[{"data":1,"prerenderedAt":1700},["ShallowReactive",2],{"guides":3},[4,476,824,1331],{"_path":5,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":9,"description":10,"protocol":11,"category":12,"difficulty":13,"estimatedTime":14,"tools":15,"body":21,"_type":470,"_id":471,"_source":472,"_file":473,"_stem":474,"_extension":475},"\u002Fguides\u002F5g-core-penetration-testing","guides",false,"","5G Core Penetration Testing Guide","End-to-end methodology for auditing 5G Standalone Core Service-Based Architecture interfaces, from reconnaissance through exploitation and reporting.","5G SA","Protocol Audit Guide","Advanced","4-6 hours",[16,17,18,19,20],"open5gs","free5gc","ueransim","gnbsim","sctpscan",{"type":22,"children":23,"toc":448},"root",[24,33,39,46,107,113,120,125,138,144,153,159,165,170,179,185,190,199,205,211,220,226,235,241,247,376,382,425,431],{"type":25,"tag":26,"props":27,"children":29},"element","h1",{"id":28},"_5g-core-penetration-testing-complete-methodology",[30],{"type":31,"value":32},"text","5G Core Penetration Testing — Complete Methodology",{"type":25,"tag":34,"props":35,"children":36},"p",{},[37],{"type":31,"value":38},"This guide provides a structured, repeatable methodology for security-testing 5G Standalone (SA) Core networks. It covers Service-Based Architecture (SBA) HTTP\u002F2 API testing, N2\u002FN3 interface exploitation, authentication protocol analysis, and network function privilege escalation.",{"type":25,"tag":40,"props":41,"children":43},"h2",{"id":42},"prerequisites",[44],{"type":31,"value":45},"Prerequisites",{"type":25,"tag":47,"props":48,"children":49},"ul",{},[50,62,78,102],{"type":25,"tag":51,"props":52,"children":53},"li",{},[54,60],{"type":25,"tag":55,"props":56,"children":57},"strong",{},[58],{"type":31,"value":59},"TelcoChisel OS",{"type":31,"value":61}," with Open5GS or free5GC installed and running",{"type":25,"tag":51,"props":63,"children":64},{},[65,70,72,76],{"type":25,"tag":55,"props":66,"children":67},{},[68],{"type":31,"value":69},"UERANSIM",{"type":31,"value":71}," or ",{"type":25,"tag":55,"props":73,"children":74},{},[75],{"type":31,"value":19},{"type":31,"value":77}," for UE\u002FgNodeB simulation",{"type":25,"tag":51,"props":79,"children":80},{},[81,86,88,93,95,100],{"type":25,"tag":55,"props":82,"children":83},{},[84],{"type":31,"value":85},"curl",{"type":31,"value":87},", ",{"type":25,"tag":55,"props":89,"children":90},{},[91],{"type":31,"value":92},"httpie",{"type":31,"value":94},", or ",{"type":25,"tag":55,"props":96,"children":97},{},[98],{"type":31,"value":99},"Burp Suite",{"type":31,"value":101}," for HTTP\u002F2 API testing",{"type":25,"tag":51,"props":103,"children":104},{},[105],{"type":31,"value":106},"Basic understanding of 3GPP 5G System Architecture (TS 23.501, TS 29.500)",{"type":25,"tag":40,"props":108,"children":110},{"id":109},"phase-1-reconnaissance-service-discovery",[111],{"type":31,"value":112},"Phase 1: Reconnaissance & Service Discovery",{"type":25,"tag":114,"props":115,"children":117},"h3",{"id":116},"_11-identify-active-network-functions",[118],{"type":31,"value":119},"1.1 Identify Active Network Functions",{"type":25,"tag":34,"props":121,"children":122},{},[123],{"type":31,"value":124},"The 5G Core SBA exposes HTTP\u002F2 REST APIs on well-known ports. Start by discovering active NFs:",{"type":25,"tag":126,"props":127,"children":132},"pre",{"className":128,"code":130,"language":131,"meta":8},[129],"language-bash","# Scan for common 5G Core SBA ports\nnmap -sT -p 7777,8000,8080,8443,29518,29519 --open -oA 5g-core-scan 127.0.0.0\u002F24\n\n# Check NRF (Network Repository Function) for registered services\ncurl -k -X GET http:\u002F\u002F127.0.0.10:8000\u002Fnnrf-disc\u002Fv1\u002Fnf-instances?nf-type=AMF\ncurl -k -X GET http:\u002F\u002F127.0.0.10:8000\u002Fnnrf-disc\u002Fv1\u002Fnf-instances?nf-type=SMF\ncurl -k -X GET http:\u002F\u002F127.0.0.10:8000\u002Fnnrf-disc\u002Fv1\u002Fnf-instances?nf-type=UDM\n","bash",[133],{"type":25,"tag":134,"props":135,"children":136},"code",{"__ignoreMap":8},[137],{"type":31,"value":130},{"type":25,"tag":114,"props":139,"children":141},{"id":140},"_12-enumerate-nf-api-surfaces",[142],{"type":31,"value":143},"1.2 Enumerate NF API Surfaces",{"type":25,"tag":126,"props":145,"children":148},{"className":146,"code":147,"language":131,"meta":8},[129],"# Discover AMF available APIs\ncurl -k http:\u002F\u002F127.0.0.5:7777\u002Fnamf-comm\u002Fv1\u002Fue-contexts\n\n# Discover SMF session management endpoints\ncurl -k http:\u002F\u002F127.0.0.4:7777\u002Fnsmf-pdusession\u002Fv1\u002Fsm-contexts\n\n# Discover UDM subscriber data endpoints\ncurl -k http:\u002F\u002F127.0.0.12:7777\u002Fnudm-sdm\u002Fv2\u002Fimsi-001010000000001\u002Fnssai\n",[149],{"type":25,"tag":134,"props":150,"children":151},{"__ignoreMap":8},[152],{"type":31,"value":147},{"type":25,"tag":40,"props":154,"children":156},{"id":155},"phase-2-authentication-authorization-testing",[157],{"type":31,"value":158},"Phase 2: Authentication & Authorization Testing",{"type":25,"tag":114,"props":160,"children":162},{"id":161},"_21-nrf-token-authorization-bypass",[163],{"type":31,"value":164},"2.1 NRF Token Authorization Bypass",{"type":25,"tag":34,"props":166,"children":167},{},[168],{"type":31,"value":169},"Test whether NFs properly validate OAuth2 tokens issued by the NRF:",{"type":25,"tag":126,"props":171,"children":174},{"className":172,"code":173,"language":131,"meta":8},[129],"# Request an access token from NRF\ncurl -k -X POST http:\u002F\u002F127.0.0.10:8000\u002Foauth2\u002Ftoken \\\n  -d \"grant_type=client_credentials&nfInstanceId=test-nf-001&nfType=AMF&targetNfType=UDM&scope=nudm-sdm\"\n\n# Attempt to use the token against a different NF than authorized\ncurl -k -H \"Authorization: Bearer \u003CTOKEN>\" \\\n  http:\u002F\u002F127.0.0.4:7777\u002Fnsmf-pdusession\u002Fv1\u002Fsm-contexts\n",[175],{"type":25,"tag":134,"props":176,"children":177},{"__ignoreMap":8},[178],{"type":31,"value":173},{"type":25,"tag":114,"props":180,"children":182},{"id":181},"_22-supisuci-privacy-testing",[183],{"type":31,"value":184},"2.2 SUPI\u002FSUCI Privacy Testing",{"type":25,"tag":34,"props":186,"children":187},{},[188],{"type":31,"value":189},"Verify that SUPI (Subscription Permanent Identifier) is properly concealed:",{"type":25,"tag":126,"props":191,"children":194},{"className":192,"code":193,"language":131,"meta":8},[129],"# Monitor N1\u002FN2 signaling for plaintext SUPI exposure\nsudo tshark -i lo -Y \"ngap\" -T fields -e nas_5gs.mm.supi\n\n# Attempt registration with a crafted SUCI using null