I recently finished two public releases from my ongoing Verkracked research into Verkada BH-series alarm hardware.
I wanted to see how much of the system could be independently recreated for people using hardware they own, without shipping vendor firmware, private captures, credentials or any of the vulnerability research still going through coordinated disclosure. So I split the work into two standalone projects.

Part 4 is the BH-series cloud emulator. It reimplements the cloud-side interfaces needed by supported BH31/BH61 hardware so an owner can point their hub at infrastructure they control. It handles device state, events, telemetry, Socket.IO, artifacts, version management and the recovered administration protocols without contacting Verkada production services.
Part 5 is the BH-series Sub-GHz framework. It is a C++20 toolkit for passive HackRF acquisition, raw IQ and SigMF analysis, framing, CRC, VMAC/VCMP parsing and analytical DSSS/OQPSK work. The public tooling is receive/offline focused and does not include an RF transmit command.
Both projects are bring-your-own-hardware and bring-your-own-data. BH61 is the primary research target and BH31 support is still experimental. No device credentials, customer data, proprietary firmware or embargoed vulnerability findings are included.
It will be interesting to see what owners and researchers build with them. The introduction to the larger project is in Verkracked Part 0. Parts 1–3 will follow when their coordinated-disclosure windows are complete.
View other parts of the Verkracked Research Project Below:
Part 0 – Verkracked – Security Research on Verkada Anti-Crime Devices – Link
Part 4&5 – Verkracked – Local Cloud and Sub-GHz Frameworks for Verkada Alarm Hubs – Link
END TRANSMISSION
