mesh-coordinated awareness that transforms isolated sensors into a unified nervous system. When node AH01 detects a deauth attack, node AH03 captures the attacker's probe requests, and node AH05 triangulates their position, you're not just logging events. You're hunting back.
The project is actively developed with beta features landing regularly. Early adopters are already deploying operational grids. The question isn't whether you need wireless perimeter defense—it's whether you'll build it yourself or wait until someone else builds it against you.
Clone the repository. Flash your first node. Join the mesh.
👉 Get AntiHunter on GitHub — Star the repo, read the assembly manual, and start building your distributed defense grid today. The airspace is yours to protect.
Featured in Seeed Studio's Best 20 XIAO Projects 2025. Community-driven. Professionally capable. Open forever.