[{"data":1,"prerenderedAt":382},["ShallowReactive",2],{"guide-sdr-gsm-capture-hackrf":3},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"protocol":10,"category":11,"difficulty":12,"estimatedTime":13,"tools":14,"body":19,"_type":376,"_id":377,"_source":378,"_file":379,"_stem":380,"_extension":381},"\u002Fguides\u002Fsdr-gsm-capture-hackrf","guides",false,"","GSM Air Interface Capture with HackRF","Step-by-step guide to passively capturing and decoding GSM over-the-air traffic using HackRF One, Gr-GSM, Kalibrate-RTL, and Wireshark on TelcoChisel.","2G GSM","SDR Guide","Intermediate","2-3 hours",[15,16,17,18],"gr-gsm","kalibrate-rtl","kraken","gqrx",{"type":20,"children":21,"toc":356},"root",[22,31,37,44,75,81,94,100,105,114,119,127,133,142,148,153,162,168,175,184,190,199,205,211,216,224,229,272,278,286,291,297,306,312,333,339],{"type":23,"tag":24,"props":25,"children":27},"element","h1",{"id":26},"gsm-air-interface-capture-with-hackrf-one",[28],{"type":29,"value":30},"text","GSM Air Interface Capture with HackRF One",{"type":23,"tag":32,"props":33,"children":34},"p",{},[35],{"type":29,"value":36},"This guide walks through passive GSM over-the-air signal capture using HackRF One hardware on TelcoChisel. You will scan for active GSM cells, calibrate your SDR, capture downlink traffic, and decode signaling and voice channels in real-time via Wireshark.",{"type":23,"tag":38,"props":39,"children":41},"h2",{"id":40},"prerequisites",[42],{"type":29,"value":43},"Prerequisites",{"type":23,"tag":45,"props":46,"children":47},"ul",{},[48,60,70],{"type":23,"tag":49,"props":50,"children":51},"li",{},[52,58],{"type":23,"tag":53,"props":54,"children":55},"strong",{},[56],{"type":29,"value":57},"TelcoChisel OS",{"type":29,"value":59}," with Gr-GSM, Kalibrate-RTL, and Gqrx pre-installed",{"type":23,"tag":49,"props":61,"children":62},{},[63,68],{"type":23,"tag":53,"props":64,"children":65},{},[66],{"type":29,"value":67},"HackRF One",{"type":29,"value":69}," with antenna (800-1900 MHz coverage)",{"type":23,"tag":49,"props":71,"children":72},{},[73],{"type":29,"value":74},"USB 2.0+ connection (USB 3.0 recommended for stability)",{"type":23,"tag":38,"props":76,"children":78},{"id":77},"step-1-verify-hackrf-hardware",[79],{"type":29,"value":80},"Step 1: Verify HackRF Hardware",{"type":23,"tag":82,"props":83,"children":88},"pre",{"code":84,"language":85,"meta":7,"className":86},"# Check that TelcoChisel detects the HackRF\nhackrf_info\n\n# Expected output:\n# Serial number: xxxxxxxx\n# Board ID: 2 (HackRF One)\n# Firmware: 2024.02.1\n# Part ID: 0xa000cb3c 0x00724764\n","bash",[87],"language-bash",[89],{"type":23,"tag":90,"props":91,"children":92},"code",{"__ignoreMap":7},[93],{"type":29,"value":84},{"type":23,"tag":38,"props":95,"children":97},{"id":96},"step-2-scan-for-active-gsm-cells",[98],{"type":29,"value":99},"Step 2: Scan for Active GSM Cells",{"type":23,"tag":32,"props":101,"children":102},{},[103],{"type":29,"value":104},"Use Kalibrate-RTL to discover active GSM base stations and calibrate the HackRF clock:",{"type":23,"tag":82,"props":106,"children":109},{"code":107,"language":85,"meta":7,"className":108},"# Scan GSM-900 band (Europe\u002FAsia\u002FAfrica)\nkal -s GSM900 -g 40\n\n# Scan DCS-1800 band (Europe)\nkal -s DCS1800 -g 40\n\n# Scan PCS-1900 band (Americas)\nkal -s PCS1900 -g 40\n",[87],[110],{"type":23,"tag":90,"props":111,"children":112},{"__ignoreMap":7},[113],{"type":29,"value":107},{"type":23,"tag":32,"props":115,"children":116},{},[117],{"type":29,"value":118},"Note the strongest channel (ARFCN) and frequency offset (PPM). Example output:",{"type":23,"tag":82,"props":120,"children":122},{"code":121},"chan: 55 (935.2MHz + 22.2kHz)  power: 