PromptHub
Back to Blog
Cybersecurity Internet of Things

AntiHunter: The Secret Weapon for Wireless Perimeter Defense

B

Bright Coding

Author

16 min read 100 views
AntiHunter: The Secret Weapon for Wireless Perimeter Defense

AntiHunter: The Secret Weapon for Wireless Perimeter Defense

What if your wireless network was already compromised—and you had no idea? Every day, rogue devices, deauth attacks, and unauthorized drones slip past traditional security tools. Firewalls can't see them. SIEMs don't log them. And by the time you notice the breach, the damage is done.

But what if you could build an invisible sensor net that watches every corner of your airspace? A system so distributed, so intelligent, that it learns what's normal—and screams when something's wrong?

Enter AntiHunter, the open-source perimeter defense platform that's making professional security teams rethink their entire wireless strategy. Built on ESP32-S3 hardware and coordinated through LoRa mesh networking, AntiHunter transforms cheap microcontrollers into a military-grade detection grid. Whether you're securing a data center, auditing event WiFi, or hunting rogue devices in the field, this is the tool that changes everything.

And here's the kicker: it's completely open-source. No licenses. No subscriptions. Just raw, distributed intelligence you can deploy today.

What is AntiHunter?

AntiHunter is an open-source wireless sensor node firmware designed for perimeter defense and spectrum awareness. Created by Luke Switzer with the original concept and hardware design from @TheRealSirHaXalot, it transforms ESP32-S3 development boards into autonomous detection nodes capable of scanning WiFi, Bluetooth Low Energy (BLE), and even drone Remote ID broadcasts.

The project emerged from a critical gap in wireless security tooling. Traditional solutions—expensive spectrum analyzers, proprietary hardware, or software-defined radio setups—require significant investment and expertise. AntiHunter democratizes this capability, putting professional-grade detection into a sub-$100 build that anyone with basic soldering skills can assemble.

The firmware runs on Seeed XIAO ESP32-S3 boards with 8MB minimum flash, paired with Meshtastic-compatible LoRa boards like the Heltec WiFi LoRa 32 V3.2. Each node operates independently, scanning 2.4GHz spectrum for suspicious activity, then coordinates findings across a Meshtastic mesh network for distributed awareness. The system was recently featured in Seeed Studio's Best 20 XIAO Projects in 2025, validating its technical innovation and practical impact.

What makes AntiHunter genuinely disruptive is its dual-mode architecture: deploy nodes as standalone Access Points with full web dashboards, or run them headless for covert, low-power operation. Every detection—MAC addresses, RSSI values, GPS coordinates, timestamps—gets logged to SD card and broadcast over mesh, creating an immutable record of wireless activity across your entire perimeter.

Key Features That Make AntiHunter Insane

AntiHunter packs capabilities that rival commercial systems costing thousands of dollars. Here's what each node brings to your defense grid:

Target Scan with Watchlist Intelligence — Maintain dynamic lists of MAC addresses, OUI prefixes, SSIDs, or identity IDs (T-XXXX). The moment a watched target enters range, every node within detection radius fires alerts via mesh, web UI, and command center integration. Combined WiFi/BLE scanning ensures no device slips through, while the global allowlist prevents false positives from known-good equipment.

Behavioral MAC Randomization Correlation — This is where AntiHunter gets scary-smart. Modern devices randomize MAC addresses every few minutes to evade tracking. AntiHunter defeats this using behavioral fingerprinting: Information Element patterns, channel sequencing, timing analysis, RSSI stability, and sequence number correlation. It links randomized MACs to persistent T-XXXX identities with adaptive confidence thresholds, detecting up to 30 simultaneous identities with 50 linked MACs each. Even dual-signature devices (full and minimal IE patterns) get tracked across randomization cycles.

