CatSniffer V3
A multiprotocol, multiband USB sniffer for authorized IoT security research: capture, analyze and interact with Zigbee, BLE, Thread and LoRa traffic from a single board.
$150.00 Original price was: $150.00.$136.00Current price is: $136.00.
Out of stock
Email when stock available
- Wireshark — extcap plugin + Zigbee/Thread/LoRa dissectors
- Kismet — passive Zigbee wardriving, exports PCAP-NG
- Sniffle (NCC Group) — officially supported BLE sniffer
- Linux Bluetooth stack — shows up as an hciX adapter
In the box
USB cable
Not included
You also need
- 937 GitHub Stars
- DragonJARCON 2021 — conference talk: "CatSniffer la herramienta para Internet de las Cosas."
- Designed and built in Aguascalientes, Mexico
- Hardware CERN-OHL v1.2 · firmware GPL-3.0
Passive Zigbee Mapping and WIDS with Kismet
CatSniffer as a Standard Linux Bluetooth Adapter
Your First Capture: Live BLE Traffic in Wireshark
Start in 10 minutes
- Install Catnip for your OS — native installers for Windows, macOS (Intel/Apple Silicon) and Linux (.deb/.pkg.tar.zst/AUR).
- Run
catniponce. On a clean environment it auto-downloads the latest official firmware release and verifies each file’s SHA256 checksum. - Run
catnip devicesto confirm the board is detected and see its three serial ports (Cat-Bridge, Cat-LoRa, Cat-Shell). - Run
catnip flash <alias>— for exampleble,zigbee,threadorlora-sniffer— to flash the matching firmware onto the CC1352. - Run
catnip verifyfor the hardware self-test, thencatnip sniff <protocol>to start capturing: Wireshark launches automatically through the extcap integration if selected. Full command reference in the CatSniffer wiki.
| Weight | 0.055 g |
|---|---|
| Dimensions | 18 × 12.5 × 2 cm |
| Bridge MCU | RP2040 dual-core Arm Cortex-M0+ @ 133MHz (USB-UART/USB-SPI bridge) |
| Radio MCU | TI CC1352P7, Arm Cortex-M4F @ 48MHz |
| LoRa Modem | Semtech SX1262 (170dB max link budget, -148dBm sensitivity) |
| Wireless Protocols | Thread, Zigbee, Matter, Bluetooth 5.2 Low Energy, IEEE 802.15.4g, 6LoWPAN, mioty, Amazon Sidewalk, Wireless M-Bus, Wi-SUN, LoRa/LoRaWAN |
| Program Flash | CC1352P7: 704KB in-system programmable; RP2040: up to 16MB off-chip via QSPI |
| SRAM / ROM | CC1352P7: 144KB ultra-low-leakage SRAM with parity + 8KB cache SRAM + 256KB ROM; RP2040: 264KB SRAM in six banks |
| Antenna Support | 433MHz up to 13dBm, 2.4GHz up to 10dBm |
| Bootloader | Automatic entry into the CC1352 TI bootloader — no external programmer needed for normal flashing |
| Debug & Recovery | cJTAG/JTAG on the CC1352 default pin; TagConnect 6-pin SWD connector for external J-Link/ST-Link recovery |
| Supported OS | Linux (full support), macOS (functional), Windows (compatible) |
| Firmware License | GNU AGPL v3.0 |
| Hardware License | CERN Open Hardware Licence v1.2 |
Both hardware generations are flashed and managed through the same Catnip CLI.
| Attribute | v1.x / v2.x | v3.x (current) |
|---|---|---|
| Bridge MCU | Microchip SAMD21E17 (USB-UART bridge) | Raspberry Pi RP2040, dual-core Arm Cortex-M0+ @ 133MHz |
| Radio MCU memory | CC1352P1: 352KB flash / 80KB SRAM | CC1352P7: 704KB flash / 144KB SRAM |
| Protocol / tooling support | Thread, Zigbee, BLE 5.2, 802.15.4g, 6LoWPAN, mioty, Wireless M-Bus, Wi-SUN, TI 15.4-Stack; Wireshark v3.0.x dissectors | Thread, Zigbee, Matter, BLE 5.2, Wi-SUN, mioty, Amazon Sidewalk, Wireless M-Bus, TI 15.4-Stack, 6LoWPAN; Wireshark v4.0.x dissectors |
| Antenna support | 868/915MHz up to 14dBm, 2.4GHz up to 20dBm | 433MHz up to 13dBm, 2.4GHz up to 10dBm |


















