GSM Air Interface Capture with HackRF
Step-by-step guide to passively capturing and decoding GSM over-the-air traffic using HackRF One, Gr-GSM, Kalibrate-RTL, and Wireshark on TelcoChisel.
GSM Air Interface Capture with HackRF One
This guide walks through passive GSM over-the-air signal capture using HackRF One hardware on TelcoChisel. You will scan for active GSM cells, calibrate your SDR, capture downlink traffic, and decode signaling and voice channels in real-time via Wireshark.
Prerequisites
- TelcoChisel OS with Gr-GSM, Kalibrate-RTL, and Gqrx pre-installed
- HackRF One with antenna (800-1900 MHz coverage)
- USB 2.0+ connection (USB 3.0 recommended for stability)
Step 1: Verify HackRF Hardware
# Check that TelcoChisel detects the HackRF
hackrf_info
# Expected output:
# Serial number: xxxxxxxx
# Board ID: 2 (HackRF One)
# Firmware: 2024.02.1
# Part ID: 0xa000cb3c 0x00724764
Step 2: Scan for Active GSM Cells
Use Kalibrate-RTL to discover active GSM base stations and calibrate the HackRF clock:
# Scan GSM-900 band (Europe/Asia/Africa)
kal -s GSM900 -g 40
# Scan DCS-1800 band (Europe)
kal -s DCS1800 -g 40
# Scan PCS-1900 band (Americas)
kal -s PCS1900 -g 40
Note the strongest channel (ARFCN) and frequency offset (PPM). Example output:
chan: 55 (935.2MHz + 22.2kHz) power: 282989.67
Step 3: Calibrate PPM Offset
# Lock to the strongest cell and calculate precise PPM
kal -c 55 -g 40 -e 0
# Note the "average absolute error" — this is your PPM value
# Example: average absolute error: 14.53 ppm
Step 4: Verify Signal with Gqrx (Optional)
For visual confirmation before capture:
# Launch Gqrx, select HackRF, tune to the GSM frequency
gqrx
# Set center frequency to the ARFCN's downlink frequency (e.g., 935.2 MHz)
# You should see GSM TDMA burst patterns in the waterfall
Step 5: Live GSM Capture with Gr-GSM
5.1 Interactive Monitoring
# Launch Gr-GSM live monitor with GUI frequency selector
grgsm_livemon -f 935.2e6 -p 14
# -f: center frequency (Hz)
# -p: PPM correction from Step 3
5.2 Headless Capture to Wireshark
# Start Gr-GSM headless and pipe GSMTAP frames to Wireshark
grgsm_livemon_headless -f 935.2e6 -p 14 &
# In a separate terminal, launch Wireshark to receive GSMTAP
wireshark -k -i lo -f "udp port 4729" -Y "gsm_a.dtap || lapdm || gsm_a.rr"
Step 6: Decode Captured Traffic
6.1 System Information Decoding
In Wireshark, filter for System Information messages:
gsm_a.rr.message_type == 0x19 || gsm_a.rr.message_type == 0x1a || gsm_a.rr.message_type == 0x1b
These reveal:
- MCC/MNC: Operator identity
- LAC/CellID: Location Area Code and Cell ID
- ARFCN neighbors: Adjacent cell frequencies
- Cipher setting: Whether A5/1, A5/2, or A5/3 is used
6.2 Paging Channel Monitoring
gsm_a.dtap.msg_rr_type == 0x21 || gsm_a.dtap.msg_rr_type == 0x22
Paging messages may contain plaintext IMSI transmissions — an indicator of active IMSI catchers.
Step 7: Record IQ Samples for Offline Analysis
# Record raw IQ samples for later processing (30 seconds at 2 MS/s)
hackrf_transfer -r /tmp/gsm_capture.cf32 -f 935200000 -s 2000000 -a 1 -l 32 -g 40 -n 60000000
# Process offline with Gr-GSM
grgsm_decode -c /tmp/gsm_capture.cf32 -a 55 -p 14 -s 2e6 -m BCCH
Safety & Legal Notice
WARNING: Active GSM transmission is illegal without authorization. This guide covers passive reception only. Ensure compliance with local telecommunications regulations. TelcoChisel tools are intended for authorized security assessments and research environments only.