Initializing DecentralRadar v0.2.0...
STATUS: Illuminating the invisible. π
LAYER: Shadowing the grid. π₯·
RESULT: Maximum signal. π₯
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
βSYSTEM::NODE_SCAN [ββββββββββ] 80% (π°οΈ) LOC: PRIVATE β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β
β β’β€ β₯β£ β
β β’β€ βββββββββββββββββ β₯β£ β
β β β β β β
β β β β’ββββββ£ β β TRK: 5.0 GHz β
β β β β β β β β SIG: STABLE β
β β β β₯ββββββ€ β β BUF: CLEAR β
β β β_________________β β β
β β₯β£ β’β€ β
β β₯β£ GOJOSIX.EYE β’β€ β
β β₯β£____________________β’β€ β
β β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β[!] Illuminating the invisible. | [!] Shadowing the grid. β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
gojosix.eye net is the identity and presentation layer for this repository's desktop app.
The Cargo package name is decentral-radar, but the app itself is presented as a highly stylized signal observatory.
This project is a Linux desktop application that scans nearby WiFi networks and transforms them into a live, radar-like observatory.
It synthesizes:
- π¦ Rust for the UI, state modeling, multi-threading, and spatial heuristics.
- β‘ Zig for high-performance, low-level
nl80211WiFi scanning through a dynamically linked shared library. - π¨ egui/eframe for the buttery-smooth, animated dashboard and radar panel.
- π§ Linux Utils (
nmcliandip neigh) for network context and LAN-neighbor visibility.
The result is a local-first tool for visualizing RF visibility in your physical space, unlocking:
- π Nearby SSIDs & BSSIDs tracking
- π Signal strength (RSSI) historical graphing
- π¦ Spatially-aware channel congestion mapping
- π·οΈ Vendor/OUI hints for unknown signals
- π΅οΈ Connected-device awareness & role hints
- πΆ RSSI-based presence and motion heuristics
- π Room fingerprinting and health summaries
- π Automated network reconnaissance (self-running
nmapscans) - π‘οΈ WiFi attack detection (evil twin / rogue AP / deauth & jamming)
- π€ AI behavioral anomaly analysis
β οΈ Consolidated threat scoring across security, recon, and AI findings
Most WiFi tools fall into two extremes: purely technical, text-heavy CLI outputs, or disconnected web dashboards. gojosix.eye net bridges this gap.
It exists to explore a more tactile, visual, and honest way of looking at the WiFi spectrum. It feels like a rich lab instrumentβgiving you dark control-room energy without relying on black-box "smart" systems.
β¨ Key Differentiators:
- Desktop First: Not a web app. Built raw and close to the metal.
- Direct Kernel Access: The Zig scanner talks directly to Linux interfaces via
nl80211. - Commodity Hardware: Requires NO custom sensor nodes; it runs on standard Linux WiFi gear.
- Environmental Context: Fuses raw WiFi visibility with heuristics for motion, posture drift, signal health, and room fingerprinting.
v0.2.0 upgrades the observatory from pure visualization into a network awareness & security suite with three new engine modules and three new GUI tabs.
The app now automatically fingerprints every LAN peer it discovers (ip neigh) and schedules tiered nmap scans (XML output parsed via quick-xml):
- Tiered scanning β Fast (
-sV -T4 --top-ports 100), Deep (-sV -sC -p- -T3), Stealth (-sS -Pn) - Port risk classification β 50+ ports mapped to Safe / Info / Suspicious / Critical (SSH safe; Telnet, SMBv1, VNC critical; RDP & admin panels suspicious)
- Vulnerability correlator β matches results against built-in CVEs (EternalBlue CVE-2017-0144, BlueKeep CVE-2019-0708, anonymous FTP, plaintext Telnet, weak SNMP, UPnPβ¦)
- Structured report generator β ASCII report + JSON export with prioritized recommendations
- Privilege-aware scans β detected via effective UID; unprivileged runs automatically drop root-only flags (
-O,-sS), so scans never fail on a non-root session - Manual target queueing + auto-scheduling (quick/deep cadence)
- Evil twin / rogue AP β same SSID on multiple vendors, security downgrades (open APs), high-signal hidden APs, new BSSIDs on known SSIDs
- Deauth / jamming detection β EMA signal baselines that flag simultaneous multi-AP drops (jamming) and repeated single-AP drops (targeted deauth)
- New device arrival, IP changes (spoofing), subnet-scan activity spikes, unusual-hour activity, RSSI variance anomalies, and disappeared devices
A unified threat score composites high-severity AI anomalies, recon risk, and critical security alerts, with per-device and network-health framing.
π Reconβ scan controls, per-device results, report generation/exportπ‘ Securityβ ranked alert feed with evidence & recommendationsβ Threatsβ composite score, AI anomalies, critical findings, network health
Requirement:
nmapmust be installed for auto-scanning (sudo apt install nmap). The Recon tab shows a warning banner if it's missing.
