Signal-Goblin

⚑ Signal Goblin Wiki

"It gobbles your signals and grins about it."


Table of Contents

  1. What is Signal Goblin?
  2. Hardware Overview
  3. PCB Design
  4. Pin Reference
  5. Module Guide β€” NFC / RFID
  6. Module Guide β€” Sub-GHz (CC1101)
  7. Module Guide β€” 2.4GHz (nRF24)
  8. Module Guide β€” Infrared
  9. Power System
  10. Audio System
  11. Firmware Setup
  12. Building Your Goblin
  13. Troubleshooting
  14. Bill of Materials
  15. Credits & License

What is Signal Goblin?

Signal Goblin is an open-source, ESP32-based multi-radio hacking and signal analysis tool built around a goblin-head shaped PCB. It combines NFC/RFID reading, Sub-GHz sniffing and replay, 2.4GHz channel scanning, and infrared signal capture into a single handheld device with a 3.5" touchscreen, LiPo battery, and a distinctive pixel-art goblin aesthetic baked into the silkscreen.

Think of it as a pocket-sized RF toolkit that looks like it belongs in a dungeon.

Key Features

Feature Details
MCU

Esp32 c5 n8r8 wroom - 1 8mb flash and 8 mb psram Wi-Fi + BT

Stm32 wb55cgu6( handles peripherals and cc1101)

Display 3.5" ILI9488 SPI TFT β€” 320Γ—480 touchscreen
NFC/RFID PN532 β€” ISO14443A, MIFARE, NTAG, FeliCa via I2C
Sub-GHz CC1101 E07-433M20S β€” 300–928MHz, OOK/ASK/FSK, 20dBm
2.4GHz nRF24 E01-ML01SP2 β€” 2.4GHz, 20dBm PA+LNA
Infrared 5V IR Tx/Rx β€” all major protocols via IRremote v4
Power TP4056+Boost module, 2000mAh LiPo, USB-C charging
Audio PAM8302 2.5W mono amplifier + mini speaker
PCB Shape Organic goblin-head silhouette β€” 208Γ—107mm, black soldermask
Antennas SMA connectors at ear tips β€” swappable rubber duck antennas

What Can It Do?

  • Read and log NFC/RFID cards β€” UID, card type, data blocks
  • Scan Sub-GHz spectrum β€” visualize signals in the 433MHz band
  • Sniff and replay RF signals β€” capture remote codes and retransmit
  • Scan 2.4GHz channel activity β€” map Wi-Fi, Bluetooth, and other congestion
  • Receive and decode IR signals β€” identify protocol, address, command
  • Replay captured IR codes β€” universal remote functionality
  • Haptic feedback β€” vibration motor for silent signal alerts
  • GPIO expansion β€” 20-pin header for add-ons (Flipper Zero style)

Hardware Overview

                    LEFT EAR                    RIGHT EAR
                   [2.4GHz SMA]               [433MHz SMA]
                       |                           |
              nRF24 IPEX pigtail          CC1101 IPEX pigtail
                       |                           |
        USB-C ←[LEFT EAR BASE]     [RIGHT EAR BASE]β†’ Power Switch
        (on TP4056 module)              (SPDT slide, BAT→Boost EN)

                    ╔═══════════════════╗
                    β•‘  GOBLIN HEAD PCB  β•‘
                    β•‘                   β•‘
              RST ● β•‘   [PIXEL ART]   ● BOOT
                    β•‘   GOBLIN FACE     β•‘
              nRF24 β•‘   [CC1101]        β•‘
           [TP4056  β•‘   [ESP32c5&STM32    β•‘
            Module] β•‘                   β•‘
                    β•‘   [ILI9488 LCD]   β•‘
                    β•‘   [UART][I2C]     β•‘
                    β•‘   [GPIO 20-pin]   β•‘
                    β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

