[{"data":1,"prerenderedAt":4519},["ShallowReactive",2],{"tools-list":3},[4,193,349,505,661,805,960,1083,1240,1375,1531,1660,1815,1947,2076,2230,2383,2539,2698,2843,2964,3120,3275,3431,3559,3792,3922,4075,4222,4389],{"_path":5,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":9,"description":10,"name":9,"protocol":11,"category":12,"hardware":13,"command":14,"academyLab":15,"body":16,"_type":187,"_id":188,"_source":189,"_file":190,"_stem":191,"_extension":192},"\u002Ftools\u002F5g-empower","tools",false,"","5G-EmPOWER","Multi-access edge computing platform for auditing RAN programmability, network slicing enforcement, and MEC application security across 5G\u002FLTE\u002FWi-Fi.","5G NR \u002F 4G LTE \u002F Wi-Fi","Multi-access Edge Computing","USRP B210 \u002F Loopback","empower-runtime --config \u002Fetc\u002Fempower\u002Fconfig.yaml","https:\u002F\u002Fapp.telcosec.net",{"type":17,"children":18,"toc":176},"root",[19,28,46,53,98,104,111,124,130,139,145,154,160],{"type":20,"tag":21,"props":22,"children":24},"element","h1",{"id":23},"_5g-empower-mec-ran-programmability-security-platform",[25],{"type":26,"value":27},"text","5G-EmPOWER — MEC & RAN Programmability Security Platform",{"type":20,"tag":29,"props":30,"children":31},"p",{},[32,37,39,44],{"type":20,"tag":33,"props":34,"children":35},"strong",{},[36],{"type":26,"value":9},{"type":26,"value":38}," is an open multi-access edge computing (MEC) runtime for programmable wireless networks. Within ",{"type":20,"tag":33,"props":40,"children":41},{},[42],{"type":26,"value":43},"TelcoChisel",{"type":26,"value":45},", 5G-EmPOWER enables security testing of RAN-level programmability APIs, network slice enforcement boundaries, and MEC application isolation across heterogeneous access technologies.",{"type":20,"tag":47,"props":48,"children":50},"h2",{"id":49},"key-capabilities-security-vectors",[51],{"type":26,"value":52},"Key Capabilities & Security Vectors",{"type":20,"tag":54,"props":55,"children":56},"ul",{},[57,68,78,88],{"type":20,"tag":58,"props":59,"children":60},"li",{},[61,66],{"type":20,"tag":33,"props":62,"children":63},{},[64],{"type":26,"value":65},"RAN Programmability API Attacks",{"type":26,"value":67},": Test REST APIs controlling eNodeB\u002FgNodeB scheduling, handover decisions, and resource block allocation for unauthorized manipulation.",{"type":20,"tag":58,"props":69,"children":70},{},[71,76],{"type":20,"tag":33,"props":72,"children":73},{},[74],{"type":26,"value":75},"Network Slice Boundary Escape",{"type":26,"value":77},": Audit slice isolation by attempting cross-slice API calls and resource exhaustion across tenant boundaries.",{"type":20,"tag":58,"props":79,"children":80},{},[81,86],{"type":20,"tag":33,"props":82,"children":83},{},[84],{"type":26,"value":85},"MEC Application Sandboxing",{"type":26,"value":87},": Test container escape vectors and API privilege escalation in edge-deployed security functions.",{"type":20,"tag":58,"props":89,"children":90},{},[91,96],{"type":20,"tag":33,"props":92,"children":93},{},[94],{"type":26,"value":95},"Multi-RAT Handover Exploitation",{"type":26,"value":97},": Analyze security implications of forced handovers between 5G NR, LTE, and Wi-Fi access points.",{"type":20,"tag":47,"props":99,"children":101},{"id":100},"telcochisel-execution-cheatsheet",[102],{"type":26,"value":103},"TelcoChisel Execution Cheatsheet",{"type":20,"tag":105,"props":106,"children":108},"h3",{"id":107},"_1-start-empower-runtime",[109],{"type":26,"value":110},"1. Start EmPOWER Runtime",{"type":20,"tag":112,"props":113,"children":118},"pre",{"className":114,"code":116,"language":117,"meta":8},[115],"language-bash","# Launch the MEC runtime with default configuration\ncd \u002Fopt\u002F5g-empower && empower-runtime --config \u002Fetc\u002Fempower\u002Fconfig.yaml\n","bash",[119],{"type":20,"tag":120,"props":121,"children":122},"code",{"__ignoreMap":8},[123],{"type":26,"value":116},{"type":20,"tag":105,"props":125,"children":127},{"id":126},"_2-list-connected-virtual-base-stations",[128],{"type":26,"value":129},"2. List Connected Virtual Base Stations",{"type":20,"tag":112,"props":131,"children":134},{"className":132,"code":133,"language":117,"meta":8},[115],"# Query active VBS instances via REST API\ncurl -u admin:admin http:\u002F\u002F127.0.0.1:8888\u002Fapi\u002Fv1\u002Fvbses\n",[135],{"type":20,"tag":120,"props":136,"children":137},{"__ignoreMap":8},[138],{"type":26,"value":133},{"type":20,"tag":105,"props":140,"children":142},{"id":141},"_3-enumerate-active-network-slices",[143],{"type":26,"value":144},"3. Enumerate Active Network Slices",{"type":20,"tag":112,"props":146,"children":149},{"className":147,"code":148,"language":117,"meta":8},[115],"# List configured slices and their tenant bindings\ncurl -u admin:admin http:\u002F\u002F127.0.0.1:8888\u002Fapi\u002Fv1\u002Fslices\n",[150],{"type":20,"tag":120,"props":151,"children":152},{"__ignoreMap":8},[153],{"type":26,"value":148},{"type":20,"tag":47,"props":155,"children":157},{"id":156},"practice-in-telcosec-academy",[158],{"type":26,"value":159},"Practice in TelcoSec Academy",{"type":20,"tag":29,"props":161,"children":162},{},[163,165],{"type":26,"value":164},"👉 ",{"type":20,"tag":33,"props":166,"children":167},{},[168],{"type":20,"tag":169,"props":170,"children":173},"a",{"href":15,"rel":171},[172],"nofollow",[174],{"type":26,"value":175},"Launch MEC Security Lab on App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":178},2,[179,180,186],{"id":49,"depth":177,"text":52},{"id":100,"depth":177,"text":103,"children":181},[182,184,185],{"id":107,"depth":183,"text":110},3,{"id":126,"depth":183,"text":129},{"id":141,"depth":183,"text":144},{"id":156,"depth":177,"text":159},"markdown","content:tools:5g-empower.md","content","tools\u002F5g-empower.md","tools\u002F5g-empower","md",{"_path":194,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":195,"description":196,"name":195,"protocol":197,"category":198,"hardware":199,"command":200,"academyLab":15,"body":201,"_type":187,"_id":346,"_source":189,"_file":347,"_stem":348,"_extension":192},"\u002Ftools\u002F5g-lena","5G-LENA","ns-3 based 5G NR module for simulating gNodeB, UE, and core interactions with detailed PHY\u002FMAC\u002FRLC layer fidelity for security research.","5G NR","5G RAN Simulator","Loopback \u002F Ethernet",".\u002Fns3 run scratch\u002Fnr-v2x-simple-demo",{"type":17,"children":202,"toc":337},[203,209,224,228,271,275,281,290,296,305,311,320,324],{"type":20,"tag":21,"props":204,"children":206},{"id":205},"_5g-lena-ns-3-5g-nr-simulator-for-telecom-security",[207],{"type":26,"value":208},"5G-LENA — ns-3 5G NR Simulator for Telecom Security",{"type":20,"tag":29,"props":210,"children":211},{},[212,216,218,222],{"type":20,"tag":33,"props":213,"children":214},{},[215],{"type":26,"value":195},{"type":26,"value":217}," (Long-term Evolution of Network Applications) is a full-fidelity 5G New Radio simulator built on the ns-3 discrete-event network simulation platform. Within ",{"type":20,"tag":33,"props":219,"children":220},{},[221],{"type":26,"value":43},{"type":26,"value":223},", 5G-LENA enables protocol-layer security analysis of gNodeB scheduling, beamforming, RLC segmentation, and MAC-layer resource allocation without requiring physical SDR hardware.",{"type":20,"tag":47,"props":225,"children":226},{"id":49},[227],{"type":26,"value":52},{"type":20,"tag":54,"props":229,"children":230},{},[231,241,251,261],{"type":20,"tag":58,"props":232,"children":233},{},[234,239],{"type":20,"tag":33,"props":235,"children":236},{},[237],{"type":26,"value":238},"PHY\u002FMAC Layer Fuzzing",{"type":26,"value":240},": Simulate malformed DCI (Downlink Control Information) messages and observe UE stack behavior under adversarial scheduling.",{"type":20,"tag":58,"props":242,"children":243},{},[244,249],{"type":20,"tag":33,"props":245,"children":246},{},[247],{"type":26,"value":248},"Beamforming Security Analysis",{"type":26,"value":250},": Test beam sweeping interception scenarios and SSB (Synchronization Signal Block) spoofing in mmWave and sub-6GHz bands.",{"type":20,"tag":58,"props":252,"children":253},{},[254,259],{"type":20,"tag":33,"props":255,"children":256},{},[257],{"type":26,"value":258},"RAN Slicing Isolation Tests",{"type":26,"value":260},": Validate network slice isolation by simulating cross-slice resource contention and priority inversion attacks.",{"type":20,"tag":58,"props":262,"children":263},{},[264,269],{"type":20,"tag":33,"props":265,"children":266},{},[267],{"type":26,"value":268},"V2X Sidelink Security",{"type":26,"value":270},": Audit NR V2X Mode 2 autonomous resource selection for message injection and replay attacks.",{"type":20,"tag":47,"props":272,"children":273},{"id":100},[274],{"type":26,"value":103},{"type":20,"tag":105,"props":276,"children":278},{"id":277},"_1-run-basic-5g-nr-simulation",[279],{"type":26,"value":280},"1. Run Basic 5G NR Simulation",{"type":20,"tag":112,"props":282,"children":285},{"className":283,"code":284,"language":117,"meta":8},[115],"# Execute a simple NR gNodeB + UE scenario\ncd \u002Fopt\u002Fns-3-dev && .\u002Fns3 run scratch\u002Fnr-simple-demo --no-build\n",[286],{"type":20,"tag":120,"props":287,"children":288},{"__ignoreMap":8},[289],{"type":26,"value":284},{"type":20,"tag":105,"props":291,"children":293},{"id":292},"_2-enable-pcap-trace-output",[294],{"type":26,"value":295},"2. Enable PCAP Trace Output",{"type":20,"tag":112,"props":297,"children":300},{"className":298,"code":299,"language":117,"meta":8},[115],"# Run with packet capture enabled for Wireshark analysis\n.\u002Fns3 run \"scratch\u002Fnr-simple-demo --enablePcap=true\" --no-build\n",[301],{"type":20,"tag":120,"props":302,"children":303},{"__ignoreMap":8},[304],{"type":26,"value":299},{"type":20,"tag":105,"props":306,"children":308},{"id":307},"_3-analyze-rlcmac-pdu-traces",[309],{"type":26,"value":310},"3. Analyze RLC\u002FMAC PDU Traces",{"type":20,"tag":112,"props":312,"children":315},{"className":313,"code":314,"language":117,"meta":8},[115],"# Generate detailed MAC scheduling traces\n.\u002Fns3 run \"scratch\u002Fnr-simple-demo --enableTraces=true\" --no-build\nls -la \u002Fopt\u002Fns-3-dev\u002F*.txt  # View generated trace files\n",[316],{"type":20,"tag":120,"props":317,"children":318},{"__ignoreMap":8},[319],{"type":26,"value":314},{"type":20,"tag":47,"props":321,"children":322},{"id":156},[323],{"type":26,"value":159},{"type":20,"tag":29,"props":325,"children":326},{},[327,328],{"type":26,"value":164},{"type":20,"tag":33,"props":329,"children":330},{},[331],{"type":20,"tag":169,"props":332,"children":334},{"href":15,"rel":333},[172],[335],{"type":26,"value":336},"Launch 5G NR Simulation Lab on App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":338},[339,340,345],{"id":49,"depth":177,"text":52},{"id":100,"depth":177,"text":103,"children":341},[342,343,344],{"id":277,"depth":183,"text":280},{"id":292,"depth":183,"text":295},{"id":307,"depth":183,"text":310},{"id":156,"depth":177,"text":159},"content:tools:5g-lena.md","tools\u002F5g-lena.md","tools\u002F5g-lena",{"_path":350,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":351,"description":352,"name":351,"protocol":353,"category":354,"hardware":355,"command":356,"academyLab":15,"body":357,"_type":187,"_id":502,"_source":189,"_file":503,"_stem":504,"_extension":192},"\u002Ftools\u002F5g-nidd","5G-NIDD","Non-IP Data Delivery testing framework for auditing 5G IoT NB-IoT and LTE-M NIDD bearer establishment, SGW tunneling, and SCEF API security.","5G NR \u002F NB-IoT","IoT Protocol Testing","USRP B210 \u002F LimeSDR","nidd-client --config \u002Fetc\u002Fnidd\u002Fdefault.yaml",{"type":17,"children":358,"toc":493},[359,365,380,384,427,431,437,446,452,461,467,476,480],{"type":20,"tag":21,"props":360,"children":362},{"id":361},"_5g-nidd-non-ip-data-delivery-security-testing",[363],{"type":26,"value":364},"5G-NIDD — Non-IP Data Delivery Security Testing",{"type":20,"tag":29,"props":366,"children":367},{},[368,372,374,378],{"type":20,"tag":33,"props":369,"children":370},{},[371],{"type":26,"value":351},{"type":26,"value":373}," enables security auditing of Non-IP Data Delivery bearers used by NB-IoT and LTE-M cellular IoT devices. Within ",{"type":20,"tag":33,"props":375,"children":376},{},[377],{"type":26,"value":43},{"type":26,"value":379},", the tool is preconfigured to test NIDD bearer establishment via the NEF\u002FSCEF exposure APIs, inspect SGW-level tunneling, and identify authentication bypass vectors in constrained IoT device communication.",{"type":20,"tag":47,"props":381,"children":382},{"id":49},[383],{"type":26,"value":52},{"type":20,"tag":54,"props":385,"children":386},{},[387,397,407,417],{"type":20,"tag":58,"props":388,"children":389},{},[390,395],{"type":20,"tag":33,"props":391,"children":392},{},[393],{"type":26,"value":394},"NIDD Bearer Hijacking",{"type":26,"value":396},": Test unauthorized NIDD session establishment by spoofing device identities (IMSI\u002FSUPI) against the SCEF\u002FNEF.",{"type":20,"tag":58,"props":398,"children":399},{},[400,405],{"type":20,"tag":33,"props":401,"children":402},{},[403],{"type":26,"value":404},"SGW Data Injection",{"type":26,"value":406},": Inject crafted non-IP payloads through GTP tunnels targeting the Serving Gateway, bypassing IP-layer firewalls.",{"type":20,"tag":58,"props":408,"children":409},{},[410,415],{"type":20,"tag":33,"props":411,"children":412},{},[413],{"type":26,"value":414},"SCEF\u002FNEF API Fuzzing",{"type":26,"value":416},": Fuzz 3GPP T8 API endpoints for authentication and authorization flaws in IoT device management.",{"type":20,"tag":58,"props":418,"children":419},{},[420,425],{"type":20,"tag":33,"props":421,"children":422},{},[423],{"type":26,"value":424},"Constrained Device Impersonation",{"type":26,"value":426},": Simulate rogue NB-IoT endpoints to test network-side device verification mechanisms.",{"type":20,"tag":47,"props":428,"children":429},{"id":100},[430],{"type":26,"value":103},{"type":20,"tag":105,"props":432,"children":434},{"id":433},"_1-start-nidd-bearer-test",[435],{"type":26,"value":436},"1. Start NIDD Bearer Test",{"type":20,"tag":112,"props":438,"children":441},{"className":439,"code":440,"language":117,"meta":8},[115],"# Initiate NIDD bearer establishment against test core\nnidd-client --config \u002Fetc\u002Fnidd\u002Fdefault.yaml --mode