WiFi Probe Mode, Passive Sniffer, MAC Addresses, TZ-DT06, ESP M2,5V
zoom_out_map
chevron_left chevron_right

Product images are for informational purposes only and may vary slightly depending on the batch and supplier. Product specifications and prices may be subject to change without notice. We do our best to provide accurate and complete product specifications, but they may not be completely accurate. If you encounter any such situation, please let us know.

The product is intended for specialists and requires qualified and authorized personnel. The product does not include assembly/use instructions . Putting the product into operation by unqualified persons leads to the loss of the warranty according to the Terms and Conditions on the site.

The specified technical parameters (current, power, etc.) represent maximum allowable values under ideal operating conditions. For safe use and optimal lifespan, it is recommended to operate the product continuously at no more than 50% of the specified maximum values.

New

WiFi Probe Mode, Passive Sniffer, MAC Addresses, TZ-DT06, ESP M2,5V

Compact module for passive 802.11 sniffing, captures MAC addresses from probe requests for monitoring nearby WiFi devices without network association. Quickly transmits data over UART in hex format with timestamp and CRC, has a FIFO buffer to prevent losses, and an adjustable RSSI threshold for distance filtering. Compatible with 3.3V or 5V, ideal for pedestrian traffic analysis and presence detection.

26.20 RON Tax included

21.65 RON Tax excluded

No reviews yet
1-2 zile
check In Stoc

Shipping by Thursday 27 August

Close

This product has a warranty of 2 years.

INTERNATIONAL DELIVERY
International fast shipping within EU. Free Shipping for orders above 100 EUR in most EU countries.
FAST DISPATCH 24H
We ship from our stock within 24H
LOYALTY POINTS
You earn points with every order, worth 5%.

The WiFi Probe TZ-DT06 module is a compact and efficient solution for passive capture of MAC addresses from 802.11 probe request frames, enabling identification and monitoring of nearby WiFi devices without requiring an active network connection or association with an access point. Built around the ESP-M2 chip (derived from the ESP8266), the module works by intercepting broadcast signals automatically emitted by any WiFi device when it searches for known networks around it.

Each capture transmitted over UART includes the sender’s MAC address, the OUI identifier for determining the device manufacturer, a microsecond-precision timestamp, and a CRC checksum for verifying data integrity. The transmission format is raw hexadecimal, with a latency of approximately 45 ms per packet. An internal FIFO buffer with a capacity of 10 packets prevents data loss during host latency periods.

The minimum RSSI reception threshold is configurable between -75 dBm and -90 dBm, allowing signals from outside the area of interest to be filtered out. The practical detection range with the integrated 2 dBi antenna is 12 - 15 meters, and MAC address capture accuracy is 96%. Communication with the host microcontroller is done via UART at configurable rates between 300 and 3686400 baud, and the module is compatible with Arduino, ESP32, STM32, and any other platform with a 3.3V or 5V TTL serial interface. The module can also operate completely independently, with no external microcontroller, thanks to the ESP-M2 chip, which is itself a complete microcontroller with integrated processor, flash memory, and WiFi.

The module features two integrated tactile buttons: the G button (SW1/FLASH), connected to GPIO0, allows entry into bootloader mode for firmware updates when held down at startup, and the R button (SW2/RESET), connected to the RST pin, resets the module without interrupting power. GPIO4 controls the built-in LED with STATE indicator function, with four distinct behaviors: continuously on when successfully connected to the WiFi router in STA mode, slow blinking in AP mode when connection fails or in STA mode while searching for networks, fast blinking when data is received or transmitted over the network or serial, and LED off in the case of abnormal operation or missing transparent transmission firmware.

Average operating consumption is 80 mA, with peaks of 170 mA during transmission. Deep sleep mode reduces consumption to 20 µA, making it suitable for battery-powered applications with periodic scanning at configurable intervals. The module supports STA, AP, and combined SoftAP+STA modes, TCP Server, TCP Client, UDP Server, UDP Client, and UDP local broadcast, OTA firmware updates, and configuration via the integrated HTTP web interface, accessible directly from the local network browser. Advanced configuration is also possible through serial AT commands, without requiring any active WiFi connection.

Typical practical applications include visitor counting in retail spaces or exhibitions, presence detection in controlled areas, pedestrian traffic analysis (frequency, dwell time, peak hours), and simple alarm systems for detecting unknown devices. By using the OUI code extracted from the captured MAC address, the module allows identification of the manufacturer of each detected device, useful in inventory or network audit scenarios.

It is important to note that modern devices running iOS 14 or newer and Android 10 or newer use MAC address randomization, generating different addresses for each scanning session. This limitation reduces the accuracy of long-term individual device identification and must be taken into account when designing the application. For statistical people-counting scenarios the impact is minimal, but for tracking a specific device over time reliability can be significantly reduced.

