FOCUSED PRODUCT

GHOSTWAVE

Wireless Intelligence Framework

A local-first wireless analysis surface for RF visibility, scanning, client roaming context, rogue detection, and evidence-oriented reporting - with a governed local API when the operator enables remote query.

Architecture Direction

Product posture

Local wireless sentinel, not a cloud console

Built with Rust, Tauri 2, SvelteKit, SQLite, Axum. Capability directions below describe intended engineering scope - not availability or production-readiness claims.

  1. 01

    Runs as a persistent, low-overhead application on Windows, macOS, and Linux.

  2. 02

    Scans 802.11 beacon and probe traffic to map nearby access points, BSSIDs, and advertised capabilities.

  3. 03

    Captures RF visibility - signal strength, channel utilization, noise floor, and airtime estimates.

  4. 04

    Reconstructs client roaming context by correlating probe requests, associations, and BSSID transitions.

  5. 05

    Detects rogue access points, spoofed BSSIDs, and unexpected SSIDs against an operator-approved allowlist.

  6. 06

    Produces evidence-oriented reports in multiple formats (CSV, XLSX, PDF, HTML).

Capability direction

What the wireless surface covers

  • Wireless Scanning

    Beacon, probe, and data-frame collection across 2.4 GHz, 5 GHz, and 6 GHz channels.

  • RF Visibility

    Signal strength, channel utilization, noise floor, and airtime estimates per BSSID.

  • Client Roaming Context

    Correlated probe requests, associations, and BSSID transitions per client.

  • Rogue Detection

    Spoofed BSSIDs, unexpected SSIDs, and allowlist violations surfaced as findings.

  • Evidence Reporting

    CSV, spreadsheet, PDF, and HTML export directions for audit-grade artifacts.

  • Local API

    Authenticated REST surface for automation and dashboards when explicitly enabled.

Sovereignty

Local ownership

GHOSTWAVE is not a cloud service. It is a sovereign, locally installed application.

The operator retains ownership of capture and findings data. No telemetry is transmitted externally unless remote API access is explicitly configured.

Runtime surfaces (expand)
  • Application Shell

    Tauri desktop shell with SvelteKit UI for local capture and review.

  • Capture Engine

    Rust-native monitor-mode handling for raw 802.11 frames and RF metrics.

  • Embedded HTTP API

    Axum-based authenticated endpoints for remote consumers when enabled.

  • Findings Store

    Local SQLite persistence for scan history, rogue findings, and roaming context.

Explore related endpoint work

GHOSTWAVE sits with other focused tools in the portfolio. Pair it with GHOSTOPS for endpoint intelligence, or ask Mythos about wireless security direction.