Sub-GHz Signal Capture and Replay on Flipper Zero
Sub-GHz Signal Capture and Replay on Flipper Zero The Flipper Zero has a built-in Sub-GHz radio (300–928 MHz) for capturing and replaying wireless signals from remotes, key fobs, and simple RF devices. ⚠️ Legal and Ethical Note Transmitting on certain frequencies may require a license in your region. The Sub-GHz radio in Flipper can transmit — use only on devices you own. Replaying signals to gain unauthorized access is illegal. Supported Frequency Ranges 300–348 MHz 387–464 MHz 779–928 MHz Most consumer remotes operate in the 315, 433, or 868/915 MHz bands. Reading/Capturing a Signal 1. Go to Sub-GHz → Read 2. Point your remote at Flipper's back-left corner 3. Press the button on your remote 4. Flipper displays the signal type if recognized, or raw data 5. Save — give it a name Recognized Protocols (Decoded) Flipper can decode many common fixed-code protocols: Decoded = Flipper stores the actual code and can retransmit as that protocol. Raw Capture (Unknown Protocols) If Flipper doesn't recognize the protocol: 1. Sub-GHz → Read RAW 2. Press button on remote — captures raw signal timing 3. Save as .sub file 4. Can replay raw (works for simple fixed-code devices) Rolling Code (Won't Work) Modern car key fobs, smart garage openers (HomeLink compatible), and security systems use rolling codes — the code changes every press. Capturing and replaying will NOT work. Flipper captures the code but replay is rejected by the receiver. Examples of rolling code (cannot replay): Modern car key fobs (2015+), LiftMaster Security+ 2.0, Chamberlain myQ, most alarm remotes Replaying 1. Open saved signal from Sub-GHz files 2. Press Send — Flipper transmits the signal 3. Point at receiver at appropriate range (0.5–5 meters typically) Frequency Scanning Sub-GHz → Read → Frequency Analyzer — sweeps and shows active frequencies. Good for finding what frequency your device uses before capturing. Practical Uses (Your Own Devices) Backup your garage door remote signal Analyze what frequency your home automation remotes use Test your own RF-controlled devices for vulnerability research Replace a lost remote (for fixed-code devices you own)
Related Guides
- How to Hack Sub-GHz Radios with the Flipper Zero: Protocols, Analysis, and Signal Crafting
- Creating Your Own Sub-GHz Remote Profiles for Custom Devices
- Flipper Zero SubGHz: Reading, Recording, and Replaying RF Signals
- Sub-GHz Replay: Fixed Code vs Rolling Code Explained
- Upgrading Flipper Zero Sub-GHz Range with an External Antenna
- Flipper Zero: Getting Started with BadUSB, Sub-GHz, and NFC
- Using Flipper Zero to Analyze and Clone Gate Remote Signals
- Flipper Zero Infrared: Clone and Control Any Remote