Frequently Asked Questions
- All
- Analysis
- Barracuda
- Compatibility
- Features
- General
- Hardware
- Kaiju
- Kaiju Fallback License
- Kaiju Free License
- Kaiju Paid License
- Marauder
- Orders
- Rogue
- Shipping
- Token
Only the Marauder Standard/Ultimate variant does. It can automatically identify device brand and model and integrate with Kaiju for rolling code analysis.
Yes. If you have no active license, you can manually unlock a Remote using the Unlock button, which consumes one token.
Tokens are consumed only when no suitable license is available or when all license quotas have been exhausted.
A token is consumed only if a decoding operation is successful.
Yes, but reassignment is not automatic. You must contact ComThings support to request a license reassignment.
A license can be associated once with an unassigned PandwaRF device.
No. Once a Remote is unlocked, it is never switched back to a locked state.
Yes. Registering a valid license allows previously locked Remotes to be unlocked.
A locked Remote can be unlocked using a valid license, provided you have sufficient quota available.
Key data such as serial number, synchronization counter, and other sensitive details are hidden.
If an analysis requires a specific license that is not available, the resulting Remote is locked and its details are hidden.
A Remote is the result of a Kaiju analysis, whether the decoding succeeds or fails.
Unavailable features are disabled and may not always be displayed in the interface.
Yes. A Kaiju license enables additional features and increases available quotas, effectively boosting the capabilities of compatible PandwaRF devices.
Feature visibility depends on your hardware (Rogue Pro, Rogue Gov, Marauder Ultimate, etc.) and your active Kaiju licenses. Features that are not available for your setup may be hidden or disabled.
If multiple licenses are active, their features and quotas are aggregated. This means quotas and enabled features accumulate across licenses.
Every PandwaRF device includes a lifetime fallback license that provides a limited number of daily or monthly quotas, even if no Kaiju license has been purchased.
No. The fallback license is automatically activated when no paid license is available.
No. All results produced with a valid license or token remain permanently accessible, even after the license expires.
When a license expires, you can still access all previously analyzed or generated remotes in your history. No previously obtained results are deleted or hidden.
Yes. Every license, free or paid, includes quotas that limit the number of actions such as data analysis, rolling code generation, or Secure Decrypt operations.
Yes. Many Kaiju features can be tested for free during a 15-day trial period.
A Kaiju paid license unlocks additional features and higher quotas, such as advanced data analysis, rolling code generation, Secure Decrypt, and other license-dependent capabilities.
Yes, subject to export regulations and product variant restrictions.
PandwaRF Marauder and Rogue Gov use HS Code 8517.70.00.00.
All products are designed, developed, and assembled in France by ComThings.
No. Each decoding or remote generation consumes one token. Tokens do not expire.
Yes. Licenses are available for 1, 2, 5 years, or lifetime. Token-based usage is also available.
Rogue Gov is restricted to Law Enforcement Agencies or companies working with LEA. Verification is required.
No. without a Kaiju license only the rolling code encryption type will be displayed by the Android App. Full rolling code analysis and generation requires Kaiju and an appropriate license.
Yes. Once started, brute force continues even if the smartphone disconnects or the device reboots.
Rogue Gov includes everything in Rogue Pro plus a full commercial device database, alarm support, rolling code attacks, jamming, and LEA-restricted features.
Battery life depends heavily on scan configuration and frequency usage. Continuous multi-frequency scanning can drain the battery quickly. External USB power is recommended for long sessions.
Yes. But only the same captured data can be replayed directly from the same Marauder or transferred to a Rogue device for replay.
Marauder Basic focuses on autonomous capture. Marauder Standard adds timestamps and multi-frequency scanning. Marauder Ultimate adds Kaiju integration, rolling code analysis, model identification, stealth BLE features, and extended warranty.
Yes. Kaiju provides a REST API with Swagger and ReDoc documentation for automation and integration.
Yes. Oversampled data is supported. However, the sampling rate must never be lower than the target device data rate.
Yes. At least two valid rolling code transmissions are recommended. Providing only one codeword significantly reduces success rate.
Yes. PandwaRF Rogue and Marauder are shipped with antennas for 315 MHz, 433 MHz, and 868/915 MHz bands.
ASK, OOK, MSK, 2-FSK, 4-FSK, and GFSK are supported on all ComThings devices.
PandwaRF Rogue and Marauder support sub-GHz frequencies from approximately 300 MHz to 928 MHz, including 315, 433, 868, and 915 MHz bands.
