Signal-Goblin
β‘ Signal Goblin Wiki
"It gobbles your signals and grins about it."
Table of Contents
- What is Signal Goblin?
- Hardware Overview
- PCB Design
- Pin Reference
- Module Guide β NFC / RFID
- Module Guide β Sub-GHz (CC1101)
- Module Guide β 2.4GHz (nRF24)
- Module Guide β Infrared
- Power System
- Audio System
- Firmware Setup
- Building Your Goblin
- Troubleshooting
- Bill of Materials
- Credits & License
What is Signal Goblin?
Signal Goblin is an open-source, ESP32-based multi-radio hacking and signal analysis tool built around a goblin-head shaped PCB. It combines NFC/RFID reading, Sub-GHz sniffing and replay, 2.4GHz channel scanning, and infrared signal capture into a single handheld device with a 3.5" touchscreen, LiPo battery, and a distinctive pixel-art goblin aesthetic baked into the silkscreen.
Think of it as a pocket-sized RF toolkit that looks like it belongs in a dungeon.
Key Features
| Feature | Details |
|---|---|
| MCU |
Esp32 c5 n8r8 wroom - 1 8mb flash and 8 mb psram Wi-Fi + BT Stm32 wb55cgu6( handles peripherals and cc1101) |
| Display | 3.5" ILI9488 SPI TFT β 320Γ480 touchscreen |
| NFC/RFID | PN532 β ISO14443A, MIFARE, NTAG, FeliCa via I2C |
| Sub-GHz | CC1101 E07-433M20S β 300β928MHz, OOK/ASK/FSK, 20dBm |
| 2.4GHz | nRF24 E01-ML01SP2 β 2.4GHz, 20dBm PA+LNA |
| Infrared | 5V IR Tx/Rx β all major protocols via IRremote v4 |
| Power | TP4056+Boost module, 2000mAh LiPo, USB-C charging |
| Audio | PAM8302 2.5W mono amplifier + mini speaker |
| PCB Shape | Organic goblin-head silhouette β 208Γ107mm, black soldermask |
| Antennas | SMA connectors at ear tips β swappable rubber duck antennas |
What Can It Do?
- Read and log NFC/RFID cards β UID, card type, data blocks
- Scan Sub-GHz spectrum β visualize signals in the 433MHz band
- Sniff and replay RF signals β capture remote codes and retransmit
- Scan 2.4GHz channel activity β map Wi-Fi, Bluetooth, and other congestion
- Receive and decode IR signals β identify protocol, address, command
- Replay captured IR codes β universal remote functionality
- Haptic feedback β vibration motor for silent signal alerts
- GPIO expansion β 20-pin header for add-ons (Flipper Zero style)
Hardware Overview
LEFT EAR RIGHT EAR
[2.4GHz SMA] [433MHz SMA]
| |
nRF24 IPEX pigtail CC1101 IPEX pigtail
| |
USB-C β[LEFT EAR BASE] [RIGHT EAR BASE]β Power Switch
(on TP4056 module) (SPDT slide, BATβBoost EN)
βββββββββββββββββββββ
β GOBLIN HEAD PCB β
β β
RST β β [PIXEL ART] β BOOT
β GOBLIN FACE β
nRF24 β [CC1101] β
[TP4056 β [ESP32c5&STM32 β
Module] β β
β [ILI9488 LCD] β
β [UART][I2C] β
β [GPIO 20-pin] β
βββββββββββββββββββββComponent List
| Ref | Component | Notes |
|---|---|---|
| U1 | ESP32c5 | Main MCU. 19Γ2 stamp holes, 1.27mm pitch |
|
U2 U3 |
Stm32 CC1101 E07-433M20S |
Sub-GHz. Right ear. EBYTE module with IPEX |
| U4 | nRF24 E01-ML01SP2 | 2.4GHz. Left ear. EBYTE module with IPEX |
| U5 | PN532 Elechouse V3 | NFC/RFID. I2C. Red PCB. Set DIP to I2C before soldering |
| U6 | TP4056+Boost Module | LiPo charger + 5V boost. USB-C built in |