Component List

Ref Component Notes
U1 ESP32c5 Main MCU. 19Γ—2 stamp holes, 1.27mm pitch

U2

U3

Stm32

CC1101 E07-433M20S

Sub-GHz. Right ear. EBYTE module with IPEX
U4 nRF24 E01-ML01SP2 2.4GHz. Left ear. EBYTE module with IPEX
U5 PN532 Elechouse V3 NFC/RFID. I2C. Red PCB. Set DIP to I2C before soldering
U6 TP4056+Boost Module LiPo charger + 5V boost. USB-C built in
U7 PAM8302A Audio amp. SO-8. 2.5W mono
LCD1 ILI9488 3.5" TFT SPI display + XPT2046 resistive touch
IR1 5V IR Tx/Rx Module 38kHz. TX=GPIO12, RX=GPIO13
BAT1 2000mAh LiPo 3.7V flat pouch, JST-PH 2.0
SW1 RST Button 6Γ—6mm SMD tactile. Pulls EN low
SW2 BOOT Button 6Γ—6mm SMD tactile. GPIO0 low = flash mode
SW3 Power Slide Switch SPDT. Right ear base. BAT+β†’MT3608 EN
LED1 WS2812B RGB LED Forehead. GPIO27. Signal feedback
J1–J2 SMA Edge Connectors Ear tips. Right=433MHz, Left=2.4GHz
J2 GPIO Header 2Γ—10 20-pin expansion, 2.54mm
J3 UART Header 1Γ—4 GND/RX/TX/3V3
J4 I2C Header 1Γ—4 GND/SDA/SCL/3V3
J5 Power Rail 1Γ—6 GNDΓ—2 / 3V3Γ—2 / 5VΓ—2

PCB Design

Board Specifications

Property Value
Shape Organic goblin-head silhouette
Dimensions 208Γ—107mm (including ear spikes)
Layers 2-layer FR4
Thickness 1.6mm
Soldermask Black
Surface Finish HASL or ENIG
Min trace width 0.15mm
Min drill 0.5mm

Board Shape

The PCB is not a rectangle. It is a fully custom goblin-head silhouette:

  • Rounded oval head β€” organic elliptical outline, no straight edges
  • Two ear spikes β€” long tapered triangles extending left and right
  • SMA connectors sit at the ear tips β€” the antenna connector IS the ear tip
  • USB-C lives on the left ear base β€” ergonomic cable routing
  • Power switch lives on the right ear base β€” natural thumb position
  • Slight chin point at the bottom center

The black soldermask makes the board look dark and menacing. The pixel-art goblin warrior silkscreen on the front and lantern goblin on the back complete the aesthetic.

Ordering from JLCPCB

  1. Upload signal_goblin_gerbers.zip
  2. Set: 2 layers, 1.6mm, Black soldermask, HASL
  3. Quantity: 5 (minimum sensible order)
  4. At checkout: add SMD stencil β€” top side only
  5. The stencil is not optional if you're soldering the stamp-hole modules

Front Silkscreen

  • Pixel-art goblin warrior β€” 38Γ—50 grid, 1.55mm pixels, rendered from reference artwork
  • Grid lines every 5 pixels for a retro aesthetic
  • All component labels, pin 1 markers, module outlines
  • Dashed RF trace lines from CC1101/nRF24 to ear SMA connectors
  • Title bar: SIGNAL GOBLIN v7.1

Back Silkscreen

  • Lantern goblin β€” 30Γ—30 pixel art
  • Full GPIO pin reference table
  • Decorative inset oval

Pin Reference

ESP32 GPIO Assignments

GPIO Function Direction Notes
2 Display DC/RS Output ILI9488 Data/Command
4 Display RST Output ILI9488 Hardware reset
5 Display CS Output ILI9488 Chip Select
6 Audio / RGB Output PWM audio or WS2812B data
12 IR TX Output IR transmitter β€” IRremote lib
13 IR RX Input IR receiver β€” IRremote lib
14 CC1101 CS Output CC1101 chip select
15 SD Card CS Output MicroSD chip select
16 nRF24 CSN Output nRF24 chip select not
17 nRF24 IRQ Input nRF24 interrupt (active low)
18 SPI SCK Output Shared: Display, SD, CC1101, nRF24
19 SPI MISO Input Shared: Display, SD, CC1101, nRF24
21 I2C SDA Bi-dir PN532 + I2C expansion header
22 I2C SCL Output PN532 + I2C expansion header
23 SPI MOSI Output Shared: Display, SD, CC1101, nRF24
25 nRF24 CE Output nRF24 Chip Enable
26 CC1101 GDO0 Input CC1101 packet interrupt
27 RGB LED Output WS2812B data pin
32 Display BL Output ILI9488 backlight (LEDC PWM)
33 Touch CS Output XPT2046 chip select
34 Spare ADC Input Input only. Expansion header
35 Spare ADC Input Input only. Expansion header
36 Battery ADC Input Voltage divider. Input only
39 Spare ADC Input Input only (VP pin)
0 BOOT Button Input Pull low = flash mode
1 UART0 TX Output Debug serial / UART header
3 UART0 RX Input Debug serial / UART header
EN RESET Input RST button pulls low

⚠️ GPIO 6–11 are connected to internal flash. Never use them as GPIO β€” the board will crash or fail to boot.