By default, yes. Kaiju runs on ComThings servers. An offline, on-premise Kaiju server option is available for organizations requiring full data control.
Yes. Once the encryption is broken, Kaiju can generate rolling codes that behave exactly like the original remote control.
Kaiju analyzes encrypted rolling code RF transmissions, breaks supported encryption schemes, extracts remote parameters (serial, counter, cipher, etc.), and generates valid new rolling codes.
Yes. Marauder can operate fully autonomously once configured. A smartphone is only required for configuration, synchronization, or data export.
Yes. Kaiju is hardware-agnostic. You can use SDRs such as HackRF or LimeSDR, as long as you provide demodulated binary or hexadecimal data, or supported IQ formats.
Yes. Kaiju is fully compatible with PandwaRF Rogue (Pro and Gov variants) and PandwaRF Marauder Ultimate. Captured RF data can be analyzed directly in Kaiju.
Kaiju supports a very large range of rolling-code based devices, mainly gate openers, garage doors. Supported brands include BFT, FAAC, Nice, Somfy, Came, Chamberlain, Erreka, Aprimatic, and many others. The full and updated list is available on the Kaiju website.
Basic RF knowledge is helpful. However, Rogue Gov and Kaiju significantly reduce the required expertise by providing device databases, automated analysis, and guided workflows.
They are professional tools intended for lawful use only. Some variants and features are restricted to Law Enforcement Agencies or authorized entities. It is the customer’s responsibility to comply with local laws.
The Marauder Standard has a larger memory size than the Basic version (512 captures vs 256 captures). It also can scan 2 frequencies simultaneously and has a higher sampling rate.
Yes, you can use your Marauder and Rogue devices without it but Kaiju is necessary for generating new rolling codes, identifying a device’s brand and model, and other advanced features.
Firmware updates can be performed through the PandwaRF app on the Update tab or via the dialog window when a new update is available. An internet connection is required during the process.
Yes, PandwaRF can be used with Linux through a USB connection for basic commands. We recommend using our custom RFCAT version. You can explore the Linux Quick Start here.
You do not need the Android app to connect to your Linux machine.
PandwaRF devices are designed to be easily held in one hand, making them convenient for on-the-go RF analysis.
You can charge your PandwaRF using a standard micro-USB (for version 3) or a USB C cable (version 4) connected to any USB power source, or by connecting it to a power bank.
During charging:
- If the device is on, the orange LED will blink.
- If the device is off, no LED will light up.
You need to fully charge your PandwaRF at least once for an accurate battery percentage display. When the battery is fully charged, the orange LED will stay on.
Yes, tutorials are available on the ComThings YouTube channel. You can also find in-app tutorials by clicking the three dots in the top right-hand corner of the app.
PandwaRF is an RF (Radio Frequency) analysis tool that allows users to capture, analyze, and manipulate RF signals.
- The PandwaRF Rogue allows you to:
- Capture, replay signals and observe their RSSI
- Transmit new rolling codes for remotes using a valid Kaiju license.
- Generate brute force attacks
- etc…
- The PandwaRF Marauder allows you to:
- Capture, replay signals and store them internally for future analysis
- Export captures to PandwaRF Rogue apps
- etc…
For more information, visit our Wiki page. Feel free to purchase your PandwaRF here!
Yes! PandwaRF can be used with Android tablets as long as they meet the minimum Android version (Lollipop 5.0) and hardware requirements, which should be the case.
Yes, this feature can be enabled in the Information tab of all PandwaRF apps. The auto power-off feature automatically turns off the device after a set period of inactivity. To turn on your PandwaRF, press a button or plug it into a power source.
Yes, PandwaRF supports multiple frequency ranges, compatible with international regulations. Typically, our products are used for sub-1 GHz frequencies, such as 315 MHz, 433 MHz, 868 MHz, and 915 MHz, which are commonly used for remote controls and key fobs.
Yes, PandwaRF Rogue Pro can capture and replay signals from many key fobs. With a valid Kaiju license, you can generate new rolling codes enabling you to replicate a remote. You can find the supported devices at the bottom of this page: Kaiju Welcome Page.
Warning: You are responsible for using this feature in compliance with the law.
The choice of antenna depends on your target frequency range and the environment. Select the antenna with the frequency value closest to your target. Typically, key fobs operate at around 315 MHz or 433 MHz.
No, the PandwaRF apps are designed specifically to detect and interact with PandwaRF devices only. You have to use the app corresponding to your device.
PandwaRF supports sub-1 GHz frequencies ranging from 300 MHz to 928 MHz. When you purchase a PandwaRF device, it comes with three antenna options: 315 MHz, 433 MHz, and 868/915 MHz.
