Al-Anqa

Offensive security firmware for the LilyGo T-Deck β€” hacker CLI in your pocket.

Al-Anqa turns the LilyGo T-Deck into a pocket pentesting terminal. No menus, no GUI β€” just a blinking cursor, a physical keyboard, and a full suite of offensive security tools running on an ESP32-S3.


⚠️ Legal Disclaimer β€” For authorized security testing, CTF competitions, and educational use only. Always get written permission before testing.


Documentation

πŸš€ Start Here


πŸ“‘ WiFi


🌐 Network

  • Net Discover β€” netdiscover
  • Net Spy β€” netspy / ns β€” [EXP] passive client-isolation device recon (AirSnitch)
  • Iso Scan β€” isoscan / is β€” [EXP] active isolation audit: GTK inject + capture (AirSnitch)
  • Port Scan β€” portscan Β· ps top Β· banner grabber Β· OS fingerprint
  • Ping β€” ping
  • SSH Client β€” ssh β€” interactive colour terminal + scrollback
  • ARP Spoof β€” arpspoof β€” L2 ARP cache poisoning + redirected-traffic log
  • Responder β€” responder β€” [EXP] LLMNR/NBT-NS/mDNS poisoner + NetNTLM capture
  • Default-Password Check β€” dpwo / dw β€” default creds on FTP/SSH/Telnet/HTTP/RTSP/Redis/MQTT/SNMP (custom ports too)
  • Chromecast Control β€” cast / ca β€” discover Cast devices, rickroll, play URLs/saved content, share local SD photos/videos

πŸ”΅ Bluetooth


πŸ”Œ USB


βš™οΈ System


Quick Start

Requirements: VSCode + PlatformIO extension

git clone https://github.com/abdallahnatsheh/AL-ANQA-FIRMWARE
# Open in VSCode β†’ select env:T-Deck or env:T-Deck-Plus β†’ click Upload

Can’t upload? Hold the trackball button, plug in USB, then try again β€” this forces download mode.


Hardware

Component Details
Devices LilyGo T-Deck Β· LilyGo T-Deck Plus
MCU ESP32-S3 (16 MB flash, 8 MB PSRAM)
Display 320Γ—240 ST7789 TFT
Input Physical QWERTY keyboard + trackball
Radio WiFi 2.4 GHz Β· Bluetooth 5 Β· LoRa SX1262
GPS L76K / u-blox M10Q (T-Deck Plus only)