ZeroTrace AirLeak Pro
Settings
The device settings you can change from the app, grouped and explained
AirLeak Pro keeps a small set of settings on the device itself. You read and change them from the ZeroTrace mobile app, and they persist across power cycles. This page lists every user-facing setting, grouped by what it affects, with its default.
There's no screen or console on the board. All of these are changed over Bluetooth from the app. Settings the device won't accept are simply rejected, valid ones apply immediately.
Identity
| Setting | Default | What it does |
|---|---|---|
Device name (device_name) | (empty) | A friendly name for this unit, shown in the app and used when the device advertises. Leave it blank to use the default. |
LED
The single status LED can be tuned or turned into an indicator.
| Setting | Default | What it does |
|---|---|---|
Startup colour (startup_led_color) | blue | The colour the LED shows at power-up. |
Brightness (led_brightness) | 50 | LED brightness, 0–255. Lower it for low-light or low-visibility work. |
Show mode on LED (led_mode_indicate) | off | When on, the LED reflects the current capture mode. |
Show threats on LED (led_threat_indicate) | off | When on, the LED flashes to signal a threat alert (see below). |
In Recon mode the LED stays off regardless of these settings, that's the whole point of the mode.
Threat alerting
AirLeak Pro can escalate an alert (yellow, then red) when it sees suspicious activity within a rolling time window, for example an unknown tracker following you. These settings tune that logic.
| Setting | Default | What it does |
|---|---|---|
Window (threat_window_sec) | 30 | Rolling window, in seconds, over which threat events are counted. |
Yellow threshold (threat_yellow_count) | 1 | Number of events within the window that raises a yellow (caution) alert. |
Red threshold (threat_red_count) | 3 | Number of events within the window that raises a red (high) alert. |
Red rules (threat_red_rules) | unknown_tracker_near | Which detection rules can trigger a red alert. |
Red severity (threat_red_severity) | 2 | Minimum event severity that counts toward a red alert. |
Ignore rules (threat_ignore_rules) | (empty) | Detection rules to suppress entirely, so they never raise an alert. |
Flash duration (threat_flash_ms) | 500 | How long, in milliseconds, the LED flash lasts on a threat (when LED threat indication is on). |
Capture tuning
Fine-tune which radios run and how chatty the live stream is.
| Setting | Default | What it does |
|---|---|---|
Scan mode (scan_mode) | all | Which radios run: all, wifi only, or ble only. Use this to focus a capture on one radio. |
RSSI change threshold (rssi_delta_emit) | 6 | How much a device's signal must change (in dB) before an update is streamed, higher means fewer, calmer updates. |
Severity change threshold (sev_delta_emit) | 5 | How much a device's severity score must change before an update is streamed. |
Ops defaults
Default timings for the active Ops tools. Most Ops let you override these per run; these are the starting values.
| Setting | Default | What it does |
|---|---|---|
BLE spam interval (ble_spam_interval_ms) | 120 | Default interval, in milliseconds, between BLE advertising bursts for spam-style ops. |
BLE spoof cycle (ble_spoof_cycle_ms) | 200 | Default time, in milliseconds, the spoofer spends on each identity before rotating to the next. |
Boot
| Setting | Default | What it does |
|---|---|---|
Always start in Recon (always_recon) | off | When on, the device powers up in Recon mode every time, overriding the last saved mode. |
Read-only device info
Alongside the settings above, the device also reports information you can't change, useful for support and record-keeping:
- Product name
- Firmware version
- Serial number (
ZT-<MAC>) - Storage and free space on the microSD card
You'll find these in the app's device info, they're read straight from the board.