Proxmark3
Open source RFID research tool for reading, sniffing, cloning, and emulating LF and HF credentials.
Technical Architecture & Overview
Proxmark3 is the research standard for RFID security, covering 125 kHz and 13.56 MHz systems including HID, MIFARE, and ISO 14443/15693 credentials. The RfidResearchGroup Iceman fork is the de facto firmware, with continuous development, extensive Lua scripting, and a next-generation Proxmark5 hardware line. Access control audits rely on it for sniffing, cloning, and vulnerability analysis of badge systems.
Targeted Technical Use Cases
Serious RFID and NFC security assessment of physical access control credentials.
Evaluation & Trade-offs
Core Strengths
- +Deepest protocol analysis capability in its class.
- +Actively maintained Iceman firmware.
- +Client runs on all major desktop platforms.
Trade-Offs & Limitations
- -Steeper learning curve than consumer devices.
- -Genuine hardware sourcing matters; clones vary in quality.
Defensive Security Application
Auditing badge systems for clonable and weakly encrypted credentials before attackers test them.
Frequently Asked Questions
What is Proxmark3?→
Proxmark3 is the research standard for RFID security, covering 125 kHz and 13.56 MHz systems including HID, MIFARE, and ISO 14443/15693 credentials. The RfidResearchGroup Iceman fork is the de facto firmware, with continuous development, extensive Lua scripting, and a next-generation Proxmark5 hardware line. Access control audits rely on it for sniffing, cloning, and vulnerability analysis of badge systems.
What is Proxmark3 used for?→
Serious RFID and NFC security assessment of physical access control credentials.
What are the strengths of Proxmark3?→
- +Deepest protocol analysis capability in its class.
- +Actively maintained Iceman firmware.
- +Client runs on all major desktop platforms.
What are the limitations of Proxmark3?→
- +Steeper learning curve than consumer devices.
- +Genuine hardware sourcing matters; clones vary in quality.
How is Proxmark3 used defensively?→
Auditing badge systems for clonable and weakly encrypted credentials before attackers test them.