282989.67\n",[123],{"type":23,"tag":90,"props":124,"children":125},{"__ignoreMap":7},[126],{"type":29,"value":121},{"type":23,"tag":38,"props":128,"children":130},{"id":129},"step-3-calibrate-ppm-offset",[131],{"type":29,"value":132},"Step 3: Calibrate PPM Offset",{"type":23,"tag":82,"props":134,"children":137},{"code":135,"language":85,"meta":7,"className":136},"# Lock to the strongest cell and calculate precise PPM\nkal -c 55 -g 40 -e 0\n\n# Note the \"average absolute error\" — this is your PPM value\n# Example: average absolute error: 14.53 ppm\n",[87],[138],{"type":23,"tag":90,"props":139,"children":140},{"__ignoreMap":7},[141],{"type":29,"value":135},{"type":23,"tag":38,"props":143,"children":145},{"id":144},"step-4-verify-signal-with-gqrx-optional",[146],{"type":29,"value":147},"Step 4: Verify Signal with Gqrx (Optional)",{"type":23,"tag":32,"props":149,"children":150},{},[151],{"type":29,"value":152},"For visual confirmation before capture:",{"type":23,"tag":82,"props":154,"children":157},{"code":155,"language":85,"meta":7,"className":156},"# Launch Gqrx, select HackRF, tune to the GSM frequency\ngqrx\n# Set center frequency to the ARFCN's downlink frequency (e.g., 935.2 MHz)\n# You should see GSM TDMA burst patterns in the waterfall\n",[87],[158],{"type":23,"tag":90,"props":159,"children":160},{"__ignoreMap":7},[161],{"type":29,"value":155},{"type":23,"tag":38,"props":163,"children":165},{"id":164},"step-5-live-gsm-capture-with-gr-gsm",[166],{"type":29,"value":167},"Step 5: Live GSM Capture with Gr-GSM",{"type":23,"tag":169,"props":170,"children":172},"h3",{"id":171},"_51-interactive-monitoring",[173],{"type":29,"value":174},"5.1 Interactive Monitoring",{"type":23,"tag":82,"props":176,"children":179},{"code":177,"language":85,"meta":7,"className":178},"# Launch Gr-GSM live monitor with GUI frequency selector\ngrgsm_livemon -f 935.2e6 -p 14\n# -f: center frequency (Hz)\n# -p: PPM correction from Step 3\n",[87],[180],{"type":23,"tag":90,"props":181,"children":182},{"__ignoreMap":7},[183],{"type":29,"value":177},{"type":23,"tag":169,"props":185,"children":187},{"id":186},"_52-headless-capture-to-wireshark",[188],{"type":29,"value":189},"5.2 Headless Capture to Wireshark",{"type":23,"tag":82,"props":191,"children":194},{"code":192,"language":85,"meta":7,"className":193},"# Start Gr-GSM headless and pipe GSMTAP frames to Wireshark\ngrgsm_livemon_headless -f 935.2e6 -p 14 &\n\n# In a separate terminal, launch Wireshark to receive GSMTAP\nwireshark -k -i lo -f \"udp port 4729\" -Y \"gsm_a.dtap || lapdm || gsm_a.rr\"\n",[87],[195],{"type":23,"tag":90,"props":196,"children":197},{"__ignoreMap":7},[198],{"type":29,"value":192},{"type":23,"tag":38,"props":200,"children":202},{"id":201},"step-6-decode-captured-traffic",[203],{"type":29,"value":204},"Step 6: Decode Captured Traffic",{"type":23,"tag":169,"props":206,"children":208},{"id":207},"_61-system-information-decoding",[209],{"type":29,"value":210},"6.1 System Information Decoding",{"type":23,"tag":32,"props":212,"children":213},{},[214],{"type":29,"value":215},"In Wireshark, filter for System Information messages:",{"type":23,"tag":82,"props":217,"children":219},{"code":218},"gsm_a.rr.message_type == 0x19 || gsm_a.rr.message_type == 0x1a || gsm_a.rr.message_type == 0x1b\n",[220],{"type":23,"tag":90,"props":221,"children":222},{"__ignoreMap":7},[223],{"type":29,"value":218},{"type":23,"tag":32,"props":225,"children":226},{},[227],{"type":29,"value":228},"These reveal:",{"type":23,"tag":45,"props":230,"children":231},{},[232,242,252,262],{"type":23,"tag":49,"props":233,"children":234},{},[235,240],{"type":23,"tag":53,"props":236,"children":237},{},[238],{"type":29,"value":239},"MCC\u002FMNC",{"type":29,"value":241},": Operator identity",{"type":23,"tag":49,"props":243,"children":244},{},[245,250],{"type":23,"tag":53,"props":246,"children":247},{},[248],{"type":29,"value":249},"LAC\u002FCellID",{"type":29,"value":251},": Location