Yes and no.
Most of PandwaRF Rogue and Marauder features are available offline:
- RX
- TX
- Spectrum Analyser
- RF brute force
Online connection (with valid Kaiju account) allows:
- rolling code analysis
- rolling codes generation
When you purchase a Kaiju license or token on PandwaRF website, you receive a License key.
This License key shall be entered in your Kaiju profile.
PandwaRF Rogue Pro can do that, assuming you have captured a RF frame previously, and submitted it to Kaiju for analysis (PandwaRF <-> Kaiju communication is handled by the app).
If analysis is succesful, Kaiju will generate new rolling codes that will open the gate.
Warning: You should only do this on your own gate opener in case you have lost the transmitter for example.
Yes PandwaRF Rogue Pro can do brute force. But brute force is not magic. You need to know the parameters to use for brute forcing: frequency, modulation, data rate, symbol length, interframe duration, repetition, etc…
The goal of the PandwaRF family of product is to make RF as much fun and simple as possible. But some RF knowledge can indeed help understand the mechanics inside: modulation, bit rate, sampling rate, deviation, binary vs hexadecimal, RX bandwidth…, etc…
If you have no idea what the previous terms mean, don’t worry, PandwaRF comes with a lot of predefined settings.
If you want to practice RF sniffing and transmission without too much technical knowledge, PandwaRF Rogue Pro is probably what you are looking for. It comes with an Android app that tries to make everything as simple as possible.
- On Android version 6, Bluetooth Low Energy (BLE) scanning will only work if Location services are enabled. This is a requirement from Google. If you don’t grant location permission to the app, the scan may not find any BLE device.
- Starting Android 13, the location/GPS doesn’t need to be enabled to use the BLE.
See Android Permissions for more details.
When you purchase a PandwaRF (Rogue Pro, Marauder Standard, …) with a Kaiju license, the PandwaRF is automatically registered into Kaiju. When you first request a Kaiju analysis from your PandwaRF, you will be requested to create or link a Kaiju account. The PandwaRF, the Kaiju license and your email will then be linked together.
Once this first association is done, you can use Kaiju without using your PandwaRF.
See Kaiju Account Creation for more details.
You need a Kaiju account and a valid Kaiju License. You will then have the option to generate a Flipper Zero .sub file for each of your generated rolling codes.
Flipper Zero Sub file generation is the ability to generate binary files (.sub files) from within the Kaiju server.
Sub files are generally used for rolling codes transmissions and can be loaded onto your Flipper Zero.
Kaiju is a rolling code management server made by ComThings.
Flipper Zero is general purpose hacking device made by Flipper Devices Inc.
There is no link between the 2 companies.
The De Bruijn sequence is an algorithm used to efficiently produce every possible code in as few bits as possible.
It is very effective against old gate openers receivers that contain shift registers.
More information here.
De Bruijn Brute Force is possibel with the PandwaRF Rogue Pro.
Kaiju is a Rolling code analyzer & generator.
It is the server that handle rolling codes decryption and generation.
Yes, but only for some fixed codes models like Came and Nice gate openers for the moment.
You can do all that with a PandwaRF Rogue Pro.
Rolling codes decryption and generation require a Kaiju License.
Once started, PandwaRF Marauder captures all RF data from the specified frequency/modulation and store it internally for future analysis.
PandwaRF Rogue Pro is more for “interactive” data manipulation: capture/replay/rolling code generation…
PandwaRF Rogue Pro is the best version to start practicing and learning.
After purchasing a Kaiju License or Token Pack, you will receive a license key by email (email used when purchasing).
This license key needs to be added to your Kaiju profile (https://rolling.pandwarf.com/profile-user) by using the buttons “Add license” or “Add tokens”.
No. New rolling code from Kaiju can only be replayed using a Rogue (Pro/Gov).
Yes! In fact Rogue & Marauder work better together.
Marauder Standard/Ultimate can export captured data to Rogue, and Rogue can also send the data to Kaiju for analysis.
Marauder can only replay the data it has previously captured.
PandwaRF can be powered by several sources:
- internal battery
- USB port with an external power bank
- USB port, powered from smartphone using an USB OTG male-male cable (provided)
Yes, there is a ON/OFF power switch inside the case.
It depends on the usage.
- PandwaRF can last several weeks in idle mode.
- In TX or RX mode, the battery will last for approx. 10 hours.
As explained here, PandwaRF is not a SDR.