bearer-test\n",[442],{"type":20,"tag":120,"props":443,"children":444},{"__ignoreMap":8},[445],{"type":26,"value":440},{"type":20,"tag":105,"props":447,"children":449},{"id":448},"_2-scef-api-endpoint-discovery",[450],{"type":26,"value":451},"2. SCEF API Endpoint Discovery",{"type":20,"tag":112,"props":453,"children":456},{"className":454,"code":455,"language":117,"meta":8},[115],"# Enumerate SCEF\u002FNEF T8 API endpoints\ncurl -k https:\u002F\u002F127.0.0.1:8443\u002F3gpp-nidd\u002Fv1\u002F\n",[457],{"type":20,"tag":120,"props":458,"children":459},{"__ignoreMap":8},[460],{"type":26,"value":455},{"type":20,"tag":105,"props":462,"children":464},{"id":463},"_3-non-ip-payload-injection",[465],{"type":26,"value":466},"3. Non-IP Payload Injection",{"type":20,"tag":112,"props":468,"children":471},{"className":469,"code":470,"language":117,"meta":8},[115],"# Send crafted non-IP payload through NIDD bearer\nnidd-client --mode inject --payload \u002Fopt\u002Fnidd\u002Fpayloads\u002Fcoap-malformed.bin\n",[472],{"type":20,"tag":120,"props":473,"children":474},{"__ignoreMap":8},[475],{"type":26,"value":470},{"type":20,"tag":47,"props":477,"children":478},{"id":156},[479],{"type":26,"value":159},{"type":20,"tag":29,"props":481,"children":482},{},[483,484],{"type":26,"value":164},{"type":20,"tag":33,"props":485,"children":486},{},[487],{"type":20,"tag":169,"props":488,"children":490},{"href":15,"rel":489},[172],[491],{"type":26,"value":492},"Launch IoT Security Lab on App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":494},[495,496,501],{"id":49,"depth":177,"text":52},{"id":100,"depth":177,"text":103,"children":497},[498,499,500],{"id":433,"depth":183,"text":436},{"id":448,"depth":183,"text":451},{"id":463,"depth":183,"text":466},{"id":156,"depth":177,"text":159},"content:tools:5g-nidd.md","tools\u002F5g-nidd.md","tools\u002F5g-nidd",{"_path":506,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":507,"description":508,"name":507,"protocol":509,"category":510,"hardware":511,"command":512,"academyLab":15,"body":513,"_type":187,"_id":658,"_source":189,"_file":659,"_stem":660,"_extension":192},"\u002Ftools\u002Fcardpeek","Cardpeek","GTK-based smartcard file system browser with Lua scripting for inspecting SIM\u002FUSIM\u002FISIM EF structures, ICCID, IMSI, ADN, and authentication parameters.","SIM \u002F USIM \u002F eSIM","Smartcard Browser","PC\u002FSC Smartcard Reader","cardpeek",{"type":17,"children":514,"toc":649},[515,521,536,540,583,587,593,602,608,617,623,632,636],{"type":20,"tag":21,"props":516,"children":518},{"id":517},"cardpeek-smartcard-file-system-browser",[519],{"type":26,"value":520},"Cardpeek — Smartcard File System Browser",{"type":20,"tag":29,"props":522,"children":523},{},[524,528,530,534],{"type":20,"tag":33,"props":525,"children":526},{},[527],{"type":26,"value":507},{"type":26,"value":529}," is a graphical smartcard exploration tool that reads and displays the file system structure of SIM, USIM, ISIM, banking, and identity cards. Within ",{"type":20,"tag":33,"props":531,"children":532},{},[533],{"type":26,"value":43},{"type":26,"value":535},", Cardpeek is configured with telecom-specific Lua scripts for deep inspection of 3GPP SIM Elementary Files (EFs), authentication keys (Ki\u002FOPc), PLMN selectors, and USIM security domains.",{"type":20,"tag":47,"props":537,"children":538},{"id":49},[539],{"type":26,"value":52},{"type":20,"tag":54,"props":541,"children":542},{},[543,553,563,573],{"type":20,"tag":58,"props":544,"children":545},{},[546,551],{"type":20,"tag":33,"props":547,"children":548},{},[549],{"type":26,"value":550},"EF Structure Browsing",{"type":26,"value":552},": Navigate the complete SIM\u002FUSIM file tree including EF_ICCID, EF_IMSI, EF_LOCI, EF_ADN, EF_FPLMN, and EF_KEYS.",{"type":20,"tag":58,"props":554,"children":555},{},[556,561],{"type":20,"tag":33,"props":557,"children":558},{},[559],{"type":26,"value":560},"Authentication Parameter Extraction",{"type":26,"value":562},": Read exposed Ki, OPc, and Milenage algorithm parameters from misconfigured test SIM cards.",{"type":20,"tag":58,"props":564,"children":565},{},[566,571],{"type":20,"tag":33,"props":567,"children":568},{},[569],{"type":26,"value":570},"PLMN Selector Analysis",{"type":26,"value":572},": Inspect EF_PLMNwAcT and EF_OPLMNwAcT to understand carrier roaming preferences and forced PLMN selection vectors.",{"type":20,"tag":58,"props":574,"children":575},{},[576,581],{"type":20,"tag":33,"props":577,"children":578},{},[579],{"type":26,"value":580},"USIM Service Table Audit",{"type":26,"value":582},": Decode EF_UST to identify enabled USIM services including OTA, GBA, MBMS, and ProSe capabilities.",{"type":20,"tag":47,"props":584,"children":585},{"id":100},[586],{"type":26,"value":103},{"type":20,"tag":105,"props":588,"children":590},{"id":589},"_1-launch-cardpeek-gui",[591],{"type":26,"value":592},"1. Launch Cardpeek GUI",{"type":20,"tag":112,"props":594,"children":597},{"className":595,"code":596,"language":117,"meta":8},[115],"# Open Cardpeek with automatic reader detection\ncardpeek\n# Select \"Telecom SIM\" script from the dropdown\n",[598],{"type":20,"tag":120,"props":599,"children":600},{"__ignoreMap":8},[601],{"type":26,"value":596},{"type":20,"tag":105,"props":603,"children":605},{"id":604},"_2-read-sim-via-cli-lua-script",[606],{"type":26,"value":607},"2. Read SIM via CLI Lua Script",{"type":20,"tag":112,"props":609,"children":612},{"className":610,"code":611,"language":117,"meta":8},[115],"# Execute USIM exploration script headlessly\ncardpeek-cli -e \u002Fusr\u002Fshare\u002Fcardpeek\u002Fscripts\u002Fusim.lua -r 0\n",[613],{"type":20,"tag":120,"props":614,"children":615},{"__ignoreMap":8},[616],{"type":26,"value":611},{"type":20,"tag":105,"props":618,"children":620},{"id":619},"_3-export-sim-data-to-xml",[621],{"type":26,"value":622},"3. Export SIM Data to XML",{"type":20,"tag":112,"props":624,"children":627},{"className":625,"code":626,"language":117,"meta":8},[115],"# Dump complete SIM file structure to XML for offline analysis\ncardpeek-cli -e \u002Fusr\u002Fshare\u002Fcardpeek\u002Fscripts\u002Fusim.lua -r 0 -x \u002Ftmp\u002Fsim-dump.xml\n",[628],{"type":20,"tag":120,"props":629,"children":630},{"__ignoreMap":8},[631],{"type":26,"value":626},{"type":20,"tag":47,"props":633,"children":634},{"id":156},[635],{"type":26,"value":159},{"type":20,"tag":29,"props":637,"children":638},{},[639,640],{"type":26,"value":164},{"type":20,"tag":33,"props":641,"children":642},{},[643],{"type":20,"tag":169,"props":644,"children":646},{"href":15,"rel":645},[172],[647],{"type":26,"value":648},"Launch Smartcard Security Lab on App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":650},[651,652,657],{"id":49,"depth":177,"text":52},{"id":100,"depth":177,"text":103,"children":653},[654,655,656],{"id":589,"depth":183,"text":592},{"id":604,"depth":183,"text":607},{"id":619,"depth":183,"text":622},{"id":156,"depth":177,"text":159},"content:tools:cardpeek.md","tools\u002Fcardpeek.md","tools\u002Fcardpeek",{"_path":662,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":663,"description":664,"name":665,"protocol":666,"category":667,"hardware":668,"command":669,"academyLab":15,"body":670,"_type":187,"_id":802,"_source":189,"_file":803,"_stem":804,"_extension":192},"\u002Ftools\u002Fdiameter-fuzzer","Diameter Fuzzer","Stateful fuzzing framework for Diameter base protocol and 3GPP application interfaces, uncovering parsing flaws and state machine vulnerabilities in HSS\u002FDRA nodes.","Diameter-Fuzzer","Diameter (3GPP S6a, Cx, Ro, Gy)","Protocol Fuzzing & Crash Discovery","Ethernet \u002F SCTP \u002F TCP Socket","diameter-fuzzer --target 10.0.0.5 --port 3868",{"type":17,"children":671,"toc":794},[672,678,683,689,738,744,750,759,765,774,780],{"type":20,"tag":21,"props":673,"children":675},{"id":674},"diameter-protocol-fuzzing-suite",[676],{"type":26,"value":677},"Diameter Protocol Fuzzing Suite",{"type":20,"tag":29,"props":679,"children":680},{},[681],{"type":26,"value":682},"Diameter-Fuzzer is a high-speed, stateful security fuzzer designed for 4G LTE and IMS telecommunication core signaling. It validates Diameter Routing Agents (DRA), Home Subscriber Servers (HSS), and Charging Gateways against malformed Attribute-Value Pairs (AVPs), length mismatch overflows, and cyclic routing loops.",{"type":20,"tag":47,"props":684,"children":686},{"id":685},"attack-surface-tested",[687],{"type":26,"value":688},"Attack Surface Tested",{"type":20,"tag":54,"props":690,"children":691},{},[692,702,720],{"type":20,"tag":58,"props":693,"children":694},{},[695,700],{"type":20,"tag":33,"props":696,"children":697},{},[698],{"type":26,"value":699},"AVP Length Mismatches & Boundary Overflows",{"type":26,"value":701},": Test DRA and HSS parsers for heap corruption when decoding nested Grouped AVPs.",{"type":20,"tag":58,"props":703,"children":704},{},[705,710,712,718],{"type":20,"tag":33,"props":706,"children":707},{},[708],{"type":26,"value":709},"Diameter Loop Attacks",{"type":26,"value":711},": Craft ",{"type":20,"tag":120,"props":713,"children":715},{"className":714},[],[716],{"type":26,"value":717},"Route-Record",{"type":26,"value":719}," AVPs to induce routing loops across international Diameter interconnects (IPX \u002F GRX).",{"type":20,"tag":58,"props":721,"children":722},{},[723,728,730,736],{"type":20,"tag":33,"props":724,"children":725},{},[726],{"type":26,"value":727},"Session State Exhaustion",{"type":26,"value":729},": Burst millions of concurrent ",{"type":20,"tag":120,"props":731,"children":733},{"className":732},[],[734],{"type":26,"value":735},"Auth-Session-State",{"type":26,"value":737}," initialization requests to consume DRA memory tables.",{"type":20,"tag":47,"props":739,"children":741},{"id":740},"pre-installed-telcochisel-cheatsheet",[742],{"type":26,"value":743},"Pre-installed TelcoChisel Cheatsheet",{"type":20,"tag":105,"props":745,"children":747},{"id":746},"_1-fuzz-s6a-interface-with-dynamic-mutation",[748],{"type":26,"value":749},"1. Fuzz S6a Interface with Dynamic Mutation",{"type":20,"tag":112,"props":751,"children":754},{"className":752,"code":753,"language":117,"meta":8},[115],"# Target HSS S6a interface on port 3868\ndiameter-fuzzer --target 10.10.10.50 --port 3868 --app-id 16777251 --mutation-rate 0.05\n",[755],{"type":20,"tag":120,"props":756,"children":757},{"__ignoreMap":8},[758],{"type":26,"value":753},{"type":20,"tag":105,"props":760,"children":762},{"id":761},"_2-verify-crash-logs-heartbeat-monitoring",[763],{"type":26,"value":764},"2. Verify Crash Logs & Heartbeat Monitoring",{"type":20,"tag":112,"props":766,"children":769},{"className":767,"code":768,"language":117,"meta":8},[115],"# Continuous Device-Watchdog-Request (DWR) watchdog monitor\ndiameter-watchdog --target 10.10.10.50 --interval 2s --alert-on-timeout\n",[770],{"type":20,"tag":120,"props":771,"children":772},{"__ignoreMap":8},[773],{"type":26,"value":768},{"type":20,"tag":47,"props":775,"children":777},{"id":776},"practice-in-telcosec-cloud-academy",[778],{"type":26,"value":779},"Practice in TelcoSec Cloud Academy",{"type":20,"tag":29,"props":781,"children":782},{},[783,785],{"type":26,"value":784},"To practice fuzzing core telecom infrastructure safely:\n👉 ",{"type":20,"tag":33,"props":786,"children":787},{},[788],{"type":20,"tag":169,"props":789,"children":791},{"href":15,"rel":790},[172],[792],{"type":26,"value":793},"Access the Core Signaling Security Lab at App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":795},[796,797,801],{"id":685,"depth":177,"text":688},{"id":740,"depth":177,"text":743,"children":798},[799,800],{"id":746,"depth":183,"text":749},{"id":761,"depth":183,"text":764},{"id":776,"depth":177,"text":779},"content:tools:diameter-fuzzer.md","tools\u002Fdiameter-fuzzer.md","tools\u002Fdiameter-fuzzer",{"_path":806,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":807,"description":808,"name":807,"protocol":197,"category":809,"hardware":810,"command":811,"academyLab":15,"body":812,"_type":187,"_id":957,"_source":189,"_file":958,"_stem":959,"_extension":192},"\u002Ftools\u002Ffree5gc","free5GC","Open-source 5G Core Network (3GPP Release 15\u002F16) written in Go, designed for research and telecom security auditing.","5G Core Network & Evolved Packet Core","USRP B210 \u002F LimeSDR \u002F BladeRF",".\u002Frun.sh",{"type":17,"children":813,"toc":948},[814,820,835,839,882,886,892,901,907,916,922,931,935],{"type":20,"tag":21,"props":815,"children":817},{"id":816},"free5gc-5g-standalone-core-security-platform",[818],{"type":26,"value":819},"free5GC — 5G Standalone Core Security Platform",{"type":20,"tag":29,"props":821,"children":822},{},[823,827,829,833],{"type":20,"tag":33,"props":824,"children":825},{},[826],{"type":26,"value":807},{"type":26,"value":828}," is a widely adopted open-source 5G Core Network written natively in Go. Within ",{"type":20,"tag":33,"props":830,"children":831},{},[832],{"type":26,"value":43},{"type":26,"value":834},", free5GC is packaged with modular network function configurations, MongoDB persistence, and real-time SBI tracing scripts.",{"type":20,"tag":47,"props":836,"children":837},{"id":49},[838],{"type":26,"value":52},{"type":20,"tag":54,"props":840,"children":841},{},[842,852,862,872],{"type":20,"tag":58,"props":843,"children":844},{},[845,850],{"type":20,"tag":33,"props":846,"children":847},{},[848],{"type":26,"value":849},"Go-based 5G SBA Functions",{"type":26,"value":851},": Complete implementations of NSSF, NRF, UDR, UDM, AUSF, N3IWF, AMF, PCF, SMF, and UPF.",{"type":20,"tag":58,"props":853,"children":854},{},[855,860],{"type":20,"tag":33,"props":856,"children":857},{},[858],{"type":26,"value":859},"N2\u002FN3 Interface Auditing",{"type":26,"value":861},": Test gNodeB SCTP signaling to AMF and GTP-U data tunnel encapsulation to UPF.",{"type":20,"tag":58,"props":863,"children":864},{},[865,870],{"type":20,"tag":33,"props":866,"children":867},{},[868],{"type":26,"value":869},"Non-3GPP Interworking (N3IWF)",{"type":26,"value":871},": Test untrusted Wi-Fi access integration, IKEv2 \u002F IPsec tunnel establishment, and authentication bypasses.",{"type":20,"tag":58,"props":873,"children":874},{},[875,880],{"type":20,"tag":33,"props":876,"children":877},{},[878],{"type":26,"value":879},"Microservice Isolation & Policy Auditing",{"type":26,"value":881},": Fuzz HTTP\u002F2 Service-Based Interfaces (SBI) between NFs to discover privilege escalation paths.",{"type":20,"tag":47,"props":883,"children":884},{"id":100},[885],{"type":26,"value":103},{"type":20,"tag":105,"props":887,"children":889},{"id":888},"_1-run-complete-free5gc-core",[890],{"type":26,"value":891},"1. Run Complete free5GC Core",{"type":20,"tag":112,"props":893,"children":896},{"className":894,"code":895,"language":117,"meta":8},[115],"# Launch free5GC core network functions with default logging\ncd \u002Fopt\u002Ffree5gc && sudo .