Ghost SSID Detection — Probe requests reveal where devices have been—home networks, corporate SSIDs, hotel WiFi from last week's conference. AntiHunter's three-field correlation engine (source address, destination address, BSSID matching) flags ghost SSIDs with no responding AP nearby, surfacing location history and travel patterns. These appear prefixed with ~ in logs: ~"HomeNetwork" versus "CoffeeShop".

Deauth Attack Detection — Real-time promiscuous monitoring catches 802.11 deauthentication and disassociation frames, identifying attack sources even through MAC randomization. Integration with the correlation engine means you don't just see an attack—you see who launched it.

Drone Remote ID Detection — With FAA and EASA mandating broadcast Remote ID for most drones, AntiHunter monitors for ODID/ASTM F3411 frames (WiFi NAN action frames and beacon frames) plus French drone ID (OUI 0x6a5c35). Extract UAV identification, pilot GPS location, and flight telemetry—critical for counter-UAV operations and airspace monitoring.

Triangulation with Kalman Filtering — Deploy multiple nodes for RSSI-based weighted trilateration. Each node records signal strength and GPS coordinates; mesh aggregation produces location estimates with confidence intervals and uncertainty metrics. The system outputs Google Maps links directly to your command center. Per-target distance tuning (0.1x–5.0x multipliers) adapts to environmental path loss models from open sky to dense industrial settings.

Secure Data Destruction — Tamper detection via vibration sensor triggers configurable auto-erase sequences. Remote wipe commands use token-authenticated mesh messages with 5-minute expiry. Post-wipe obfuscation plants dummy IoT weather configurations to mislead forensic analysis. This isn't just deletion—it's plausible deniability engineering.

Privacy Mode — One-click MAC/GPS/SSID redaction for screenshots and shared reports. SSIDs hash to net#XXXX format, preserving correlation capability without exposing sensitive network names.

Real-World Use Cases Where AntiHunter Dominates

Corporate Perimeter & Data Center Security

Deploy nodes at fence lines, loading docks, and parking structures. Baseline anomaly detection learns your facility's normal wireless landscape over days, then alerts on new devices, disappeared equipment, or RSSI shifts indicating closer proximity. The MAC randomization correlation defeats employee privacy attempts and contractor evasion—track who brings unauthorized devices into restricted zones without relying on enterprise WiFi logs that attackers already bypassed.

Penetration Testing & Red Team Exercises

Professional pentesters use AntiHunter to audit their own operational security. Deploy during engagements to detect if the target's blue team has deployed wireless IDS, identify surveillance detection attempts, or map defensive sensor coverage. Probe request analysis reveals which networks the target's devices prefer—valuable intelligence for evil twin and credential harvesting attacks. Post-engagement, verify no rogue access points were left behind by the red team itself.

Event Security & Executive Protection

At conferences, political events, or high-profile gatherings, AntiHunter nodes create an invisible detection bubble. Drone RID detection identifies unauthorized UAVs before they reach camera range. Deauth attack detection catches WiFi jammers and evil twins targeting VIP communications. The battery saver mode extends runtime to 12+ hours for all-day operations, with mesh coordination ensuring no gap in coverage.

Counter-UAV & Critical Infrastructure Protection

Power plants, water treatment facilities, and transportation hubs face increasing drone threats. AntiHunter's Remote ID detection provides regulatory-compliant identification without military-grade radar. Multiple nodes create overlapping detection zones; triangulation pinches location to within meters. Integration with the AntiHunter Command Center Pro enables real-time mapping and automated response triggers.

Surveillance Detection & OPSEC Audits

Journalists, diplomats, and executives in hostile environments use AntiHunter for technical surveillance countermeasures (TSCM). Ghost SSID detection reveals if tracking devices have connected to foreign networks. MAC randomization correlation identifies persistent trackers despite address rotation. The privacy mode ensures your own operational data doesn't leak during collaborative analysis.

