Files
roro9stack/site/content/howto/lora-capture.md
T
twislaandClaude Opus 5.5 305818466f
CI / build (pull_request) Successful in 2m19s
Site / build (pull_request) Successful in 9s
LoRa Scanner: MeshCore by default, and its public channel read
The MeshCore preset is the default for a new device, in the Settings and
in the radio before the Scanner is opened. The setting now accepts it:
it only took the 7 Meshtastic presets, so MeshCore picked in the App was
not saved.

Messages on MeshCore's public channel are decrypted with the channel's
published key (AES-128, checked with 2 bytes of HMAC-SHA256): the row
shows who says they sent it and the start of the text, the details the
sender, the time and the whole text. Other channels and private messages
stay encrypted.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0162FokPdvY2KsS4NBfwyWPk
2026-10-09 22:19:14 +02:00

1.6 KiB

+++ title = "Capture LoRa packets and open them in Wireshark" description = "Record what the radio hears into a pcap file, then read it on a computer." weight = 6 [extra] tag = "LoRa Scanner" +++

The radio only listens: nothing is transmitted. You need the Cap LoRa-1262 and an SD card.

  1. Open the LoRa Scanner. The Status Bar shows L while the radio listens.
  2. Pick a preset with p. The Scanner offers MeshCore (the default) and the 7 Meshtastic presets allowed in EU868.
  3. Wait for packets. Each line is a packet: the time, RSSI and SNR, and for a Meshtastic packet the sender, the receiver and the hops. Enter shows a packet's header and its bytes.
  4. Press c to start a capture. The Status Bar shows CAP. It keeps recording with the App closed.
  5. Press c again to stop.
  6. Get the file. It is in /captures/lora/, a .pcap with LoRaTap headers. In the Storage App you can already look at its packets; on a computer, open it in Wireshark.

What you will and will not see. Meshtastic's header is never encrypted, so who sent a packet and how far it hopped is visible. The message itself is encrypted with the channel's key, and the Scanner does not decrypt it. MeshCore's public channel is the exception: its key is published, and the Scanner reads what is said there.

Hearing nothing is normal if no node is in range, or if the preset does not match what the nodes nearby use. The Sweep (Tab) shows whether anything is on the air at all across 863 to 870 MHz.