| U7 | PAM8302A | Audio amp. SO-8. 2.5W mono |
| LCD1 | ILI9488 3.5" TFT | SPI display + XPT2046 resistive touch |
| IR1 | 5V IR Tx/Rx Module | 38kHz. TX=GPIO12, RX=GPIO13 |
| BAT1 | 2000mAh LiPo | 3.7V flat pouch, JST-PH 2.0 |
| SW1 | RST Button | 6Γ6mm SMD tactile. Pulls EN low |
| SW2 | BOOT Button | 6Γ6mm SMD tactile. GPIO0 low = flash mode |
| SW3 | Power Slide Switch | SPDT. Right ear base. BAT+βMT3608 EN |
| LED1 | WS2812B RGB LED | Forehead. GPIO27. Signal feedback |
| J1βJ2 | SMA Edge Connectors | Ear tips. Right=433MHz, Left=2.4GHz |
| J2 | GPIO Header 2Γ10 | 20-pin expansion, 2.54mm |
| J3 | UART Header 1Γ4 | GND/RX/TX/3V3 |
| J4 | I2C Header 1Γ4 | GND/SDA/SCL/3V3 |
| J5 | Power Rail 1Γ6 | GNDΓ2 / 3V3Γ2 / 5VΓ2 |
PCB Design
Board Specifications
| Property | Value |
|---|---|
| Shape | Organic goblin-head silhouette |
| Dimensions | 208Γ107mm (including ear spikes) |
| Layers | 2-layer FR4 |
| Thickness | 1.6mm |
| Soldermask | Black |
| Surface Finish | HASL or ENIG |
| Min trace width | 0.15mm |
| Min drill | 0.5mm |
Board Shape
The PCB is not a rectangle. It is a fully custom goblin-head silhouette:
- Rounded oval head β organic elliptical outline, no straight edges
- Two ear spikes β long tapered triangles extending left and right
- SMA connectors sit at the ear tips β the antenna connector IS the ear tip
- USB-C lives on the left ear base β ergonomic cable routing
- Power switch lives on the right ear base β natural thumb position
- Slight chin point at the bottom center
The black soldermask makes the board look dark and menacing. The pixel-art goblin warrior silkscreen on the front and lantern goblin on the back complete the aesthetic.
Ordering from JLCPCB
- Upload
signal_goblin_gerbers.zip - Set: 2 layers, 1.6mm, Black soldermask, HASL
- Quantity: 5 (minimum sensible order)
- At checkout: add SMD stencil β top side only
- The stencil is not optional if you're soldering the stamp-hole modules
Front Silkscreen
- Pixel-art goblin warrior β 38Γ50 grid, 1.55mm pixels, rendered from reference artwork
- Grid lines every 5 pixels for a retro aesthetic
- All component labels, pin 1 markers, module outlines
- Dashed RF trace lines from CC1101/nRF24 to ear SMA connectors
- Title bar: SIGNAL GOBLIN v7.1
Back Silkscreen
- Lantern goblin β 30Γ30 pixel art
- Full GPIO pin reference table
- Decorative inset oval
Pin Reference
ESP32 GPIO Assignments
| GPIO | Function | Direction | Notes |
|---|---|---|---|
| 2 | Display DC/RS | Output | ILI9488 Data/Command |
| 4 | Display RST | Output | ILI9488 Hardware reset |
| 5 | Display CS | Output | ILI9488 Chip Select |
| 6 | Audio / RGB | Output | PWM audio or WS2812B data |
| 12 | IR TX | Output | IR transmitter β IRremote lib |
| 13 | IR RX | Input | IR receiver β IRremote lib |
| 14 | CC1101 CS | Output | CC1101 chip select |
| 15 | SD Card CS | Output | MicroSD chip select |
| 16 | nRF24 CSN | Output | nRF24 chip select not |
| 17 | nRF24 IRQ | Input | nRF24 interrupt (active low) |