Step-by-Step Installation & Setup Guide

Hardware Assembly

Before flashing, assemble your detection node. Required components:

Component Specification
Main Controller Seeed XIAO ESP32-S3 (8MB+ flash)
Mesh Radio Heltec WiFi LoRa 32 V3.2 (recommended) or T114
GPS Module ATGM336H
Storage Micro SD SDHC TF Card Adapter + 16GB FAT32 SD
Tamper Detection SW-420 Vibration Sensor
Timekeeping DS3231 RTC Module
Thermal Protection KSD9700 Normally Open Thermal Sensor (30-40°C)
Power Type-C 15W 3A 5V UPS with 2S 18650
Cooling 30mm 5V JST Fan
Enclosure Weatherproof 3D-printed case (STL files in repo)

Follow the illustrated assembly manual for PCB mounting, antenna routing, and weatherproofing. Critical: use regulated 5V power only—unregulated battery sources cause voltage instability and random crashes.

Pinout Configuration

Function GPIO Description
Vibration Sensor 2 SW-420 tamper interrupt
RTC SDA 6 DS3231 I2C data
RTC SCL 3 DS3231 I2C clock
GPS RX 44 NMEA data receive
SD CS 1 SD card chip select
SD SCK 7 SPI clock
SD MISO 8 SPI MISO
SD MOSI 9 SPI MOSI
Mesh RX 4 Meshtastic UART receive
Mesh TX 5 Meshtastic UART transmit

Firmware Installation (Web Flasher - Recommended)

The zero-installation method using Chrome or Edge:

  1. Navigate to https://lukeswitz.github.io/AntiHunter/
  2. Select Full (web UI + AP mode) or Headless (mesh/serial only)
  3. Connect your ESP32-S3 via USB, click Connect & Flash
  4. Choose "Erase Device" if upgrading from pre-v0.9.2 or clearing corrupted settings
  5. After flashing, optionally push configuration without physical access

CLI Flash Method

For automation and batch deployment:

# Download and execute the flash script
curl -fsSL -o flashAntihunter.sh https://raw.githubusercontent.com/lukeswitz/AntiHunter/main/Dist/flashAntihunter.sh
chmod +x flashAntihunter.sh
./flashAntihunter.sh

Use -c flag to configure parameters during flash, -e to erase first:

./flashAntihunter.sh -e -c  # Full erase with configuration prompt

Build from Source (PlatformIO)

For customization and development:

# Clone the repository
git clone https://github.com/lukeswitz/AntiHunter.git
cd AntiHunter

# List connected devices
pio device list

# Flash full firmware with web UI
pio run -e AntiHunter-full -t upload

# Flash headless firmware (minimal, no web server)
pio run -e AntiHunter-headless -t upload

# Monitor serial output
pio device monitor -e AntiHunter-full

# Clean flash: erase all then upload
pio run -e AntiHunter-full -t erase -t upload

Post-flash configuration:

  • Full firmware: Connect to Antihunter AP (password: antihunt3r123), browse to http://192.168.4.1, immediately change default credentials in RF Settings
  • Headless firmware: Use serial monitor or mesh commands exclusively

Meshtastic Mesh Integration

Configure your LoRa radio for TEXTMSG mode at 115200 baud:

Board Mesh RX Mesh TX
T114 GPIO 10 GPIO 9
Heltec V3 GPIO 19 GPIO 20

Join public or encrypted Meshtastic channels. Nodes auto-discover and coordinate with 3-second rate-limited mesh broadcasts.

