FOCUSED PRODUCT
GHOSTWAVE
Wireless Intelligence Framework
A local-first wireless analysis surface for RF visibility, scanning, client roaming context, rogue detection, and evidence-oriented reporting - with a governed local API when the operator enables remote query.
Product posture
Local wireless sentinel, not a cloud console
Built with Rust, Tauri 2, SvelteKit, SQLite, Axum. Capability directions below describe intended engineering scope - not availability or production-readiness claims.
-
Runs as a persistent, low-overhead application on Windows, macOS, and Linux.
-
Scans 802.11 beacon and probe traffic to map nearby access points, BSSIDs, and advertised capabilities.
-
Captures RF visibility - signal strength, channel utilization, noise floor, and airtime estimates.
-
Reconstructs client roaming context by correlating probe requests, associations, and BSSID transitions.
-
Detects rogue access points, spoofed BSSIDs, and unexpected SSIDs against an operator-approved allowlist.
-
Produces evidence-oriented reports in multiple formats (CSV, XLSX, PDF, HTML).
Capability direction
What the wireless surface covers
Wireless Scanning
Beacon, probe, and data-frame collection across 2.4 GHz, 5 GHz, and 6 GHz channels.
RF Visibility
Signal strength, channel utilization, noise floor, and airtime estimates per BSSID.
Client Roaming Context
Correlated probe requests, associations, and BSSID transitions per client.
Rogue Detection
Spoofed BSSIDs, unexpected SSIDs, and allowlist violations surfaced as findings.
Evidence Reporting
CSV, spreadsheet, PDF, and HTML export directions for audit-grade artifacts.
Local API
Authenticated REST surface for automation and dashboards when explicitly enabled.
Sovereignty
Local ownership
GHOSTWAVE is not a cloud service. It is a sovereign, locally installed application.
The operator retains ownership of capture and findings data. No telemetry is transmitted externally unless remote API access is explicitly configured.
Runtime surfaces (expand)
Application Shell
Tauri desktop shell with SvelteKit UI for local capture and review.
Capture Engine
Rust-native monitor-mode handling for raw 802.11 frames and RF metrics.
Embedded HTTP API
Axum-based authenticated endpoints for remote consumers when enabled.
Findings Store
Local SQLite persistence for scan history, rogue findings, and roaming context.
Explore related endpoint work
GHOSTWAVE sits with other focused tools in the portfolio. Pair it with GHOSTOPS for endpoint intelligence, or ask Mythos about wireless security direction.