ZeroTrace AirLeak Pro
What It Captures
The Wi-Fi networks, clients and Bluetooth devices AirLeak Pro identifies
AirLeak Pro captures on two fronts at once, Wi-Fi (2.4 GHz and 5 GHz) and Bluetooth LE, and merges both into one live view in the app.
Wi-Fi scanning runs on the Pro's dedicated dual-band radio; Bluetooth runs alongside it. You don't switch between them, both feed the same capture at the same time.
Wi-Fi: access points
For every network it hears, AirLeak Pro surfaces:
| Field | What it tells you |
|---|---|
| SSID | The network name (or a hidden marker when the network cloaks its name; also flags a network that was hidden but has since revealed its name) |
| BSSID | The access point's MAC address |
| Band | 2.4 GHz or 5 GHz (the Pro sweeps these two bands only, no 6 GHz) |
| Channel | The operating channel |
| Signal (RSSI) | How strong it was heard, in dBm, kept as current / best / min / max |
| Security | Open, WEP, WPA-PSK, WPA2-PSK, WPA/WPA2, WPA2-Enterprise, WPA3-SAE, WPA2/WPA3, WAPI, or OWE (enhanced open) |
| Protected management frames | PMF required and/or capable |
| WPS | Whether Wi-Fi Protected Setup is advertised, plus locked and active-registrar states |
| Wi-Fi generation | Wi-Fi 4 (n), Wi-Fi 5 (ac), Wi-Fi 6 (ax), or Wi-Fi 7 (be) |
| Device class | Best-guess AP type: router, mobile hotspot, public hotspot, enterprise AP, repeater, printer, camera, smart TV, IoT, smart-home hub, gaming console, vehicle |
| Hidden | Whether the network hides its SSID (and whether it was previously hidden) |
| First / last seen | When it entered and was last heard |
Networks are de-duplicated as you move, one row per access point, updated as its signal changes, so a drive through a dense area produces a clean inventory rather than thousands of repeats.
The Pro sweeps 2.4 GHz and 5 GHz only. It classifies each network's generation as Wi-Fi 4/5/6/7 from the advertised capabilities. There is no separate "Wi-Fi 6E" marker and no 6 GHz sweep, a 6 GHz-capable radio's 2.4/5 GHz presence is still seen and reported as Wi-Fi 6.
Most modern routers run their fastest network on 5 GHz. A 2.4-GHz-only scanner misses those entirely. AirLeak Pro sees both bands, so your survey reflects what's actually deployed.
Alongside listening, the Pro does light active probing, it injects randomized probe requests and a single KARMA wildcard probe to coax hidden SSIDs into the open and to surface lure responders (rogue APs that answer any network name). Networks that answered the wildcard, or that behave like a lure, are flagged (answered_wildcard, lure_responder, karma). This transmits, so treat the survey as active and only run it where you're authorized to.
Wi-Fi: clients
Beyond access points, the Pro also picks up client devices that are actively looking for networks. When a phone or laptop probes for a remembered network by name, the Pro captures:
- The client's MAC address, flagged as randomized or real
- The network name it's searching for
- Signal strength and when it was seen
This is the surface that reveals which networks a device "remembers", useful for privacy audits and understanding a device's history. Devices using MAC randomization are clearly marked as such.
Bluetooth LE: devices
On the Bluetooth side, AirLeak Pro runs the full AirLeak device-intelligence stack. It listens to BLE advertisements and classifies each device into a specific type with a confidence score, and decodes rich per-device detail.
The recognized device classes and the per-device fields are the same as the standard AirLeak, covering the Apple ecosystem, phones, PCs, TVs, wearables, trackers, audio, smart-home/IoT, and more.
For the complete list of Bluetooth device classes, the fields captured per device, and the privacy signals detected, see the standard AirLeak's What AirLeak Sees, the Pro's Bluetooth capture is identical.
Highlights of the BLE side:
- Device class + confidence, each device is sorted into one of ~35 classes (iPhone, iPad, Mac, Apple Watch, AirPods, AirTag, Android/Samsung/Pixel phones, Windows PC, printer, smart TV, HomeKit light/lock/sensor, IoT sensor, headphones, speaker, fitness, HID, vehicle, beacon, Flipper Zero, Matter, smart watch, Samsung SmartTag, Google tracker, and more) with a 0–100 confidence score
- Trackers, AirTag / Find My, Tile, Samsung SmartTag, Google Find My Network, Chipolo, with separated-from-owner and unpaired state
- Apple Continuity, live device state (screen on/off, in-call, handoff, OS hints), plus AirPods L/R/case battery and charging
- Find My battery level on supported accessories
- Environmental sensors, temperature, humidity and battery broadcast by BLE sensor beacons
- MAC-randomization type, whether the address is public, RPA (resolvable), NRPA (non-resolvable), or random-static
- Rich per-device fields, appearance, advertised service UUIDs, TX power, distance estimate, company ID, model, and more
- Privacy signals, AirDrop discoverable, unwanted-tracker flags, combined leakage score
- Cross-MAC tracking, follows a device across MAC rotation where its advertisement is fingerprintable
Location tagging
On a drive, observations are tagged with the location where each network or device was heard strongest, using your phone's GPS through the app, and exported as WiGLE-compatible CSV for mapping. Want the board to wardrive without a phone? An optional on-board GPS module lets it run standalone. See GPS.
Where a field hasn't been observed (for example, no name from a hidden network or a randomized client), the app shows an em-dash rather than guessing.