SPI Bus Sharing

All SPI devices share MOSI (IO23), MISO (IO19), and SCK (IO18). They are separated by individual chip select pins:

in the works now

J2 β€” GPIO 20-pin (2Γ—10, 2.54mm)

Pin Signal Pin Signal
1 IO0 (BOOT) 2 IO1 (TX)
3 IO3 (RX) 4 IO16 (nRF CSN)
5 IO17 (nRF IRQ) 6 IO22 (I2C SCL)
7 IO34 (ADC) 8 IO35 (ADC)
9 IO39 (ADC) 10 IO26 (CC GDO0)
11 3V3 12 3V3
13 5V 14 5V
15-20 GND

J3 β€” UART (1Γ—4, 2.54mm) GND | RX (IO3) | TX (IO1) | 3V3

J4 β€” I2C (1Γ—4, 2.54mm) GND | SDA (IO21) | SCL (IO22) | 3V3

J5 β€” Power Rail (1Γ—6, 2.54mm) GND | GND | 3V3 | 3V3 | 5V | 5V


Module Guide β€” NFC / RFID

Hardware

PN532 β€” Elechouse V3 red PCB module, connected via I2C.

⚠️ Critical: The PN532 ships in UART mode by default. You MUST switch the two DIP switches to I2C mode BEFORE soldering. With the component side facing you: SW1 = OFF (down), SW2 = ON (up). Once soldered to the PCB you cannot reach the switches.

Supported Card Types

Type Standard Notes
MIFARE Classic 1K ISO14443A Most common. 1KB memory, 16 sectors
MIFARE Classic 4K ISO14443A 4KB, 40 sectors
MIFARE Ultralight ISO14443A 512 bits, no encryption
NTAG213/215/216 ISO14443A NFC tags β€” phone compatible
FeliCa ISO18092 Japanese transit cards

What Signal Goblin Can Do

  • Read card UID (unique identifier)
  • Identify card type and manufacturer
  • Read data from unencrypted blocks
  • Log multiple card scans

What It Cannot Do (Yet)

  • Crack MIFARE Classic encryption (requires Proxmark-level hardware)
  • Emulate cards (PN532 supports emulation but not implemented in v1 firmware)
  • Read EMV bank cards (requires different protocol stack)

I2C Address

PN532 default I2C address: 0x24


Module Guide β€” Sub-GHz (CC1101)

Hardware

CC1101 E07-433M20S by EBYTE. Connected via SPI. External antenna via IPEX pigtail to right ear SMA connector.

Frequency Range

The CC1101 can operate from 300MHz to 928MHz. Signal Goblin defaults to 433.92MHz (common for remote controls, car key fobs, weather stations, garage doors).

Common frequencies to explore:

Frequency Common Uses
315 MHz US garage doors, some car remotes
433.92 MHz EU/AU garage doors, weather stations, 433MHz ISM band
868 MHz EU smart meters, alarm systems
915 MHz US ISM band, some IoT sensors

Modulation Modes

Mode Use Case
OOK (On-Off Keying) Simple remote controls, most 433MHz devices
ASK (Amplitude Shift Keying) Similar to OOK
FSK (2-FSK) Higher-data devices, some key fobs
GFSK Bluetooth-adjacent devices

Wiring Summary

CC1101 Pin ESP32 GPIO
VCC 3.3V
GND GND
MOSI GPIO23
SCK GPIO18
MISO GPIO19
CSN GPIO14
GDO0 GPIO26
GDO2 GPIO27

Module Guide β€” 2.4GHz (nRF24)

Hardware

nRF24L01+ E01-ML01SP2 by EBYTE. 20dBm PA+LNA. Connected via SPI. External antenna via IPEX pigtail to left ear SMA connector.