| 18 | SPI SCK | Output | Shared: Display, SD, CC1101, nRF24 |
| 19 | SPI MISO | Input | Shared: Display, SD, CC1101, nRF24 |
| 21 | I2C SDA | Bi-dir | PN532 + I2C expansion header |
| 22 | I2C SCL | Output | PN532 + I2C expansion header |
| 23 | SPI MOSI | Output | Shared: Display, SD, CC1101, nRF24 |
| 25 | nRF24 CE | Output | nRF24 Chip Enable |
| 26 | CC1101 GDO0 | Input | CC1101 packet interrupt |
| 27 | RGB LED | Output | WS2812B data pin |
| 32 | Display BL | Output | ILI9488 backlight (LEDC PWM) |
| 33 | Touch CS | Output | XPT2046 chip select |
| 34 | Spare ADC | Input | Input only. Expansion header |
| 35 | Spare ADC | Input | Input only. Expansion header |
| 36 | Battery ADC | Input | Voltage divider. Input only |
| 39 | Spare ADC | Input | Input only (VP pin) |
| 0 | BOOT Button | Input | Pull low = flash mode |
| 1 | UART0 TX | Output | Debug serial / UART header |
| 3 | UART0 RX | Input | Debug serial / UART header |
| EN | RESET | Input | RST button pulls low |
β οΈ GPIO 6β11 are connected to internal flash. Never use them as GPIO β the board will crash or fail to boot.
SPI Bus Sharing
All SPI devices share MOSI (IO23), MISO (IO19), and SCK (IO18). They are separated by individual chip select pins:
in the works nowJ2 β GPIO 20-pin (2Γ10, 2.54mm)
| Pin | Signal | Pin | Signal |
|---|---|---|---|
| 1 | IO0 (BOOT) | 2 | IO1 (TX) |
| 3 | IO3 (RX) | 4 | IO16 (nRF CSN) |
| 5 | IO17 (nRF IRQ) | 6 | IO22 (I2C SCL) |
| 7 | IO34 (ADC) | 8 | IO35 (ADC) |
| 9 | IO39 (ADC) | 10 | IO26 (CC GDO0) |
| 11 | 3V3 | 12 | 3V3 |
| 13 | 5V | 14 | 5V |
| 15-20 | GND |
J3 β UART (1Γ4, 2.54mm) GND | RX (IO3) | TX (IO1) | 3V3
J4 β I2C (1Γ4, 2.54mm) GND | SDA (IO21) | SCL (IO22) | 3V3
J5 β Power Rail (1Γ6, 2.54mm) GND | GND | 3V3 | 3V3 | 5V | 5V
Module Guide β NFC / RFID
Hardware
PN532 β Elechouse V3 red PCB module, connected via I2C.
β οΈ Critical: The PN532 ships in UART mode by default. You MUST switch the two DIP switches to I2C mode BEFORE soldering. With the component side facing you: SW1 = OFF (down), SW2 = ON (up). Once soldered to the PCB you cannot reach the switches.
Supported Card Types
| Type | Standard | Notes |
|---|---|---|
| MIFARE Classic 1K | ISO14443A | Most common. 1KB memory, 16 sectors |
| MIFARE Classic 4K | ISO14443A | 4KB, 40 sectors |
| MIFARE Ultralight | ISO14443A | 512 bits, no encryption |
| NTAG213/215/216 | ISO14443A | NFC tags β phone compatible |
| FeliCa | ISO18092 | Japanese transit cards |
What Signal Goblin Can Do
- Read card UID (unique identifier)
- Identify card type and manufacturer
- Read data from unencrypted blocks
- Log multiple card scans
What It Cannot Do (Yet)
- Crack MIFARE Classic encryption (requires Proxmark-level hardware)
- Emulate cards (PN532 supports emulation but not implemented in v1 firmware)
- Read EMV bank cards (requires different protocol stack)
I2C Address
PN532 default I2C address: 0x24
Module Guide β Sub-GHz (CC1101)
Hardware
CC1101 E07-433M20S by EBYTE. Connected via SPI. External antenna via IPEX pigtail to right ear SMA connector.