\u002Frun.sh\n",[897],{"type":20,"tag":120,"props":898,"children":899},{"__ignoreMap":8},[900],{"type":26,"value":895},{"type":20,"tag":105,"props":902,"children":904},{"id":903},"_2-inspect-5g-core-web-management-console",[905],{"type":26,"value":906},"2. Inspect 5G Core Web Management Console",{"type":20,"tag":112,"props":908,"children":911},{"className":909,"code":910,"language":117,"meta":8},[115],"# Start free5GC webconsole on port 5000\ncd \u002Fopt\u002Ffree5gc\u002Fwebconsole && .\u002Fbin\u002Fwebconsole\n# Open in browser: http:\u002F\u002Flocalhost:5000 (admin \u002F free5gc)\n",[912],{"type":20,"tag":120,"props":913,"children":914},{"__ignoreMap":8},[915],{"type":26,"value":910},{"type":20,"tag":105,"props":917,"children":919},{"id":918},"_3-fuzz-sba-api-endpoints",[920],{"type":26,"value":921},"3. Fuzz SBA API Endpoints",{"type":20,"tag":112,"props":923,"children":926},{"className":924,"code":925,"language":117,"meta":8},[115],"# Verify NRF registration endpoint via curl\ncurl -k -X GET http:\u002F\u002F127.0.0.10:8000\u002Fnnrf-disc\u002Fv1\u002Fnf-instances?nf-type=AMF\n",[927],{"type":20,"tag":120,"props":928,"children":929},{"__ignoreMap":8},[930],{"type":26,"value":925},{"type":20,"tag":47,"props":932,"children":933},{"id":156},[934],{"type":26,"value":159},{"type":20,"tag":29,"props":936,"children":937},{},[938,939],{"type":26,"value":164},{"type":20,"tag":33,"props":940,"children":941},{},[942],{"type":20,"tag":169,"props":943,"children":945},{"href":15,"rel":944},[172],[946],{"type":26,"value":947},"Launch 5G Core Security Lab on App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":949},[950,951,956],{"id":49,"depth":177,"text":52},{"id":100,"depth":177,"text":103,"children":952},[953,954,955],{"id":888,"depth":183,"text":891},{"id":903,"depth":183,"text":906},{"id":918,"depth":183,"text":921},{"id":156,"depth":177,"text":159},"content:tools:free5gc.md","tools\u002Ffree5gc.md","tools\u002Ffree5gc",{"_path":961,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":962,"description":963,"name":962,"protocol":964,"category":965,"hardware":966,"command":967,"academyLab":15,"body":968,"_type":187,"_id":1080,"_source":189,"_file":1081,"_stem":1082,"_extension":192},"\u002Ftools\u002Fgnbsim","gNBSim","5G SA gNodeB and UE simulator for testing 5G Core scalability, registration procedures, PDU session establishment, and N2\u002FN3 signaling fuzzing.","5G SA (Release 16)","5G gNodeB & UE Traffic Load Simulator","Ethernet \u002F Loopback (No SDR Required)",".\u002Fgnbsim --cfg .\u002Fconfig\u002Fgnb.json",{"type":17,"children":969,"toc":1072},[970,976,981,987,1020,1024,1030,1039,1045,1054,1058],{"type":20,"tag":21,"props":971,"children":973},{"id":972},"gnbsim-5g-sa-gnodeb-multi-ue-simulator",[974],{"type":26,"value":975},"gNBSim — 5G SA gNodeB & Multi-UE Simulator",{"type":20,"tag":29,"props":977,"children":978},{},[979],{"type":26,"value":980},"gNBSim is an indispensable 5G Standalone load generation and security auditing tool. It simulates the behavior of hundreds of 5G UEs and gNodeBs concurrently without needing physical SDR radios, communicating directly over SCTP (N2\u002FNG-AP) and GTP-U (N3) with any 3GPP-compliant 5G Core.",{"type":20,"tag":47,"props":982,"children":984},{"id":983},"security-testing-applications",[985],{"type":26,"value":986},"Security Testing Applications",{"type":20,"tag":54,"props":988,"children":989},{},[990,1000,1010],{"type":20,"tag":58,"props":991,"children":992},{},[993,998],{"type":20,"tag":33,"props":994,"children":995},{},[996],{"type":26,"value":997},"5G Core High-Volume Registration Flooding",{"type":26,"value":999},": Test AMF resistance against high-frequency Registration Request bursts (DDoS resilience).",{"type":20,"tag":58,"props":1001,"children":1002},{},[1003,1008],{"type":20,"tag":33,"props":1004,"children":1005},{},[1006],{"type":26,"value":1007},"NG-AP Malformed Message Injection",{"type":26,"value":1009},": Send fuzzing payloads inside NGAP InitialUEMessage containers to uncover memory safety vulnerabilities in Core AMF parsers.",{"type":20,"tag":58,"props":1011,"children":1012},{},[1013,1018],{"type":20,"tag":33,"props":1014,"children":1015},{},[1016],{"type":26,"value":1017},"PDU Session Hijacking",{"type":26,"value":1019},": Test SMF and UPF TEID collision handling during simultaneous PDU Session Establishment requests.",{"type":20,"tag":47,"props":1021,"children":1022},{"id":740},[1023],{"type":26,"value":743},{"type":20,"tag":105,"props":1025,"children":1027},{"id":1026},"_1-execute-simulated-5g-registration-workflow",[1028],{"type":26,"value":1029},"1. Execute Simulated 5G Registration Workflow",{"type":20,"tag":112,"props":1031,"children":1034},{"className":1032,"code":1033,"language":117,"meta":8},[115],"# Run automated 5G Registration and PDU Session establishment\ngnbsim --cfg \u002Fetc\u002Fgnbsim\u002Fdefault.json --run=\"ue-reg-pdu-test\"\n",[1035],{"type":20,"tag":120,"props":1036,"children":1037},{"__ignoreMap":8},[1038],{"type":26,"value":1033},{"type":20,"tag":105,"props":1040,"children":1042},{"id":1041},"_2-capture-n2n3-signaling-in-wireshark",[1043],{"type":26,"value":1044},"2. Capture N2\u002FN3 Signaling in Wireshark",{"type":20,"tag":112,"props":1046,"children":1049},{"className":1047,"code":1048,"language":117,"meta":8},[115],"# Capture NGAP and GTP-U signaling during the simulation\nsudo tshark -i lo -f \"sctp port 38412 or udp port 2152\" -w \u002Ftmp\u002F5g_sim_capture.pcap\n",[1050],{"type":20,"tag":120,"props":1051,"children":1052},{"__ignoreMap":8},[1053],{"type":26,"value":1048},{"type":20,"tag":47,"props":1055,"children":1056},{"id":776},[1057],{"type":26,"value":779},{"type":20,"tag":29,"props":1059,"children":1060},{},[1061,1063],{"type":26,"value":1062},"To practice automated 5G Core penetration testing with gNBSim and UERANSIM:\n👉 ",{"type":20,"tag":33,"props":1064,"children":1065},{},[1066],{"type":20,"tag":169,"props":1067,"children":1069},{"href":15,"rel":1068},[172],[1070],{"type":26,"value":1071},"Access the 5G SBA Automation Lab at App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":1073},[1074,1075,1079],{"id":983,"depth":177,"text":986},{"id":740,"depth":177,"text":743,"children":1076},[1077,1078],{"id":1026,"depth":183,"text":1029},{"id":1041,"depth":183,"text":1044},{"id":776,"depth":177,"text":779},"content:tools:gnbsim.md","tools\u002Fgnbsim.md","tools\u002Fgnbsim",{"_path":1084,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":1085,"description":1086,"name":1085,"protocol":1087,"category":1088,"hardware":1089,"command":1090,"academyLab":15,"body":1091,"_type":187,"_id":1237,"_source":189,"_file":1238,"_stem":1239,"_extension":192},"\u002Ftools\u002Fgnuradio-telecom","GNU Radio Telecom OOT","GNU Radio with telecom-specific out-of-tree (OOT) modules for cellular signal processing, LTE\u002F5G channel estimation, custom demodulation, and RF fingerprinting.","RF \u002F 2G-5G","SDR Framework","USRP B210 \u002F X310 \u002F HackRF \u002F LimeSDR \u002F RTL-SDR","gnuradio-companion",{"type":17,"children":1092,"toc":1228},[1093,1099,1115,1119,1162,1166,1172,1181,1187,1196,1202,1211,1215],{"type":20,"tag":21,"props":1094,"children":1096},{"id":1095},"gnu-radio-telecom-oot-cellular-sdr-signal-processing",[1097],{"type":26,"value":1098},"GNU Radio Telecom OOT — Cellular SDR Signal Processing",{"type":20,"tag":29,"props":1100,"children":1101},{},[1102,1107,1109,1113],{"type":20,"tag":33,"props":1103,"children":1104},{},[1105],{"type":26,"value":1106},"GNU Radio",{"type":26,"value":1108}," is the foundational SDR signal processing framework, extended in ",{"type":20,"tag":33,"props":1110,"children":1111},{},[1112],{"type":26,"value":43},{"type":26,"value":1114}," with telecom-specific out-of-tree (OOT) modules for LTE\u002F5G waveform generation, cellular channel estimation, OFDM subcarrier manipulation, and RF device fingerprinting. Pre-installed OOT blocks include gr-lte, gr-gsm, gr-cellurar, gr-rds, and custom TelcoChisel telecom flow graphs.",{"type":20,"tag":47,"props":1116,"children":1117},{"id":49},[1118],{"type":26,"value":52},{"type":20,"tag":54,"props":1120,"children":1121},{},[1122,1132,1142,1152],{"type":20,"tag":58,"props":1123,"children":1124},{},[1125,1130],{"type":20,"tag":33,"props":1126,"children":1127},{},[1128],{"type":26,"value":1129},"Custom LTE\u002F5G Waveform Generation",{"type":26,"value":1131},": Build arbitrary OFDM waveforms matching 3GPP physical layer specifications for protocol-level RF testing.",{"type":20,"tag":58,"props":1133,"children":1134},{},[1135,1140],{"type":20,"tag":33,"props":1136,"children":1137},{},[1138],{"type":26,"value":1139},"Channel Estimation Attacks",{"type":26,"value":1141},": Exploit pilot signal knowledge to perform channel estimation on encrypted LTE\u002F5G downlink for passive RF fingerprinting.",{"type":20,"tag":58,"props":1143,"children":1144},{},[1145,1150],{"type":20,"tag":33,"props":1146,"children":1147},{},[1148],{"type":26,"value":1149},"OFDM Subcarrier Injection",{"type":26,"value":1151},": Target specific OFDM subcarriers carrying control information (PDCCH, PBCH) for selective signal manipulation.",{"type":20,"tag":58,"props":1153,"children":1154},{},[1155,1160],{"type":20,"tag":33,"props":1156,"children":1157},{},[1158],{"type":26,"value":1159},"RF Device Fingerprinting",{"type":26,"value":1161},": Analyze transmitter-specific imperfections (I\u002FQ imbalance, carrier leakage, phase noise) to identify and track individual SDR devices.",{"type":20,"tag":47,"props":1163,"children":1164},{"id":100},[1165],{"type":26,"value":103},{"type":20,"tag":105,"props":1167,"children":1169},{"id":1168},"_1-launch-gnu-radio-companion",[1170],{"type":26,"value":1171},"1. Launch GNU Radio Companion",{"type":20,"tag":112,"props":1173,"children":1176},{"className":1174,"code":1175,"language":117,"meta":8},[115],"# Open the graphical flow graph editor\ngnuradio-companion\n# Load telecom flow graphs from: \u002Fopt\u002Ftelcochisel\u002Fgnuradio-flows\u002F\n",[1177],{"type":20,"tag":120,"props":1178,"children":1179},{"__ignoreMap":8},[1180],{"type":26,"value":1175},{"type":20,"tag":105,"props":1182,"children":1184},{"id":1183},"_2-run-lte-cell-search-flow-graph",[1185],{"type":26,"value":1186},"2. Run LTE Cell Search Flow Graph",{"type":20,"tag":112,"props":1188,"children":1191},{"className":1189,"code":1190,"language":117,"meta":8},[115],"# Execute headless LTE cell search using gr-lte blocks\npython3 \u002Fopt\u002Ftelcochisel\u002Fgnuradio-flows\u002Flte_cell_search.py --freq 1842.5e6 --gain 40\n",[1192],{"type":20,"tag":120,"props":1193,"children":1194},{"__ignoreMap":8},[1195],{"type":26,"value":1190},{"type":20,"tag":105,"props":1197,"children":1199},{"id":1198},"_3-record-wideband-cellular-spectrum",[1200],{"type":26,"value":1201},"3. Record Wideband Cellular Spectrum",{"type":20,"tag":112,"props":1203,"children":1206},{"className":1204,"code":1205,"language":117,"meta":8},[115],"# Capture 20 MHz wideband IQ samples for offline analysis\npython3 \u002Fopt\u002Ftelcochisel\u002Fgnuradio-flows\u002Fwideband_recorder.py --freq 2140e6 --rate 20e6 --duration 30 --output \u002Ftmp\u002Fcapture.cf32\n",[1207],{"type":20,"tag":120,"props":1208,"children":1209},{"__ignoreMap":8},[1210],{"type":26,"value":1205},{"type":20,"tag":47,"props":1212,"children":1213},{"id":156},[1214],{"type":26,"value":159},{"type":20,"tag":29,"props":1216,"children":1217},{},[1218,1219],{"type":26,"value":164},{"type":20,"tag":33,"props":1220,"children":1221},{},[1222],{"type":20,"tag":169,"props":1223,"children":1225},{"href":15,"rel":1224},[172],[1226],{"type":26,"value":1227},"Launch SDR Signal Processing Lab on App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":1229},[1230,1231,1236],{"id":49,"depth":177,"text":52},{"id":100,"depth":177,"text":103,"children":1232},[1233,1234,1235],{"id":1168,"depth":183,"text":1171},{"id":1183,"depth":183,"text":1186},{"id":1198,"depth":183,"text":1201},{"id":156,"depth":177,"text":159},"content:tools:gnuradio-telecom.md","tools\u002Fgnuradio-telecom.md","tools\u002Fgnuradio-telecom",{"_path":1241,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":1242,"description":1243,"name":1242,"protocol":1244,"category":1245,"hardware":1246,"command":1247,"academyLab":15,"body":1248,"_type":187,"_id":1372,"_source":189,"_file":1373,"_stem":1374,"_extension":192},"\u002Ftools\u002Fgqrx","Gqrx SDR","Open-source software defined radio receiver powered by GNU Radio and Qt GUI, ideal for live RF spectrum monitoring and telecom uplink hunting.","RF \u002F SDR \u002F Spectrum","RF & Baseband Reverse Engineering","HackRF \u002F RTL-SDR \u002F LimeSDR \u002F BladeRF \u002F USRP","gqrx",{"type":17,"children":1249,"toc":1364},[1250,1256,1272,1278,1311,1317,1323,1332,1338,1347,1351],{"type":20,"tag":21,"props":1251,"children":1253},{"id":1252},"gqrx-sdr-interactive-rf-spectrum-analyzer-receiver",[1254],{"type":26,"value":1255},"Gqrx SDR — Interactive RF Spectrum Analyzer & Receiver",{"type":20,"tag":29,"props":1257,"children":1258},{},[1259,1264,1266,1270],{"type":20,"tag":33,"props":1260,"children":1261},{},[1262],{"type":26,"value":1263},"Gqrx",{"type":26,"value":1265}," is an open-source software-defined radio receiver powered by GNU Radio and the Qt graphical toolkit. In ",{"type":20,"tag":33,"props":1267,"children":1268},{},[1269],{"type":26,"value":43},{"type":26,"value":1271},", Gqrx is configured out-of-the-box with drivers for all supported SDR hardware (HackRF One, RTL-SDR v4, LimeSDR, BladeRF 2.0 micro, Ettus USRP), allowing researchers to sweep cellular frequency bands, capture IQ data, and demodulate analog and digital transmissions.",{"type":20,"tag":47,"props":1273,"children":1275},{"id":1274},"key-capabilities",[1276],{"type":26,"value":1277},"Key Capabilities",{"type":20,"tag":54,"props":1279,"children":1280},{},[1281,1291,1301],{"type":20,"tag":58,"props":1282,"children":1283},{},[1284,1289],{"type":20,"tag":33,"props":1285,"children":1286},{},[1287],{"type":26,"value":1288},"Real-Time FFT Waterfall & Spectrum Scope",{"type":26,"value":1290},": Visual inspection of cellular downlink\u002Fuplink carriers across 2G, 3G, 4G LTE, and 5G NR FR1 bands.",{"type":20,"tag":58,"props":1292,"children":1293},{},[1294,1299],{"type":20,"tag":33,"props":1295,"children":1296},{},[1297],{"type":26,"value":1298},"IQ Recording to Disk",{"type":26,"value":1300},": Capture raw complex IQ samples with timestamping for post-processing in Inspectrum and URH.",{"type":20,"tag":58,"props":1302,"children":1303},{},[1304,1309],{"type":20,"tag":33,"props":1305,"children":1306},{},[1307],{"type":26,"value":1308},"AM\u002FFM\u002FSSB Demodulation & Audio Streaming",{"type":26,"value":1310},": Live demodulation of analog signals and audio routing via ALSA \u002F PulseAudio.",{"type":20,"tag":47,"props":1312,"children":1314},{"id":1313},"cheatsheet",[1315],{"type":26,"value":1316},"Cheatsheet",{"type":20,"tag":105,"props":1318,"children":1320},{"id":1319},"_1-launch-gqrx-with-hackrf-one",[1321],{"type":26,"value":1322},"1. Launch Gqrx with HackRF One",{"type":20,"tag":112,"props":1324,"children":1327},{"className":1325,"code":1326,"language":117,"meta":8},[115],"# Launch Gqrx GUI\ngqrx\n",[1328],{"type":20,"tag":120,"props":1329,"children":1330},{"__ignoreMap":8},[1331],{"type":26,"value":1326},{"type":20,"tag":105,"props":1333,"children":1335},{"id":1334},"_2-capture-iq-samples-to-ram-disk",[1336],{"type":26,"value":1337},"2. Capture IQ Samples to RAM Disk",{"type":20,"tag":112,"props":1339,"children":1342},{"className":1340,"code":1341,"language":117,"meta":8},[115],"# Record 10 MHz bandwidth IQ stream directly to tmpfs for fast IO\n# Trigger via Gqrx UI \"Record IQ\" button -> \u002Fdev\u002Fshm\u002Fcell_capture.raw\n",[1343],{"type":20,"tag":120,"props":1344,"children":1345},{"__ignoreMap":8},[1346],{"type":26,"value":1341},{"type":20,"tag":47,"props":1348,"children":1349},{"id":156},[1350],{"type":26,"value":159},{"type":20,"tag":29,"props":1352,"children":1353},{},[1354,1355],{"type":26,"value":164},{"type":20,"tag":33,"props":1356,"children":1357},{},[1358],{"type":20,"tag":169,"props":1359,"children":1361},{"href":15,"rel":1360},[172],[1362],{"type":26,"value":1363},"Access SDR & RF Signal Analysis Labs at App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":1365},[1366,1367,1371],{"id":1274,"depth":177,"text":1277},{"id":1313,"depth":177,"text":1316,"children":1368},[1369,1370],{"id":1319,"depth":183,"text":1322},{"id":1334,"depth":183,"text":1337},{"id":156,"depth":177,"text":159},"content:tools:gqrx.md","tools\u002Fgqrx.md","tools\u002Fgqrx",{"_path":1376,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":1377,"description":1378,"name":1377,"protocol":1379,"category":1380,"hardware":1381,"command":1382,"academyLab":15,"body":1383,"_type":187,"_id":1528,"_source":189,"_file":1529,"_stem":1530,"_extension":192},"\u002Ftools\u002Fgr-gsm","Gr-GSM","GNU Radio based GSM receiver and decoder for passive over-the-air capture, BCCH decoding, and real-time Wireshark integration of GSM signaling and traffic.","2G GSM","GSM Sniffer & Decoder","RTL-SDR \u002F HackRF \u002F USRP B210","grgsm_livemon -f 935.2e6",{"type":17,"children":1384,"toc":1519},[1385,1391,1406,1410,1453,1457,1463,1472,1478,1487,1493,1502,1506],{"type":20,"tag":21,"props":1386,"children":1388},{"id":1387},"gr-gsm-gnu-radio-gsm-receiver-decoder",[1389],{"type":26,"value":1390},"Gr-GSM — GNU Radio GSM Receiver & Decoder",{"type":20,"tag":29,"props":1392,"children":1393},{},[1394,1398,1400,1404],{"type":20,"tag":33,"props":1395,"children":1396},{},[1397],{"type":26,"value":1377},{"type":26,"value":1399}," is a set of GNU Radio out-of-tree (OOT) blocks implementing a GSM receiver for passive over-the-air capture. Within ",{"type":20,"tag":33,"props":1401,"children":1402},{},[1403],{"type":26,"value":43},{"type":26,"value":1405},", Gr-GSM is pre-installed with live monitoring tools, Wireshark GSMTAP integration, and support for RTL-SDR, HackRF, and USRP hardware for real-time GSM signal analysis and IMSI catcher detection.",{"type":20,"tag":47,"props":1407,"children":1408},{"id":49},[1409],{"type":26,"value":52},{"type":20,"tag":54,"props":1411,"children":1412},{},[1413,1423,1433,1443],{"type":20,"tag":58,"props":1414,"children":1415},{},[1416,1421],{"type":20,"tag":33,"props":1417,"children":1418},{},[1419],{"type":26,"value":1420},"Passive GSM Capture",{"type":26,"value":1422},": Receive and decode GSM downlink channels (BCCH, SDCCH, TCH) without active transmission.",{"type":20,"tag":58,"props":1424,"children":1425},{},[1426,1431],{"type":20,"tag":33,"props":1427,"children":1428},{},[1429],{"type":26,"value":1430},"GSMTAP Wireshark Integration",{"type":26,"value":1432},": Stream decoded GSM frames in real-time to Wireshark for LAPDm, RR, MM, and CC protocol analysis.",{"type":20,"tag":58,"props":1434,"children":1435},{},[1436,1441],{"type":20,"tag":33,"props":1437,"children":1438},{},[1439],{"type":26,"value":1440},"Cell Information Extraction",{"type":26,"value":1442},": Decode System Information messages to extract MCC, MNC, LAC, Cell ID, and neighboring cell lists.",{"type":20,"tag":58,"props":1444,"children":1445},{},[1446,1451],{"type":20,"tag":33,"props":1447,"children":1448},{},[1449],{"type":26,"value":1450},"IMSI Catcher Detection",{"type":26,"value":1452},": Monitor paging channels for plaintext IMSI transmissions indicating active IMSI catchers.",{"type":20,"tag":47,"props":1454,"children":1455},{"id":100},[1456],{"type":26,"value":103},{"type":20,"tag":105,"props":1458,"children":1460},{"id":1459},"_1-live-gsm-monitoring-with-gui",[1461],{"type":26,"value":1462},"1. Live GSM Monitoring with GUI",{"type":20,"tag":112,"props":1464,"children":1467},{"className":1465,"code":1466,"language":117,"meta":8},[115],"# Launch interactive GSM monitor with frequency selector\ngrgsm_livemon -f 935.2e6\n",[1468],{"type":20,"tag":120,"props":1469,"children":1470},{"__ignoreMap":8},[1471],{"type":26,"value":1466},{"type":20,"tag":105,"props":1473,"children":1475},{"id":1474},"_2-headless-capture-to-wireshark",[1476],{"type":26,"value":1477},"2. Headless Capture to Wireshark",{"type":20,"tag":112,"props":1479,"children":1482},{"className":1480,"code":1481,"language":117,"meta":8},[115],"# Capture BCCH and pipe to Wireshark via GSMTAP\ngrgsm_livemon_headless -f 935.2e6 | wireshark -k -i lo -f \"udp port 4729\"\n",[1483],{"type":20,"tag":120,"props":1484,"children":1485},{"__ignoreMap":8},[1486],{"type":26,"value":1481},{"type":20,"tag":105,"props":1488,"children":1490},{"id":1489},"_3-scan-for-active-gsm-channels",[1491],{"type":26,"value":1492},"3. Scan for Active GSM Channels",{"type":20,"tag":112,"props":1494,"children":1497},{"className":1495,"code":1496,"language":117,"meta":8},[115],"# Scan and list all active GSM ARFCN channels in range\ngrgsm_scanner --band GSM900 --speed 2\n",[1498],{"type":20,"tag":120,"props":1499,"children":1500},{"__ignoreMap":8},[1501],{"type":26,"value":1496},{"type":20,"tag":47,"props":1503,"children":1504},{"id":156},[1505],{"type":26,"value":159},{"type":20,"tag":29,"props":1507,"children":1508},{},[1509,1510],{"type":26,"value":164},{"type":20,"tag":33,"props":1511,"children":1512},{},[1513],{"type":20,"tag":169,"props":1514,"children":1516},{"href":15,"rel":1515},[172],[1517],{"type":26,"value":1518},"Launch GSM Sniffing Lab on App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":1520},[1521,1522,1527],{"id":49,"depth":177,"text":52},{"id":100,"depth":177,"text":103,"children":1523},[1524,1525,1526],{"id":1459,"depth":183,"text":1462},{"id":1474,"depth":183,"text":1477},{"id":1489,"depth":183,"text":1492},{"id":156,"depth":177,"text":159},"content:tools:gr-gsm.md","tools\u002Fgr-gsm.md","tools\u002Fgr-gsm",{"_path":1532,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":1533,"description":1534,"name":1533,"protocol":1535,"category":1245,"hardware":1536,"command":1537,"academyLab":15,"body":1538,"_type":187,"_id":1657,"_source":189,"_file":1658,"_stem":1659,"_extension":192},"\u002Ftools\u002Finspectrum","Inspectrum","Fast, interactive tool for analyzing captured Software-Defined Radio IQ files, symbol extraction, and digital transmission reverse-engineering.","RF \u002F DSP \u002F IQ","HackRF \u002F BladeRF \u002F LimeSDR \u002F USRP \u002F RTL-SDR","inspectrum capture.sigmf-data",{"type":17,"children":1539,"toc":1649},[1540,1546,1561,1565,1598,1602,1608,1617,1623,1632,1636],{"type":20,"tag":21,"props":1541,"children":1543},{"id":1542},"inspectrum-radio-signal-iq-analysis-symbol-extraction",[1544],{"type":26,"value":1545},"Inspectrum — Radio Signal IQ Analysis & Symbol Extraction",{"type":20,"tag":29,"props":1547,"children":1548},{},[1549,1553,1555,1559],{"type":20,"tag":33,"props":1550,"children":1551},{},[1552],{"type":26,"value":1533},{"type":26,"value":1554}," is a specialized visualization tool for analyzing captured radio frequency signals recorded by software-defined radio hardware. Within ",{"type":20,"tag":33,"props":1556,"children":1557},{},[1558],{"type":26,"value":43},{"type":26,"value":1560},", Inspectrum supports SigMF (Signal Metadata Format), raw complex float\u002Fint files, and includes symbol alignment rulers for extracting raw digital bitstreams from wireless transmissions.",{"type":20,"tag":47,"props":1562,"children":1563},{"id":1274},[1564],{"type":26,"value":1277},{"type":20,"tag":54,"props":1566,"children":1567},{},[1568,1578,1588],{"type":20,"tag":58,"props":1569,"children":1570},{},[1571,1576],{"type":20,"tag":33,"props":1572,"children":1573},{},[1574],{"type":26,"value":1575},"High-Speed Spectrogram Navigation",{"type":26,"value":1577},": Smooth zooming and panning through gigabyte-sized IQ recordings.",{"type":20,"tag":58,"props":1579,"children":1580},{},[1581,1586],{"type":20,"tag":33,"props":1582,"children":1583},{},[1584],{"type":26,"value":1585},"Symbol Synchronization & Grid Overlays",{"type":26,"value":1587},": Align symbol clock cursors to visually recover baud rate and digital modulation parameters.",{"type":20,"tag":58,"props":1589,"children":1590},{},[1591,1596],{"type":20,"tag":33,"props":1592,"children":1593},{},[1594],{"type":26,"value":1595},"Amplitude, Frequency & Phase Plots",{"type":26,"value":1597},": Derive FSK, PSK, and ASK digital demodulations visually and export recovered symbols directly to files.",{"type":20,"tag":47,"props":1599,"children":1600},{"id":1313},[1601],{"type":26,"value":1316},{"type":20,"tag":105,"props":1603,"children":1605},{"id":1604},"_1-open-sigmf-recording",[1606],{"type":26,"value":1607},"1. Open SigMF Recording",{"type":20,"tag":112,"props":1609,"children":1612},{"className":1610,"code":1611,"language":117,"meta":8},[115],"# Open raw IQ capture file in inspectrum\ninspectrum \u002Fvar\u002Fcaptures\u002Fcellular_downlink.sigmf-data\n",[1613],{"type":20,"tag":120,"props":1614,"children":1615},{"__ignoreMap":8},[1616],{"type":26,"value":1611},{"type":20,"tag":105,"props":1618,"children":1620},{"id":1619},"_2-export-extracted-symbols-to-bitstream",[1621],{"type":26,"value":1622},"2. Export Extracted Symbols to Bitstream",{"type":20,"tag":112,"props":1624,"children":1627},{"className":1625,"code":1626,"language":117,"meta":8},[115],"# Add Amplitude Plot -> Add Derived Threshold -> Export Symbols to text file\n",[1628],{"type":20,"tag":120,"props":1629,"children":1630},{"__ignoreMap":8},[1631],{"type":26,"value":1626},{"type":20,"tag":47,"props":1633,"children":1634},{"id":156},[1635],{"type":26,"value":159},{"type":20,"tag":29,"props":1637,"children":1638},{},[1639,1640],{"type":26,"value":164},{"type":20,"tag":33,"props":1641,"children":1642},{},[1643],{"type":20,"tag":169,"props":1644,"children":1646},{"href":15,"rel":1645},[172],[1647],{"type":26,"value":1648},"Access Radio Signal Reverse Engineering Labs at App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":1650},[1651,1652,1656],{"id":1274,"depth":177,"text":1277},{"id":1313,"depth":177,"text":1316,"children":1653},[1654,1655],{"id":1604,"depth":183,"text":1607},{"id":1619,"depth":183,"text":1622},{"id":156,"depth":177,"text":159},"content:tools:inspectrum.md","tools\u002Finspectrum.md","tools\u002Finspectrum",{"_path":1661,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":1662,"description":1663,"name":1662,"protocol":1379,"category":1664,"hardware":1665,"command":1666,"academyLab":15,"body":1667,"_type":187,"_id":1812,"_source":189,"_file":1813,"_stem":1814,"_extension":192},"\u002Ftools\u002Fkalibrate-rtl","Kalibrate-RTL","GSM base station frequency scanner using RTL-SDR to identify ARFCNs, measure clock offsets, and calibrate SDR hardware oscillators against carrier signals.","Frequency Scanner","RTL-SDR \u002F HackRF","kal -s GSM900",{"type":17,"children":1668,"toc":1803},[1669,1675,1690,1694,1737,1741,1747,1756,1762,1771,1777,1786,1790],{"type":20,"tag":21,"props":1670,"children":1672},{"id":1671},"kalibrate-rtl-gsm-frequency-scanner-clock-calibrator",[1673],{"type":26,"value":1674},"Kalibrate-RTL — GSM Frequency Scanner & Clock Calibrator",{"type":20,"tag":29,"props":1676,"children":1677},{},[1678,1682,1684,1688],{"type":20,"tag":33,"props":1679,"children":1680},{},[1681],{"type":26,"value":1662},{"type":26,"value":1683}," (kal) is a GSM base station frequency scanner that leverages the known timing structure of GSM FCCH and SCH bursts to precisely calibrate SDR hardware oscillators. Within ",{"type":20,"tag":33,"props":1685,"children":1686},{},[1687],{"type":26,"value":43},{"type":26,"value":1689},", it serves dual purposes: scanning for active GSM base stations for reconnaissance, and calibrating RTL-SDR frequency offsets for accurate reception in downstream tools like Gr-GSM and Kraken.",{"type":20,"tag":47,"props":1691,"children":1692},{"id":49},[1693],{"type":26,"value":52},{"type":20,"tag":54,"props":1695,"children":1696},{},[1697,1707,1717,1727],{"type":20,"tag":58,"props":1698,"children":1699},{},[1700,1705],{"type":20,"tag":33,"props":1701,"children":1702},{},[1703],{"type":26,"value":1704},"Broadband GSM Cell Scanning",{"type":26,"value":1706},": Rapidly enumerate all active GSM ARFCN channels across GSM-850, GSM-900, DCS-1800, and PCS-1900 bands.",{"type":20,"tag":58,"props":1708,"children":1709},{},[1710,1715],{"type":20,"tag":33,"props":1711,"children":1712},{},[1713],{"type":26,"value":1714},"SDR Clock Calibration",{"type":26,"value":1716},": Calculate precise frequency offset (PPM) of RTL-SDR and HackRF dongles using