See the invisible. Legally.
A receive-only RF diagnostic tool that paints a live picture of everything happening in the 2.4 GHz ISM band around you โ WiFi, Bluetooth, Zigbee, microwave ovens, RC links โ on an OLED and in your browser.
โ๏ธ 100% legal. The NRF24 modules are used purely as energy detectors โ they never transmit. This is a passive spectrum analyzer, not a jammer.
| ๐ Dual-radio parallel sweep | Radio A covers ch 0โ62, Radio B covers ch 63โ125 โ ~2ร sweep speed |
| ๐ Full 2.4 GHz coverage | All 126 NRF24 channels (2.400โ2.525 GHz), ~20 sweeps/sec |
| ๐บ OLED live display | Two pages: spectrum bar graph with peak-hold, and peak stats |
| ๐ Browser web UI | Color-coded chart with band overlays (WiFi / BLE / Zigbee / microwave) |
| ๐ CSV serial logging | Full spectrum dump every 5s for offline analysis |
| ๐ก๏ธ Graceful degradation | Unplug one radio? The other half keeps sweeping |
| ๐ Hot-plug friendly | Radios detected at boot, status shown live |
graph TD
A[Radio A - NRF24L01+] -->|VSPI| E[ESP32]
B[Radio B - NRF24L01+] -->|HSPI| E
E -->|I2C| O[SSD1306 OLED]
E -->|WiFi AP| W[Browser Web UI]
E -->|Serial| C[CSV Log]
subgraph 2.4 GHz Band
A
B
end
Each radio walks half the band. The firmware merges both halves into one 126-channel spectrum every cycle, then renders it to the OLED, the web UI, and the serial CSV log.
2.400 GHz 2.525 GHz
|โโโโโโโโโโ Radio A (VSPI) โโโโโโโโโโ|โโโโโโโโโโ Radio B (HSPI) โโโโโโโโโโ|
ch 0 ch 62 ch 63 ch 125
| Component | Qty | Notes |
|---|---|---|
| ESP32-WROOM-32 dev board | 1 | Any variant with the pins below free |
| NRF24L01+ module | 2 | Add a 10 ยตF cap across VCC/GND on each โ they're picky about power |
| SSD1306 OLED 128ร64 | 1 | I2C, address 0x3C |
| 10 ยตF electrolytic capacitor | 2 | One per radio โ not optional |
| Breadboard + jumpers | ~20 | Female-to-male fit the NRF24 header |
| NRF24 Pin | Radio A (VSPI) | Radio B (HSPI) |
|---|---|---|
| CE | GPIO 22 | GPIO 16 |
| CSN | GPIO 21 | GPIO 15 |
| SCK | GPIO 18 | GPIO 14 |
| MOSI | GPIO 23 | GPIO 13 |
| MISO | GPIO 19 | GPIO 12 |
| VCC | 3.3V | 3.3V |
| GND | GND | GND |
OLED: SDA โ GPIO 4 ยท SCL โ GPIO 5 ยท VCC โ 3.3V ยท GND โ GND
โ ๏ธ NRF24 modules run on 3.3V only. Never connect VCC to 5V โ it will kill the radio.
๐ Full step-by-step guide with circuit diagrams: docs/wiring.md
pio run -t upload
pio device monitorOr open the folder in VS Code with the PlatformIO extension and hit Upload.
Within ~2 seconds you'll see A+ B+ and live spectrum bars.
Connect to the ESP32's WiFi AP and open the dashboard:
| ๐ถ SSID | NRF24-Scope |
| ๐ Password | spectrum24 |
| ๐ URL | http://192.168.4.1 |
The browser shows a full-resolution spectrum chart with:
- ๐จ Color-coded bars โ green (quiet) โ yellow โ red (busy)
- ๐บ๏ธ Band overlays โ semi-transparent markers for known 2.4 GHz bands
- ๐ Live stats โ radio health, sweep counter, peak channel + frequency + level
- ๐ท๏ธ Legend โ all marked bands with colors
| Band | NRF24 ch | Color | Typical source |
|---|---|---|---|
| WiFi 1 | 1โ5 | ๐ต Blue | WiFi channel 1 (2412 MHz) |
| WiFi 6 | 4โ8 | ๐ต Blue | WiFi channel 6 (2437 MHz) |
| WiFi 11 | 9โ13 | ๐ต Blue | WiFi channel 11 (2462 MHz) |
| BLE adv | 0โ2 | ๐ข Green | BLE advertising (ch 37/38/39) |
| Zigbee | 11โ26 | ๐ Orange | Zigbee / Thread channels |
| Microwave | 40โ70 | ๐ด Red | Oven leakage (~2.45 GHz) |
| URL | Purpose |
|---|---|
/ |
Main web UI |
/data |
JSON โ full spectrum + stats |
/toggle |
Switch OLED page (spectrum โ peak stats) |
Page 1 โ Spectrum (default)
A+ B+ #1234
[live bar graph with peak-hold dots]
Page 2 โ Peak stats
PEAK STATS
Ch: 6 (2406 MHz)
Level: 87%
Sweeps: 1234
Radio A: OK
Radio B: OK
Toggle via http://192.168.4.1/toggle.
The firmware dumps a CSV line every 5 seconds to serial:
CSV,timestamp_ms,ch0,ch1,ch2,...,ch125
Capture it:
pio device monitor > spectrum_log.csvThen analyze offline โ see docs/usage.md for a ready-to-run Python/pandas example.
| What you see | What it is |
|---|---|
| Tall bars at ch 1โ5 / 4โ8 / 9โ13 | ๐ถ WiFi channels 1 / 6 / 11 |
| Hopping spikes across ch 0โ79 | ๐ง Bluetooth classic |
| Persistent spikes at ch 0โ2 | ๐ณ BLE advertising |
| Broad hump at ch 40โ70 | ๐ฟ Microwave oven (when running) |
| Periodic narrow spikes at ch 11โ26 | ๐ Zigbee / Thread |
| Fixed repeating narrow spikes | ๐ฎ RC links, wireless keyboards/mice |
- ๐ง docs/wiring.md โ step-by-step wiring, circuit diagrams, troubleshooting
- ๐ docs/usage.md โ web UI, OLED, CSV logging, signal interpretation, performance notes
| Metric | Value |
|---|---|
| Sweep rate | ~20 full-band sweeps/sec (50 ms/sweep) |
| Sensitivity | ~โ64 dBm (NRF24 carrier-detect threshold) |
| Resolution | 1 MHz per channel (126 channels / 126 MHz) |
| Web UI latency | 300 ms refresh |
| OLED latency | 50 ms refresh |
This is a poor-man's spectrum analyzer โ energy presence only, no demodulation. That's exactly what makes it legal and safe. For protocol-level decoding you'd need an SDR or dedicated sniffer.
MIT โ see LICENSE. Built from scratch, yours to use and modify.