Frequency Range
The CC1101 can operate from 300MHz to 928MHz. Signal Goblin defaults to 433.92MHz (common for remote controls, car key fobs, weather stations, garage doors).
Common frequencies to explore:
| Frequency | Common Uses |
|---|---|
| 315 MHz | US garage doors, some car remotes |
| 433.92 MHz | EU/AU garage doors, weather stations, 433MHz ISM band |
| 868 MHz | EU smart meters, alarm systems |
| 915 MHz | US ISM band, some IoT sensors |
Modulation Modes
| Mode | Use Case |
|---|---|
| OOK (On-Off Keying) | Simple remote controls, most 433MHz devices |
| ASK (Amplitude Shift Keying) | Similar to OOK |
| FSK (2-FSK) | Higher-data devices, some key fobs |
| GFSK | Bluetooth-adjacent devices |
Wiring Summary
| CC1101 Pin | ESP32 GPIO |
|---|---|
| VCC | 3.3V |
| GND | GND |
| MOSI | GPIO23 |
| SCK | GPIO18 |
| MISO | GPIO19 |
| CSN | GPIO14 |
| GDO0 | GPIO26 |
| GDO2 | GPIO27 |
Module Guide β 2.4GHz (nRF24)
Hardware
nRF24L01+ E01-ML01SP2 by EBYTE. 20dBm PA+LNA. Connected via SPI. External antenna via IPEX pigtail to left ear SMA connector.
What It Scans
The nRF24 scans all 126 channels in the 2.4GHz band (2400MHz to 2525MHz, 1MHz steps). This lets you visualize:
- Wi-Fi congestion β channels 1, 6, 11 (2.4GHz Wi-Fi)
- Bluetooth activity β frequency-hopping pattern across all channels
- Wireless keyboards and mice β often fixed or pseudo-fixed channels
- Zigbee/Z-Wave devices β home automation protocols
- Baby monitors, drones β various proprietary protocols
Channel vs Frequency
Channel 0 = 2400 MHz
Channel 1 = 2401 MHz
...
Channel 25 = 2425 MHz β Wi-Fi Ch 1 center (approx)
Channel 50 = 2450 MHz β Wi-Fi Ch 6 center (approx)
Channel 80 = 2480 MHz β Wi-Fi Ch 11 center (approx)
Channel 125= 2525 MHzWiring Summary
| nRF24 Pin | ESP32 GPIO |
|---|---|
| VCC | 3.3V |
| GND | GND |
| MOSI | GPIO23 |
| SCK | GPIO18 |
| MISO | GPIO19 |
| CSN | GPIO16 |
| CE | GPIO25 |
| IRQ | GPIO17 |
Note: nRF24 is 3.3V only. Never connect to 5V.
Module Guide β Infrared
Hardware
5V IR Transmitter/Receiver combo module. TX connected to GPIO12, RX to GPIO13. Powered from 5V rail.
Supported Protocols (via IRremote v4)
NEC, Samsung, Sony, RC5, RC6, JVC, LG, Panasonic, Denon, Sharp, Dish, Kaseikyo, and raw pulse capture.
TV Remote Presets (built into firmware)
| Button | Code | Works With |
|---|---|---|
| TV Power | 0x20DF10EF (NEC) | LG TVs |
More presets can be added in firmware by extending the IR presets section.