GSM carrier signals as references.",{"type":20,"tag":58,"props":1718,"children":1719},{},[1720,1725],{"type":20,"tag":33,"props":1721,"children":1722},{},[1723],{"type":26,"value":1724},"Signal Strength Mapping",{"type":26,"value":1726},": Measure received signal power across ARFCNs for RF site survey and coverage analysis.",{"type":20,"tag":58,"props":1728,"children":1729},{},[1730,1735],{"type":20,"tag":33,"props":1731,"children":1732},{},[1733],{"type":26,"value":1734},"Rogue BTS Pre-Reconnaissance",{"type":26,"value":1736},": Identify unexpected GSM cells that may indicate IMSI catchers or unauthorized base stations.",{"type":20,"tag":47,"props":1738,"children":1739},{"id":100},[1740],{"type":26,"value":103},{"type":20,"tag":105,"props":1742,"children":1744},{"id":1743},"_1-scan-gsm-900-band",[1745],{"type":26,"value":1746},"1. Scan GSM-900 Band",{"type":20,"tag":112,"props":1748,"children":1751},{"className":1749,"code":1750,"language":117,"meta":8},[115],"# Scan and list all GSM-900 base stations with power levels\nkal -s GSM900 -g 40\n",[1752],{"type":20,"tag":120,"props":1753,"children":1754},{"__ignoreMap":8},[1755],{"type":26,"value":1750},{"type":20,"tag":105,"props":1757,"children":1759},{"id":1758},"_2-scan-dcs-1800-band",[1760],{"type":26,"value":1761},"2. Scan DCS-1800 Band",{"type":20,"tag":112,"props":1763,"children":1766},{"className":1764,"code":1765,"language":117,"meta":8},[115],"# European DCS-1800 cell scan\nkal -s DCS1800 -g 40\n",[1767],{"type":20,"tag":120,"props":1768,"children":1769},{"__ignoreMap":8},[1770],{"type":26,"value":1765},{"type":20,"tag":105,"props":1772,"children":1774},{"id":1773},"_3-calibrate-rtl-sdr-ppm-offset",[1775],{"type":26,"value":1776},"3. Calibrate RTL-SDR PPM Offset",{"type":20,"tag":112,"props":1778,"children":1781},{"className":1779,"code":1780,"language":117,"meta":8},[115],"# Lock to a strong GSM cell and calculate PPM correction\nkal -c 55 -g 40 -e 0\n# Use the output PPM value with other SDR tools: grgsm_livemon -p \u003Cppm>\n",[1782],{"type":20,"tag":120,"props":1783,"children":1784},{"__ignoreMap":8},[1785],{"type":26,"value":1780},{"type":20,"tag":47,"props":1787,"children":1788},{"id":156},[1789],{"type":26,"value":159},{"type":20,"tag":29,"props":1791,"children":1792},{},[1793,1794],{"type":26,"value":164},{"type":20,"tag":33,"props":1795,"children":1796},{},[1797],{"type":20,"tag":169,"props":1798,"children":1800},{"href":15,"rel":1799},[172],[1801],{"type":26,"value":1802},"Launch GSM Reconnaissance Lab on App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":1804},[1805,1806,1811],{"id":49,"depth":177,"text":52},{"id":100,"depth":177,"text":103,"children":1807},[1808,1809,1810],{"id":1743,"depth":183,"text":1746},{"id":1758,"depth":183,"text":1761},{"id":1773,"depth":183,"text":1776},{"id":156,"depth":177,"text":159},"content:tools:kalibrate-rtl.md","tools\u002Fkalibrate-rtl.md","tools\u002Fkalibrate-rtl",{"_path":1816,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":1817,"description":1818,"name":1817,"protocol":1819,"category":1820,"hardware":1821,"command":1822,"academyLab":15,"body":1823,"_type":187,"_id":1944,"_source":189,"_file":1945,"_stem":1946,"_extension":192},"\u002Ftools\u002Fkamailio","Kamailio","Open source SIP Server and IMS Security Gateway capable of handling thousands of call setups per second, used as P-CSCF\u002FI-CSCF testbed.","SIP \u002F IMS \u002F VoLTE \u002F VoNR","IMS & VoLTE Security","IP Network Interface","kamailio -f \u002Fetc\u002Fkamailio\u002Fkamailio.cfg",{"type":17,"children":1824,"toc":1936},[1825,1831,1846,1852,1885,1889,1895,1904,1910,1919,1923],{"type":20,"tag":21,"props":1826,"children":1828},{"id":1827},"kamailio-open-source-sip-server-ims-security-proxy",[1829],{"type":26,"value":1830},"Kamailio — Open Source SIP Server & IMS Security Proxy",{"type":20,"tag":29,"props":1832,"children":1833},{},[1834,1838,1840,1844],{"type":20,"tag":33,"props":1835,"children":1836},{},[1837],{"type":26,"value":1817},{"type":26,"value":1839}," is an enterprise-grade SIP server used widely across telecom carriers as a SIP proxy, registrar, location server, and IMS Core P-CSCF\u002FI-CSCF\u002FS-CSCF. In ",{"type":20,"tag":33,"props":1841,"children":1842},{},[1843],{"type":26,"value":43},{"type":26,"value":1845},", Kamailio is pre-configured to inspect, filter, rewrite, and secure VoLTE and VoNR call signaling.",{"type":20,"tag":47,"props":1847,"children":1849},{"id":1848},"key-telecom-security-capabilities",[1850],{"type":26,"value":1851},"Key Telecom Security Capabilities",{"type":20,"tag":54,"props":1853,"children":1854},{},[1855,1865,1875],{"type":20,"tag":58,"props":1856,"children":1857},{},[1858,1863],{"type":20,"tag":33,"props":1859,"children":1860},{},[1861],{"type":26,"value":1862},"IMS P-CSCF Security Layer",{"type":26,"value":1864},": Test IPSec association establishment between VoLTE handsets and the carrier core.",{"type":20,"tag":58,"props":1866,"children":1867},{},[1868,1873],{"type":20,"tag":33,"props":1869,"children":1870},{},[1871],{"type":26,"value":1872},"SIP Firewall & Rate Limiting (Pike Module)",{"type":26,"value":1874},": Simulate and evaluate automated mitigation of SIP flooding and brute-force registration attempts.",{"type":20,"tag":58,"props":1876,"children":1877},{},[1878,1883],{"type":20,"tag":33,"props":1879,"children":1880},{},[1881],{"type":26,"value":1882},"TLS & SRTP Inspection",{"type":26,"value":1884},": Set up man-in-the-middle decryption proxy pipelines to analyze encrypted carrier voice sessions.",{"type":20,"tag":47,"props":1886,"children":1887},{"id":1313},[1888],{"type":26,"value":1316},{"type":20,"tag":105,"props":1890,"children":1892},{"id":1891},"_1-launch-kamailio-ims-proxy",[1893],{"type":26,"value":1894},"1. Launch Kamailio IMS Proxy",{"type":20,"tag":112,"props":1896,"children":1899},{"className":1897,"code":1898,"language":117,"meta":8},[115],"# Start Kamailio with telecom IMS profile\nsudo kamailio -f \u002Fetc\u002Fkamailio\u002Fkamailio-ims.cfg -DD -E\n",[1900],{"type":20,"tag":120,"props":1901,"children":1902},{"__ignoreMap":8},[1903],{"type":26,"value":1898},{"type":20,"tag":105,"props":1905,"children":1907},{"id":1906},"_2-monitor-live-sip-routing-registrations",[1908],{"type":26,"value":1909},"2. Monitor Live SIP Routing & Registrations",{"type":20,"tag":112,"props":1911,"children":1914},{"className":1912,"code":1913,"language":117,"meta":8},[115],"# Query active registered VoLTE endpoints\nkamctl ul show\n",[1915],{"type":20,"tag":120,"props":1916,"children":1917},{"__ignoreMap":8},[1918],{"type":26,"value":1913},{"type":20,"tag":47,"props":1920,"children":1921},{"id":156},[1922],{"type":26,"value":159},{"type":20,"tag":29,"props":1924,"children":1925},{},[1926,1927],{"type":26,"value":164},{"type":20,"tag":33,"props":1928,"children":1929},{},[1930],{"type":20,"tag":169,"props":1931,"children":1933},{"href":15,"rel":1932},[172],[1934],{"type":26,"value":1935},"Access VoLTE & IMS Security Labs at App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":1937},[1938,1939,1943],{"id":1848,"depth":177,"text":1851},{"id":1313,"depth":177,"text":1316,"children":1940},[1941,1942],{"id":1891,"depth":183,"text":1894},{"id":1906,"depth":183,"text":1909},{"id":156,"depth":177,"text":159},"content:tools:kamailio.md","tools\u002Fkamailio.md","tools\u002Fkamailio",{"_path":1948,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":1949,"description":1950,"name":1949,"protocol":1951,"category":1245,"hardware":1952,"command":1953,"academyLab":15,"body":1954,"_type":187,"_id":2073,"_source":189,"_file":2074,"_stem":2075,"_extension":192},"\u002Ftools\u002Fkraken","Kraken","Fast GSM A5\u002F1 encryption cracking tool utilizing rainbow tables to reverse-engineer 2G cellular bursts in sub-second timeframes.","GSM 2G \u002F A5\u002F1","HackRF One \u002F RTL-SDR \u002F USRP + SSD Storage","kraken \u002Fopt\u002Fkraken\u002Ftables\u002F",{"type":17,"children":1955,"toc":2065},[1956,1962,1977,1981,2014,2018,2024,2033,2039,2048,2052],{"type":20,"tag":21,"props":1957,"children":1959},{"id":1958},"kraken-gsm-a51-real-time-cipher-cracker",[1960],{"type":26,"value":1961},"Kraken — GSM A5\u002F1 Real-Time Cipher Cracker",{"type":20,"tag":29,"props":1963,"children":1964},{},[1965,1969,1971,1975],{"type":20,"tag":33,"props":1966,"children":1967},{},[1968],{"type":26,"value":1949},{"type":26,"value":1970}," is the famous open-source tool for finding 64-bit GSM A5\u002F1 session encryption keys (Kc) in real time using pre-computed Berlin Rainbow Tables. Within ",{"type":20,"tag":33,"props":1972,"children":1973},{},[1974],{"type":26,"value":43},{"type":26,"value":1976},", Kraken is integrated alongside OsmocomBB and gr-gsm for analyzing 2G radio burst captures.",{"type":20,"tag":47,"props":1978,"children":1979},{"id":1848},[1980],{"type":26,"value":1851},{"type":20,"tag":54,"props":1982,"children":1983},{},[1984,1994,2004],{"type":20,"tag":58,"props":1985,"children":1986},{},[1987,1992],{"type":20,"tag":33,"props":1988,"children":1989},{},[1990],{"type":26,"value":1991},"A5\u002F1 Keystream Cracking",{"type":26,"value":1993},": Reverse 114-bit keystreams extracted from encrypted GSM CCH (Control Channel) and TCH (Traffic Channel) bursts.",{"type":20,"tag":58,"props":1995,"children":1996},{},[1997,2002],{"type":20,"tag":33,"props":1998,"children":1999},{},[2000],{"type":26,"value":2001},"Interception Pipeline Integration",{"type":26,"value":2003},": Feeds decrypted session keys directly into Wireshark \u002F gr-gsm for real-time voice and SMS decoding.",{"type":20,"tag":58,"props":2005,"children":2006},{},[2007,2012],{"type":20,"tag":33,"props":2008,"children":2009},{},[2010],{"type":26,"value":2011},"Carrier Downward Compatibility Audits",{"type":26,"value":2013},": Demonstrate why 2G legacy fallbacks remain critical attack surfaces on modern multi-mode smartphones.",{"type":20,"tag":47,"props":2015,"children":2016},{"id":1313},[2017],{"type":26,"value":1316},{"type":20,"tag":105,"props":2019,"children":2021},{"id":2020},"_1-launch-kraken-with-rainbow-tables",[2022],{"type":26,"value":2023},"1. Launch Kraken with Rainbow Tables",{"type":20,"tag":112,"props":2025,"children":2028},{"className":2026,"code":2027,"language":117,"meta":8},[115],"# Point Kraken to SSD-mounted A5\u002F1 rainbow tables\ncd \u002Fopt\u002Fkraken && sudo .\u002Fkraken \u002Fmedia\u002Ffast_ssd\u002Fkraken_tables\u002F\n",[2029],{"type":20,"tag":120,"props":2030,"children":2031},{"__ignoreMap":8},[2032],{"type":26,"value":2027},{"type":20,"tag":105,"props":2034,"children":2036},{"id":2035},"_2-crack-keystream-sample",[2037],{"type":26,"value":2038},"2. Crack Keystream Sample",{"type":20,"tag":112,"props":2040,"children":2043},{"className":2041,"code":2042,"language":117,"meta":8},[115],"# Query Kraken with 114-bit keystream from gr-gsm\n.\u002Ffind_kc 00101011100100100010101010010010110001001010100100101100010010101001001011000100101010010010110001001010100100101100\n",[2044],{"type":20,"tag":120,"props":2045,"children":2046},{"__ignoreMap":8},[2047],{"type":26,"value":2042},{"type":20,"tag":47,"props":2049,"children":2050},{"id":156},[2051],{"type":26,"value":159},{"type":20,"tag":29,"props":2053,"children":2054},{},[2055,2056],{"type":26,"value":164},{"type":20,"tag":33,"props":2057,"children":2058},{},[2059],{"type":20,"tag":169,"props":2060,"children":2062},{"href":15,"rel":2061},[172],[2063],{"type":26,"value":2064},"Access GSM & 2G Interception Labs at App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":2066},[2067,2068,2072],{"id":1848,"depth":177,"text":1851},{"id":1313,"depth":177,"text":1316,"children":2069},[2070,2071],{"id":2020,"depth":183,"text":2023},{"id":2035,"depth":183,"text":2038},{"id":156,"depth":177,"text":159},"content:tools:kraken.md","tools\u002Fkraken.md","tools\u002Fkraken",{"_path":2077,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":2078,"description":2079,"name":2078,"protocol":2080,"category":2081,"hardware":1381,"command":2082,"academyLab":15,"body":2083,"_type":187,"_id":2227,"_source":189,"_file":2228,"_stem":2229,"_extension":192},"\u002Ftools\u002Flte-cell-scanner","LTE-Cell-Scanner","Passive LTE cell discovery and MIB\u002FSIB decoder using RTL-SDR or USRP to enumerate nearby eNodeBs, tracking areas, and operator configurations.","4G LTE","Passive Cell Discovery","CellSearch --freq-start 700e6 --freq-end 2700e6",{"type":17,"children":2084,"toc":2218},[2085,2091,2106,2110,2152,2156,2162,2171,2177,2186,2192,2201,2205],{"type":20,"tag":21,"props":2086,"children":2088},{"id":2087},"lte-cell-scanner-passive-lte-cell-enumeration",[2089],{"type":26,"value":2090},"LTE-Cell-Scanner — Passive LTE Cell Enumeration",{"type":20,"tag":29,"props":2092,"children":2093},{},[2094,2098,2100,2104],{"type":20,"tag":33,"props":2095,"children":2096},{},[2097],{"type":26,"value":2078},{"type":26,"value":2099}," is a passive reconnaissance tool that scans for LTE eNodeB cells across configurable frequency ranges. Within ",{"type":20,"tag":33,"props":2101,"children":2102},{},[2103],{"type":26,"value":43},{"type":26,"value":2105},", it is pre-compiled with RTL-SDR, HackRF, and UHD driver support, enabling broadband LTE cell discovery, Physical Cell ID (PCI) enumeration, and MIB\u002FSIB system information decoding for site survey and IMSI catcher detection.",{"type":20,"tag":47,"props":2107,"children":2108},{"id":49},[2109],{"type":26,"value":52},{"type":20,"tag":54,"props":2111,"children":2112},{},[2113,2123,2133,2143],{"type":20,"tag":58,"props":2114,"children":2115},{},[2116,2121],{"type":20,"tag":33,"props":2117,"children":2118},{},[2119],{"type":26,"value":2120},"Broadband eNodeB Discovery",{"type":26,"value":2122},": Scan entire LTE frequency allocations (700 MHz–2700 MHz) to map all active cells in range.",{"type":20,"tag":58,"props":2124,"children":2125},{},[2126,2131],{"type":20,"tag":33,"props":2127,"children":2128},{},[2129],{"type":26,"value":2130},"PCI & TAC Enumeration",{"type":26,"value":2132},": Extract Physical Cell IDs, Tracking Area Codes, and PLMN identifiers to fingerprint operator infrastructure.",{"type":20,"tag":58,"props":2134,"children":2135},{},[2136,2141],{"type":20,"tag":33,"props":2137,"children":2138},{},[2139],{"type":26,"value":2140},"MIB\u002FSIB Decoding",{"type":26,"value":2142},": Decode Master and System Information Blocks to reveal cell bandwidth, SIB scheduling, PRACH configuration, and emergency alert