REAL Code Examples from AntiHunter

Example 1: Starting a Target Scan via Mesh Command

AntiHunter's mesh command protocol enables remote orchestration of entire sensor grids. Here's how to initiate a combined WiFi/BLE target scan across all nodes:

@ALL SCAN_START:2:300:1,6,11

Command breakdown:

  • @ALL — Broadcast to all nodes (replace with AH01 for single-node targeting)
  • SCAN_START — Initiate target watchlist scan
  • 2 — Mode: 0=WiFi only, 1=BLE only, 2=both
  • 300 — Duration in seconds (5 minutes)
  • 1,6,11 — WiFi channels to scan (comma-separated or 1..14 for range)

The FOREVER flag (append as fourth parameter) creates persistent scanning until STOP command. Nodes report hits in real-time:

AH01: Target: WIFI AA:BB:CC:DD:EE:FF RSSI:-62dBm [Name:SuspiciousAP] GPS=40.7128,-74.0060

This distributed command structure means one operator can coordinate dozens of nodes across kilometers of terrain, with each node filtering against its local watchlist and aggregating results through mesh.

Example 2: Configuring Baseline Anomaly Detection

Baseline mode learns "normal" wireless environment, then alerts on deviations. Critical for facilities with dynamic but predictable device populations:

@ALL BASELINE_START:300

This 5-minute baseline establishment captures all visible devices to RAM (200-500 devices) with SD overflow to 1,000-100,000 entries. After baseline completes, subsequent scans trigger alerts:

AH02: ANOMALY-NEW: WIFI 11:22:33:44:55:66 RSSI:-71dBm [Not in baseline]
AH02: ANOMALY-RETURN: BLE AA:BB:CC:11:22:33 RSSI:-54dBm [Absent 3600s]
AH02: ANOMALY-RSSI: WIFI CC:DD:EE:FF:00:11 RSSI:-45dBm [Delta +23dBm, closer?]

The three anomaly types—NEW, RETURN, and RSSI—cover infiltration, sleeper activation, and physical proximity changes. Persistent SD storage survives reboots; reset via @ALL BASELINE_RESET or API call.

Example 3: Triangulation with Environmental Calibration

Multi-node target location requires precise RF environment modeling. Here's a suburban triangulation command with custom power multipliers:

@AH01 TRIANGULATE_START:AA:BB:CC:DD:EE:FF:60:1:1.5:0.8

Parameter analysis:

  • AA:BB:CC:DD:EE:FF — Target MAC address
  • 60 — Duration in seconds
  • 1 — RF environment: 0=OpenSky, 1=Suburban, 2=Indoor, 3=IndoorDense, 4=Industrial
  • 1.5 — WiFi power multiplier (adjusts path loss calculation)
  • 0.8 — BLE power multiplier (fine-tunes for BLE's different propagation)

Nodes broadcast triangulation data during scan:

AH01: T_D: AA:BB:CC:DD:EE:FF RSSI:-67dBm Type:WiFi GPS=40.7128,-74.0060 HDOP=1.20
AH02: T_D: AA:BB:CC:DD:EE:FF RSSI:-82dBm Type:WiFi GPS=40.7135,-74.0072 HDOP=0.85
AH03: T_D: AA:BB:CC:DD:EE:FF RSSI:-71dBm Type:WiFi GPS=40.7121,-74.0055 HDOP=1.05

Final aggregation produces:

AH01: T_F: MAC=AA:BB:CC:DD:EE:FF GPS=40.7127,-74.0063 CONF=87.3 UNC=8.7
AH01: T_C: MAC=AA:BB:CC:DD:EE:FF Nodes=3 https://maps.google.com/?q=40.7127,-74.0063

The 87.3% confidence with 8.7 meter uncertainty demonstrates practical accuracy for physical response coordination. Per-target distance multipliers compensate for device-specific transmit power variations.

Example 4: Secure Erase with Token Authentication

Emergency data destruction uses time-bound token authentication to prevent spoofed wipe commands:

@AH01 ERASE_REQUEST

Node responds with device-specific token:

AH01: ERASE_TOKEN: AH_12345678_87654321_00001234

Execute within 5-minute expiry:

@AH01 ERASE_FORCE:AH_12345678_87654321_00001234

Post-wipe, the node broadcasts:

AH01: WIPE_COMPLETE: All data destroyed. Obfuscation active.