What It Scans

The nRF24 scans all 126 channels in the 2.4GHz band (2400MHz to 2525MHz, 1MHz steps). This lets you visualize:

  • Wi-Fi congestion β€” channels 1, 6, 11 (2.4GHz Wi-Fi)
  • Bluetooth activity β€” frequency-hopping pattern across all channels
  • Wireless keyboards and mice β€” often fixed or pseudo-fixed channels
  • Zigbee/Z-Wave devices β€” home automation protocols
  • Baby monitors, drones β€” various proprietary protocols

Channel vs Frequency

Channel 0  = 2400 MHz
Channel 1  = 2401 MHz
...
Channel 25 = 2425 MHz  ← Wi-Fi Ch 1 center (approx)
Channel 50 = 2450 MHz  ← Wi-Fi Ch 6 center (approx)
Channel 80 = 2480 MHz  ← Wi-Fi Ch 11 center (approx)
Channel 125= 2525 MHz

Wiring Summary

nRF24 Pin ESP32 GPIO
VCC 3.3V
GND GND
MOSI GPIO23
SCK GPIO18
MISO GPIO19
CSN GPIO16
CE GPIO25
IRQ GPIO17

Note: nRF24 is 3.3V only. Never connect to 5V.


Module Guide β€” Infrared

Hardware

5V IR Transmitter/Receiver combo module. TX connected to GPIO12, RX to GPIO13. Powered from 5V rail.

Supported Protocols (via IRremote v4)

NEC, Samsung, Sony, RC5, RC6, JVC, LG, Panasonic, Denon, Sharp, Dish, Kaseikyo, and raw pulse capture.

TV Remote Presets (built into firmware)

Button Code Works With
TV Power 0x20DF10EF (NEC) LG TVs

More presets can be added in firmware by extending the IR presets section.

Capturing a New Code

  1. Open the IR module screen
  2. Point your remote at the IR receiver
  3. Press RECEIVE on screen
  4. Press the button on your remote
  5. The protocol, address, and command display on screen
  6. Press REPLAY to retransmit

Adding a Permanent Preset

In signal_goblin.ino, find the TV power preset section in handleModuleTouch and add:

IrSender.sendNEC(0xYOURCODE, 32);   // NEC protocol, 32 bits
IrSender.sendSony(0xYOURCODE, 12);  // Sony SIRC, 12 bits

Power System

Architecture

USB-C (on TP4056 module)
       β”‚
       β–Ό
   TP4056 LiPo Charger ──────────────────────── Charge LEDs
       β”‚                                         (Red = charging)
       β–Ό                                         (Green = full)
  LiPo Battery 3.7V 2000mAh
  (JST-PH 2.0 connector)
       β”‚
       β”œβ”€β”€β”€β”€ SS14 Schottky Diode (reverse polarity protection)
       β”‚
       β”œβ”€β”€β”€β”€ PTC Fuse 500mA (overcurrent protection)
       β”‚
       └──── Power Switch (right ear) ──── MT3608 Boost EN
                                                 β”‚
                                                 β–Ό
                                          5V Boost Output
                                                 β”‚
                                    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                                    β–Ό                         β–Ό
                               ESP32 5V pin              IR Module
                             (internal LDO               PAM8302
                              β†’ 3.3V rail)               etc.

TP4056 Module Notes

The TP4056+Boost module you already own has everything built in:

  • USB-C charging port
  • TP4056 LiPo charge IC
  • DW01 battery protection (overcharge, overdischarge, short circuit)
  • MT3608 5V boost converter

You only need to wire 4 pads on the PCB:

  • B+ β†’ Battery positive (JST red wire)
  • B- β†’ Battery negative (JST black wire)
  • OUT+ β†’ 5V power rail
  • OUT- β†’ Ground rail

Battery Life Estimates

Usage Estimated Runtime
Display on, active scanning ~3–4 hours
Display on, idle ~5–6 hours
Display dimmed, light use ~8+ hours

Battery Gauge

GPIO36 reads a voltage divider (two 47kΞ© resistors) connected across the LiPo. The firmware maps the voltage range 3.2V–4.2V to 0–100% and displays it in the status bar and Settings screen.

Charging

Plug any USB-C cable into the left ear base connector. The red LED lights while charging. Green LED lights when full. Charge time from empty: approximately 3–4 hours at 500mA.


Audio System

Hardware

PAM8302A mono amplifier (SO-8) connected to a small 8Ξ© speaker via JST connector. Audio signal comes from ESP32 GPIO6 via PWM/DAC.

Uses in Firmware

  • Boot jingle on startup
  • Scan success alert (short beep)
  • Signal detected tone (CC1101/nRF24)
  • Card read confirmation (NFC)

Muting

The PAM8302 SD pin is tied to GPIO11. Pull low to mute, high to enable. The firmware mutes audio during active RF scanning to prevent interference pickup on the IR receiver.