- A SDR sends I/Q samples directly (over USB) to the host. This allows the I/Q demodulation to be made by the SW running on the host.
- PandwaRF doesn’t send the I/Q samples to the host over USB. These I/Q samples are directly demodulated by the chipset and the demodulated data is then sent to the host.
The battery lasts about 10 hours and depending on the Marauder version, it can perform a maximum of 256 or 512 captures of 1-second duration each.
We don’t provide free samples.
Long time ago we provided one free to an Elf, but he was famous. If you are famous or an Elf, contact us. You will not get a free sample, but we will discuss about Orcs.
You can find the user guide here or have a look at our wiki.
If you are a company in Europe and have a VAT number, please contact us to provide your billing information (including VAT number) and the VAT will not be charged.
Orders from unauthorized resellers are poor quality clones and do not benefit from technical support and bug fixes, and are not compatible with the PandwaRF Android application.
The connection from smartphone to PandwaRF uses Bluetooth 4.0 (LE), and theoretical range is up to 100m, but depends on radio conditions.
The range from remote control to PandwaRF is approx. 30m, but also depends on radio conditions.
No, our office is not open to the public. You can only buy online.
Yes, use a coin or similar tool as shown here.
PandwaRF Rogue Pro has many auto-detection features:
- Auto frequency detection
- auto data rate measurement
- data rate computation from over-sampled data
- model searcher…
Well, we would love to say yes, but the truth is that you need to understand the basis, like modulation, data rate, sampling rate, deviation, RSSI, etc…
Hopefully, we have made the app as easy as possible.
The PandwaRF family is composed of several product versions:
- PandwaRF Bare: the cheapest version, no battery, no case. To experiment without big investment. €.
- PandwaRF: Fits in your pocket, battery, nice black case. For basic RF tasks. €€.
- PandwaRF Rogue Pro: Better at pentesting and brute forcing. Faster and more powerful. €€€.
- PandwaRF Rogue Gov: Faster. Home Alarm hacking feature. Not for the Dark Side. €€€€.
- PandwaRF Marauder: drop and forget. Capture and replay. Works without a Smartphone. €€€ to €€€€.
Before choosing a product version, you should think about what you are planning to use your PandwaRF for.
- If you are not sure or you just want to try it out, the PandwaRF is probably right for you.
- If you have a more specific purpose you should take a look at the Rogue Pro or the Marauder.
- If you are part of/working with LEA and you don’t have a vast RF knowledge, the Rogue Gov is probably the best choice.
More details here: https://pandwarf.com/news/which-pandwarf-variant-should-you-choose/
It can happen that your battery become weak, or dead. Don’t worry you can replace your battery easily with instructions.
PandwaRF is a tool. Like any tool, it can be used to do good or bad. We are not responsible for what you do with it. PandwaRF is made to assess the security of your own devices only.
Please raise a ticket for any technical issue. Contact us directly if you have a malfunctioning board.
Any technical issue can be handled through our GitHub issue tracking. You can also reach us by chat/email/forum.
PandwaRF application can only work on Android KitKat (API level 19 and higher). However, some phones have better Bluetooth than others. Please check the list of Android Tested Devices.
PandwaRF prefers working on OOK modulation, because it is the most common. However, supported modulation are ASK/OOK/MSK/2-FSK/GFSK.
PandwaRF can capture data from devices like:
- car keyfobs
- garage door opener keyfobs
- wireless plugs
- wireless chimes etc.
We only use express carriers like UPS or DHL.
If you prefer another shipping option like the postal service, please request it in the Notes for seller section when checking out and we will see what we can do 🙂
Occasionally we may request documents or more information in order to confirm your identity or address before shipping your order.
This is necessary for us to be covered in case of credit card fraud.
If you do not wish to provide the requested documents or information, you can also pay by bank transfer or purchase PandwaRF from one of our resellers (listed on our website) and soon on Amazon.
Please check the Product return information page in our wiki.
Please check the Requirements page in our wiki to see if your Android version is compatible with PandwaRF.
We did our best to make sure that PandwaRF can be used by anybody, but basic RF knowledge (being familiar with terms like data rate, modulation etc) is recommended in order to fully enjoy all the features.
You can only replace items in your order with other items that have the same price. Please contact us at pandwarf@comthings.com and we’ll update your order.
You can’t, so please contact us and we will do it for you.
For PandwaRF and Rogue Family: no, this is not possible. Each product version is independent.
For Marauder, yes you can upgrade from one version to the other. Please check the Marauder version table for more information.
