← LibraryTechnique entry
IOT-BLE-EAVESDROPCredential Access
BLE Eavesdropping
Sniff BLE pairing with Ubertooth / Sniffle / nRF52 — capture LTK / IRK on insecure (Just Works) pairing.
§ Where this technique fits
IOT-BLE-EAVESDROP is catalogued under the Credential Access tactic of the offensive-security kill-chain. It appears in 2 approved dossiers in the registry, typically at step 1.5 on average.
§ Dossiers chaining this technique
- step 1 / 5
Zigbee network key sniff → smart-home control
Sniff a fresh device-join with an Atmel RZRAVEN — Zigbee broadcasts the network key in plaintext during pairing. Decrypt all subsequent traffic + send commands.
- step 2 / 5
BLE eavesdrop + replay → smart lock open
Smart lock uses BLE Just-Works pairing + plaintext 'unlock' opcode. Sniff once with a nRF52 in monitor mode, replay later from a $10 device.
§ What commonly comes next
- 01Deauthentication DoSseen 1×WIFI-DEAUTH · Impact
- 02File and Directory Discoveryseen 1×T1083 · Discovery