Sniffing Zigbee and Thread Traffic with a Flipper Zero and an External CC2652 Add-On Board
This site's Flipper Zero coverage includes external radio add-ons for Sub-GHz relay work and GPS logging over the GPIO header, but the Flipper's own radios — Sub-GHz, NFC, Infrared, and BLE — have no path into 802.15.4, the 2.4GHz link layer that both Zigbee and Thread run on. Zigbee2MQTT and Home Assistant users troubleshooting mesh network problems, or anyone curious what their smart-home devices are actually saying to each other, need a proper 802.15.4-capable radio to see that traffic at all. Texas Instruments' CC2652 (and its close relatives, the CC1352 and CC2650) are the parts the open-source Zigbee/Thread sniffing community has standardized on, and pairing one with a Flipper Zero over GPIO turns the Flipper into a portable, battery-powered logging and triggering front-end for a capability it doesn't have natively.
Why Zigbee and Thread Need Different Hardware
Zigbee and Thread both operate in the 2.4GHz ISM band using the IEEE 802.15.4 physical and MAC layer — a direct-sequence spread spectrum, O-QPSK modulated protocol that has nothing in common with the Flipper's Sub-GHz CC1101 transceiver (which covers 300-928 MHz ISM bands entirely below 1GHz) or its NFC/RFID front end. Capturing 802.15.4 frames requires a radio built for that specific PHY, and the CC2652 is purpose-built for exactly this: it's the radio at the heart of many commercial Zigbee coordinators and, running TI's open-source sniffer firmware, turns into a capable packet capture device that outputs standard PCAP-compatible frames over a serial connection.
Parts List
- CC2652P or CC2652RB USB dongle (the same hardware family used for Zigbee2MQTT coordinators, flashed with TI sniffer firmware)
- Flipper Zero
- Jumper wires or a GPIO breakout for the Flipper's header
- USB OTG adapter (if driving the sniffer dongle directly from a phone or laptop instead of the Flipper's UART)
- Filament for a printed mount joining the Flipper and sniffer dongle into one handheld unit (optional)
Difficulty, Time, and Tools
Difficulty: Intermediate — requires flashing third-party firmware onto the CC2652 dongle and comfort with Wireshark for the payload-analysis side.
Build time: 1-2 hours for firmware flashing and wiring; longer if you 3D print a combined enclosure.
Tools required: A computer to flash the CC2652 dongle's firmware over its own USB port, and a way to view captured traffic (Wireshark, with TI's sniffer plugin, is the standard tool for 802.15.4 capture).
Flashing the Sniffer Firmware
TI publishes an open-source packet sniffer firmware for the CC2652/CC1352 family as part of their SimpleLink SDK, and community-maintained builds (widely used within the Zigbee2MQTT ecosystem, which relies on the same silicon) are readily available pre-compiled. Flash it using TI's UniFlash tool or the dongle's built-in bootloader over USB — the same process used to load Zigbee2MQTT coordinator firmware onto this hardware, just a different firmware image. Once flashed, the dongle enumerates as a serial device and speaks TI's sniffer protocol: it can be commanded to tune to a specific 802.15.4 channel (channels 11-26 cover the 2.4GHz Zigbee/Thread range) and streams captured frames as they're heard.
Wiring the Flipper Zero as the Front End
The Flipper Zero's role here is as a portable UART bridge and logger rather than a full packet decoder — the CC2652's own firmware does the actual 802.15.4 reception and framing. Two practical integration paths:
- Flipper GPIO UART bridge mode — wire the CC2652 dongle's TX/RX/GND lines to the Flipper's GPIO header UART pins (following the same UART wiring convention this site's Flipper GPIO pinout guide covers), and use the Flipper's built-in UART terminal app to view and log the raw serial stream to its SD card for later analysis on a computer — genuinely useful for field capture sessions where carrying a laptop isn't practical.
- Flipper as USB host to the dongle — using the Flipper's USB-UART bridge capability, the dongle can be powered and read through the Flipper acting as an intermediary, letting you trigger capture start/stop from the Flipper's screen and buttons rather than a keyboard.
Either way, the heavy lifting — actually decoding 802.15.4 MAC headers, Zigbee network layer framing, or Thread's 6LoWPAN encapsulation — happens afterward in Wireshark on a full computer, following the same PCAP workflow this site's Flipper PCAP guide describes for other capture sources. The Flipper's job is field-portable capture and logging, not on-device protocol decode.
What You Can Actually See
Captured 802.15.4 traffic reveals network topology (which devices are talking to which coordinator or router), timing and retry patterns useful for diagnosing a flaky mesh, and — for unencrypted commissioning traffic on some networks — join procedure details. Zigbee's application-layer payloads are typically encrypted with a network key that isn't visible in the capture itself unless you already have that key from your own coordinator's configuration (Zigbee2MQTT users can export their own network key to decrypt their own captured traffic in Wireshark, which is the main practical use case: diagnosing your own mesh, not reading someone else's).
Legal and Practical Notes
This build only receives — it has no transmit capability and does not interfere with or inject anything into a Zigbee or Thread network. Passively receiving radio traffic in an unlicensed ISM band you have a receiver for is broadly legal, the same footing as the site's other RF-monitoring builds, though decrypting and using data from a network you don't own or have permission to analyze raises separate ethical and, depending on jurisdiction, legal considerations beyond just receiving the signal — keep this tool pointed at your own network's diagnostics.
This gives the Flipper Zero ecosystem a genuinely missing capability — visibility into the 2.4GHz mesh protocols running most smart-home networks — using the same open hardware already trusted by the Zigbee2MQTT community, wired in through the Flipper's existing GPIO UART pattern rather than requiring a whole separate capture rig.