No. We developed one iOS app 2 years ago, but it was a bad move as the Android App evolves constantly and we cannot maintain 2 apps at the same time. But one day we will… Also we can’t afford spending more than 1000€ on a single phone 🙂
Nordic or CC1111 are not planned to be open source. But we are working on “starter” code, like some basic BSP code to use the UART, GPIO, SPI, USB etc.
If you want to run some scripts, we have the Python USB RfCat script for Linux machine or JavaScript for BLE/USB on Android. If you feel that something is missing, please submit a GitHub ticket and we will see what we can do.
Yes, if the length is < 16bits. But it is not plug and play. You will have to configure PandwaRF with the correct settings (frequency, modulation, data rate, symbols etc).
We kindly remind you that brute forcing something that doesn’t belong to you is very very bad. Don’t do it. Seriously.
The PandwaRF uses a cloud connection to check for FW updates, provide anonymous statistic data about crashes, ANR etc. This is default Android/Google behaviour.
But you can still use your PandwaRF without being connected, it will work. However you won’t receive any FW update and will not be able to use the “Post data to API” feature (cf. github.com/ComThings/PandwaRF/wiki/Android-RX-Data-Post-Rest-API).
And we will not be able to spy on you and make money by selling your personal data to evil third parties. No, we are kidding.
No, it cannot be used with GNU radio, as PandwaRF is not a SDR and doesn’t send/receive IQ samples.
Bluetooth Smart (aka Bluetooth Low Energy – BLE) is not the same as Bluetooth.
Unfortunately PandwaRF cannot use normal Bluetooth.
We have added this message “The device does not have a Bluetooth feature” to indicate the lack of Bluetooth Smart HW support from your phone.
In doubt, please install System Info for Android or equivalent and check in System/Functionalities if you see android.hardware.bluetooth.le.
If you don’t, your phone doesn’t support Bluetooth Smart. Keep it preciously, it is a collector.
Possible applications include:
- Receive keyfobs transmission (car, alarm, gate opener, …)
- Replay captured transmission from keyfobs
- Replay a modified captured transmission
- Transmit your own custom payload
- Capture RF data and transmit it on another frequency
- Brute force wireless devices (alarms, gate openers, ..)
- Spectrum Analyzer
- Find the frequency used by a RF device
- Reverse engineer unknown protocols
- Measure the data rate of a transmission
- Check the RF jam-resistance of your own devices
- Send captured data to a server for post-processing
- Write custom Javascript scenarios
- Develop your own Android application
We normally ship once a week, so your order may be shipped between 1 day and 1 week after you made the payment.
But it can sometimes take 2 or 3 weeks because, well, we may be on holidays, or are busy working on a new feature. So if you are in a hurry, we recommend you order from one of our reseller.
We’ll mark your order as:
- completed: when it is ready and shipping has been scheduled with the delivery service
- fulfilled: when the order has been shipped
You’ll also receive an email with the tracking number once it has been shipped.
If you’re interested in becoming a reseller, please contact us.
Both.
You can link with PandwaRF using an Android/iOS smartphone with a Bluetooth Smart feature.
In some cases, you will need a higher throughput than what BLE can offer, so you will have to use PandwaRF using its USB port.
You can connect PandwaRF to an Android Smartphone with an USB Host mode (the USB host mode is supported in Android 3.1 and higher) using a USB micro Male/Male cable.
You can also connect PandwaRF to a computer (Linux) and use #rfcat Python scripts or our native C stack to send/receive data.
Well, partially.
Some pieces are definitely open source (e.g. the #rfcat fork that we have made), and others will also be open source as they are important for developers in order to use PandwaRF
Other pieces are custom parts of our CTbee product, and cannot be disclosed without altering our relationship with existing CTbee customers.
But we will release everything needed for developers in order to use PandwaRF.
PandwaRF can be paired with a smartphone & used immediately after unboxing.
ComThings provides:
- PandwaRF:
- Nordic Semiconductor nRF51822 Multiprotocol Bluetooth® low energy/2.4 GHz RF System on Chip with ARM® Cortex™-M0
- Texas Instruments CC1111 Low-Power SoC (System-on-Chip) with MCU, Memory, Sub-1 GHz RF Transceiver, and USB Controller
- Micro USB type B connection with full-speed USB 2.0 interface
- SPI memory
- Fuel Gauge
- 350mAh LiPo battery
- 4 buttons
- 3 LEDs
- preflashed with bootloaders
- Firmware: we provide binary firmware for both MCUs: Nordic nRF51822 & TI CC1111
- Software libraries: we provide Gollum Java Android libraries
- Reference application: we provide Android reference test application