 

Specifications:

Chip: ESP-M2 (based on ESP8266)

CPU: Tensilica L106, 32-bit, 80MHz / 160MHz, RTOS support

Internal flash: 1MB SPI

ADC: 1 channel, 10-bit

Supply voltage: 4.5 - 6.0 VDC (recommended 5 VDC)

TTL voltage: 3.3V (5V compatible)

Average active consumption: 80mA

Transmission peak consumption: 170mA

Deep sleep consumption: 20µA

Standby consumption (DTIM3): 1.0mW

Wake-up time from deep sleep: 2ms

Frequency: 2.4GHz (802.11 b/g/n/e/i)

WiFi security: WPA/WPA2 PSK, WPS, Wi-Fi Direct (P2P), SmartConfig

Scan mode: Passive (probe request sniffing)

Detection range: 12 - 15m (integrated 2dBi antenna)

Main interface: UART (300 - 3686400 baud)

Serial settings: baud rate, data bits, parity, stop bits, subpacketization time

Network modes: TCP Server, TCP Client, UDP Server, UDP Client, UDP broadcast

Internal buffer: FIFO, 10 packets

Configurable RSSI threshold: -75dBm - -90dBm

Data latency: ~45ms

Timestamp precision: microsecond

MAC capture accuracy: 96%

Data format: raw hexadecimal

Configuration: HTTP web interface, serial AT commands, OTA

Alternative firmware: ESP-LINK v3.0.14

Integrated buttons: SW1/G - FLASH (GPIO0), SW2/R - RESET (RST)

Drop-in compatibility: directly replaces the HT-06 serial Bluetooth module

Platform compatibility: Arduino, ESP32, STM32, any platform with 3.3V/5V TTL UART, standalone

Operating temperature: -40 - +125°C

Dimensions: 34 x 17 x 4mm

 

Pinout:

Pin Name Function
1 GPIO4 STATE - WiFi status indicator / built-in LED
2 GPIO3 RXD0 - UART reception - connected to host TX
3 GPIO1 TXD0 - UART transmission - connected to host RX
4 GND Common ground
5 VCC Supply 4.5V - 6.0V, recommended 5V
6 EN Module enable: HIGH active, LOW disabled
- GPIO0 SW1/G - FLASH button, bootloader mode at startup
- RST SW2/R - module RESET button

 

Usage:

Power the module with 5V through the VCC and GND pins. Make sure the power supply can provide at least 200mA to cover transmission current peaks.

Leave the EN pin connected to VCC for normal operation. Connect EN to GND to disable the module without interrupting power, useful in software-controlled low-power scenarios.

At first power-up, the module automatically enters AP mode and creates its own WiFi network. Connect from your phone or laptop to this network, open the browser, and access 192.168.4.1 to open the integrated HTTP web interface.

From the web interface, configure the WiFi network the module should connect to, the baud rate, the RSSI threshold, the operating mode (STA, AP, STA+AP), and the network connection type (TCP/UDP Server or Client).

After saving the configuration, the module resets and connects to the configured WiFi network. The STATE LED (GPIO4) lights continuously upon successful connection.

For UART use: connect the module’s TXD 0 (GPIO1) pin to the host microcontroller’s RX pin and RXD 0 (GPIO3) to its TX pin. Do not reverse the data lines. Configure the host serial port to 115200 baud, 8N1 (8 data bits, 1 stop bit, no parity).

At startup, the module automatically begins passive scanning and transmits captured MAC addresses over UART in raw hexadecimal format. Watch the STATE LED to confirm operation: slow blinking indicates active network searching, fast blinking indicates data transmission.

Adjust the RSSI threshold to filter devices outside the area of interest. A value of -75 dBm limits captures to devices in the immediate vicinity, while -90 dBm extends the detection range to the maximum.

Enable deep sleep mode from the web interface or via a serial AT command for battery-powered applications. Configure the wake-up interval according to the desired scanning frequency.

To update the firmware via serial port: hold down the SW1/G (FLASH) button, then briefly press SW2/R (RESET) and release SW1. The module enters bootloader mode and is ready for programming. After the transfer is complete, briefly press SW2/R (RESET) to restart normally.

For a simple module restart without firmware update, briefly press the SW2/R (RESET) button. The module resets and resumes passive scanning automatically.

Firmware updates can also be performed wirelessly via OTA, directly from the HTTP web interface, without needing a physical connection to a programmer.

When processing captured data, keep in mind the MAC randomization limitation present on devices with iOS 14 or newer and Android 10 or newer. For statistical counting applications this limitation has a reduced impact, but for tracking a specific device a supplementary data correlation strategy is required.

 

Documentation:

Below you will find external documentation and, in the Download Firmware section, the official documentation.

https://mischianti.org/doit-dt-06-high-resolution-pinout-and-specs/

88244

Produs destinat utilizarii in proiecte electronice, automatizari, prototipare, educatie si cercetare.

Produsul trebuie utilizat numai conform specificatiilor tehnice mentionate in descriere si/sau in documentatia produsului.

Avertismente generale de siguranta:

Nu utilizati produsul la tensiuni, curenti sau temperaturi peste valorile specificate.

Montajul si conectarea trebuie realizate de persoane cu cunostinte tehnice minime in domeniul electric/electronic.

Evitati scurtcircuitele, inversarea polaritatii si conectarea gresita a alimentarii.

Nu lasati produsul alimentat nesupravegheat in timpul testelor.

Produsul nu este jucarie si nu este destinat copiilor.

Pentru modulele electronice, se recomanda utilizarea in carcase, panouri sau montaje protejate, dupa caz.

Identificare produs:

Denumirea produsului, codul/SKU-ul si caracteristicile tehnice sunt mentionate in pagina produsului si/sau pe eticheta ambalajului.

Producator / Importator / Distribuitor:

Sigmanortec S.R.L.

Calea Bucuresti nr. 9, Targu Jiu, Gorj, Romania

E-mail: [email protected]

Website: www.sigmanortec.ro

Persoana responsabila in UE:

Sigmanortec S.R.L.

Calea Bucuresti nr. 9, Targu Jiu, Gorj, Romania

E-mail: [email protected]

Documentatie si siguranta:

Pentru informatii suplimentare, fise tehnice, declaratii de conformitate sau instructiuni, ne puteti contacta la [email protected].