Firmware Setup

Required Libraries

Install all of these via Arduino Library Manager before compiling:

Library Author Version
TFT_eSPI Bodmer Latest
IRremote shirriff/z3t0 4.x only
Adafruit_PN532 Adafruit Latest
RF24 TMRh20 Latest
SmartRC-CC1101-Driver-Lib LSatan Latest
FastLED FastLED Latest

TFT_eSPI Configuration

This is required before the firmware will compile. Find User_Setup.h inside the TFT_eSPI library folder and add/replace these lines:

#define ILI9488_DRIVER
#define TFT_MOSI  23
#define TFT_SCLK  18
#define TFT_CS     5
#define TFT_DC     2
#define TFT_RST    4
#define TOUCH_CS  33
#define SPI_FREQUENCY       27000000
#define SPI_TOUCH_FREQUENCY  2500000

Arduino IDE Board Settings

Setting Value
Board ESP32 Dev Module
Upload Speed 921600
CPU Frequency 240MHz
Flash Frequency 80MHz
Flash Mode QIO
Flash Size 16MB (128Mb)
Partition Scheme Default 4MB with spiffs
Core Debug Level None

Flashing the Firmware

  1. Connect USB-C cable to the Signal Goblin left ear port
  2. Hold BOOT button and press RST button simultaneously
  3. Release RST, then release BOOT β€” device enters flash mode
  4. Upload from Arduino IDE
  5. Press RST once after upload completes

First Boot

On first power-on you will see:

  1. Green orb pulsing in darkness
  2. Goblin silhouette materializes
  3. "SIGNAL GOBLIN" title flashes 3 times
  4. Scan line sweeps down the screen
  5. "INITIALIZING SYSTEMS..." message
  6. Main menu appears with animated goblin mascot

Building Your Goblin

Assembly Order

Follow this order to avoid regret:

  1. Flash the ESP32 first β€” test firmware on a breadboard before soldering anything to the PCB. Much easier to debug before it's mounted.
  2. Set PN532 DIP switches β€” SW1 OFF, SW2 ON for I2C. Do this before anything else because you can't reach them after soldering.
  3. Solder SMD passives first β€” 0402 resistors and capacitors. Decoupling caps, voltage divider, LED current resistors. Use paste + hot air if possible.
  4. Solder SMD ICs β€” PAM8302A (SO-8). SOT-23 components if using bare ICs.
  5. Apply stencil and paste to stamp-hole pads β€” CC1101, nRF24, ESP32. Do all at once, place modules, reflow together.
  6. Solder through-hole components β€” tactile buttons, pin headers, SMA connectors, power switch.
  7. Wire TP4056 module pads β€” B+, B-, OUT+, OUT- to PCB pads. Use short thick wire.
  8. Connect battery JST β€” double-check polarity before connecting. Red = B+, Black = B-.
  9. Test before closing up β€” power on, verify all modules initialize in the boot sequence.
  10. Attach IPEX pigtails β€” route CC1101 pigtail to right ear SMA, nRF24 pigtail to left ear SMA. The pigtails are fragile β€” route them carefully before screwing down the SMA connectors.

Solder Paste Tips

  • Use a steel stencil (order with PCB from JLCPCB)
  • Apply paste, place all modules, then reflow in one pass
  • The ESP32 stamp holes need proper paste coverage or you'll get cold joints
  • After reflow, inspect stamp holes with a magnifier β€” add solder to any that look dry

IPEX Connector Warning

The IPEX (U.FL) connectors on the CC1101 and nRF24 modules are extremely fragile. They are rated for approximately 30 connect/disconnect cycles. Once the pigtail is routed to the SMA connector, leave it connected. If you need to disconnect it, apply firm straight pressure β€” never lever or twist.


Troubleshooting

Display Shows Nothing

  • Check TFT_eSPI User_Setup.h is configured correctly
  • Verify backlight β€” GPIO32 should be PWM high
  • Check SPI connections: MOSI=23, SCK=18, CS=5, DC=2, RST=4
  • Try a slower SPI frequency in User_Setup.h: #define SPI_FREQUENCY 20000000

PN532 Not Found

  • Most likely cause: DIP switches are still in UART mode. If already soldered, you'll need to desolder the module.
  • Check I2C pull-ups are present (4.7kΞ© or 10kΞ© from SDA/SCL to 3.3V)
  • Verify I2C address: default is 0x24, scan with Wire.begin(); for(int i=1;i<127;i++){Wire.beginTransmission(i);if(!Wire.endTransmission())Serial.println(i,HEX);}

