iBT — a passive Bluetooth / BLE observer for Sailfish OS
iBT turns a Sailfish OS phone into a strictly passive Bluetooth / BLE security and analysis tool. Using only the phone's own radio (via BlueZ), it listens to the advertising data that nearby devices broadcast anyway and makes sense of it — without ever transmitting, connecting, intercepting, attacking, logging or exporting anything.
Developed and tested on J2 and Xperia10III.
What it does
-
Live device scan — name, MAC, address type (random/static), RSSI, rough distance, device kind (LE / Classic / dual), advertised services and manufacturer data.Radar view — a heading-up proximity radar of the devices around you, plus a sortable list and a per-device detail page.
-
Beacon decoding — iBeacon, Eddystone and AltBeacon.Unwanted-tracker detection — flags AirTag / SmartTag / Tile-style trackers that may be following you.
-
Threat-gadget recognition — passively classifies well-known hostile Bluetooth gadgets by their advertising signature.
-
Attack detection — spots advertising-layer BLE-spam / flood activity.
-
Vendor fingerprinting — offline OUI → vendor lookup.
-
CVE lookup — on request, queries public vulnerability data for a device's vendor / model (egress happens only when you tap it).
-
Map view — an optional OpenStreetMap view, used purely to centre on your current position; the location never leaves the device except for the tile request you trigger.
What it deliberately does NOT do
iBT is built to be legally unambiguous and privacy-respecting:
-
beyond the ordinary link-layer discovery signal that every Bluetooth scan (including the phone's own system settings) uses to find nearby devices, it sends no information and actively queries nothing — no connection, no GATT, no pairing;
-
it never intercepts or decrypts traffic;
-
it never attacks, jams or manipulates anything;
-
it keeps no logs, performs no data export, and does no background data collection or aggregation;
-
the only thing it persists is your own app settings.
Everything it shows — device fields, advertised services, service data and the connection/pairing status — is read locally from the phone's BlueZ interface, never asked of the remote device. It reads what every device freely advertises into the air — nothing more.
Recent comments