# SubRabbit (wrait8)

> Open-source CC1101 sub-GHz RF tool with a serial CLI for scanning, recording, replaying, jamming and brute-forcing signals.

- **Category:** Radio & mesh
- **Availability:** In development
- **Good for:** Scan, capture, replay and brute-force fixed-code sub-GHz signals from a serial command line.
- **You'll need:** An ESP32 or the ATmega32u4 PCB with a CC1101 module and an SMA antenna, plus a serial terminal or the web flasher.
- **Trade-off:** It is beta: the shipped firmware and the published PCB target different microcontrollers, and it includes jamming which is illegal to transmit in most places.
- **Page:** https://gadgets.sh/devices/subrabbit/

## Where to buy

| Shop | Status | Link |
|---|---|---|
| wrait8 | Source repository | https://github.com/wrait8/SubRabbit?utm_source=gadgets.sh&utm_medium=referral&utm_campaign=subrabbit&utm_content=api |

## Blueprint

**Open hardware.** wrait8 publishes Gerbers + BOM (and a 3D render model) for the Mk.I PCB, but the current Mk.II firmware's PCB revision has no hardware files published yet.

### Design files

- gerbers: [Mk.I Gerbers (zip)](https://github.com/wrait8/SubRabbit/blob/main/PCB/beta/Mk.I/Gerber.zip) (ZIP)
- bom: [Mk.I BOM (XLSX)](https://github.com/wrait8/SubRabbit/blob/main/PCB/beta/Mk.I/BOM.xlsx) (XLSX)

### Source repositories

- [wrait8/SubRabbit](https://github.com/wrait8/SubRabbit) — hardware, ★12

### Key parts

| Part | Role | Datasheet |
|---|---|---|
| TI CC1101 | sub-GHz transceiver (315/433/868/915 MHz) | https://www.ti.com/product/CC1101 |
| Espressif ESP32 | MCU (inferred) | https://www.espressif.com/sites/default/files/documentation/esp32_datasheet_en.pdf |

_Notes:_ Only PCB/beta/Mk.I has Gerbers+BOM (curl-verified 200); PCB/beta/Mk.II contains only a placeholder 'null' file, so the Mk.II hardware the current firmware targets is not yet published. MCU identified as ESP32 from VSPI-default pin assignments (GPIO18/19/23/5) in SubRabbit/Mk.II/SubRabbit.ino; not stated explicitly in the README.

## Specifications

### Radio and platform

| | |
|---|---|
| Radio | CC1101 transceiver covering the 315, 433, 868 and 915 MHz sub-GHz bands |
| Controller | Firmware in main targets an ESP32; the published PCB is designed around an ATmega32u4 (Arduino Pro Micro) |
| Control | A full command-line interface over serial, with a Web Serial flasher and UI for the Mk.II |
| Display | None; the tool is driven entirely from the serial CLI |

### What it does

| | |
|---|---|
| Analyze and monitor | Frequency analyzer to detect active channels, plus RSSI and link-quality monitoring |
| Raw capture and replay | Record raw RF samples (recraw) and replay them (playraw) |
| Fixed-code capture and replay | Capture and replay fixed-code remote signals (recsig, playsig) and buffer packets (rec, show, play) |
| Modulations | 2-FSK, GFSK, ASK/OOK, 4-FSK and MSK with configurable radio parameters |
| Jamming and brute force | Continuous transmission on a selected band (jam) and timing-based brute forcing (brute) |
| Flipper interchange | Interrupt-driven edge capture with .sub file import and export for Flipper Zero compatibility |

### Hardware files, status and licence

| | |
|---|---|
| PCB bill of materials | Mk.I PCB uses an ATMEGA32U4-AU, a CC1101 module, an 8 MHz crystal, an SMA antenna connector and a USB-A connector |
| Project status | Marked beta; the firmware target is changing and a Pro Micro firmware port is still in progress |
| Licence | MIT |

## Documentation

- [Maker repository](https://github.com/wrait8/SubRabbit)
- [README at the reviewed commit](https://github.com/wrait8/SubRabbit/blob/7c464c12d03e209e54cbca506016aad454010394/README.md)
- [Docs landing page at the reviewed commit](https://github.com/wrait8/SubRabbit/blob/7c464c12d03e209e54cbca506016aad454010394/docs/index.html)
- [Mk.I PCB bill of materials](https://github.com/wrait8/SubRabbit/blob/7c464c12d03e209e54cbca506016aad454010394/PCB/beta/Mk.I/BOM.xlsx)
- [Project wiki](https://github.com/wrait8/SubRabbit/wiki)
- [Licence](https://github.com/wrait8/SubRabbit/blob/7c464c12d03e209e54cbca506016aad454010394/LICENSE)

---
Source: gadgets.sh · https://gadgets.sh/devices/subrabbit/ · JSON: https://gadgets.sh/api/v1/devices/subrabbit.json