CC1101 Not Responding

  • Check CS is GPIO14 in firmware init
  • Verify SPI is initialized before calling CC1101 init
  • CC1101 runs on 3.3V β€” ensure it's not on 5V rail
  • Cold joint on stamp-hole pads is the most common physical cause

nRF24 Not Found

  • nRF24 is extremely sensitive to power supply noise β€” add a 100Β΅F cap close to its VCC/GND pins
  • Ensure CSN=16 and CE=25 are correct
  • Try radio.begin() and check return value β€” false means no response

Touch Not Working

  • TOUCH_CS must be GPIO33 in User_Setup.h
  • Touch IRQ is GPIO36 β€” this is an input-only pin, which is correct
  • Calibrate touch: tft.calibrateTouch(calData, TFT_WHITE, TFT_BLACK, 15)

Device Won't Enter Flash Mode

  • Hold BOOT (GPIO0), tap RST, release RST, then release BOOT
  • If that fails: hold BOOT, plug in USB-C, release BOOT
  • GPIO0 must be pulled LOW during boot to enter flash mode

Battery Not Charging

  • Check TP4056 module LED β€” red = charging, no LED = no input power
  • Verify USB-C connector orientation and wiring to module
  • Module OUT+ must connect to 5V rail, OUT- to GND

Audio No Sound

  • PAM8302 SD pin must be HIGH to enable (GPIO11 high)
  • Check speaker JST polarity
  • Confirm OUT+ and OUT- from PAM8302 go to speaker, not GND

Bill of Materials

Already Ordered / Owned

Item Status
CC1101 E07-433M20S Γ—4 βœ… Ordered
nRF24 E01-ML01SP2 βœ… Ordered
SMA edge connectors Γ—25 βœ… Ordered
PN532 Elechouse V3 βœ… Owned
MicroSD breakout βœ… Owned
TP4056+Boost module with USB-C βœ… Owned
MicroSD breakout board βœ… Owned
Power slide switch (SPDT) βœ… Owned
Vibration motor (bonus haptics) βœ… Owned
100Ξ© resistors 0402 (101) βœ… Owned
10kΞ© resistors 0402 (103) βœ… Owned
47kΞ© resistors 0402 (473) βœ… Owned
SMD ceramic caps (likely 100nF) βœ… Owned
SOD-80 signal diodes (1N4148) βœ… Owned

Still Needed

Item Source Notes
ESP32-WROOM-32E-N16 AliExpress Main MCU
ILI9488 3.5" SPI TFT AliExpress 320Γ—480 with XPT2046 touch
5V IR Tx/Rx module AliExpress Transmitter + receiver combo
LiPo 3.7V 2000mAh Amazon JST-PH 2.0, flat pouch style
Signal Goblin PCB v7.1 Γ—5 JLCPCB Black soldermask, with stencil
SS14 Schottky diode SOD-123 Γ—5 LCSC Battery reverse polarity protection
PTC fuse 500mA 1206 Γ—3 LCSC Overcurrent protection
4.7Β΅H inductor 0805 Γ—3 LCSC MT3608 boost (if using bare ICs)
10Β΅F cap 0805 Γ—10 LCSC Filter caps
PAM8302A SO-8 Γ—2 LCSC Audio amp
WS2812B RGB LED Γ—3 AliExpress Forehead indicator
6Γ—6mm SMD tactile button Γ—5 LCSC RST + BOOT
330Ξ© resistors 0402 Γ—10 LCSC LED current limiting
8Ξ© 0.5W mini speaker + JST AliExpress Audio output
2.54mm pin headers assorted AliExpress All connectors
JST-PH 2.0 2-pin connectors Γ—10 AliExpress Battery + speaker
M2Γ—4mm screws + nuts Γ—10 Hardware Display mounting
M2.7Γ—5mm screws + nuts Γ—10 Hardware Board mounting

Credits & License

Signal Goblin is an original open-source hardware project.

  • PCB Design: Custom Python-generated Gerbers using PIL/numpy
  • Firmware: Arduino framework for ESP32
  • Inspiration: Flipper Zero, HackRF, Proxmark

Libraries Used

Signal Goblin is an educational tool for security research and RF analysis on systems you own or have explicit permission to test. Transmitting on regulated frequencies without authorization is illegal in most jurisdictions. The CC1101 and nRF24 modules must be used in compliance with local radio regulations. The author takes no responsibility for misuse.


Built with spite, solder, and goblin energy.

/\ /\\

( o o )
\ ^ / SIGNAL GOBLIN
||||| v7.1 FINAL
|||||