scheme\n# (Tests ECIES Profile A\u002FB implementation)\n",[195],{"type":25,"tag":134,"props":196,"children":197},{"__ignoreMap":8},[198],{"type":31,"value":193},{"type":25,"tag":40,"props":200,"children":202},{"id":201},"phase-3-protocol-fuzzing-injection",[203],{"type":31,"value":204},"Phase 3: Protocol Fuzzing & Injection",{"type":25,"tag":114,"props":206,"children":208},{"id":207},"_31-ngap-n2-interface-fuzzing",[209],{"type":31,"value":210},"3.1 NGAP (N2 Interface) Fuzzing",{"type":25,"tag":126,"props":212,"children":215},{"className":213,"code":214,"language":131,"meta":8},[129],"# Launch UERANSIM gNodeB against the target AMF\nnr-gnb -c \u002Fetc\u002Fueransim\u002Fgnb.yaml\n\n# Send malformed NGAP messages\n# Monitor AMF crash behavior and error handling\nsudo tshark -i lo -Y \"ngap\" -T pdml > ngap_capture.xml\n",[216],{"type":25,"tag":134,"props":217,"children":218},{"__ignoreMap":8},[219],{"type":31,"value":214},{"type":25,"tag":114,"props":221,"children":223},{"id":222},"_32-gtp-u-n3-interface-data-plane-testing",[224],{"type":31,"value":225},"3.2 GTP-U (N3 Interface) Data Plane Testing",{"type":25,"tag":126,"props":227,"children":230},{"className":228,"code":229,"language":131,"meta":8},[129],"# Test UPF TEID allocation and GTP tunnel handling\n# Use gnbsim to generate high-volume GTP-U traffic\ngnbsim --cfg \u002Fetc\u002Fgnbsim\u002Ffuzz-config.json --num-ue 100\n\n# Monitor for data plane leaks across UE sessions\nsudo tshark -i ogstun -Y \"gtp\" -T fields -e gtp.teid -e ip.src -e ip.dst\n",[231],{"type":25,"tag":134,"props":232,"children":233},{"__ignoreMap":8},[234],{"type":31,"value":229},{"type":25,"tag":40,"props":236,"children":238},{"id":237},"phase-4-reporting-remediation",[239],{"type":31,"value":240},"Phase 4: Reporting & Remediation",{"type":25,"tag":114,"props":242,"children":244},{"id":243},"_41-common-findings",[245],{"type":31,"value":246},"4.1 Common Findings",{"type":25,"tag":248,"props":249,"children":250},"table",{},[251,280],{"type":25,"tag":252,"props":253,"children":254},"thead",{},[255],{"type":25,"tag":256,"props":257,"children":258},"tr",{},[259,265,270,275],{"type":25,"tag":260,"props":261,"children":262},"th",{},[263],{"type":31,"value":264},"Finding",{"type":25,"tag":260,"props":266,"children":267},{},[268],{"type":31,"value":269},"Severity",{"type":25,"tag":260,"props":271,"children":272},{},[273],{"type":31,"value":274},"CVSS",{"type":25,"tag":260,"props":276,"children":277},{},[278],{"type":31,"value":279},"Remediation",{"type":25,"tag":281,"props":282,"children":283},"tbody",{},[284,308,331,354],{"type":25,"tag":256,"props":285,"children":286},{},[287,293,298,303],{"type":25,"tag":288,"props":289,"children":290},"td",{},[291],{"type":31,"value":292},"NRF token not validated by NFs",{"type":25,"tag":288,"props":294,"children":295},{},[296],{"type":31,"value":297},"Critical",{"type":25,"tag":288,"props":299,"children":300},{},[301],{"type":31,"value":302},"9.8",{"type":25,"tag":288,"props":304,"children":305},{},[306],{"type":31,"value":307},"Enable mandatory OAuth2 token verification on all SBI endpoints",{"type":25,"tag":256,"props":309,"children":310},{},[311,316,321,326],{"type":25,"tag":288,"props":312,"children":313},{},[314],{"type":31,"value":315},"SUPI exposed in plaintext on N1",{"type":25,"tag":288,"props":317,"children":318},{},[319],{"type":31,"value":320},"High",{"type":25,"tag":288,"props":322,"children":323},{},[324],{"type":31,"value":325},"8.1",{"type":25,"tag":288,"props":327,"children":328},{},[329],{"type":31,"value":330},"Enforce SUCI with ECIES Profile A (curve25519)",{"type":25,"tag":256,"props":332,"children":333},{},[334,339,344,349],{"type":25,"tag":288,"props":335,"children":336},{},[337],{"type":31,"value":338},"No rate limiting on SBI APIs",{"type":25,"tag":288,"props":340,"children":341},{},[342],{"type":31,"value":343},"Medium",{"type":25,"tag":288,"props":345,"children":346},{},[347],{"type":31,"value":348},"5.3",{"type":25,"tag":288,"props":350,"children":351},{},[352],{"type":31,"value":353},"Implement per-NF request rate limiting",{"type":25,"tag":256,"props":355,"children":356},{},[357,362,366,371],{"type":25,"tag":288,"props":358,"children":359},{},[360],{"type":31,"value":361},"GTP-U cross-session data leak",{"type":25,"tag":288,"props":363,"children":364},{},[365],{"type":31,"value":297},{"type":25,"tag":288,"props":367,"children":368},{},[369],{"type":31,"value":370},"9.1",{"type":25,"tag":288,"props":372,"children":373},{},[374],{"type":31,"value":375},"Enforce TEID isolation per PDU session",{"type":25,"tag":114,"props":377,"children":379},{"id":378},"_42-3gpp-security-specification-references",[380],{"type":31,"value":381},"4.2 3GPP Security Specification References",{"type":25,"tag":47,"props":383,"children":384},{},[385,395,405,415],{"type":25,"tag":51,"props":386,"children":387},{},[388,393],{"type":25,"tag":55,"props":389,"children":390},{},[391],{"type":31,"value":392},"TS 33.501",{"type":31,"value":394},": Security architecture and procedures for 5G System",{"type":25,"tag":51,"props":396,"children":397},{},[398,403],{"type":25,"tag":55,"props":399,"children":400},{},[401],{"type":31,"value":402},"TS 29.510",{"type":31,"value":404},": NRF Services (NFDiscovery, NFManagement, AccessToken)",{"type":25,"tag":51,"props":406,"children":407},{},[408,413],{"type":25,"tag":55,"props":409,"children":410},{},[411],{"type":31,"value":412},"TS 33.535",{"type":31,"value":414},": Authentication and Key Management for HTTP-based APIs",{"type":25,"tag":51,"props":416,"children":417},{},[418,423],{"type":25,"tag":55,"props":419,"children":420},{},[421],{"type":31,"value":422},"TS 29.244",{"type":31,"value":424},": PFCP interface specification (UPF control)",{"type":25,"tag":40,"props":426,"children":428},{"id":427},"practice-in-telcosec-academy",[429],{"type":31,"value":430},"Practice in TelcoSec Academy",{"type":25,"tag":34,"props":432,"children":433},{},[434,436],{"type":31,"value":435},"👉 ",{"type":25,"tag":55,"props":437,"children":438},{},[439],{"type":25,"tag":440,"props":441,"children":445},"a",{"href":442,"rel":443},"https:\u002F\u002Fapp.telcosec.net",[444],"nofollow",[446],{"type":31,"value":447},"Launch the 5G Core Red Team Lab on