Skip to content

ZeroTrace AirLeak Pro

What It Captures

The Wi-Fi networks, clients and Bluetooth devices AirLeak Pro identifies

AirLeak Pro captures on two fronts at once, Wi-Fi (2.4 GHz and 5 GHz) and Bluetooth LE, and merges both into one live view in the app.

Two radios, one picture

Wi-Fi scanning runs on the Pro's dedicated dual-band radio; Bluetooth runs alongside it. You don't switch between them, both feed the same capture at the same time.


Wi-Fi: access points

For every network it hears, AirLeak Pro surfaces:

FieldWhat it tells you
SSIDThe network name (or a hidden marker when the network cloaks its name; also flags a network that was hidden but has since revealed its name)
BSSIDThe access point's MAC address
Band2.4 GHz or 5 GHz (the Pro sweeps these two bands only, no 6 GHz)
ChannelThe operating channel
Signal (RSSI)How strong it was heard, in dBm, kept as current / best / min / max
SecurityOpen, WEP, WPA-PSK, WPA2-PSK, WPA/WPA2, WPA2-Enterprise, WPA3-SAE, WPA2/WPA3, WAPI, or OWE (enhanced open)
Protected management framesPMF required and/or capable
WPSWhether Wi-Fi Protected Setup is advertised, plus locked and active-registrar states
Wi-Fi generationWi-Fi 4 (n), Wi-Fi 5 (ac), Wi-Fi 6 (ax), or Wi-Fi 7 (be)
Device classBest-guess AP type: router, mobile hotspot, public hotspot, enterprise AP, repeater, printer, camera, smart TV, IoT, smart-home hub, gaming console, vehicle
HiddenWhether the network hides its SSID (and whether it was previously hidden)
First / last seenWhen it entered and was last heard

Networks are de-duplicated as you move, one row per access point, updated as its signal changes, so a drive through a dense area produces a clean inventory rather than thousands of repeats.

No 6 GHz / 6E band

The Pro sweeps 2.4 GHz and 5 GHz only. It classifies each network's generation as Wi-Fi 4/5/6/7 from the advertised capabilities. There is no separate "Wi-Fi 6E" marker and no 6 GHz sweep, a 6 GHz-capable radio's 2.4/5 GHz presence is still seen and reported as Wi-Fi 6.

Why 5 GHz matters

Most modern routers run their fastest network on 5 GHz. A 2.4-GHz-only scanner misses those entirely. AirLeak Pro sees both bands, so your survey reflects what's actually deployed.

The Wi-Fi survey is not purely passive

Alongside listening, the Pro does light active probing, it injects randomized probe requests and a single KARMA wildcard probe to coax hidden SSIDs into the open and to surface lure responders (rogue APs that answer any network name). Networks that answered the wildcard, or that behave like a lure, are flagged (answered_wildcard, lure_responder, karma). This transmits, so treat the survey as active and only run it where you're authorized to.


Wi-Fi: clients

Beyond access points, the Pro also picks up client devices that are actively looking for networks. When a phone or laptop probes for a remembered network by name, the Pro captures:

  • The client's MAC address, flagged as randomized or real
  • The network name it's searching for
  • Signal strength and when it was seen

This is the surface that reveals which networks a device "remembers", useful for privacy audits and understanding a device's history. Devices using MAC randomization are clearly marked as such.


Bluetooth LE: devices

On the Bluetooth side, AirLeak Pro runs the full AirLeak device-intelligence stack. It listens to BLE advertisements and classifies each device into a specific type with a confidence score, and decodes rich per-device detail.

The recognized device classes and the per-device fields are the same as the standard AirLeak, covering the Apple ecosystem, phones, PCs, TVs, wearables, trackers, audio, smart-home/IoT, and more.

Full BLE reference

For the complete list of Bluetooth device classes, the fields captured per device, and the privacy signals detected, see the standard AirLeak's What AirLeak Sees, the Pro's Bluetooth capture is identical.

Highlights of the BLE side:

  • Device class + confidence, each device is sorted into one of ~35 classes (iPhone, iPad, Mac, Apple Watch, AirPods, AirTag, Android/Samsung/Pixel phones, Windows PC, printer, smart TV, HomeKit light/lock/sensor, IoT sensor, headphones, speaker, fitness, HID, vehicle, beacon, Flipper Zero, Matter, smart watch, Samsung SmartTag, Google tracker, and more) with a 0–100 confidence score
  • Trackers, AirTag / Find My, Tile, Samsung SmartTag, Google Find My Network, Chipolo, with separated-from-owner and unpaired state
  • Apple Continuity, live device state (screen on/off, in-call, handoff, OS hints), plus AirPods L/R/case battery and charging
  • Find My battery level on supported accessories
  • Environmental sensors, temperature, humidity and battery broadcast by BLE sensor beacons
  • MAC-randomization type, whether the address is public, RPA (resolvable), NRPA (non-resolvable), or random-static
  • Rich per-device fields, appearance, advertised service UUIDs, TX power, distance estimate, company ID, model, and more
  • Privacy signals, AirDrop discoverable, unwanted-tracker flags, combined leakage score
  • Cross-MAC tracking, follows a device across MAC rotation where its advertisement is fingerprintable

Location tagging

On a drive, observations are tagged with the location where each network or device was heard strongest, using your phone's GPS through the app, and exported as WiGLE-compatible CSV for mapping. Want the board to wardrive without a phone? An optional on-board GPS module lets it run standalone. See GPS.


Where a field hasn't been observed (for example, no name from a hidden network or a randomized client), the app shows an em-dash rather than guessing.

Command Palette

Search for a command to run...