This project intentionally keeps expectations realistic.
- It uses WiFi RSSI heuristics, not dedicated body sensors.
- Words like "Pose", "vitals", "presence", and "motion" are interpretive estimates based on RF signal behavior.
- π Disclaimer: Treat this as an experimental observatory tool, not as a medical, safety, surveillance, or security system.
Linux WiFi / NetworkManager / neighbor table
β
βββ Zig scanner (.so) ββ> nl80211 kernel path
β
βββ nmcli / ip neigh ββ> local network context
β
βΌ
Rust app state ββ> monitoring heuristics ββ> egui observatory & radar
β²
β (background threads, each sharing Arc<Mutex<T>> state)
βββ recon:: nmap XML parsing + vulnerability correlation + reports
βββ security:: evil twin / rogue AP / deauth / jamming detection
βββ ai:: behavioral anomaly analysis
Key moving parts:
build.rs: Automatically invokeszig build -Doptimize=ReleaseSafe(falls back to a prebuiltlibwifi_scan.sowhen the Zig toolchain is unavailable).native/src/scanner.zig: Builds the fast, low-level shared scanner library.src/scanner/: Handles Rust FFI and scan data parsing.src/gui/: Renders the immersive dashboard, tabs, and sweeping radar.src/monitoring/,src/pose/,src/vitals/: Computes heuristics and summaries.src/recon/: Self-runningnmapscans, port-risk database, CVE correlator, report/JSON export.src/security/: RF-attack detection (evil twin, deauth, jamming).src/ai/: Behavioral anomaly analysis (subnet scans, spoofing, unusual activity).
This project is currently Linux-first and targeted at Ubuntu-style desktop environments.
Note: It expects a graphical session for
eframe/winit. Headless or compositor-less runs may fail withWaylandError. Scan depth depends on your adapter's capabilities.
Required Tooling:
rustc&cargo(1.94.0+)zig(0.13.0) - Use version 0.13.0 to prevent build API drift.nmap(for the Recon feature's automated scanning) -sudo apt install nmap
π¦ Install Rust:
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
source "$HOME/.cargo/env"β‘ Install Zig (0.13.0):
mkdir -p ~/opt && cd ~/opt
# Download the Zig release archive manually from ziglang.org/download -> Linux x86_64
tar -xf zig-linux-x86_64-0.13.0.tar.xz
echo 'export PATH="$PATH:$HOME/opt/zig-linux-x86_64-0.13.0"' >> ~/.zshrc
source ~/.zshrcgit clone https://github.com/zang7777/six-eye gojosix-eye
cd gojosix-eye
cargo runBehind the scenes: Cargo builds the Rust front-end, triggers build.rs to compile the Zig library in native/, links them, and launches the UI.
| Task | Command |
|---|---|
| Run App | cargo run |
| Test Rust | cargo test |
| Test Zig | cd native && zig build test |
| Format Rust | cargo fmt |
gojosix-eye/
βββ build.rs # Rust build script (runs Zig / prebuilt .so fallback)
βββ native/ # Zig codebase
β βββ build.zig # Zig build definition
β βββ src/scanner.zig # nl80211 WiFi scanner core
β βββ zig-out/lib/ # Prebuilt libwifi_scan.so (build fallback)
βββ src/ # Rust codebase
β βββ gui/ # UI components (dashboard, radar, tabs, export)
β βββ monitoring/ # Observatory summary logic
β βββ pose/ # Posture estimation heuristics
β βββ vitals/ # Vitals-like RSSI drop/spike analysis
β βββ scanner/ # Rust FFI wrapper for Zig scanner
β βββ signal_health.rs # Environmental health & fingerprinting
β βββ recon/ # nmap scanning, port risk, CVE correlator, reports
β βββ security/ # evil twin / rogue AP / deauth / jamming detection
β βββ ai/ # behavioral anomaly analysis
β βββ models/ # Shared domain data models
βββ assets/
βββ oui/oui.txt # Vendor MAC lookup data
βββ gojosix-eye-net.svg # Original SVG assets
The app can export JSON snapshots of the current observatory state for external analysis.
gojosix_eye_net_export_YYYYMMDD_HHMMSS.json
- Richer radar animation and decaying target trails
- Stronger per-band filtering (2.4GHz / 5GHz / 6GHz)
- Spectrum-style frequency overlays
- Better Linux packaging (AppImage / Flatpak / DEB)
- Saved sessions and historical replay mode
- Temporal diffing between saved room fingerprints
- Export recon reports to Markdown/HTML
- Historical threat timeline & alert dedup across reboots
- Integration with
nmapOS detection when run as root
Licensing Dual-licensed under either:
Credits
- Inspired by the legendary RuView aesthetic.
- Built locally by builders, for RF experimenters, and systems-minded tinkerers.