App.TelcoSec.Net",{"title":8,"searchDepth":449,"depth":449,"links":450},2,[451,452,457,461,465,469],{"id":42,"depth":449,"text":45},{"id":109,"depth":449,"text":112,"children":453},[454,456],{"id":116,"depth":455,"text":119},3,{"id":140,"depth":455,"text":143},{"id":155,"depth":449,"text":158,"children":458},[459,460],{"id":161,"depth":455,"text":164},{"id":181,"depth":455,"text":184},{"id":201,"depth":449,"text":204,"children":462},[463,464],{"id":207,"depth":455,"text":210},{"id":222,"depth":455,"text":225},{"id":237,"depth":449,"text":240,"children":466},[467,468],{"id":243,"depth":455,"text":246},{"id":378,"depth":455,"text":381},{"id":427,"depth":449,"text":430},"markdown","content:guides:5g-core-penetration-testing.md","content","guides\u002F5g-core-penetration-testing.md","guides\u002F5g-core-penetration-testing","md",{"_path":477,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":478,"description":479,"protocol":480,"category":481,"difficulty":482,"estimatedTime":483,"tools":484,"body":489,"_type":470,"_id":821,"_source":472,"_file":822,"_stem":823,"_extension":475},"\u002Fguides\u002Fsdr-gsm-capture-hackrf","GSM Air Interface Capture with HackRF","Step-by-step guide to passively capturing and decoding GSM over-the-air traffic using HackRF One, Gr-GSM, Kalibrate-RTL, and Wireshark on TelcoChisel.","2G GSM","SDR Guide","Intermediate","2-3 hours",[485,486,487,488],"gr-gsm","kalibrate-rtl","kraken","gqrx",{"type":22,"children":490,"toc":803},[491,497,502,506,533,539,548,554,559,568,573,581,587,596,602,607,616,622,628,637,643,652,658,664,669,677,682,725,731,739,744,750,759,765,786,790],{"type":25,"tag":26,"props":492,"children":494},{"id":493},"gsm-air-interface-capture-with-hackrf-one",[495],{"type":31,"value":496},"GSM Air Interface Capture with HackRF One",{"type":25,"tag":34,"props":498,"children":499},{},[500],{"type":31,"value":501},"This guide walks through passive GSM over-the-air signal capture using HackRF One hardware on TelcoChisel. You will scan for active GSM cells, calibrate your SDR, capture downlink traffic, and decode signaling and voice channels in real-time via Wireshark.",{"type":25,"tag":40,"props":503,"children":504},{"id":42},[505],{"type":31,"value":45},{"type":25,"tag":47,"props":507,"children":508},{},[509,518,528],{"type":25,"tag":51,"props":510,"children":511},{},[512,516],{"type":25,"tag":55,"props":513,"children":514},{},[515],{"type":31,"value":59},{"type":31,"value":517}," with Gr-GSM, Kalibrate-RTL, and Gqrx pre-installed",{"type":25,"tag":51,"props":519,"children":520},{},[521,526],{"type":25,"tag":55,"props":522,"children":523},{},[524],{"type":31,"value":525},"HackRF One",{"type":31,"value":527}," with antenna (800-1900 MHz coverage)",{"type":25,"tag":51,"props":529,"children":530},{},[531],{"type":31,"value":532},"USB 2.0+ connection (USB 3.0 recommended for stability)",{"type":25,"tag":40,"props":534,"children":536},{"id":535},"step-1-verify-hackrf-hardware",[537],{"type":31,"value":538},"Step 1: Verify HackRF Hardware",{"type":25,"tag":126,"props":540,"children":543},{"code":541,"language":131,"meta":8,"className":542},"# Check that TelcoChisel detects the HackRF\nhackrf_info\n\n# Expected output:\n# Serial number: xxxxxxxx\n# Board ID: 2 (HackRF One)\n# Firmware: 2024.02.1\n# Part ID: 0xa000cb3c 0x00724764\n",[129],[544],{"type":25,"tag":134,"props":545,"children":546},{"__ignoreMap":8},[547],{"type":31,"value":541},{"type":25,"tag":40,"props":549,"children":551},{"id":550},"step-2-scan-for-active-gsm-cells",[552],{"type":31,"value":553},"Step 2: Scan for Active GSM Cells",{"type":25,"tag":34,"props":555,"children":556},{},[557],{"type":31,"value":558},"Use Kalibrate-RTL to discover active GSM base stations and calibrate the HackRF clock:",{"type":25,"tag":126,"props":560,"children":563},{"code":561,"language":131,"meta":8,"className":562},"# Scan GSM-900 band (Europe\u002FAsia\u002FAfrica)\nkal -s GSM900 -g 40\n\n# Scan DCS-1800 band (Europe)\nkal -s DCS1800 -g 40\n\n# Scan PCS-1900 band (Americas)\nkal -s PCS1900 -g 40\n",[129],[564],{"type":25,"tag":134,"props":565,"children":566},{"__ignoreMap":8},[567],{"type":31,"value":561},{"type":25,"tag":34,"props":569,"children":570},{},[571],{"type":31,"value":572},"Note the strongest channel (ARFCN) and frequency offset (PPM). Example output:",{"type":25,"tag":126,"props":574,"children":576},{"code":575},"chan: 55 (935.2MHz + 22.2kHz)  power: 282989.67\n",[577],{"type":25,"tag":134,"props":578,"children":579},{"__ignoreMap":8},[580],{"type":31,"value":575},{"type":25,"tag":40,"props":582,"children":584},{"id":583},"step-3-calibrate-ppm-offset",[585],{"type":31,"value":586},"Step 3: Calibrate PPM Offset",{"type":25,"tag":126,"props":588,"children":591},{"code":589,"language":131,"meta":8,"className":590},"# Lock to the strongest cell and calculate precise PPM\nkal -c 55 -g 40 -e 0\n\n# Note the \"average absolute error\" — this is your PPM value\n# Example: average absolute error: 14.53 ppm\n",[129],[592],{"type":25,"tag":134,"props":593,"children":594},{"__ignoreMap":8},[595],{"type":31,"value":589},{"type":25,"tag":40,"props":597,"children":599},{"id":598},"step-4-verify-signal-with-gqrx-optional",[600],{"type":31,"value":601},"Step 4: Verify Signal with Gqrx (Optional)",{"type":25,"tag":34,"props":603,"children":604},{},[605],{"type":31,"value":606},"For visual confirmation before capture:",{"type":25,"tag":126,"props":608,"children":611},{"code":609,"language":131,"meta":8,"className":610},"# Launch Gqrx, select HackRF, tune to the GSM frequency\ngqrx\n# Set center frequency to the ARFCN's downlink frequency (e.g., 935.2 MHz)\n# You should see GSM TDMA burst patterns in the waterfall\n",[129],[612],{"type":25,"tag":134,"props":613,"children":614},{"__ignoreMap":8},[615],{"type":31,"value":609},{"type":25,"tag":40,"props":617,"children":619},{"id":618},"step-5-live-gsm-capture-with-gr-gsm",[620],{"type":31,"value":621},"Step 5: Live GSM Capture with Gr-GSM",{"type":25,"tag":114,"props":623,"children":625},{"id":624},"_51-interactive-monitoring",[626],{"type":31,"value":627},"5.1 Interactive Monitoring",{"type":25,"tag":126,"props":629,"children":632},{"code":630,"language":131,"meta":8,"className":631},"# Launch Gr-GSM live monitor with GUI frequency selector\ngrgsm_livemon -f 935.2e6 -p 14\n# -f: center frequency (Hz)\n# -p: PPM correction from Step 3\n",[129],[633],{"type":25,"tag":134,"props":634,"children":635},{"__ignoreMap":8},[636],{"type":31,"value":630},{"type":25,"tag":114,"props":638,"children":640},{"id":639},"_52-headless-capture-to-wireshark",[641],{"type":31,"value":642},"5.2 Headless Capture to Wireshark",{"type":25,"tag":126,"props":644,"children":647},{"code":645,"language":131,"meta":8,"className":646},"# Start Gr-GSM headless and pipe GSMTAP frames to Wireshark\ngrgsm_livemon_headless -f 935.2e6 -p 14 &\n\n# In a separate terminal, launch Wireshark to receive GSMTAP\nwireshark -k -i lo -f \"udp port 4729\" -Y \"gsm_a.dtap || lapdm || gsm_a.rr\"\n",[129],[648],{"type":25,"tag":134,"props":649,"children":650},{"__ignoreMap":8},[651],{"type":31,"value":645},{"type":25,"tag":40,"props":653,"children":655},{"id":654},"step-6-decode-captured-traffic",[656],{"type":31,"value":657},"Step 6: Decode Captured Traffic",{"type":25,"tag":114,"props":659,"children":661},{"id":660},"_61-system-information-decoding",[662],{"type":31,"value":663},"6.1 System Information Decoding",{"type":25,"tag":34,"props":665,"children":666},{},[667],{"type":31,"value":668},"In Wireshark, filter for System Information messages:",{"type":25,"tag":126,"props":670,"children":672},{"code":671},"gsm_a.rr.message_type == 0x19 || gsm_a.rr.message_type == 0x1a || gsm_a.rr.message_type == 0x1b\n",[673],{"type":25,"tag":134,"props":674,"children":675},{"__ignoreMap":8},[676],{"type":31,"value":671},{"type":25,"tag":34,"props":678,"children":679},{},[680],{"type":31,"value":681},"These reveal:",{"type":25,"tag":47,"props":683,"children":684},{},[685,695,705,715],{"type":25,"tag":51,"props":686,"children":687},{},[688,693],{"type":25,"tag":55,"props":689,"children":690},{},[691],{"type":31,"value":692},"MCC\u002FMNC",{"type":31,"value":694},": Operator identity",{"type":25,"tag":51,"props":696,"children":697},{},[698,703],{"type":25,"tag":55,"props":699,"children":700},{},[701],{"type":31,"value":702},"LAC\u002FCellID",{"type":31,"value":704},": Location Area Code and Cell ID",{"type":25,"tag":51,"props":706,"children":707},{},[708,713],{"type":25,"tag":55,"props":709,"children":710},{},[711],{"type":31,"value":712},"ARFCN neighbors",{"type":31,"value":714},": Adjacent cell frequencies",{"type":25,"tag":51,"props":716,"children":717},{},[718,723],{"type":25,"tag":55,"props":719,"children":720},{},[721],{"type":31,"value":722},"Cipher setting",{"type":31,"value":724},": Whether A5\u002F1, A5\u002F2, or A5\u002F3 is used",{"type":25,"tag":114,"props":726,"children":728},{"id":727},"_62-paging-channel-monitoring",[729],{"type":31,"value":730},"6.2 Paging Channel Monitoring",{"type":25,"tag":126,"props":732,"children":734},{"code":733},"gsm_a.dtap.msg_rr_type == 0x21 || gsm_a.dtap.msg_rr_type == 0x22\n",[735],{"type":25,"tag":134,"props":736,"children":737},{"__ignoreMap":8},[738],{"type":31,"value":733},{"type":25,"tag":34,"props":740,"children":741},{},[742],{"type":31,"value":743},"Paging messages may contain plaintext IMSI transmissions — an indicator of active IMSI catchers.",{"type":25,"tag":40,"props":745,"children":747},{"id":746},"step-7-record-iq-samples-for-offline-analysis",[748],{"type":31,"value":749},"Step 7: Record IQ Samples for Offline Analysis",{"type":25,"tag":126,"props":751,"children":754},{"code":752,"language":131,"meta":8,"className":753},"# Record raw IQ samples for later processing (30 seconds at 2 MS\u002Fs)\nhackrf_transfer -r \u002Ftmp\u002Fgsm_capture.cf32 -f 935200000 -s 2000000 -a 1 -l 32 -g 40 -n 60000000\n\n# Process offline with Gr-GSM\ngrgsm_decode -c \u002Ftmp\u002Fgsm_capture.cf32 -a 55 -p 14 -s 2e6 -m BCCH\n",[129],[755],{"type":25,"tag":134,"props":756,"children":757},{"__ignoreMap":8},[758],{"type":31,"value":752},{"type":25,"tag":40,"props":760,"children":762},{"id":761},"safety-legal-notice",[763],{"type":31,"value":764},"Safety & Legal Notice",{"type":25,"tag":766,"props":767,"children":768},"blockquote",{},[769],{"type":25,"tag":34,"props":770,"children":771},{},[772,777,779,784],{"type":25,"tag":55,"props":773,"children":774},{},[775],{"type":31,"value":776},"WARNING",{"type":31,"value":778},": Active GSM transmission is illegal without authorization. This guide covers ",{"type":25,"tag":55,"props":780,"children":781},{},[782],{"type":31,"value":783},"passive reception only",{"type":31,"value":785},". Ensure compliance with local telecommunications regulations. TelcoChisel tools are intended for authorized security assessments and research environments only.",{"type":25,"tag":40,"props":787,"children":788},{"id":427},[789],{"type":31,"value":430},{"type":25,"tag":34,"props":791,"children":792},{},[793,794],{"type":31,"value":435},{"type":25,"tag":55,"props":795,"children":796},{},[797],{"type":25,"tag":440,"props":798,"children":800},{"href":442,"rel":799},[444],[801],{"type":31,"value":802},"Launch the SDR GSM Capture Lab on App.TelcoSec.Net",{"title":8,"searchDepth":449,"depth":449,"links":804},[805,806,807,808,809,810,814,818,819,820],{"id":42,"depth":449,"text":45},{"id":535,"depth":449,"text":538},{"id":550,"depth":449,"text":553},{"id":583,"depth":449,"text":586},{"id":598,"depth":449,"text":601},{"id":618,"depth":449,"text":621,"children":811},[812,813],{"id":624,"depth":455,"text":627},{"id":639,"depth":455,"text":642},{"id":654,"depth":449,"text":657,"children":815},[816,817],{"id":660,"depth":455,"text":663},{"id":727,"depth":455,"text":730},{"id":746,"depth":449,"text":749},{"id":761,"depth":449,"text":764},{"id":427,"depth":449,"text":430},"content:guides:sdr-gsm-capture-hackrf.md","guides\u002Fsdr-gsm-capture-hackrf.md","guides\u002Fsdr-gsm-capture-hackrf",{"_path":825,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":826,"description":827,"protocol":828,"category":12,"difficulty":13,"estimatedTime":829,"tools":830,"body":833,"_type":470,"_id":1328,"_source":472,"_file":1329,"_stem":1330,"_extension":475},"\u002Fguides\u002Fss7-location-tracking-assessment","SS7 Location Tracking Assessment","Methodology for assessing carrier vulnerability to SS7 MAP-based subscriber location tracking via AnyTimeInterrogation, ProvideSubscriberInfo, and SendRoutingInfo.","SS7 \u002F MAP \u002F SIGTRAN","3-4 hours",[831,832,20],"sigploit","ss7maper",{"type":22,"children":834,"toc":1307},[835,841,846,850,877,883,889,898,904,913,919,925,930,939,947,965,971,976,985,991,996,1005,1011,1017,1026,1032,1131,1137,1143,1241,1247,1290,1294],{"type":25,"tag":26,"props":836,"children":838},{"id":837},"ss7-location-tracking-assessment-map-protocol-methodology",[839],{"type":31,"value":840},"SS7 Location Tracking Assessment — MAP Protocol Methodology",{"type":25,"tag":34,"props":842,"children":843},{},[844],{"type":31,"value":845},"This guide documents the methodology for testing carrier SS7 networks against unauthorized subscriber location tracking. It covers MAP (Mobile Application Part) operations including AnyTimeInterrogation (ATI), ProvideSubscriberInfo (PSI), and SendRoutingInfo (SRI) that enable real-time geolocation of mobile