Area Code and Cell ID",{"type":23,"tag":49,"props":253,"children":254},{},[255,260],{"type":23,"tag":53,"props":256,"children":257},{},[258],{"type":29,"value":259},"ARFCN neighbors",{"type":29,"value":261},": Adjacent cell frequencies",{"type":23,"tag":49,"props":263,"children":264},{},[265,270],{"type":23,"tag":53,"props":266,"children":267},{},[268],{"type":29,"value":269},"Cipher setting",{"type":29,"value":271},": Whether A5\u002F1, A5\u002F2, or A5\u002F3 is used",{"type":23,"tag":169,"props":273,"children":275},{"id":274},"_62-paging-channel-monitoring",[276],{"type":29,"value":277},"6.2 Paging Channel Monitoring",{"type":23,"tag":82,"props":279,"children":281},{"code":280},"gsm_a.dtap.msg_rr_type == 0x21 || gsm_a.dtap.msg_rr_type == 0x22\n",[282],{"type":23,"tag":90,"props":283,"children":284},{"__ignoreMap":7},[285],{"type":29,"value":280},{"type":23,"tag":32,"props":287,"children":288},{},[289],{"type":29,"value":290},"Paging messages may contain plaintext IMSI transmissions — an indicator of active IMSI catchers.",{"type":23,"tag":38,"props":292,"children":294},{"id":293},"step-7-record-iq-samples-for-offline-analysis",[295],{"type":29,"value":296},"Step 7: Record IQ Samples for Offline Analysis",{"type":23,"tag":82,"props":298,"children":301},{"code":299,"language":85,"meta":7,"className":300},"# Record raw IQ samples for later processing (30 seconds at 2 MS\u002Fs)\nhackrf_transfer -r \u002Ftmp\u002Fgsm_capture.cf32 -f 935200000 -s 2000000 -a 1 -l 32 -g 40 -n 60000000\n\n# Process offline with Gr-GSM\ngrgsm_decode -c \u002Ftmp\u002Fgsm_capture.cf32 -a 55 -p 14 -s 2e6 -m BCCH\n",[87],[302],{"type":23,"tag":90,"props":303,"children":304},{"__ignoreMap":7},[305],{"type":29,"value":299},{"type":23,"tag":38,"props":307,"children":309},{"id":308},"safety-legal-notice",[310],{"type":29,"value":311},"Safety & Legal Notice",{"type":23,"tag":313,"props":314,"children":315},"blockquote",{},[316],{"type":23,"tag":32,"props":317,"children":318},{},[319,324,326,331],{"type":23,"tag":53,"props":320,"children":321},{},[322],{"type":29,"value":323},"WARNING",{"type":29,"value":325},": Active GSM transmission is illegal without authorization. This guide covers ",{"type":23,"tag":53,"props":327,"children":328},{},[329],{"type":29,"value":330},"passive reception only",{"type":29,"value":332},". Ensure compliance with local telecommunications regulations. TelcoChisel tools are intended for authorized security assessments and research environments only.",{"type":23,"tag":38,"props":334,"children":336},{"id":335},"practice-in-telcosec-academy",[337],{"type":29,"value":338},"Practice in TelcoSec Academy",{"type":23,"tag":32,"props":340,"children":341},{},[342,344],{"type":29,"value":343},"👉 ",{"type":23,"tag":53,"props":345,"children":346},{},[347],{"type":23,"tag":348,"props":349,"children":353},"a",{"href":350,"rel":351},"https:\u002F\u002Fapp.telcosec.net",[352],"nofollow",[354],{"type":29,"value":355},"Launch the SDR GSM Capture Lab on App.TelcoSec.Net",{"title":7,"searchDepth":357,"depth":357,"links":358},2,[359,360,361,362,363,364,369,373,374,375],{"id":40,"depth":357,"text":43},{"id":77,"depth":357,"text":80},{"id":96,"depth":357,"text":99},{"id":129,"depth":357,"text":132},{"id":144,"depth":357,"text":147},{"id":164,"depth":357,"text":167,"children":365},[366,368],{"id":171,"depth":367,"text":174},3,{"id":186,"depth":367,"text":189},{"id":201,"depth":357,"text":204,"children":370},[371,372],{"id":207,"depth":367,"text":210},{"id":274,"depth":367,"text":277},{"id":293,"depth":357,"text":296},{"id":308,"depth":357,"text":311},{"id":335,"depth":357,"text":338},"markdown","content:guides:sdr-gsm-capture-hackrf.md","content","guides\u002Fsdr-gsm-capture-hackrf.md","guides\u002Fsdr-gsm-capture-hackrf","md",1790363496617]