esp32.diy

Bruce Firmware: Offensive Security Tools for ESP32

Oct 11, 2026 · 5 min read

Intermediate 7k stars 2.3k forks C++ AGPL-3.0 Updated 2026-10-10

Bruce main menu displayed on a supported ESP32 device

TL;DR Bruce is an open-source C++ firmware that turns supported ESP32 handhelds into portable red team platforms with WiFi, RF, RFID, IR, BLE, and BadUSB tools. Flash it in minutes using the official web flasher or esptool.py, then navigate every feature from the device menu.
What you need
  • M5Stack Cardputer
  • M5Stack M5StickC PLUS2
  • M5Stack M5StickC PLUS
  • M5Stack M5Core BASIC
  • M5Stack M5Core2
  • M5Stack M5CoreS3
  • M5Stack M5CoreS3 SE
  • JCZN CYD-2432S028
  • Lilygo T-Embed CC1101
  • Lilygo T-Embed
  • Lilygo T-Display-S3
  • Lilygo T-Deck
  • Lilygo T-Deck Pro
  • Lilygo T-Watch-S3
  • Lilygo T-LoRa Pager
  • Smoochiee V2
  • ESP32-C5 DevKitC-1
  • Bruce RF Reaper (ESP32-S3, 16 MB Flash, 8 MB PSRAM)
  • Elecrow 24B
  • Elecrow 3.5" ESP Terminal
  • NM-CYD-C5 + RF HAT
  • CC1101 Sub-GHz module
  • NRF24 2.4 GHz module
  • PN532 NFC/RFID module
  • PN532Killer NFC/RFID module
BoardESP32-S3 / ESP32-C5 (and many ESP32 variants)
LanguageC++
LicenseAGPL-3.0
Latest Release1.16.1 (2026-08-11)
DifficultyIntermediate
Flash MethodWeb flasher or esptool.py

What You Will Build

Bruce is an open-source ESP32 firmware that turns a supported handheld device into a portable offensive security platform. After a single flash you have access to WiFi attack tools (beacon spam, deauthentication, evil portal, ARP spoofing and poisoning), Sub-GHz radio scan and replay, RFID and NFC read-and-clone, IR remote capture including TV-B-Gone, Bluetooth Low Energy scanning and device spam, BadUSB payload execution, FM broadcast, a 2.4 GHz NRF24 jammer, and a built-in JavaScript interpreter — all driven from the device's own screen and buttons.

The project describes itself as built to make Red Team operations fast and portable. It draws direct inspiration from the Flipper Zero workflow: load a payload file from an SD card, select a target, run the operation. The difference is you are running on hardware you already own or can source yourself, and every line of firmware is open-source under AGPL-3.0.

Bruce firmware running on handheld hardware\2
Bruce firmware running on handheld hardware
Bruce on an M5Stack Core device\2
Bruce on an M5Stack Core device
Bruce on an M5StickC\2
Bruce on an M5StickC
Bruce running on a CYD (Cheap Yellow Display) board\2
Bruce running on a CYD (Cheap Yellow Display) board

Hardware and Software You Need

Supported boards — pick one that fits your budget and use case:

Optional add-on modules (support varies by board; check the README compatibility table):

Software:

Typical use cases

Wireless Security Auditing

Run WiFi deauthentication, beacon spam, evil portal, ARP spoofing, and TCP port scanning from a pocket-sized device during authorized penetration tests.

RF and RFID Research

Scan, capture, and replay Sub-GHz signals via CC1101, read and clone 125 kHz and NFC tags with a PN532, and probe 2.4 GHz traffic with a NRF24 module.

BadUSB and HID Payloads

Load Ducky-compatible scripts from SD card or LittleFS to run keystroke injection over USB or BLE, supported on Cardputer, T-Deck, and other keyboard-equipped boards.

Portable Red Team Toolkit

Combine WiFi, RF, IR, BLE, and JavaScript scripting in one belt-clip device, with ESP-NOW for device-to-device file and command transfer without an access point.

How Bruce Works

Bruce is written in C++ and compiled as a separate binary for each supported board. Pin assignments, display drivers, speaker codecs, and available peripherals are all baked in at compile time, which is why selecting the correct binary matters — a Cardputer build will not work correctly on a T-Deck.

At runtime, the firmware presents a menu-driven interface on the device's screen. Every major radio and protocol stack — WiFi, BLE, Sub-GHz RF via CC1101, NRF24, IR, RFID/NFC, FM — is available as a selectable menu item. Payload files such as Ducky-compatible BadUSB scripts, raw RF captures, and custom IR sequences are loaded from a microSD card or LittleFS internal storage, matching the Flipper Zero file format where possible. A built-in JavaScript interpreter lets you write and run custom scripts directly on the device without recompiling firmware.

ESP-NOW is used for the Connect menu, which lets two Bruce devices exchange files and commands wirelessly without an access point. The WebUI feature starts a local web server so you can manage SD card and SPIFFS files from a browser on the same network.

Flash Bruce onto Your Device

Option 1 — Web Flasher (easiest, no tools required)

Open a Chromium-based browser and navigate to https://bruce.computer/flasher. Connect your device via USB, select your board from the dropdown, and click Flash. The site handles driver negotiation and puts the device into download mode automatically.

Option 2 — esptool.py (local, works on any OS)

Download the correct Bruce-<device>.bin from the Releases page. Then run:

esptool.py --port /dev/ttyACM0 write_flash 0x00000 Bruce-<device>.bin

Replace /dev/ttyACM0 with your actual serial port (COM3 on Windows, /dev/cu.usbserial-... on macOS). Replace Bruce-<device>.bin with the exact filename for your board.

Option 3 — M5Stack tools

If you already use M5Launcher to manage an M5Stack device, install Bruce over-the-air directly from the launcher. Alternatively, open the m5burner tool, search for "Bruce", select the listing uploaded by "owner" (official builds have photos), and click Burn.

After flashing, the device boots straight into the Bruce main menu. Navigate with the buttons or touchscreen to reach any feature.

Ideas to Extend It — and Limitations to Know

Ways to take it further:

Limitations to check before you buy:

Verdict

Bruce is one of the most feature-complete offensive security firmwares available for commodity ESP32 hardware, with a wide board support matrix, active development, and a web flasher that removes almost all setup friction. The main catch is that feature availability varies substantially by board, so cross-referencing the README compatibility table before buying hardware is essential. For anyone who wants everything working out of the box, the RF REAPER devkit removes the guesswork entirely.

Sources

github.comBruceDevices/firmware — repository & README bruce.computerOfficial website

Facts in this article come from the project's public README and GitHub metadata at the time of writing. Images belong to their respective owners and link back to the original source.