Skip to content

ZeroTrace AirLeak Pro

Bluetooth Ops

The complete reference for AirLeak Pro's authorized Bluetooth-LE assessment tools — purpose, options, all 11 spam modes, and results, for sanctioned engagements only.

Bluetooth ops

Authorized use only

Every tool on this page transmits on Bluetooth LE and interacts with nearby devices. Use them only on devices you own or are explicitly authorized in writing to test, and stay within your engagement's scope. See Ops Suite overview and Safety & legal.

These are the active Bluetooth-LE tools in the Ops Suite, run one at a time from the main processor's radio. Each is described by what it is for in a sanctioned assessment, the options you set, and the result it gives the tester.

iBeacon broadcast

Broadcasts a standard iBeacon signal. In an assessment this is used to test how apps and systems that react to beacons behave, and to confirm beacon detection and coverage in the space under test.

BLE spoofer

Broadcasts a chosen device profile to test whether nearby systems can tell a genuine device from an imitation. In an authorized engagement this measures whether a pairing flow, an access system, or a companion app validates the devices it trusts before acting on their presence.

BLE advertisement spam

Broadcasts a high volume of advertisement messages in one of eleven ecosystem-specific modes, used to test how phones and accessories cope with — and whether they detect — a flood of pairing-style prompts.

Cycles through the full range of Apple pairing-prompt types (AirPods, other accessories) to exercise every prompt style an iOS device recognizes.

Options: the mode (above), and the broadcast rate.

Result: a measure of how target devices respond to each ecosystem's prompts, and whether the flood is detected and surfaced to the user — evidence for a notification-abuse or user-awareness finding.

GATT clone and relay

Bluetooth devices expose their features through a structure called GATT. AirLeak Pro can present a clone of a target device's GATT profile, and can act as a relay (man-in-the-middle) between a device and the thing it talks to, so the tester can observe the exchange. In an authorized engagement this tests whether a device and its app properly authenticate each other and protect their communication.

What you take away

As with the Wi-Fi tools, the deliverable is evidence — a device that could or could not be impersonated, a prompt flood that was or was not detected. Use it to recommend stronger device authentication and better detection, not to harass nearby users.

Command Palette

Search for a command to run...