Capturing a New Code
- Open the IR module screen
- Point your remote at the IR receiver
- Press RECEIVE on screen
- Press the button on your remote
- The protocol, address, and command display on screen
- Press REPLAY to retransmit
Adding a Permanent Preset
In signal_goblin.ino, find the TV power preset section in handleModuleTouch and add:
IrSender.sendNEC(0xYOURCODE, 32); // NEC protocol, 32 bits
IrSender.sendSony(0xYOURCODE, 12); // Sony SIRC, 12 bitsPower System
Architecture
USB-C (on TP4056 module)
β
βΌ
TP4056 LiPo Charger ββββββββββββββββββββββββ Charge LEDs
β (Red = charging)
βΌ (Green = full)
LiPo Battery 3.7V 2000mAh
(JST-PH 2.0 connector)
β
βββββ SS14 Schottky Diode (reverse polarity protection)
β
βββββ PTC Fuse 500mA (overcurrent protection)
β
βββββ Power Switch (right ear) ββββ MT3608 Boost EN
β
βΌ
5V Boost Output
β
ββββββββββββββ΄βββββββββββββ
βΌ βΌ
ESP32 5V pin IR Module
(internal LDO PAM8302
β 3.3V rail) etc.TP4056 Module Notes
The TP4056+Boost module you already own has everything built in:
- USB-C charging port
- TP4056 LiPo charge IC
- DW01 battery protection (overcharge, overdischarge, short circuit)
- MT3608 5V boost converter
You only need to wire 4 pads on the PCB:
- B+ β Battery positive (JST red wire)
- B- β Battery negative (JST black wire)
- OUT+ β 5V power rail
- OUT- β Ground rail
Battery Life Estimates
| Usage | Estimated Runtime |
|---|---|
| Display on, active scanning | ~3β4 hours |
| Display on, idle | ~5β6 hours |
| Display dimmed, light use | ~8+ hours |
Battery Gauge
GPIO36 reads a voltage divider (two 47kΞ© resistors) connected across the LiPo. The firmware maps the voltage range 3.2Vβ4.2V to 0β100% and displays it in the status bar and Settings screen.
Charging
Plug any USB-C cable into the left ear base connector. The red LED lights while charging. Green LED lights when full. Charge time from empty: approximately 3β4 hours at 500mA.
Audio System
Hardware
PAM8302A mono amplifier (SO-8) connected to a small 8Ξ© speaker via JST connector. Audio signal comes from ESP32 GPIO6 via PWM/DAC.
Uses in Firmware
- Boot jingle on startup
- Scan success alert (short beep)
- Signal detected tone (CC1101/nRF24)
- Card read confirmation (NFC)
Muting
The PAM8302 SD pin is tied to GPIO11. Pull low to mute, high to enable. The firmware mutes audio during active RF scanning to prevent interference pickup on the IR receiver.
Firmware Setup
Required Libraries
Install all of these via Arduino Library Manager before compiling:
| Library | Author | Version |
|---|---|---|
| TFT_eSPI | Bodmer | Latest |
| IRremote | shirriff/z3t0 | 4.x only |
| Adafruit_PN532 | Adafruit | Latest |
| RF24 | TMRh20 | Latest |
| SmartRC-CC1101-Driver-Lib | LSatan | Latest |
| FastLED | FastLED | Latest |
TFT_eSPI Configuration
This is required before the firmware will compile. Find User_Setup.h inside the TFT_eSPI library folder and add/replace these lines:
#define ILI9488_DRIVER
#define TFT_MOSI 23
#define TFT_SCLK 18
#define TFT_CS 5
#define TFT_DC 2
#define TFT_RST 4
#define TOUCH_CS 33
#define SPI_FREQUENCY 27000000
#define SPI_TOUCH_FREQUENCY 2500000Arduino IDE Board Settings
| Setting | Value |
|---|---|
| Board | ESP32 Dev Module |
| Upload Speed | 921600 |
| CPU Frequency | 240MHz |
| Flash Frequency | 80MHz |
| Flash Mode | QIO |
| Flash Size | 16MB (128Mb) |
| Partition Scheme | Default 4MB with spiffs |
| Core Debug Level | None |
Flashing the Firmware
- Connect USB-C cable to the Signal Goblin left ear port
- Hold BOOT button and press RST button simultaneously
- Release RST, then release BOOT β device enters flash mode
- Upload from Arduino IDE
- Press RST once after upload completes
First Boot
On first power-on you will see:
- Green orb pulsing in darkness
- Goblin silhouette materializes
- "SIGNAL GOBLIN" title flashes 3 times
- Scan line sweeps down the screen
- "INITIALIZING SYSTEMS..." message
- Main menu appears with animated goblin mascot
Building Your Goblin
Assembly Order
Follow this order to avoid regret:
- Flash the ESP32 first β test firmware on a breadboard before soldering anything to the PCB. Much easier to debug before it's mounted.