capabilities.",{"type":20,"tag":58,"props":2144,"children":2145},{},[2146,2150],{"type":20,"tag":33,"props":2147,"children":2148},{},[2149],{"type":26,"value":1450},{"type":26,"value":2151},": Compare discovered cell parameters against known operator databases to identify rogue base stations and stingrays.",{"type":20,"tag":47,"props":2153,"children":2154},{"id":100},[2155],{"type":26,"value":103},{"type":20,"tag":105,"props":2157,"children":2159},{"id":2158},"_1-scan-all-lte-bands-with-rtl-sdr",[2160],{"type":26,"value":2161},"1. Scan All LTE Bands with RTL-SDR",{"type":20,"tag":112,"props":2163,"children":2166},{"className":2164,"code":2165,"language":117,"meta":8},[115],"# Wideband LTE cell search across common bands\nCellSearch --freq-start 700e6 --freq-end 2700e6 --device-type rtlsdr\n",[2167],{"type":20,"tag":120,"props":2168,"children":2169},{"__ignoreMap":8},[2170],{"type":26,"value":2165},{"type":20,"tag":105,"props":2172,"children":2174},{"id":2173},"_2-target-specific-band-band-7-2600-mhz",[2175],{"type":26,"value":2176},"2. Target Specific Band (Band 7 \u002F 2600 MHz)",{"type":20,"tag":112,"props":2178,"children":2181},{"className":2179,"code":2180,"language":117,"meta":8},[115],"# Focused scan on LTE Band 7 (2620-2690 MHz downlink)\nCellSearch --freq-start 2620e6 --freq-end 2690e6\n",[2182],{"type":20,"tag":120,"props":2183,"children":2184},{"__ignoreMap":8},[2185],{"type":26,"value":2180},{"type":20,"tag":105,"props":2187,"children":2189},{"id":2188},"_3-decode-system-information",[2190],{"type":26,"value":2191},"3. Decode System Information",{"type":20,"tag":112,"props":2193,"children":2196},{"className":2194,"code":2195,"language":117,"meta":8},[115],"# Lock to a discovered cell and decode SIBs\nCellSearch --freq-start 1805e6 --freq-end 1880e6 --num-sib-decode 10\n",[2197],{"type":20,"tag":120,"props":2198,"children":2199},{"__ignoreMap":8},[2200],{"type":26,"value":2195},{"type":20,"tag":47,"props":2202,"children":2203},{"id":156},[2204],{"type":26,"value":159},{"type":20,"tag":29,"props":2206,"children":2207},{},[2208,2209],{"type":26,"value":164},{"type":20,"tag":33,"props":2210,"children":2211},{},[2212],{"type":20,"tag":169,"props":2213,"children":2215},{"href":15,"rel":2214},[172],[2216],{"type":26,"value":2217},"Launch LTE Reconnaissance Lab on App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":2219},[2220,2221,2226],{"id":49,"depth":177,"text":52},{"id":100,"depth":177,"text":103,"children":2222},[2223,2224,2225],{"id":2158,"depth":183,"text":2161},{"id":2173,"depth":183,"text":2176},{"id":2188,"depth":183,"text":2191},{"id":156,"depth":177,"text":159},"content:tools:lte-cell-scanner.md","tools\u002Flte-cell-scanner.md","tools\u002Flte-cell-scanner",{"_path":2231,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":2232,"description":2233,"name":2232,"protocol":2234,"category":809,"hardware":810,"command":2235,"academyLab":15,"body":2236,"_type":187,"_id":2380,"_source":189,"_file":2381,"_stem":2382,"_extension":192},"\u002Ftools\u002Fopen5gs","Open5GS","Open-source implementation of 5G Standalone (SA) Core and 4G EPC network functions in C, supporting 3GPP Release 16\u002F17 SBA architecture.","5G NR \u002F 4G LTE","open5gs-amfd -c \u002Fetc\u002Fopen5gs\u002Famf.yaml",{"type":17,"children":2237,"toc":2371},[2238,2244,2255,2261,2304,2308,2314,2323,2329,2338,2344,2353,2357],{"type":20,"tag":21,"props":2239,"children":2241},{"id":2240},"open5gs-5g-sa-core-4g-epc-suite",[2242],{"type":26,"value":2243},"Open5GS — 5G SA Core & 4G EPC Suite",{"type":20,"tag":29,"props":2245,"children":2246},{},[2247,2249,2253],{"type":26,"value":2248},"Open5GS is an open-source implementation for 5G Core Network and 4G LTE Evolved Packet Core (EPC). Within ",{"type":20,"tag":33,"props":2250,"children":2251},{},[2252],{"type":26,"value":43},{"type":26,"value":2254},", Open5GS is pre-configured with real-time logging, loopback network interfaces, MongoDB database bindings, and integrated Wireshark dissectors for inspecting 5G Service-Based Architecture (SBA) HTTP\u002F2 JSON REST interfaces.",{"type":20,"tag":47,"props":2256,"children":2258},{"id":2257},"key-capabilities-attack-surface-testing",[2259],{"type":26,"value":2260},"Key Capabilities & Attack Surface Testing",{"type":20,"tag":54,"props":2262,"children":2263},{},[2264,2274,2284,2294],{"type":20,"tag":58,"props":2265,"children":2266},{},[2267,2272],{"type":20,"tag":33,"props":2268,"children":2269},{},[2270],{"type":26,"value":2271},"5G SBA (Service-Based Architecture) Verification",{"type":26,"value":2273},": Test HTTP\u002F2 SBI interfaces across AMF, SMF, NRF, NSSF, AUSF, UDM, and PCF.",{"type":20,"tag":58,"props":2275,"children":2276},{},[2277,2282],{"type":20,"tag":33,"props":2278,"children":2279},{},[2280],{"type":26,"value":2281},"SUPI \u002F SUCI De-concealment Audits",{"type":26,"value":2283},": Validate ECIES Profile A & Profile B key derivation implementations on UDM\u002FAUSF.",{"type":20,"tag":58,"props":2285,"children":2286},{},[2287,2292],{"type":20,"tag":33,"props":2288,"children":2289},{},[2290],{"type":26,"value":2291},"Rogue gNodeB Authentication",{"type":26,"value":2293},": Audit AMF vulnerability against unauthorized N2\u002FN3 connection attempts and SCTP malformed payloads.",{"type":20,"tag":58,"props":2295,"children":2296},{},[2297,2302],{"type":20,"tag":33,"props":2298,"children":2299},{},[2300],{"type":26,"value":2301},"GTP-U User Plane Penetration",{"type":26,"value":2303},": Test UPF TEID allocation, GTP encapsulation injection, and subscriber data leaks.",{"type":20,"tag":47,"props":2305,"children":2306},{"id":740},[2307],{"type":26,"value":743},{"type":20,"tag":105,"props":2309,"children":2311},{"id":2310},"_1-launch-all-5g-core-network-functions",[2312],{"type":26,"value":2313},"1. Launch All 5G Core Network Functions",{"type":20,"tag":112,"props":2315,"children":2318},{"className":2316,"code":2317,"language":117,"meta":8},[115],"# Start the entire 5G Standalone Core suite\nsudo systemctl start open5gs-nrfd open5gs-amfd open5gs-smfd open5gs-upfd open5gs-udmd open5gs-ausfd open5gs-nssfd open5gs-pcfd open5gs-bsfd open5gs-udrd\n",[2319],{"type":20,"tag":120,"props":2320,"children":2321},{"__ignoreMap":8},[2322],{"type":26,"value":2317},{"type":20,"tag":105,"props":2324,"children":2326},{"id":2325},"_2-live-sba-packet-capture-http2-sbi",[2327],{"type":26,"value":2328},"2. Live SBA Packet Capture (HTTP\u002F2 \u002F SBI)",{"type":20,"tag":112,"props":2330,"children":2333},{"className":2331,"code":2332,"language":117,"meta":8},[115],"# Capture all internal 5G Service-Based Architecture signaling on loopback\nsudo tshark -i lo -f \"tcp port 7777 or tcp port 8000\" -Y \"http2\" -T fields -e ip.src -e ip.dst -e http2.header.value\n",[2334],{"type":20,"tag":120,"props":2335,"children":2336},{"__ignoreMap":8},[2337],{"type":26,"value":2332},{"type":20,"tag":105,"props":2339,"children":2341},{"id":2340},"_3-subscriber-database-provisioning",[2342],{"type":26,"value":2343},"3. Subscriber Database Provisioning",{"type":20,"tag":112,"props":2345,"children":2348},{"className":2346,"code":2347,"language":117,"meta":8},[115],"# Access the web administration portal (pre-installed on port 3000)\nopen-browser http:\u002F\u002F127.0.0.1:3000\n# Default Credentials: admin \u002F 1423\n",[2349],{"type":20,"tag":120,"props":2350,"children":2351},{"__ignoreMap":8},[2352],{"type":26,"value":2347},{"type":20,"tag":47,"props":2354,"children":2355},{"id":776},[2356],{"type":26,"value":779},{"type":20,"tag":29,"props":2358,"children":2359},{},[2360,2362],{"type":26,"value":2361},"To practice compromising, intercepting, and hardening 5G Core network functions in isolated cloud virtual machines with real simulated UEs and gNodeBs:\n👉 ",{"type":20,"tag":33,"props":2363,"children":2364},{},[2365],{"type":20,"tag":169,"props":2366,"children":2368},{"href":15,"rel":2367},[172],[2369],{"type":26,"value":2370},"Access the 5G Core Red Team Lab at App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":2372},[2373,2374,2379],{"id":2257,"depth":177,"text":2260},{"id":740,"depth":177,"text":743,"children":2375},[2376,2377,2378],{"id":2310,"depth":183,"text":2313},{"id":2325,"depth":183,"text":2328},{"id":2340,"depth":183,"text":2343},{"id":776,"depth":177,"text":779},"content:tools:open5gs.md","tools\u002Fopen5gs.md","tools\u002Fopen5gs",{"_path":2384,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":2385,"description":2386,"name":2387,"protocol":2234,"category":2388,"hardware":2389,"command":2390,"academyLab":15,"body":2391,"_type":187,"_id":2536,"_source":189,"_file":2537,"_stem":2538,"_extension":192},"\u002Ftools\u002Fopenairinterface","OpenAirInterface","Full 3GPP-compliant 5G NR and 4G LTE software radio stack implementing gNodeB, eNodeB, nrUE, and core network functions for RF security research.","OpenAirInterface (OAI)","SDR Base Station & Core","USRP B210 \u002F X310 \u002F BladeRF","sudo .\u002Fnr-softmodem -O \u002Fopt\u002Foai\u002Ftargets\u002FPROJECTS\u002FGENERIC-NR-LTE\u002FCONF\u002Fgnb.sa.band78.conf",{"type":17,"children":2392,"toc":2527},[2393,2399,2414,2418,2461,2465,2471,2480,2486,2495,2501,2510,2514],{"type":20,"tag":21,"props":2394,"children":2396},{"id":2395},"openairinterface-5glte-software-radio-security-stack",[2397],{"type":26,"value":2398},"OpenAirInterface — 5G\u002FLTE Software Radio Security Stack",{"type":20,"tag":29,"props":2400,"children":2401},{},[2402,2406,2408,2412],{"type":20,"tag":33,"props":2403,"children":2404},{},[2405],{"type":26,"value":2387},{"type":26,"value":2407}," is a 3GPP-compliant open-source software radio platform implementing the full 5G NR and 4G LTE protocol stack. Within ",{"type":20,"tag":33,"props":2409,"children":2410},{},[2411],{"type":26,"value":43},{"type":26,"value":2413},", OAI provides real over-the-air gNodeB\u002FeNodeB transmission capability for testing rogue base station scenarios, RRC protocol fuzzing, and NAS authentication bypass attacks using SDR hardware.",{"type":20,"tag":47,"props":2415,"children":2416},{"id":49},[2417],{"type":26,"value":52},{"type":20,"tag":54,"props":2419,"children":2420},{},[2421,2431,2441,2451],{"type":20,"tag":58,"props":2422,"children":2423},{},[2424,2429],{"type":20,"tag":33,"props":2425,"children":2426},{},[2427],{"type":26,"value":2428},"Rogue gNodeB \u002F eNodeB Deployment",{"type":26,"value":2430},": Stand up unauthorized base stations on target frequency bands to test UE camping and redirection attacks.",{"type":20,"tag":58,"props":2432,"children":2433},{},[2434,2439],{"type":20,"tag":33,"props":2435,"children":2436},{},[2437],{"type":26,"value":2438},"RRC Protocol Fuzzing",{"type":26,"value":2440},": Inject malformed RRC Setup, Reconfiguration, and Security Mode Command messages to crash or exploit UE stacks.",{"type":20,"tag":58,"props":2442,"children":2443},{},[2444,2449],{"type":20,"tag":33,"props":2445,"children":2446},{},[2447],{"type":26,"value":2448},"NAS Authentication Testing",{"type":26,"value":2450},": Test AKA (Authentication and Key Agreement) implementation flaws including SUPI\u002FIMSI exposure via null cipher attacks.",{"type":20,"tag":58,"props":2452,"children":2453},{},[2454,2459],{"type":20,"tag":33,"props":2455,"children":2456},{},[2457],{"type":26,"value":2458},"Downlink NAS Replay",{"type":26,"value":2460},": Capture and replay NAS signaling to test anti-replay counter implementations in commercial UEs.",{"type":20,"tag":47,"props":2462,"children":2463},{"id":100},[2464],{"type":26,"value":103},{"type":20,"tag":105,"props":2466,"children":2468},{"id":2467},"_1-launch-5g-sa-gnodeb",[2469],{"type":26,"value":2470},"1. Launch 5G SA gNodeB",{"type":20,"tag":112,"props":2472,"children":2475},{"className":2473,"code":2474,"language":117,"meta":8},[115],"# Start 5G NR Standalone gNodeB with USRP B210\ncd \u002Fopt\u002Foai\u002Fcmake_targets\u002Fran_build\u002Fbuild\nsudo .\u002Fnr-softmodem -O \u002Fopt\u002Foai\u002Ftargets\u002FPROJECTS\u002FGENERIC-NR-LTE\u002FCONF\u002Fgnb.sa.band78.conf --sa\n",[2476],{"type":20,"tag":120,"props":2477,"children":2478},{"__ignoreMap":8},[2479],{"type":26,"value":2474},{"type":20,"tag":105,"props":2481,"children":2483},{"id":2482},"_2-launch-5g-nr-ue-emulator",[2484],{"type":26,"value":2485},"2. Launch 5G NR UE Emulator",{"type":20,"tag":112,"props":2487,"children":2490},{"className":2488,"code":2489,"language":117,"meta":8},[115],"# Start NR UE softmodem for controlled testing\nsudo .