The obfuscation layer plants a dummy weather station configuration, misleading casual forensic examination into believing the device was always a harmless IoT sensor.

Example 5: API-Driven Probe Database Analysis

For integration with external analysis tools, stream the complete probe database:

# Fetch structured probe data with correlation intelligence
curl http://192.168.4.1/api/probedb

Response includes behavioral fingerprints:

{
  "devices": [
    {
      "mac": "AA:BB:CC:11:22:33",
      "vendor": "Apple, Inc.",
      "ssids": ["CorpWiFi", "HomeNetwork", "Starbucks_Guest"],
      "rssi_min": -82,
      "rssi_max": -34,
      "rssi_current": -67,
      "randomization": true,
      "identity_id": "T-0042",
      "confidence": 0.94,
      "first_seen": "2025-01-15T09:23:17Z",
      "last_seen": "2025-01-15T14:56:03Z",
      "probe_count": 247
    }
  ]
}

The identity_id and confidence fields reveal AntiHunter's correlation engine at work—linking 247 probe requests across randomized MACs to persistent identity T-0042 with 94% confidence based on IE fingerprint and timing pattern matching.

Advanced Usage & Best Practices

Deploy in Overlapping Triads for Triangulation — Minimum three nodes with 30-50% coverage overlap enables reliable location estimation. Heltec V3 boards handle mesh buffer better than T114; use V3 for triangulation anchors.

Calibrate RF Environment Before Critical Operations — Default path loss models vary dramatically. Perform calibration walks with known-distance reference devices, then apply custom wifiPwr/blePwr multipliers. Document your environment's n and RSSI0 values for repeatable accuracy.

Layer Defenses: Baseline + Target + Anomaly — Don't rely on single detection mode. Run perpetual baseline with periodic target scans and continuous deauth monitoring. The intersection of alerts—new device in baseline and probe request hit for ghost SSID—produces highest-confidence threat indicators.

Secure Your Mesh — Default Meshtastic public channels are interceptable. Configure encrypted channels with rotated keys for sensitive deployments. Treat mesh traffic as you would any radio communication—assume adversaries are listening.

Automate with API Polling — The JSON/JSONL endpoints enable SIEM integration. Poll /api/probedb every 60 seconds, /deauth-results every 10 seconds during active operations. The headless firmware logs identical data without web UI attack surface.

Battery Saver for Extended Operations@ALL BATTERY_SAVER_START:10 reduces CPU to 80MHz, enables light sleep, polls GPS once per minute. Mesh heartbeat format reveals status without full scan activation. Critical for 48+ hour unmanned deployments.

Comparison with Alternatives

Capability AntiHunter WiFi Pineapple ESP32 Marauder Commercial RF Sensors
Cost per Node ~$75 DIY ~$200 ~$25 $2,000-$50,000
Distributed Mesh ✅ Native LoRa ❌ USB tether ❌ None ⚠️ Proprietary
MAC Randomization Defeat ✅ Behavioral ❌ Basic OUI ❌ None ⚠️ Partial
Drone RID Detection ✅ FAA/EASA ❌ None ❌ None ⚠️ Limited models
Triangulation ✅ RSSI + Kalman ❌ None ❌ None ✅ Radar/TDOA
Secure Data Destruction ✅ Tamper + Remote ❌ None ❌ None ⚠️ Physical only
Open Source ✅ Full ⚠️ Partial ✅ Full ❌ Proprietary
Battery Operation ✅ 12+ hours ⚠️ Power bank ✅ Hours ⚠️ Vehicle/AC
Web Dashboard ✅ Full + Headless ✅ Extensive ⚠️ Basic ✅ Varies
API/SIEM Integration ✅ REST + JSONL ⚠️ Cloud ❌ None ✅ Often

AntiHunter's unique position: professional-grade distributed detection at hobbyist cost, with open architecture preventing vendor lock-in. The Pineapple excels at active attacks; Marauder at portable simplicity; commercial sensors at plug-and-play reliability. AntiHunter dominates where you need coordinated, persistent, intelligent defense across wide areas.