subscribers.",{"type":25,"tag":40,"props":847,"children":848},{"id":42},[849],{"type":31,"value":45},{"type":25,"tag":47,"props":851,"children":852},{},[853,862,867,872],{"type":25,"tag":51,"props":854,"children":855},{},[856,860],{"type":25,"tag":55,"props":857,"children":858},{},[859],{"type":31,"value":59},{"type":31,"value":861}," with SigPloit and SS7MAPer installed",{"type":25,"tag":51,"props":863,"children":864},{},[865],{"type":31,"value":866},"SCTP connectivity to the target SS7 network (via legitimate test interconnect or lab setup)",{"type":25,"tag":51,"props":868,"children":869},{},[870],{"type":31,"value":871},"Valid SS7 Global Title (GT) for source addressing",{"type":25,"tag":51,"props":873,"children":874},{},[875],{"type":31,"value":876},"Understanding of ITU-T Q.700 series and 3GPP TS 29.002 (MAP specification)",{"type":25,"tag":40,"props":878,"children":880},{"id":879},"phase-1-ss7-network-reconnaissance",[881],{"type":31,"value":882},"Phase 1: SS7 Network Reconnaissance",{"type":25,"tag":114,"props":884,"children":886},{"id":885},"_11-sctp-endpoint-discovery",[887],{"type":31,"value":888},"1.1 SCTP Endpoint Discovery",{"type":25,"tag":126,"props":890,"children":893},{"className":891,"code":892,"language":131,"meta":8},[129],"# Discover SIGTRAN M3UA signaling endpoints on the target network\nsudo sctpscan -d 10.0.0.0\u002F24 -p 2905 -r\n\n# Identify STP (Signaling Transfer Point) addresses\nsudo sctpscan -d 172.16.0.0\u002F16 -p 2905,14001 -r\n",[894],{"type":25,"tag":134,"props":895,"children":896},{"__ignoreMap":8},[897],{"type":31,"value":892},{"type":25,"tag":114,"props":899,"children":901},{"id":900},"_12-ss7-topology-mapping",[902],{"type":31,"value":903},"1.2 SS7 Topology Mapping",{"type":25,"tag":126,"props":905,"children":908},{"className":906,"code":907,"language":131,"meta":8},[129],"# Use SS7MAPer for automated topology discovery\npython3 ss7maper.py --target-gt 441234567890 --source-gt 441111111111 --mode discovery\n\n# Map accessible HLR, VLR, MSC, and SMSC nodes\npython3 ss7maper.py --target-gt 441234567890 --mode map-nodes\n",[909],{"type":25,"tag":134,"props":910,"children":911},{"__ignoreMap":8},[912],{"type":31,"value":907},{"type":25,"tag":40,"props":914,"children":916},{"id":915},"phase-2-location-tracking-tests",[917],{"type":31,"value":918},"Phase 2: Location Tracking Tests",{"type":25,"tag":114,"props":920,"children":922},{"id":921},"_21-anytimeinterrogation-ati",[923],{"type":31,"value":924},"2.1 AnyTimeInterrogation (ATI)",{"type":25,"tag":34,"props":926,"children":927},{},[928],{"type":31,"value":929},"ATI queries the HLR\u002FHSS directly for the subscriber's current Cell-ID, LAC, and serving MSC address:",{"type":25,"tag":126,"props":931,"children":934},{"className":932,"code":933,"language":131,"meta":8},[129],"# Send ATI request via SigPloit\ncd \u002Fopt\u002Fsigploit && python3 sigploit.py\n\n# Select: SS7 > Location Tracking > AnyTimeInterrogation\n# Target MSISDN: +44xxxxxxxxxx\n# Source GT: \u003Cyour-test-GT>\n",[935],{"type":25,"tag":134,"props":936,"children":937},{"__ignoreMap":8},[938],{"type":31,"value":933},{"type":25,"tag":34,"props":940,"children":941},{},[942],{"type":25,"tag":55,"props":943,"children":944},{},[945],{"type":31,"value":946},"Expected Response (if unfiltered):",{"type":25,"tag":47,"props":948,"children":949},{},[950,955,960],{"type":25,"tag":51,"props":951,"children":952},{},[953],{"type":31,"value":954},"Current Cell Global Identity (CGI): MCC-MNC-LAC-CellID",{"type":25,"tag":51,"props":956,"children":957},{},[958],{"type":31,"value":959},"Age of Location Information (seconds since last location update)",{"type":25,"tag":51,"props":961,"children":962},{},[963],{"type":31,"value":964},"Serving MSC\u002FVLR address",{"type":25,"tag":114,"props":966,"children":968},{"id":967},"_22-sendroutinginfo-sri",[969],{"type":31,"value":970},"2.2 SendRoutingInfo (SRI)",{"type":25,"tag":34,"props":972,"children":973},{},[974],{"type":31,"value":975},"SRI is a legitimate MAP operation (used for call routing) that reveals the serving MSC address and IMSI:",{"type":25,"tag":126,"props":977,"children":980},{"className":978,"code":979,"language":131,"meta":8},[129],"# Send SRI request\npython3 sigploit.py\n# Select: SS7 > Location Tracking > SendRoutingInfo\n# Target MSISDN: +44xxxxxxxxxx\n\n# This reveals:\n# - IMSI (subscriber permanent identity)\n# - Serving MSC Global Title\n# - Roaming Number (MSRN)\n",[981],{"type":25,"tag":134,"props":982,"children":983},{"__ignoreMap":8},[984],{"type":31,"value":979},{"type":25,"tag":114,"props":986,"children":988},{"id":987},"_23-providesubscriberinfo-psi",[989],{"type":31,"value":990},"2.3 ProvideSubscriberInfo (PSI)",{"type":25,"tag":34,"props":992,"children":993},{},[994],{"type":31,"value":995},"PSI is sent to the VLR\u002FMSC to retrieve current subscriber state:",{"type":25,"tag":126,"props":997,"children":1000},{"className":998,"code":999,"language":131,"meta":8},[129],"# PSI request via SigPloit MAP module\n# This returns:\n# - Subscriber State (idle\u002Fbusy\u002Fnot-reachable)\n# - Current Cell-ID (if Type A location info)\n# - IMEISV (handset identification)\n",[1001],{"type":25,"tag":134,"props":1002,"children":1003},{"__ignoreMap":8},[1004],{"type":31,"value":999},{"type":25,"tag":40,"props":1006,"children":1008},{"id":1007},"phase-3-firewall-testing-evasion",[1009],{"type":31,"value":1010},"Phase 3: Firewall Testing & Evasion",{"type":25,"tag":114,"props":1012,"children":1014},{"id":1013},"_31-test-ss7-firewall-rules",[1015],{"type":31,"value":1016},"3.1 Test SS7 Firewall Rules",{"type":25,"tag":126,"props":1018,"children":1021},{"className":1019,"code":1020,"language":131,"meta":8},[129],"# Test with different SCCP Calling Party addresses\npython3 ss7maper.py --target-gt 441234567890 --source-gt 331111111111 --mode ati\n\n# Test GT translation bypass\npython3 ss7maper.py --target-gt 441234567890 --source-gt 441234567890 --mode ati --spoof-hlr\n\n# Test with different MAP Application Contexts\npython3 ss7maper.py --target-gt 441234567890 --mode ati --map-ac v3\npython3 ss7maper.py --target-gt 441234567890 --mode ati --map-ac v1\n",[1022],{"type":25,"tag":134,"props":1023,"children":1024},{"__ignoreMap":8},[1025],{"type":31,"value":1020},{"type":25,"tag":114,"props":1027,"children":1029},{"id":1028},"_32-common-bypass-techniques",[1030],{"type":31,"value":1031},"3.2 Common Bypass