\u002Fnr-uesoftmodem -O \u002Fopt\u002Foai\u002Ftargets\u002FPROJECTS\u002FGENERIC-NR-LTE\u002FCONF\u002Fue.conf --sa --nokrnmod\n",[2491],{"type":20,"tag":120,"props":2492,"children":2493},{"__ignoreMap":8},[2494],{"type":26,"value":2489},{"type":20,"tag":105,"props":2496,"children":2498},{"id":2497},"_3-capture-over-the-air-nr-signaling",[2499],{"type":26,"value":2500},"3. Capture Over-the-Air NR Signaling",{"type":20,"tag":112,"props":2502,"children":2505},{"className":2503,"code":2504,"language":117,"meta":8},[115],"# Live capture NR-ARFCN signaling via T tracer\nsudo tshark -i oaitun_ue1 -Y \"ngap || nas-5gs\" -T fields -e frame.time -e nas_5gs.mm.message_type\n",[2506],{"type":20,"tag":120,"props":2507,"children":2508},{"__ignoreMap":8},[2509],{"type":26,"value":2504},{"type":20,"tag":47,"props":2511,"children":2512},{"id":156},[2513],{"type":26,"value":159},{"type":20,"tag":29,"props":2515,"children":2516},{},[2517,2518],{"type":26,"value":164},{"type":20,"tag":33,"props":2519,"children":2520},{},[2521],{"type":20,"tag":169,"props":2522,"children":2524},{"href":15,"rel":2523},[172],[2525],{"type":26,"value":2526},"Launch RF Base Station Lab on App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":2528},[2529,2530,2535],{"id":49,"depth":177,"text":52},{"id":100,"depth":177,"text":103,"children":2531},[2532,2533,2534],{"id":2467,"depth":183,"text":2470},{"id":2482,"depth":183,"text":2485},{"id":2497,"depth":183,"text":2500},{"id":156,"depth":177,"text":159},"content:tools:openairinterface.md","tools\u002Fopenairinterface.md","tools\u002Fopenairinterface",{"_path":2540,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":2541,"description":2542,"name":2541,"protocol":2543,"category":2544,"hardware":2545,"command":2546,"academyLab":15,"body":2547,"_type":187,"_id":2695,"_source":189,"_file":2696,"_stem":2697,"_extension":192},"\u002Ftools\u002Fosmocom-suite","Osmocom Suite","Complete open-source 2G\u002F3G cellular infrastructure stack including BTS, BSC, MSC, HLR, SGSN, and STP for GSM network security auditing and IMSI catcher research.","2G GSM \u002F 3G UMTS","GSM Infrastructure","USRP B210 \u002F LimeSDR \u002F Osmocom SIMtrace 2","osmo-nitb -c \u002Fetc\u002Fosmocom\u002Fopenbsc.cfg",{"type":17,"children":2548,"toc":2686},[2549,2555,2573,2577,2620,2624,2630,2639,2645,2654,2660,2669,2673],{"type":20,"tag":21,"props":2550,"children":2552},{"id":2551},"osmocom-suite-gsmumts-infrastructure-security-stack",[2553],{"type":26,"value":2554},"Osmocom Suite — GSM\u002FUMTS Infrastructure Security Stack",{"type":20,"tag":29,"props":2556,"children":2557},{},[2558,2560,2565,2567,2571],{"type":26,"value":2559},"The ",{"type":20,"tag":33,"props":2561,"children":2562},{},[2563],{"type":26,"value":2564},"Osmocom",{"type":26,"value":2566}," (Open Source Mobile Communications) project provides a complete, production-grade implementation of 2G GSM and 3G UMTS cellular network infrastructure. Within ",{"type":20,"tag":33,"props":2568,"children":2569},{},[2570],{"type":26,"value":43},{"type":26,"value":2572},", the full Osmocom suite (OsmoBTS, OsmoBSC, OsmoMSC, OsmoHLR, OsmoSGSN, OsmoSTP) is pre-installed and configured for security research including rogue BTS deployment, A5\u002F1 cipher downgrade testing, and SS7\u002FSIGTRAN stack auditing.",{"type":20,"tag":47,"props":2574,"children":2575},{"id":49},[2576],{"type":26,"value":52},{"type":20,"tag":54,"props":2578,"children":2579},{},[2580,2590,2600,2610],{"type":20,"tag":58,"props":2581,"children":2582},{},[2583,2588],{"type":20,"tag":33,"props":2584,"children":2585},{},[2586],{"type":26,"value":2587},"Rogue BTS Deployment",{"type":26,"value":2589},": Deploy a complete 2G base station using OsmoBTS + OsmoTRX to test UE camping, IMSI collection, and voice interception.",{"type":20,"tag":58,"props":2591,"children":2592},{},[2593,2598],{"type":20,"tag":33,"props":2594,"children":2595},{},[2596],{"type":26,"value":2597},"A5 Cipher Downgrade Attacks",{"type":26,"value":2599},": Force cipher mode negotiation to A5\u002F0 (no encryption) or A5\u002F1 (known-broken) to intercept GSM voice and SMS traffic.",{"type":20,"tag":58,"props":2601,"children":2602},{},[2603,2608],{"type":20,"tag":33,"props":2604,"children":2605},{},[2606],{"type":26,"value":2607},"HLR\u002FVLR Subscriber Manipulation",{"type":26,"value":2609},": Inject, modify, and delete subscriber records in OsmoHLR to test authentication triplet handling and subscriber identity spoofing.",{"type":20,"tag":58,"props":2611,"children":2612},{},[2613,2618],{"type":20,"tag":33,"props":2614,"children":2615},{},[2616],{"type":26,"value":2617},"SIGTRAN\u002FSS7 Stack Testing",{"type":26,"value":2619},": Use OsmoSTP (Signaling Transfer Point) for M2UA\u002FM3UA\u002FSCCP protocol security analysis.",{"type":20,"tag":47,"props":2621,"children":2622},{"id":100},[2623],{"type":26,"value":103},{"type":20,"tag":105,"props":2625,"children":2627},{"id":2626},"_1-launch-minimal-gsm-network",[2628],{"type":26,"value":2629},"1. Launch Minimal GSM Network",{"type":20,"tag":112,"props":2631,"children":2634},{"className":2632,"code":2633,"language":117,"meta":8},[115],"# Start the complete GSM core (HLR → MSC → BSC → BTS chain)\nsudo systemctl start osmo-hlr osmo-msc osmo-bsc osmo-bts-trx osmo-trx-uhd\n",[2635],{"type":20,"tag":120,"props":2636,"children":2637},{"__ignoreMap":8},[2638],{"type":26,"value":2633},{"type":20,"tag":105,"props":2640,"children":2642},{"id":2641},"_2-provision-test-sim-subscriber",[2643],{"type":26,"value":2644},"2. Provision Test SIM Subscriber",{"type":20,"tag":112,"props":2646,"children":2649},{"className":2647,"code":2648,"language":117,"meta":8},[115],"# Add subscriber via OsmoHLR VTY interface\ntelnet 127.0.0.1 4258\n# > enable\n# > subscriber imsi 001010000000001 create\n# > subscriber imsi 001010000000001 update msisdn 555000001\n",[2650],{"type":20,"tag":120,"props":2651,"children":2652},{"__ignoreMap":8},[2653],{"type":26,"value":2648},{"type":20,"tag":105,"props":2655,"children":2657},{"id":2656},"_3-monitor-gsm-air-interface",[2658],{"type":26,"value":2659},"3. Monitor GSM Air Interface",{"type":20,"tag":112,"props":2661,"children":2664},{"className":2662,"code":2663,"language":117,"meta":8},[115],"# Capture Um interface signaling with Gr-GSM\ngrgsm_livemon -f 935.2e6 | wireshark -k -i -\n",[2665],{"type":20,"tag":120,"props":2666,"children":2667},{"__ignoreMap":8},[2668],{"type":26,"value":2663},{"type":20,"tag":47,"props":2670,"children":2671},{"id":156},[2672],{"type":26,"value":159},{"type":20,"tag":29,"props":2674,"children":2675},{},[2676,2677],{"type":26,"value":164},{"type":20,"tag":33,"props":2678,"children":2679},{},[2680],{"type":20,"tag":169,"props":2681,"children":2683},{"href":15,"rel":2682},[172],[2684],{"type":26,"value":2685},"Launch GSM Infrastructure Lab on App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":2687},[2688,2689,2694],{"id":49,"depth":177,"text":52},{"id":100,"depth":177,"text":103,"children":2690},[2691,2692,2693],{"id":2626,"depth":183,"text":2629},{"id":2641,"depth":183,"text":2644},{"id":2656,"depth":183,"text":2659},{"id":156,"depth":177,"text":159},"content:tools:osmocom-suite.md","tools\u002Fosmocom-suite.md","tools\u002Fosmocom-suite",{"_path":2699,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":2700,"description":2701,"name":2700,"protocol":2702,"category":2703,"hardware":2704,"command":2705,"academyLab":15,"body":2706,"_type":187,"_id":2840,"_source":189,"_file":2841,"_stem":2842,"_extension":192},"\u002Ftools\u002Fpysim","pySim","Osmocom tool suite for reading, programming, and auditing SIM, USIM, ISIM, and eSIM cards over standard PC\u002FSC interfaces.","SIM \u002F USIM \u002F ISIM \u002F eSIM","Smartcard & UICC Security Toolkit","PC\u002FSC Smartcard Reader (Omnikey \u002F ACR38U)","pySim-prog.py -p 0 -a 1234",{"type":17,"children":2707,"toc":2831},[2708,2714,2725,2731,2764,2768,2774,2783,2789,2798,2804,2813,2817],{"type":20,"tag":21,"props":2709,"children":2711},{"id":2710},"pysim-sim-usim-esim-security-programming-suite",[2712],{"type":26,"value":2713},"pySim — SIM \u002F USIM \u002F eSIM Security & Programming Suite",{"type":20,"tag":29,"props":2715,"children":2716},{},[2717,2719,2723],{"type":26,"value":2718},"pySim is the authoritative Osmocom tool for interacting with telecommunication smartcards (UICC). In ",{"type":20,"tag":33,"props":2720,"children":2721},{},[2722],{"type":26,"value":43},{"type":26,"value":2724},", pySim comes with full support for PC\u002FSC daemon bindings, SysmoSIM programmable cards, and eSIM Local Profile Assistant (LPA) commands.",{"type":20,"tag":47,"props":2726,"children":2728},{"id":2727},"capabilities",[2729],{"type":26,"value":2730},"Capabilities",{"type":20,"tag":54,"props":2732,"children":2733},{},[2734,2744,2754],{"type":20,"tag":58,"props":2735,"children":2736},{},[2737,2742],{"type":20,"tag":33,"props":2738,"children":2739},{},[2740],{"type":26,"value":2741},"Key Extraction & Inspection",{"type":26,"value":2743},": Read Elementary Files (EF_IMSI, EF_ICCID, EF_HPLMN, EF_AD, EF_AUTH) to extract subscriber credentials and carrier parameters.",{"type":20,"tag":58,"props":2745,"children":2746},{},[2747,2752],{"type":20,"tag":33,"props":2748,"children":2749},{},[2750],{"type":26,"value":2751},"Milena \u002F Tuak Key Derivation",{"type":26,"value":2753},": Program authentication keys (Ki, OP, OPC) for test carrier deployment in Open5GS\u002FsrsRAN test environments.",{"type":20,"tag":58,"props":2755,"children":2756},{},[2757,2762],{"type":20,"tag":33,"props":2758,"children":2759},{},[2760],{"type":26,"value":2761},"eSIM Profile Audits",{"type":26,"value":2763},": Interact with eUICC security domains (ISD-P, ECASD) to test eSIM profile downloading and mutual authentication certificates.",{"type":20,"tag":47,"props":2765,"children":2766},{"id":740},[2767],{"type":26,"value":743},{"type":20,"tag":105,"props":2769,"children":2771},{"id":2770},"_1-detect-connected-smartcard-reader",[2772],{"type":26,"value":2773},"1. Detect Connected Smartcard Reader",{"type":20,"tag":112,"props":2775,"children":2778},{"className":2776,"code":2777,"language":117,"meta":8},[115],"# Check PC\u002FSC reader status and card ATR\npcsc_scan\n",[2779],{"type":20,"tag":120,"props":2780,"children":2781},{"__ignoreMap":8},[2782],{"type":26,"value":2777},{"type":20,"tag":105,"props":2784,"children":2786},{"id":2785},"_2-launch-interactive-pysim-shell",[2787],{"type":26,"value":2788},"2. Launch Interactive pySim Shell",{"type":20,"tag":112,"props":2790,"children":2793},{"className":2791,"code":2792,"language":117,"meta":8},[115],"# Enter interactive pySim terminal\npySim-shell.py -p 0\n",[2794],{"type":20,"tag":120,"props":2795,"children":2796},{"__ignoreMap":8},[2797],{"type":26,"value":2792},{"type":20,"tag":105,"props":2799,"children":2801},{"id":2800},"_3-read-imsi-and-carrier-elementary-files",[2802],{"type":26,"value":2803},"3. Read IMSI and Carrier Elementary Files",{"type":20,"tag":112,"props":2805,"children":2808},{"className":2806,"code":2807,"language":117,"meta":8},[115],"# Inside pySim-shell:\npySim-shell (0:MF)> select ADF.USIM\npySim-shell (0:MF\u002FADF.USIM)> select EF.IMSI\npySim-shell (0:MF\u002FADF.USIM\u002FEF.IMSI)> read_binary\n",[2809],{"type":20,"tag":120,"props":2810,"children":2811},{"__ignoreMap":8},[2812],{"type":26,"value":2807},{"type":20,"tag":47,"props":2814,"children":2815},{"id":776},[2816],{"type":26,"value":779},{"type":20,"tag":29,"props":2818,"children":2819},{},[2820,2822],{"type":26,"value":2821},"To learn smartcard hardware security and eSIM penetration testing:\n👉 ",{"type":20,"tag":33,"props":2823,"children":2824},{},[2825],{"type":20,"tag":169,"props":2826,"children":2828},{"href":15,"rel":2827},[172],[2829],{"type":26,"value":2830},"Access the SIM & UICC Lab at App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":2832},[2833,2834,2839],{"id":2727,"depth":177,"text":2730},{"id":740,"depth":177,"text":743,"children":2835},[2836,2837,2838],{"id":2770,"depth":183,"text":2773},{"id":2785,"depth":183,"text":2788},{"id":2800,"depth":183,"text":2803},{"id":776,"depth":177,"text":779},"content:tools:pysim.md","tools\u002Fpysim.md","tools\u002Fpysim",{"_path":2844,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":2845,"description":2846,"name":2845,"protocol":2847,"category":2848,"hardware":2849,"command":2850,"academyLab":15,"body":2851,"_type":187,"_id":2961,"_source":189,"_file":2962,"_stem":2963,"_extension":192},"\u002Ftools\u002Fqcsuper","QCSuper","Tool for capturing raw cellular network signaling (RRC, NAS, MAC) from Qualcomm baseband chipsets and streaming directly to Wireshark in real-time.","2G \u002F 3G \u002F 4G \u002F 5G Baseband","Qualcomm Baseband Traffic Sniffer & PCAP Exporter","Rooted Android Phone with Qualcomm SoC \u002F USB Modem","qcsuper --adb --wireshark-live",{"type":17,"children":2852,"toc":2953},[2853,2859,2864,2868,2901,2905,2911,2920,2926,2935,2939],{"type":20,"tag":21,"props":2854,"children":2856},{"id":2855},"qcsuper-qualcomm-baseband-signaling-sniffer",[2857],{"type":26,"value":2858},"QCSuper — Qualcomm Baseband Signaling Sniffer",{"type":20,"tag":29,"props":2860,"children":2861},{},[2862],{"type":26,"value":2863},"QCSuper communicates directly with Qualcomm DIAG diagnostic interfaces on rooted mobile devices or cellular USB dongles to capture raw baseband signaling messages before and after encryption layers.",{"type":20,"tag":47,"props":2865,"children":2866},{"id":1274},[2867],{"type":26,"value":1277},{"type":20,"tag":54,"props":2869,"children":2870},{},[2871,2881,2891],{"type":20,"tag":58,"props":2872,"children":2873},{},[2874,2879],{"type":20,"tag":33,"props":2875,"children":2876},{},[2877],{"type":26,"value":2878},"Real-Time Wireshark Live Streaming",{"type":26,"value":2880},": Stream 2G\u002F3G\u002F4G\u002F5G Radio Resource Control (RRC) and Non-Access Stratum (NAS) packets directly into Wireshark using GSMTAP encapsulation.",{"type":20,"tag":58,"props":2882,"children":2883},{},[2884,2889],{"type":20,"tag":33,"props":2885,"children":2886},{},[2887],{"type":26,"value":2888},"Layer 3 Signaling Decode",{"type":26,"value":2890},": Inspect SIB broadcasts, attach requests, paging messages, and measurement reports sent between the mobile station and carrier base station.",{"type":20,"tag":58,"props":2892,"children":2893},{},[2894,2899],{"type":20,"tag":33,"props":2895,"children":2896},{},[2897],{"type":26,"value":2898},"IMSI Disclosure Detection",{"type":26,"value":2900},": Track when carrier towers request identity responses containing unencrypted IMSI numbers over 2G\u002F3G\u002F4G.",{"type":20,"tag":47,"props":2902,"children":2903},{"id":740},[2904],{"type":26,"value":743},{"type":20,"tag":105,"props":2906,"children":2908},{"id":2907},"_1-launch-live-wireshark-capture-via-adb",[2909],{"type":26,"value":2910},"1. Launch Live Wireshark Capture via ADB",{"type":20,"tag":112,"props":2912,"children":2915},{"className":2913,"code":2914,"language":117,"meta":8},[115],"# Connect rooted Android phone over USB and launch live Wireshark feed\nqcsuper --adb --wireshark-live\n",[2916],{"type":20,"tag":120,"props":2917,"children":2918},{"__ignoreMap":8},[2919],{"type":26,"value":2914},{"type":20,"tag":105,"props":2921,"children":2923},{"id":2922},"_2-save-signaling-to-pcap-for-offline-analysis",[2924],{"type":26,"value":2925},"2. Save Signaling to PCAP for Offline Analysis",{"type":20,"tag":112,"props":2927,"children":2930},{"className":2928,"code":2929,"language":117,"meta":8},[115],"# Log raw DIAG frames to PCAP with GSMTAP headers\nqcsuper --adb --pcap-dump \u002Ftmp\u002Fcellular_capture.pcap\n",[2931],{"type":20,"tag":120,"props":2932,"children":2933},{"__ignoreMap":8},[2934],{"type":26,"value":2929},{"type":20,"tag":47,"props":2936,"children":2937},{"id":776},[2938],{"type":26,"value":779},{"type":20,"tag":29,"props":2940,"children":2941},{},[2942,2944],{"type":26,"value":2943},"To master baseband diagnostic analysis and cellular protocol inspection:\n👉 ",{"type":20,"tag":33,"props":2945,"children":2946},{},[2947],{"type":20,"tag":169,"props":2948,"children":2950},{"href":15,"rel":2949},[172],[2951],{"type":26,"value":2952},"Access the Cellular Baseband Lab at