Frequently Asked Questions

Is AntiHunter legal to use?

AntiHunter is legal for authorized security operations on your own networks and spectrum, or with explicit written permission. The legal disclaimer emphasizes lawful use only—research, training, and authorized assessments. Compliance with GDPR, local radio regulations (LoRa duty cycles), and privacy laws is your responsibility. Never use for unauthorized tracking or surveillance.

What's the detection range per node?

WiFi/BLE detection typically reaches 50-100 meters depending on antenna quality and environment. LoRa mesh communication extends 1-5+ kilometers line-of-sight with appropriate antennas. Triangulation accuracy improves with node density—three nodes within 200 meters of target area yields 5-15 meter precision.

Can AntiHunter detect AirTags or other trackers?

Yes—BLE scanning captures AirTags, Tile, Samsung SmartTags, and similar devices. MAC randomization correlation links rotating addresses to persistent identities, defeating Apple's privacy-preserving address rotation. The baseline anomaly mode specifically excels at detecting planted trackers that appear suddenly in your environment.

How does the mesh network avoid interference with detection?

AntiHunter uses UART serial connection to separate Meshtastic LoRa boards, keeping mesh traffic on sub-GHz ISM bands (868/915/923 MHz) while WiFi/BLE scanning operates at 2.4 GHz. This physical separation eliminates self-interference. Rate limiting (3-second default) prevents mesh saturation during high-activity periods.

What's the difference between Full and Headless firmware?

Full firmware includes ESPAsyncWebServer with complete web UI, AP mode for direct connection, and all API endpoints. Headless firmware removes web dependencies for minimal attack surface, reduced memory usage, and lower power consumption—ideal for covert deployment where only mesh coordination is needed. Both log identically to SD card.

How do I update firmware on deployed nodes?

Physical USB access required for flashing. For remote updates, the web flasher supports OTA-style reconfiguration of RF parameters, scan modes, and target lists via API—no reflashing needed. Mesh commands update all operational parameters dynamically. Plan deployment locations with maintenance access in mind.

Can I integrate with my existing security stack?

The JSON/JSONL API endpoints enable straightforward integration with Splunk, Elasticsearch, or custom SIEMs. The AntiHunter Command Center Pro provides dedicated visualization and aggregation. MQTT bridge scripts (community-contributed) connect to Home Assistant, Node-RED, and other automation platforms.

Conclusion

Wireless threats aren't coming—they're already here, invisible to traditional defenses, exploiting the blind spot between your firewall and the air. AntiHunter demolishes that blind spot with an open-source, distributed detection architecture that scales from single-node audits to multi-kilometer sensor grids.

The combination of behavioral MAC correlation, drone RID detection, RSSI triangulation, and tamper-resistant operation creates capabilities previously reserved for government and enterprise budgets. At roughly $75 per node and completely open firmware, this is the democratization of wireless security intelligence.

But the real power isn't any single feature—it's the mesh-coordinated awareness that transforms isolated sensors into a unified nervous system. When node AH01 detects a deauth attack, node AH03 captures the attacker's probe requests, and node AH05 triangulates their position, you're not just logging events. You're hunting back.

The project is actively developed with beta features landing regularly. Early adopters are already deploying operational grids. The question isn't whether you need wireless perimeter defense—it's whether you'll build it yourself or wait until someone else builds it against you.

Clone the repository. Flash your first node. Join the mesh.

👉 Get AntiHunter on GitHub — Star the repo, read the assembly manual, and start building your distributed defense grid today. The airspace is yours to protect.

Featured in Seeed Studio's Best 20 XIAO Projects 2025. Community-driven. Professionally capable. Open forever.

Comments (0)

Comments are moderated before appearing.

No comments yet. Be the first to share your thoughts!

All tools