Pocket Pentest Stick – M5Stick
Pocket-size radio lab: run deauths, Evil-Twin captive portals, beacon floods, BLE HID tests, and record Wireshark-ready PCAPs — add CC1101 or PN532 for sub-GHz and NFC.
Radio-first testing
Wi-Fi (Client/AP/Monitor) + BLE in one pocketable device for scan, emulate, hijack.
Capture & analyze
RAW PCAP + WPA handshake capture — export to Wireshark for deep inspection.
Rapid lab workflows
One-tap presets (deauth, Evil-Twin, beacon spam) and scriptable SDK automation.
- Wireless Radios – Powerful Wi-Fi + BLE radios in a pocketable platform for full protocol visibility and control.
- Offensive Suite – Pre-built attacks and automation for fast lab testing and red-team workflows.
- Modular Expansion – Plug in CC1101 or PN532 to add sub-GHz and NFC capabilities.
- Payload Ready – Use stock or custom scripts
- Pocket UI & Control – Bright TFT, USB-C, microSD, and SDKs — control from GUI or script.
- Power & Responsible Use – Long-run battery, OTA-safe recovery, and clear ethical usage guidance.
Multi-Mode Operation
When connected directly, it functions as a HID keyboard for scripted keystroke execution. Over Wi-Fi, it allows remote payload execution, mouse control, and keystroke injection without physical interaction.
Wireless Network Simulation
The ZS Cactus PRO can create a honeypot or fake Wi-Fi network to simulate phishing and credential-harvesting scenarios in a controlled environment.
Customizable & Flexible
Use the included ready-to-run payloads for rapid testing, or upload your own scripts for tailored scenarios. Extract information through web-based commands or the built-in FTP server to replicate potential attack vectors.
Cross-Platform Compatibility
Compatible with Windows, Linux, and macOS, making it a versatile tool for labs, training, and penetration testing.
How it compares
If you’re choosing between the Pocket Pentest Stick and other crowd-favorite tools, here are the high-level differences that matter for wireless testing.
vs Flipper Zero
Our stick
- Built-in Wi-Fi / BLE / IR
- Add CC1101 / PN532 as needed
Flipper
- Built-in sub-GHz, NFC, 125 kHz, IR, iButton
- No Wi-Fi without add-on
Best pairing
Use stick for Wi-Fi/BLE & Evil-Twin; Flipper for badges and sub-GHz.
vs LilyGO T-Embed CC1101
Our stick
- Smaller & cheaper
- Focuses on Wi-Fi / BLE / IR first
T-Embed
- Integrates CC1101 + PN532 + IR by default
- Broader RF/NFC labs out of the box
Best pairing
Start with the stick, graduate to T-Embed for sub-GHz/NFC heavy work.
vs LilyGO T-Watch S3
Our stick
- Handheld with IR
- Great for hands-on Wi-Fi/IR demos and drops
T-Watch
- Wearable stealth form factor
- LoRa (not general sub-GHz)
Choose when
Pick T-Watch for on-person recon; use the stick for hands-on demos.




Compare ZS VenomPRO vs ZS Venom
Same trusted toolkit — with a Keylogger available only in PRO.
Tiny, stealthy, deployable
Pocket-size with screen + buttons. Hide it behind a monitor or carry it on a lanyard.
Expand when you’re ready
Snap on CH9329 for USB BadUSB (wired HID), CC1101 for 315/433/868/915 MHz RF replay, or PN532 for NFC labs.
Open & scriptable
Run Bruce modules, host a local web UI, or flash custom ESP32 firmware for bespoke workflows.
Applications
What the Pocket Pentest Stick can be used for:
- ✔️ Penetration Testing: Run deauth, Evil-Twin, beacon spam, and handshake capture to validate Wi-Fi defenses under scope.
- ✔️ Social Engineering: Spin up captive portals and rogue SSIDs to test user behavior and MFA flows safely.
- ✔️ Wireless Recon & PCAPs: Discover APs/clients, enumerate SSIDs, and capture frames for analysis and reporting.
- ✔️ Detection Tuning (Blue-Team): Generate known-bad patterns to calibrate WIPS/WIDS and SIEM rules without guesswork.
- ✔️ BLE/IoT Hardening: Scan and probe BLE devices and shadow IoT to verify segmentation, pairing, and access controls.
All Features & Possible Attacks
Connect to Wi-Fi (client mode)
Wi-Fi Deauthentication
Beacon / SSID Spam (presets)
Phishing Simulations
Offline Cracking Exercises
Packet Capture for Analysis
ARP sweep + TCP port scan
Station Deauth (targeted)
ARP Spoofing (MITM)
ARP Poisoning (broadcast)
TCP Tools
SD Card Logging
Optional Add-on Possibilities
SD Card Expansion
CC1101 Sub-GHz Module
PN532 NFC Add-on
High-Capacity Battery Pack
Bluetooth Antenna Upgrade
Custom Firmware Builds
Recommended Add-ons
CH9329 USB HID Kit
USB HIDEnable wired BadUSB (DuckyScript) via Grove for fast, reliable keystroke delivery.
CC1101 RF Kit
Sub-GHzAdd 315/433/868/915 MHz capture & replay.
PN532 NFC Kit
NFCRead/write/emulate HF NFC badges.
USB-C Power Pack
PowerRun longer deauth/portal sessions.
Attack Simulations
*For authorized environments only.*
- Kick test clients from a lab AP to validate detection & resilience.
- Spin up a phishing captive portal to train staff with safe simulations.
- Trigger TV power-off across common brands with a single payload.