Techniques",{"type":25,"tag":248,"props":1033,"children":1034},{},[1035,1056],{"type":25,"tag":252,"props":1036,"children":1037},{},[1038],{"type":25,"tag":256,"props":1039,"children":1040},{},[1041,1046,1051],{"type":25,"tag":260,"props":1042,"children":1043},{},[1044],{"type":31,"value":1045},"Technique",{"type":25,"tag":260,"props":1047,"children":1048},{},[1049],{"type":31,"value":1050},"Description",{"type":25,"tag":260,"props":1052,"children":1053},{},[1054],{"type":31,"value":1055},"Detection",{"type":25,"tag":281,"props":1057,"children":1058},{},[1059,1077,1095,1113],{"type":25,"tag":256,"props":1060,"children":1061},{},[1062,1067,1072],{"type":25,"tag":288,"props":1063,"children":1064},{},[1065],{"type":31,"value":1066},"GT Spoofing",{"type":25,"tag":288,"props":1068,"children":1069},{},[1070],{"type":31,"value":1071},"Use a GT belonging to a legitimate roaming partner",{"type":25,"tag":288,"props":1073,"children":1074},{},[1075],{"type":31,"value":1076},"GT allowlist validation",{"type":25,"tag":256,"props":1078,"children":1079},{},[1080,1085,1090],{"type":25,"tag":288,"props":1081,"children":1082},{},[1083],{"type":31,"value":1084},"AC Downgrade",{"type":25,"tag":288,"props":1086,"children":1087},{},[1088],{"type":31,"value":1089},"Use older MAP Application Context versions",{"type":25,"tag":288,"props":1091,"children":1092},{},[1093],{"type":31,"value":1094},"AC version enforcement",{"type":25,"tag":256,"props":1096,"children":1097},{},[1098,1103,1108],{"type":25,"tag":288,"props":1099,"children":1100},{},[1101],{"type":31,"value":1102},"OpCode Encoding",{"type":25,"tag":288,"props":1104,"children":1105},{},[1106],{"type":31,"value":1107},"Alternate BER encoding of MAP operations",{"type":25,"tag":288,"props":1109,"children":1110},{},[1111],{"type":31,"value":1112},"Deep packet inspection",{"type":25,"tag":256,"props":1114,"children":1115},{},[1116,1121,1126],{"type":25,"tag":288,"props":1117,"children":1118},{},[1119],{"type":31,"value":1120},"Split Messages",{"type":25,"tag":288,"props":1122,"children":1123},{},[1124],{"type":31,"value":1125},"Fragment across SCCP segments",{"type":25,"tag":288,"props":1127,"children":1128},{},[1129],{"type":31,"value":1130},"Reassembly-based inspection",{"type":25,"tag":40,"props":1132,"children":1134},{"id":1133},"phase-4-reporting",[1135],{"type":31,"value":1136},"Phase 4: Reporting",{"type":25,"tag":114,"props":1138,"children":1140},{"id":1139},"_41-finding-template",[1141],{"type":31,"value":1142},"4.1 Finding Template",{"type":25,"tag":248,"props":1144,"children":1145},{},[1146,1162],{"type":25,"tag":252,"props":1147,"children":1148},{},[1149],{"type":25,"tag":256,"props":1150,"children":1151},{},[1152,1157],{"type":25,"tag":260,"props":1153,"children":1154},{},[1155],{"type":31,"value":1156},"Field",{"type":25,"tag":260,"props":1158,"children":1159},{},[1160],{"type":31,"value":1161},"Value",{"type":25,"tag":281,"props":1163,"children":1164},{},[1165,1181,1195,1210,1226],{"type":25,"tag":256,"props":1166,"children":1167},{},[1168,1176],{"type":25,"tag":288,"props":1169,"children":1170},{},[1171],{"type":25,"tag":55,"props":1172,"children":1173},{},[1174],{"type":31,"value":1175},"Title",{"type":25,"tag":288,"props":1177,"children":1178},{},[1179],{"type":31,"value":1180},"Unauthorized Subscriber Location Tracking via SS7 ATI",{"type":25,"tag":256,"props":1182,"children":1183},{},[1184,1191],{"type":25,"tag":288,"props":1185,"children":1186},{},[1187],{"type":25,"tag":55,"props":1188,"children":1189},{},[1190],{"type":31,"value":269},{"type":25,"tag":288,"props":1192,"children":1193},{},[1194],{"type":31,"value":297},{"type":25,"tag":256,"props":1196,"children":1197},{},[1198,1205],{"type":25,"tag":288,"props":1199,"children":1200},{},[1201],{"type":25,"tag":55,"props":1202,"children":1203},{},[1204],{"type":31,"value":274},{"type":25,"tag":288,"props":1206,"children":1207},{},[1208],{"type":31,"value":1209},"9.1 (AV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:H)",{"type":25,"tag":256,"props":1211,"children":1212},{},[1213,1221],{"type":25,"tag":288,"props":1214,"children":1215},{},[1216],{"type":25,"tag":55,"props":1217,"children":1218},{},[1219],{"type":31,"value":1220},"Impact",{"type":25,"tag":288,"props":1222,"children":1223},{},[1224],{"type":31,"value":1225},"Real-time geolocation of any subscriber on the network",{"type":25,"tag":256,"props":1227,"children":1228},{},[1229,1236],{"type":25,"tag":288,"props":1230,"children":1231},{},[1232],{"type":25,"tag":55,"props":1233,"children":1234},{},[1235],{"type":31,"value":279},{"type":25,"tag":288,"props":1237,"children":1238},{},[1239],{"type":31,"value":1240},"Deploy SS7 firewall with ATI\u002FPSI blocking for untrusted GTs, implement GSMA FS.11 category filtering",{"type":25,"tag":114,"props":1242,"children":1244},{"id":1243},"_42-reference-standards",[1245],{"type":31,"value":1246},"4.2 Reference Standards",{"type":25,"tag":47,"props":1248,"children":1249},{},[1250,1260,1270,1280],{"type":25,"tag":51,"props":1251,"children":1252},{},[1253,1258],{"type":25,"tag":55,"props":1254,"children":1255},{},[1256],{"type":31,"value":1257},"GSMA FS.11",{"type":31,"value":1259},": SS7 Interconnect Security Monitoring and Firewall Guidelines",{"type":25,"tag":51,"props":1261,"children":1262},{},[1263,1268],{"type":25,"tag":55,"props":1264,"children":1265},{},[1266],{"type":31,"value":1267},"GSMA IR.82",{"type":31,"value":1269},": SS7 Security Network Implementation Guidelines",{"type":25,"tag":51,"props":1271,"children":1272},{},[1273,1278],{"type":25,"tag":55,"props":1274,"children":1275},{},[1276],{"type":31,"value":1277},"3GPP TS 29.002",{"type":31,"value":1279},": MAP Protocol Specification",{"type":25,"tag":51,"props":1281,"children":1282},{},[1283,1288],{"type":25,"tag":55,"props":1284,"children":1285},{},[1286],{"type":31,"value":1287},"ITU-T Q.713",{"type":31,"value":1289},": SCCP Formats and Codes",{"type":25,"tag":40,"props":1291,"children":1292},{"id":427},[1293],{"type":31,"value":430},{"type":25,"tag":34,"props":1295,"children":1296},{},[1297,1298],{"type":31,"value":435},{"type":25,"tag":55,"props":1299,"children":1300},{},[1301],{"type":25,"tag":440,"props":1302,"children":1304},{"href":442,"rel":1303},[444],[1305],{"type":31,"value":1306},"Launch the SS7 Red Team Lab on