- Set PN532 DIP switches β SW1 OFF, SW2 ON for I2C. Do this before anything else because you can't reach them after soldering.
- Solder SMD passives first β 0402 resistors and capacitors. Decoupling caps, voltage divider, LED current resistors. Use paste + hot air if possible.
- Solder SMD ICs β PAM8302A (SO-8). SOT-23 components if using bare ICs.
- Apply stencil and paste to stamp-hole pads β CC1101, nRF24, ESP32. Do all at once, place modules, reflow together.
- Solder through-hole components β tactile buttons, pin headers, SMA connectors, power switch.
- Wire TP4056 module pads β B+, B-, OUT+, OUT- to PCB pads. Use short thick wire.
- Connect battery JST β double-check polarity before connecting. Red = B+, Black = B-.
- Test before closing up β power on, verify all modules initialize in the boot sequence.
- Attach IPEX pigtails β route CC1101 pigtail to right ear SMA, nRF24 pigtail to left ear SMA. The pigtails are fragile β route them carefully before screwing down the SMA connectors.
Solder Paste Tips
- Use a steel stencil (order with PCB from JLCPCB)
- Apply paste, place all modules, then reflow in one pass
- The ESP32 stamp holes need proper paste coverage or you'll get cold joints
- After reflow, inspect stamp holes with a magnifier β add solder to any that look dry
IPEX Connector Warning
The IPEX (U.FL) connectors on the CC1101 and nRF24 modules are extremely fragile. They are rated for approximately 30 connect/disconnect cycles. Once the pigtail is routed to the SMA connector, leave it connected. If you need to disconnect it, apply firm straight pressure β never lever or twist.
Troubleshooting
Display Shows Nothing
- Check TFT_eSPI
User_Setup.his configured correctly - Verify backlight β GPIO32 should be PWM high
- Check SPI connections: MOSI=23, SCK=18, CS=5, DC=2, RST=4
- Try a slower SPI frequency in User_Setup.h:
#define SPI_FREQUENCY 20000000
PN532 Not Found
- Most likely cause: DIP switches are still in UART mode. If already soldered, you'll need to desolder the module.
- Check I2C pull-ups are present (4.7kΞ© or 10kΞ© from SDA/SCL to 3.3V)
- Verify I2C address: default is 0x24, scan with
Wire.begin(); for(int i=1;i<127;i++){Wire.beginTransmission(i);if(!Wire.endTransmission())Serial.println(i,HEX);}
CC1101 Not Responding
- Check CS is GPIO14 in firmware init
- Verify SPI is initialized before calling CC1101 init
- CC1101 runs on 3.3V β ensure it's not on 5V rail
- Cold joint on stamp-hole pads is the most common physical cause
nRF24 Not Found
- nRF24 is extremely sensitive to power supply noise β add a 100Β΅F cap close to its VCC/GND pins
- Ensure CSN=16 and CE=25 are correct
- Try
radio.begin()and check return value β false means no response
Touch Not Working
- TOUCH_CS must be GPIO33 in User_Setup.h
- Touch IRQ is GPIO36 β this is an input-only pin, which is correct
- Calibrate touch:
tft.calibrateTouch(calData, TFT_WHITE, TFT_BLACK, 15)
Device Won't Enter Flash Mode
- Hold BOOT (GPIO0), tap RST, release RST, then release BOOT