Technical specs
Core
- MCU: ESP32-PICO-V3 (dual-core, Wi-Fi 2.4 GHz + BLE 5)
- Display: 1.14″ IPS TFT (135×240)
- Battery: ~200 mAh Li-Po (USB-C charging)
- Sensors: IMU (motion), microphone
Radio & I/O
- Wi-Fi: 802.11 b/g/n attack suite (deauth, Evil-Twin, handshake capture)
- Bluetooth: BLE scan/advertise, beacon spam experiments
- Infrared: TX diode onboard (TV-B-Gone and custom codes)
- Expansion: Grove port for CC1101 (sub-GHz) & PN532 (NFC) modules
Capabilities depend on local law and target hardware. Use responsibly.
Hacker Starter Kit
Save $10 with this bundle
► + Free 1 Month zSecurity Trial VIP membership.
$99.97
BadUSB Silent Intrusion Kit
Save $5 with this bundle
► + Free 1 Month zSecurity Trial VIP membership.
$59.97
BadUSB Silent Intrusion Kit Plus
Save $5 with this bundle
► USB Data Blocker
► + Free 1 Month zSecurity Trial VIP membership.
$69.97
Detailed Specification
| Spec | Detail |
|---|---|
| Brand | Alfa |
| Model | AWUS036ACH |
| Chipset | Realtek RTL8812AU |
| Wi-Fi standards | IEEE 802.11 a/b/g/n/ac |
| Data rates |
|
| Frequency range | 2.4 GHz & 5 GHz |
| Antennas | 2 × 6 dBi dual-band, RP-SMA detachable |
| OS support | Kali Linux (native or VM) |
| Security | WEP 64/128, 802.1X, WPA/WPA2 Personal & Enterprise, WPA-PSK, WPA2-PSK |
| Dimensions | L8.5cm x W6.3cm x H2.0cm |
Looking for something different?
![]() Alfa AWUS036ACH | ![]() zSecurity RTL8812AU | ![]() zSecurity AR9271 | |
|---|---|---|---|
| Chipset | Realtek RTL8812AU | Realtek RTL8812AU | Atheros AR9271 |
| Wi-Fi Standards | 802.11 a/b/g/n/ac | 802.11 a/b/g/n/ac | 802.11 b/g/n |
| Dual-band | ✅ | ✅ | ❌ |
| Max speed | up to 867 Mbps | up to 867 Mbps | up to 150 Mbps |
| Frequency Range | 2.4 & 5 GHz | 2.4 & 5 GHz | 2.4 GHz only |
| Interface | USB 3.0 | USB 3.0 | USB 2.0 Mini USB |
| Antennas | 2 × 5 dBi | 2 × 5 dBi | 1 × 5 dBi |
| Security Protocols | WEP, WPA/WPA2, WPA-PSK | WEP, WPA/WPA2, WPA-PSK | WEP, WPA/WPA2, WPA-PSK |
| OS Support | Kali Linux (VM & Native) | Kali Linux (VM & Native) | Kali Linux (VM & Native) |
| Monitor & injection | ✔ | ✔ | ✔ |
| Signal Sensitivity | Not specified | Not specified | 11b: -96dBm, 11g/n: -91dBm |
| Price (USD) | $69.99 | $34.99 | $24.99 |
Setting up your ZS Cactus
|
|
|
|
Frequently Asked Questions
Is this legal?
Yes when used on networks/devices you own or have explicit, written authorization to test. Some features (e.g., deauth) may be restricted by local law. Always follow the rules of engagement.
Can it do sub‑GHz or NFC out of the box?
Out of the box it focuses on Wi‑Fi/BLE/IR. Add our CC1101 RF kit for 315/433/868/915 MHz replay or our PN532 kit for NFC labs.
Does it support BadUSB and BadBLE?
BadBLE (BLE HID) is built in. For USB BadUSB (HID over USB cable), add our CH9329 USB HID kit via the Grove port — Bruce supports DuckyScript on StickC Plus2 with this module.
How is this different from Flipper Zero?
Flipper includes sub‑GHz, NFC, 125 kHz and iButton built‑in but lacks Wi‑Fi. The Pocket Pentest Stick excels at Wi‑Fi/BLE/IR in a smaller, lower‑cost form; expand later as needed.
Can I script or extend it?
Absolutely. Bruce firmware offers a web UI and modular apps. You can also flash custom ESP32 firmware (Arduino/IDF/MicroPython).
What’s included?
Pocket Pentest Stick (M5StickC Plus2, Bruce pre‑installed), USB‑C cable, quick‑start card. Add‑ons sold separately.
































Reviews
There are no reviews yet.