App.TelcoSec.Net",{"title":8,"searchDepth":449,"depth":449,"links":1308},[1309,1310,1314,1319,1323,1327],{"id":42,"depth":449,"text":45},{"id":879,"depth":449,"text":882,"children":1311},[1312,1313],{"id":885,"depth":455,"text":888},{"id":900,"depth":455,"text":903},{"id":915,"depth":449,"text":918,"children":1315},[1316,1317,1318],{"id":921,"depth":455,"text":924},{"id":967,"depth":455,"text":970},{"id":987,"depth":455,"text":990},{"id":1007,"depth":449,"text":1010,"children":1320},[1321,1322],{"id":1013,"depth":455,"text":1016},{"id":1028,"depth":455,"text":1031},{"id":1133,"depth":449,"text":1136,"children":1324},[1325,1326],{"id":1139,"depth":455,"text":1142},{"id":1243,"depth":455,"text":1246},{"id":427,"depth":449,"text":430},"content:guides:ss7-location-tracking-assessment.md","guides\u002Fss7-location-tracking-assessment.md","guides\u002Fss7-location-tracking-assessment",{"_path":1332,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":1333,"description":1334,"protocol":1335,"category":1336,"difficulty":1337,"estimatedTime":1338,"tools":1339,"body":1343,"_type":470,"_id":1697,"_source":472,"_file":1698,"_stem":1699,"_extension":475},"\u002Fguides\u002Fusrp-b210-driver-setup","USRP B210 Driver Setup Guide","Complete driver installation and verification guide for Ettus Research USRP B210 on TelcoChisel, including UHD firmware, USB buffer tuning, and PREEMPT_RT kernel optimizations.","SDR \u002F RF","Hardware Guide","Beginner","30-45 minutes",[1340,1341,1342],"srsran","openairinterface","gnuradio-telecom",{"type":22,"children":1344,"toc":1684},[1345,1351,1356,1360,1392,1398,1407,1413,1418,1427,1432,1441,1447,1456,1462,1471,1477,1482,1491,1497,1506,1512,1517,1526,1532,1537,1546,1552,1667,1671],{"type":25,"tag":26,"props":1346,"children":1348},{"id":1347},"usrp-b210-driver-setup-on-telcochisel",[1349],{"type":31,"value":1350},"USRP B210 Driver Setup on TelcoChisel",{"type":25,"tag":34,"props":1352,"children":1353},{},[1354],{"type":31,"value":1355},"The Ettus Research USRP B210 is the most versatile SDR platform for telecom security testing, supporting 2×2 MIMO with 56 MHz bandwidth from 70 MHz to 6 GHz. This guide covers complete driver installation, firmware flashing, USB buffer optimization, and PREEMPT_RT kernel configuration for zero-underrun operation on TelcoChisel.",{"type":25,"tag":40,"props":1357,"children":1358},{"id":42},[1359],{"type":31,"value":45},{"type":25,"tag":47,"props":1361,"children":1362},{},[1363,1372,1382],{"type":25,"tag":51,"props":1364,"children":1365},{},[1366,1370],{"type":25,"tag":55,"props":1367,"children":1368},{},[1369],{"type":31,"value":59},{"type":31,"value":1371}," (4.0.0 or later recommended)",{"type":25,"tag":51,"props":1373,"children":1374},{},[1375,1380],{"type":25,"tag":55,"props":1376,"children":1377},{},[1378],{"type":31,"value":1379},"Ettus USRP B210",{"type":31,"value":1381}," with USB 3.0 cable",{"type":25,"tag":51,"props":1383,"children":1384},{},[1385,1390],{"type":25,"tag":55,"props":1386,"children":1387},{},[1388],{"type":31,"value":1389},"USB 3.0 port",{"type":31,"value":1391}," (blue connector) — USB 2.0 will limit bandwidth",{"type":25,"tag":40,"props":1393,"children":1395},{"id":1394},"step-1-verify-usb-connection",[1396],{"type":31,"value":1397},"Step 1: Verify USB Connection",{"type":25,"tag":126,"props":1399,"children":1402},{"className":1400,"code":1401,"language":131,"meta":8},[129],"# Check USB detection\nlsusb | grep -i ettus\n# Expected: Bus 002 Device 003: ID 2500:0020 Ettus Research LLC USRP B200\n\n# Verify USB 3.0 speed (important for high-bandwidth captures)\nlsusb -t | grep -A2 \"2500:0020\"\n# Look for \"5000M\" (USB 3.0) not \"480M\" (USB 2.0)\n",[1403],{"type":25,"tag":134,"props":1404,"children":1405},{"__ignoreMap":8},[1406],{"type":31,"value":1401},{"type":25,"tag":40,"props":1408,"children":1410},{"id":1409},"step-2-installverify-uhd-drivers",[1411],{"type":31,"value":1412},"Step 2: Install\u002FVerify UHD Drivers",{"type":25,"tag":34,"props":1414,"children":1415},{},[1416],{"type":31,"value":1417},"TelcoChisel pre-installs UHD, but verify the version:",{"type":25,"tag":126,"props":1419,"children":1422},{"className":1420,"code":1421,"language":131,"meta":8},[129],"# Check UHD library version\nuhd_config_info --version\n# Expected: UHD 4.6.0 or later\n\n# Verify UHD firmware images are present\nuhd_images_downloader --list-targets | head -20\n",[1423],{"type":25,"tag":134,"props":1424,"children":1425},{"__ignoreMap":8},[1426],{"type":31,"value":1421},{"type":25,"tag":34,"props":1428,"children":1429},{},[1430],{"type":31,"value":1431},"If UHD needs updating:",{"type":25,"tag":126,"props":1433,"children":1436},{"className":1434,"code":1435,"language":131,"meta":8},[129],"# Update UHD from TelcoChisel repositories\nsudo apt update && sudo apt install -y uhd-host libuhd-dev uhd-firmware\n",[1437],{"type":25,"tag":134,"props":1438,"children":1439},{"__ignoreMap":8},[1440],{"type":31,"value":1435},{"type":25,"tag":40,"props":1442,"children":1444},{"id":1443},"step-3-download-fpga-firmware",[1445],{"type":31,"value":1446},"Step 3: Download FPGA Firmware",{"type":25,"tag":126,"props":1448,"children":1451},{"className":1449,"code":1450,"language":131,"meta":8},[129],"# Download B210 FPGA images (required for first-time setup)\nsudo uhd_images_downloader\n\n# Verify firmware files exist\nls -la \u002Fusr\u002Fshare\u002Fuhd\u002Fimages\u002F | grep b2\n# Should show: usrp_b200_fpga.bin, usrp_b210_fpga.bin\n",[1452],{"type":25,"tag":134,"props":1453,"children":1454},{"__ignoreMap":8},[1455],{"type":31,"value":1450},{"type":25,"tag":40,"props":1457,"children":1459},{"id":1458},"step-4-detect-and-test-the-device",[1460],{"type":31,"value":1461},"Step 4: Detect and Test the Device",{"type":25,"tag":126,"props":1463,"children":1466},{"className":1464,"code":1465,"language":131,"meta":8},[129],"# Scan for connected USRP devices\nuhd_find_devices\n\n# Expected output:\n# --------------------------------------------------\n# -- UHD Device 0\n# --------------------------------------------------\n# Device Address:\n#     serial: 318B42\n#     name:\n#     product: B210\n#     type: b200\n\n# Run comprehensive hardware self-test\nuhd_usrp_probe\n",[1467],{"type":25,"tag":134,"props":1468,"children":1469},{"__ignoreMap":8},[1470],{"type":31,"value":1465},{"type":25,"tag":40,"props":1472,"children":1474},{"id":1473},"step-5-usb-buffer-optimization",[1475],{"type":31,"value":1476},"Step 5: USB Buffer Optimization",{"type":25,"tag":34,"props":1478,"children":1479},{},[1480],{"type":31,"value":1481},"Critical for preventing buffer underruns at high sample rates:",{"type":25,"tag":126,"props":1483,"children":1486},{"className":1484,"code":1485,"language":131,"meta":8},[129],"# Increase USB buffer size (temporary — active until reboot)\nsudo sysctl -w net.core.rmem_max=33554432\nsudo sysctl -w net.core.wmem_max=33554432\n\n# Make permanent\necho \"net.core.rmem_max=33554432\" | sudo tee -a \u002Fetc\u002Fsysctl.d\u002F99-usrp-buffers.conf\necho \"net.core.wmem_max=33554432\" | sudo tee -a \u002Fetc\u002Fsysctl.d\u002F99-usrp-buffers.conf\nsudo sysctl -p \u002Fetc\u002Fsysctl.d\u002F99-usrp-buffers.conf\n",[1487],{"type":25,"tag":134,"props":1488,"children":1489},{"__ignoreMap":8},[1490],{"type":31,"value":1485},{"type":25,"tag":40,"props":1492,"children":1494},{"id":1493},"step-6-usb-permissions-udev-rules",[1495],{"type":31,"value":1496},"Step 6: USB Permissions (udev Rules)",{"type":25,"tag":126,"props":1498,"children":1501},{"className":1499,"code":1500,"language":131,"meta":8},[129],"# Verify TelcoChisel UHD udev rules are installed\ncat \u002Fetc\u002Fudev\u002Frules.d\u002Fuhd-usrp.rules\n# Should contain: ATTR{idVendor}==\"2500\", MODE=\"0666\"\n\n# If missing, create the rule\necho 'ATTR{idVendor}==\"2500\", ATTR{idProduct}==\"0020\", MODE=\"0666\"' | \\\n  sudo tee \u002Fetc\u002Fudev\u002Frules.d\u002F99-uhd-usrp.rules\nsudo udevadm control --reload-rules\nsudo udevadm trigger\n",[1502],{"type":25,"tag":134,"props":1503,"children":1504},{"__ignoreMap":8},[1505],{"type":31,"value":1500},{"type":25,"tag":40,"props":1507,"children":1509},{"id":1508},"step-7-preempt_rt-kernel-verification",[1510],{"type":31,"value":1511},"Step 7: PREEMPT_RT Kernel Verification",{"type":25,"tag":34,"props":1513,"children":1514},{},[1515],{"type":31,"value":1516},"TelcoChisel ships with a PREEMPT_RT kernel for zero-underrun SDR operation:",{"type":25,"tag":126,"props":1518,"children":1521},{"className":1519,"code":1520,"language":131,"meta":8},[129],"# Verify RT kernel is active\nuname -r\n# Expected: 6.8.0-rt-telco\n\n# Check preemption model\ncat \u002Fsys\u002Fkernel\u002Frealtime\n# Expected: 1\n\n# Set real-time scheduling priority for UHD threads\nsudo chrt -f 99 uhd_rx_samples_to_file --args \"type=b200\" --rate 30.72e6 --freq 2140e6 --duration 5 --file \u002Ftmp\u002Ftest.cf32\n",[1522],{"type":25,"tag":134,"props":1523,"children":1524},{"__ignoreMap":8},[1525],{"type":31,"value":1520},{"type":25,"tag":40,"props":1527,"children":1529},{"id":1528},"step-8-validation-test",[1530],{"type":31,"value":1531},"Step 8: Validation Test",{"type":25,"tag":34,"props":1533,"children":1534},{},[1535],{"type":31,"value":1536},"Run a full bandwidth test at 5G-ready sample rates:",{"type":25,"tag":126,"props":1538,"children":1541},{"className":1539,"code":1540,"language":131,"meta":8},[129],"# Test 30.72 MS\u002Fs (20 MHz LTE\u002F5G bandwidth) for 10 seconds\nuhd_rx_samples_to_file --args \"type=b200\" --rate 30.72e6 --freq 2140e6 --duration 10 --file \u002Ftmp\u002Fbandwidth-test.cf32\n\n# Check for underruns in output — should see 0\n# \"U\" characters in output indicate buffer underruns\n\n# Test MIMO 2x2 configuration\nuhd_rx_samples_to_file --args \"type=b200\" --channels \"0,1\" --rate 15.36e6 --freq 2140e6 --duration 5 --file \u002Ftmp\u002Fmimo-test.cf32\n",[1542],{"type":25,"tag":134,"props":1543,"children":1544},{"__ignoreMap":8},[1545],{"type":31,"value":1540},{"type":25,"tag":40,"props":1547,"children":1549},{"id":1548},"troubleshooting",[1550],{"type":31,"value":1551},"Troubleshooting",{"type":25,"tag":248,"props":1553,"children":1554},{},[1555,1571],{"type":25,"tag":252,"props":1556,"children":1557},{},[1558],{"type":25,"tag":256,"props":1559,"children":1560},{},[1561,1566],{"type":25,"tag":260,"props":1562,"children":1563},{},[1564],{"type":31,"value":1565},"Issue",{"type":25,"tag":260,"props":1567,"children":1568},{},[1569],{"type":31,"value":1570},"Solution",{"type":25,"tag":281,"props":1572,"children":1573},{},[1574,1591,1608,1625,1642],{"type":25,"tag":256,"props":1575,"children":1576},{},[1577,1586],{"type":25,"tag":288,"props":1578,"children":1579},{},[1580],{"type":25,"tag":134,"props":1581,"children":1583},{"className":1582},[],[1584],{"type":31,"value":1585},"No devices found",{"type":25,"tag":288,"props":1587,"children":1588},{},[1589],{"type":31,"value":1590},"Check USB cable, try different USB 3.0 port, verify udev rules",{"type":25,"tag":256,"props":1592,"children":1593},{},[1594,1603],{"type":25,"tag":288,"props":1595,"children":1596},{},[1597],{"type":25,"tag":134,"props":1598,"children":1600},{"className":1599},[],[1601],{"type":31,"value":1602},"USB 2.0 detected",{"type":25,"tag":288,"props":1604,"children":1605},{},[1606],{"type":31,"value":1607},"Use a blue USB 3.0 port, avoid USB hubs",{"type":25,"tag":256,"props":1609,"children":1610},{},[1611,1620],{"type":25,"tag":288,"props":1612,"children":1613},{},[1614],{"type":25,"tag":134,"props":1615,"children":1617},{"className":1616},[],[1618],{"type":31,"value":1619},"Buffer underruns (U)",{"type":25,"tag":288,"props":1621,"children":1622},{},[1623],{"type":31,"value":1624},"Increase USB buffers (Step 5), verify RT kernel, reduce sample rate",{"type":25,"tag":256,"props":1626,"children":1627},{},[1628,1637],{"type":25,"tag":288,"props":1629,"children":1630},{},[1631],{"type":25,"tag":134,"props":1632,"children":1634},{"className":1633},[],[1635],{"type":31,"value":1636},"Permission denied",{"type":25,"tag":288,"props":1638,"children":1639},{},[1640],{"type":31,"value":1641},"Run as root or fix udev rules (Step 6)",{"type":25,"tag":256,"props":1643,"children":1644},{},[1645,1654],{"type":25,"tag":288,"props":1646,"children":1647},{},[1648],{"type":25,"tag":134,"props":1649,"children":1651},{"className":1650},[],[1652],{"type":31,"value":1653},"FPGA compatibility error",{"type":25,"tag":288,"props":1655,"children":1656},{},[1657,1659,1665],{"type":31,"value":1658},"Re-run ",{"type":25,"tag":134,"props":1660,"children":1662},{"className":1661},[],[1663],{"type":31,"value":1664},"uhd_images_downloader",{"type":31,"value":1666},", power-cycle the B210",{"type":25,"tag":40,"props":1668,"children":1669},{"id":427},[1670],{"type":31,"value":430},{"type":25,"tag":34,"props":1672,"children":1673},{},[1674,1675],{"type":31,"value":435},{"type":25,"tag":55,"props":1676,"children":1677},{},[1678],{"type":25,"tag":440,"props":1679,"children":1681},{"href":442,"rel":1680},[444],[1682],{"type":31,"value":1683},"Launch the SDR Hardware Lab on App.TelcoSec.Net",{"title":8,"searchDepth":449,"depth":449,"links":1685},[1686,1687,1688,1689,1690,1691,1692,1693,1694,1695,1696],{"id":42,"depth":449,"text":45},{"id":1394,"depth":449,"text":1397},{"id":1409,"depth":449,"text":1412},{"id":1443,"depth":449,"text":1446},{"id":1458,"depth":449,"text":1461},{"id":1473,"depth":449,"text":1476},{"id":1493,"depth":449,"text":1496},{"id":1508,"depth":449,"text":1511},{"id":1528,"depth":449,"text":1531},{"id":1548,"depth":449,"text":1551},{"id":427,"depth":449,"text":430},"content:guides:usrp-b210-driver-setup.md","guides\u002Fusrp-b210-driver-setup.md","guides\u002Fusrp-b210-driver-setup",1790363494531]