- If that fails: hold BOOT, plug in USB-C, release BOOT
- GPIO0 must be pulled LOW during boot to enter flash mode
Battery Not Charging
- Check TP4056 module LED β red = charging, no LED = no input power
- Verify USB-C connector orientation and wiring to module
- Module OUT+ must connect to 5V rail, OUT- to GND
Audio No Sound
- PAM8302 SD pin must be HIGH to enable (GPIO11 high)
- Check speaker JST polarity
- Confirm OUT+ and OUT- from PAM8302 go to speaker, not GND
Bill of Materials
Already Ordered / Owned
| Item | Status |
|---|---|
| CC1101 E07-433M20S Γ4 | |
| nRF24 E01-ML01SP2 | |
| SMA edge connectors Γ25 | |
| PN532 Elechouse V3 | |
| MicroSD breakout | |
| TP4056+Boost module with USB-C | |
| MicroSD breakout board | |
| Power slide switch (SPDT) | |
| Vibration motor (bonus haptics) | |
| 100Ξ© resistors 0402 (101) | |
| 10kΞ© resistors 0402 (103) | |
| 47kΞ© resistors 0402 (473) | |
| SMD ceramic caps (likely 100nF) | |
| SOD-80 signal diodes (1N4148) |
Still Needed
| Item | Source | Notes |
|---|---|---|
| ESP32-WROOM-32E-N16 | AliExpress | Main MCU |
| ILI9488 3.5" SPI TFT | AliExpress | 320Γ480 with XPT2046 touch |
| 5V IR Tx/Rx module | AliExpress | Transmitter + receiver combo |
| LiPo 3.7V 2000mAh | Amazon | JST-PH 2.0, flat pouch style |
| Signal Goblin PCB v7.1 Γ5 | JLCPCB | Black soldermask, with stencil |
| SS14 Schottky diode SOD-123 Γ5 | LCSC | Battery reverse polarity protection |
| PTC fuse 500mA 1206 Γ3 | LCSC | Overcurrent protection |
| 4.7Β΅H inductor 0805 Γ3 | LCSC | MT3608 boost (if using bare ICs) |
| 10Β΅F cap 0805 Γ10 | LCSC | Filter caps |
| PAM8302A SO-8 Γ2 | LCSC | Audio amp |
| WS2812B RGB LED Γ3 | AliExpress | Forehead indicator |
| 6Γ6mm SMD tactile button Γ5 | LCSC | RST + BOOT |
| 330Ξ© resistors 0402 Γ10 | LCSC | LED current limiting |
| 8Ξ© 0.5W mini speaker + JST | AliExpress | Audio output |
| 2.54mm pin headers assorted | AliExpress | All connectors |
| JST-PH 2.0 2-pin connectors Γ10 | AliExpress | Battery + speaker |
| M2Γ4mm screws + nuts Γ10 | Hardware | Display mounting |
| M2.7Γ5mm screws + nuts Γ10 | Hardware | Board mounting |
Credits & License
Signal Goblin is an original open-source hardware project.
- PCB Design: Custom Python-generated Gerbers using PIL/numpy
- Firmware: Arduino framework for ESP32
- Inspiration: Flipper Zero, HackRF, Proxmark
Libraries Used
- TFT_eSPI β Bodmer β MIT
- IRremote β z3t0/shirriff β MIT
- Adafruit_PN532 β Adafruit β BSD
- RF24 β TMRh20 β GPL-2.0
- SmartRC-CC1101 β LSatan β MIT
- FastLED β FastLED β MIT
Legal Notice
Signal Goblin is an educational tool for security research and RF analysis on systems you own or have explicit permission to test. Transmitting on regulated frequencies without authorization is illegal in most jurisdictions. The CC1101 and nRF24 modules must be used in compliance with local radio regulations. The author takes no responsibility for misuse.
Built with spite, solder, and goblin energy.
/\ /\\
( o o )
\ ^ / SIGNAL GOBLIN
||||| v7.1 FINAL
|||||