App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":2954},[2955,2956,2960],{"id":1274,"depth":177,"text":1277},{"id":740,"depth":177,"text":743,"children":2957},[2958,2959],{"id":2907,"depth":183,"text":2910},{"id":2922,"depth":183,"text":2925},{"id":776,"depth":177,"text":779},"content:tools:qcsuper.md","tools\u002Fqcsuper.md","tools\u002Fqcsuper",{"_path":2965,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":2966,"description":2967,"name":2966,"protocol":2968,"category":2969,"hardware":2970,"command":2971,"academyLab":15,"body":2972,"_type":187,"_id":3117,"_source":189,"_file":3118,"_stem":3119,"_extension":192},"\u002Ftools\u002Fsctpscan","SCTPScan","SCTP network scanner for discovering telecom signaling endpoints including SIGTRAN SS7 nodes, Diameter peers, and S1-MME interfaces on carrier networks.","SS7 \u002F SIGTRAN \u002F Diameter","Network Scanner","Ethernet Interface","sctpscan -d 10.0.0.0\u002F24 -p 2905,3868",{"type":17,"children":2973,"toc":3108},[2974,2980,2995,2999,3042,3046,3052,3061,3067,3076,3082,3091,3095],{"type":20,"tag":21,"props":2975,"children":2977},{"id":2976},"sctpscan-sctp-telecom-signaling-discovery-scanner",[2978],{"type":26,"value":2979},"SCTPScan — SCTP Telecom Signaling Discovery Scanner",{"type":20,"tag":29,"props":2981,"children":2982},{},[2983,2987,2989,2993],{"type":20,"tag":33,"props":2984,"children":2985},{},[2986],{"type":26,"value":2966},{"type":26,"value":2988}," is a specialized network scanner for the Stream Control Transmission Protocol (SCTP), the transport protocol underpinning all modern telecom signaling. Within ",{"type":20,"tag":33,"props":2990,"children":2991},{},[2992],{"type":26,"value":43},{"type":26,"value":2994},", it is used to discover SIGTRAN SS7 signaling endpoints (M2UA\u002FM3UA), Diameter peers (S6a, Gx, Gy), and 4G\u002F5G S1-AP\u002FNG-AP interfaces during carrier network penetration tests.",{"type":20,"tag":47,"props":2996,"children":2997},{"id":49},[2998],{"type":26,"value":52},{"type":20,"tag":54,"props":3000,"children":3001},{},[3002,3012,3022,3032],{"type":20,"tag":58,"props":3003,"children":3004},{},[3005,3010],{"type":20,"tag":33,"props":3006,"children":3007},{},[3008],{"type":26,"value":3009},"SIGTRAN Endpoint Discovery",{"type":26,"value":3011},": Scan IP ranges for M2UA (port 2904), M3UA (port 2905), and SUA (port 14001) signaling gateways.",{"type":20,"tag":58,"props":3013,"children":3014},{},[3015,3020],{"type":20,"tag":33,"props":3016,"children":3017},{},[3018],{"type":26,"value":3019},"Diameter Peer Enumeration",{"type":26,"value":3021},": Identify Diameter relay agents and proxies on standard ports (3868 TCP\u002FSCTP) for S6a\u002FGx\u002FGy testing.",{"type":20,"tag":58,"props":3023,"children":3024},{},[3025,3030],{"type":20,"tag":33,"props":3026,"children":3027},{},[3028],{"type":26,"value":3029},"S1-MME \u002F NG-AP Discovery",{"type":26,"value":3031},": Find exposed eNodeB and gNodeB SCTP associations on carrier infrastructure (port 36412 \u002F 38412).",{"type":20,"tag":58,"props":3033,"children":3034},{},[3035,3040],{"type":20,"tag":33,"props":3036,"children":3037},{},[3038],{"type":26,"value":3039},"SCTP INIT Fingerprinting",{"type":26,"value":3041},": Fingerprint SCTP stack implementations to identify vendor-specific signaling equipment.",{"type":20,"tag":47,"props":3043,"children":3044},{"id":100},[3045],{"type":26,"value":103},{"type":20,"tag":105,"props":3047,"children":3049},{"id":3048},"_1-scan-for-sigtran-ss7-nodes",[3050],{"type":26,"value":3051},"1. Scan for SIGTRAN SS7 Nodes",{"type":20,"tag":112,"props":3053,"children":3056},{"className":3054,"code":3055,"language":117,"meta":8},[115],"# Discover M3UA signaling transfer points on a carrier subnet\nsudo sctpscan -d 10.0.0.0\u002F24 -p 2905 -r\n",[3057],{"type":20,"tag":120,"props":3058,"children":3059},{"__ignoreMap":8},[3060],{"type":26,"value":3055},{"type":20,"tag":105,"props":3062,"children":3064},{"id":3063},"_2-scan-for-diameter-peers",[3065],{"type":26,"value":3066},"2. Scan for Diameter Peers",{"type":20,"tag":112,"props":3068,"children":3071},{"className":3069,"code":3070,"language":117,"meta":8},[115],"# Find Diameter relay agents (HSS, PCRF, OCS endpoints)\nsudo sctpscan -d 172.16.0.0\u002F16 -p 3868 -r\n",[3072],{"type":20,"tag":120,"props":3073,"children":3074},{"__ignoreMap":8},[3075],{"type":26,"value":3070},{"type":20,"tag":105,"props":3077,"children":3079},{"id":3078},"_3-enumerate-s1-mme-interfaces",[3080],{"type":26,"value":3081},"3. Enumerate S1-MME Interfaces",{"type":20,"tag":112,"props":3083,"children":3086},{"className":3084,"code":3085,"language":117,"meta":8},[115],"# Discover LTE eNodeB S1-AP SCTP associations\nsudo sctpscan -d 192.168.0.0\u002F16 -p 36412 -r\n",[3087],{"type":20,"tag":120,"props":3088,"children":3089},{"__ignoreMap":8},[3090],{"type":26,"value":3085},{"type":20,"tag":47,"props":3092,"children":3093},{"id":156},[3094],{"type":26,"value":159},{"type":20,"tag":29,"props":3096,"children":3097},{},[3098,3099],{"type":26,"value":164},{"type":20,"tag":33,"props":3100,"children":3101},{},[3102],{"type":20,"tag":169,"props":3103,"children":3105},{"href":15,"rel":3104},[172],[3106],{"type":26,"value":3107},"Launch SCTP Reconnaissance Lab on App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":3109},[3110,3111,3116],{"id":49,"depth":177,"text":52},{"id":100,"depth":177,"text":103,"children":3112},[3113,3114,3115],{"id":3048,"depth":183,"text":3051},{"id":3063,"depth":183,"text":3066},{"id":3078,"depth":183,"text":3081},{"id":156,"depth":177,"text":159},"content:tools:sctpscan.md","tools\u002Fsctpscan.md","tools\u002Fsctpscan",{"_path":3121,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":3122,"description":3123,"name":3122,"protocol":2234,"category":3124,"hardware":3125,"command":3126,"academyLab":15,"body":3127,"_type":187,"_id":3272,"_source":189,"_file":3273,"_stem":3274,"_extension":192},"\u002Ftools\u002Fsdr-beam","sdr-beam","SDR beamforming and MIMO antenna array toolkit for testing spatial multiplexing, beam sweeping interception, and directional RF security assessments.","SDR Beamforming Toolkit","USRP X310 \u002F N210 (multi-channel)","sdr-beam --config \u002Fetc\u002Fsdr-beam\u002F4x4-mimo.yaml",{"type":17,"children":3128,"toc":3263},[3129,3135,3150,3154,3197,3201,3207,3216,3222,3231,3237,3246,3250],{"type":20,"tag":21,"props":3130,"children":3132},{"id":3131},"sdr-beam-sdr-beamforming-mimo-security-toolkit",[3133],{"type":26,"value":3134},"sdr-beam — SDR Beamforming & MIMO Security Toolkit",{"type":20,"tag":29,"props":3136,"children":3137},{},[3138,3142,3144,3148],{"type":20,"tag":33,"props":3139,"children":3140},{},[3141],{"type":26,"value":3122},{"type":26,"value":3143}," is a software-defined beamforming framework for multi-channel SDR hardware. Within ",{"type":20,"tag":33,"props":3145,"children":3146},{},[3147],{"type":26,"value":43},{"type":26,"value":3149},", it enables security researchers to test beamforming interception techniques, MIMO spatial multiplexing vulnerabilities, and directional signal injection using phased array configurations on USRP X310\u002FN310 hardware.",{"type":20,"tag":47,"props":3151,"children":3152},{"id":49},[3153],{"type":26,"value":52},{"type":20,"tag":54,"props":3155,"children":3156},{},[3157,3167,3177,3187],{"type":20,"tag":58,"props":3158,"children":3159},{},[3160,3165],{"type":20,"tag":33,"props":3161,"children":3162},{},[3163],{"type":26,"value":3164},"Beam Sweeping Interception",{"type":26,"value":3166},": Capture and decode 5G NR SSB beam sweep patterns to determine gNodeB beam directions and predict UE-specific beamforming.",{"type":20,"tag":58,"props":3168,"children":3169},{},[3170,3175],{"type":20,"tag":33,"props":3171,"children":3172},{},[3173],{"type":26,"value":3174},"MIMO Spatial Analysis",{"type":26,"value":3176},": Analyze multi-layer spatial multiplexing to test eavesdropping feasibility on MIMO-encrypted channels.",{"type":20,"tag":58,"props":3178,"children":3179},{},[3180,3185],{"type":20,"tag":33,"props":3181,"children":3182},{},[3183],{"type":26,"value":3184},"Directional Signal Injection",{"type":26,"value":3186},": Focus RF energy on specific UE targets for precision jamming and rogue cell redirection attacks.",{"type":20,"tag":58,"props":3188,"children":3189},{},[3190,3195],{"type":20,"tag":33,"props":3191,"children":3192},{},[3193],{"type":26,"value":3194},"Antenna Array Calibration",{"type":26,"value":3196},": Calibrate phased array SDR setups for coherent reception across 4×4 and 8×8 MIMO configurations.",{"type":20,"tag":47,"props":3198,"children":3199},{"id":100},[3200],{"type":26,"value":103},{"type":20,"tag":105,"props":3202,"children":3204},{"id":3203},"_1-initialize-44-mimo-configuration",[3205],{"type":26,"value":3206},"1. Initialize 4×4 MIMO Configuration",{"type":20,"tag":112,"props":3208,"children":3211},{"className":3209,"code":3210,"language":117,"meta":8},[115],"# Start beam scanning with 4-channel USRP X310\nsdr-beam --config \u002Fetc\u002Fsdr-beam\u002F4x4-mimo.yaml --mode scan\n",[3212],{"type":20,"tag":120,"props":3213,"children":3214},{"__ignoreMap":8},[3215],{"type":26,"value":3210},{"type":20,"tag":105,"props":3217,"children":3219},{"id":3218},"_2-capture-ssb-beam-sweep",[3220],{"type":26,"value":3221},"2. Capture SSB Beam Sweep",{"type":20,"tag":112,"props":3223,"children":3226},{"className":3224,"code":3225,"language":117,"meta":8},[115],"# Lock to 5G NR SSB and record beam sweep pattern\nsdr-beam --freq 3600e6 --bw 100e6 --mode ssb-sweep --output \u002Ftmp\u002Fbeams.json\n",[3227],{"type":20,"tag":120,"props":3228,"children":3229},{"__ignoreMap":8},[3230],{"type":26,"value":3225},{"type":20,"tag":105,"props":3232,"children":3234},{"id":3233},"_3-generate-beam-pattern-visualization",[3235],{"type":26,"value":3236},"3. Generate Beam Pattern Visualization",{"type":20,"tag":112,"props":3238,"children":3241},{"className":3239,"code":3240,"language":117,"meta":8},[115],"# Plot antenna radiation pattern from captured data\nsdr-beam --mode visualize --input \u002Ftmp\u002Fbeams.json --output \u002Ftmp\u002Fbeam-pattern.png\n",[3242],{"type":20,"tag":120,"props":3243,"children":3244},{"__ignoreMap":8},[3245],{"type":26,"value":3240},{"type":20,"tag":47,"props":3247,"children":3248},{"id":156},[3249],{"type":26,"value":159},{"type":20,"tag":29,"props":3251,"children":3252},{},[3253,3254],{"type":26,"value":164},{"type":20,"tag":33,"props":3255,"children":3256},{},[3257],{"type":20,"tag":169,"props":3258,"children":3260},{"href":15,"rel":3259},[172],[3261],{"type":26,"value":3262},"Launch MIMO Beamforming Lab on App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":3264},[3265,3266,3271],{"id":49,"depth":177,"text":52},{"id":100,"depth":177,"text":103,"children":3267},[3268,3269,3270],{"id":3203,"depth":183,"text":3206},{"id":3218,"depth":183,"text":3221},{"id":3233,"depth":183,"text":3236},{"id":156,"depth":177,"text":159},"content:tools:sdr-beam.md","tools\u002Fsdr-beam.md","tools\u002Fsdr-beam",{"_path":3276,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":3277,"description":3278,"name":3277,"protocol":3279,"category":3280,"hardware":3281,"command":3282,"academyLab":15,"body":3283,"_type":187,"_id":3428,"_source":189,"_file":3429,"_stem":3430,"_extension":192},"\u002Ftools\u002Fshadysim","ShadySIM","SIM card application installation and exploitation toolkit for loading custom Java Card applets onto SIM\u002FUSIM cards for OTA attack simulation and SIM toolkit research.","SIM \u002F USIM","SIM Card Exploitation","PC\u002FSC Smartcard Reader (ACR38U \u002F Omnikey)","shadysim -l",{"type":17,"children":3284,"toc":3419},[3285,3291,3306,3310,3353,3357,3363,3372,3378,3387,3393,3402,3406],{"type":20,"tag":21,"props":3286,"children":3288},{"id":3287},"shadysim-sim-card-applet-exploitation-toolkit",[3289],{"type":26,"value":3290},"ShadySIM — SIM Card Applet Exploitation Toolkit",{"type":20,"tag":29,"props":3292,"children":3293},{},[3294,3298,3300,3304],{"type":20,"tag":33,"props":3295,"children":3296},{},[3297],{"type":26,"value":3277},{"type":26,"value":3299}," enables loading custom Java Card applets onto programmable SIM cards (sysmoISIM-SJA2, Gialer blanks). Within ",{"type":20,"tag":33,"props":3301,"children":3302},{},[3303],{"type":26,"value":43},{"type":26,"value":3305},", it is preconfigured with PC\u002FSC reader drivers and sample exploit applets for testing SIM Toolkit (STK) command injection, OTA SMS key bruteforcing, and carrier OTA platform security assessment.",{"type":20,"tag":47,"props":3307,"children":3308},{"id":49},[3309],{"type":26,"value":52},{"type":20,"tag":54,"props":3311,"children":3312},{},[3313,3323,3333,3343],{"type":20,"tag":58,"props":3314,"children":3315},{},[3316,3321],{"type":20,"tag":33,"props":3317,"children":3318},{},[3319],{"type":26,"value":3320},"Custom Applet Installation",{"type":26,"value":3322},": Load arbitrary Java Card applets onto writeable SIM\u002FUSIM cards for security testing.",{"type":20,"tag":58,"props":3324,"children":3325},{},[3326,3331],{"type":20,"tag":33,"props":3327,"children":3328},{},[3329],{"type":26,"value":3330},"SIM Toolkit Hijacking",{"type":26,"value":3332},": Install rogue STK menus that intercept user interactions (call setup, SMS sending, USSD queries).",{"type":20,"tag":58,"props":3334,"children":3335},{},[3336,3341],{"type":20,"tag":33,"props":3337,"children":3338},{},[3339],{"type":26,"value":3340},"OTA Attack Simulation",{"type":26,"value":3342},": Simulate over-the-air SIM update attacks by testing OTA key derivation and binary SMS payload handling.",{"type":20,"tag":58,"props":3344,"children":3345},{},[3346,3351],{"type":20,"tag":33,"props":3347,"children":3348},{},[3349],{"type":26,"value":3350},"APDU Trace Analysis",{"type":26,"value":3352},": Log and analyze SIM ↔ ME (Mobile Equipment) APDU command sequences for protocol reverse engineering.",{"type":20,"tag":47,"props":3354,"children":3355},{"id":100},[3356],{"type":26,"value":103},{"type":20,"tag":105,"props":3358,"children":3360},{"id":3359},"_1-list-installed-sim-applets",[3361],{"type":26,"value":3362},"1. List Installed SIM Applets",{"type":20,"tag":112,"props":3364,"children":3367},{"className":3365,"code":3366,"language":117,"meta":8},[115],"# Enumerate all applets installed on the target SIM card\nshadysim -l -r 0\n",[3368],{"type":20,"tag":120,"props":3369,"children":3370},{"__ignoreMap":8},[3371],{"type":26,"value":3366},{"type":20,"tag":105,"props":3373,"children":3375},{"id":3374},"_2-install-custom-stk-applet",[3376],{"type":26,"value":3377},"2. Install Custom STK Applet",{"type":20,"tag":112,"props":3379,"children":3382},{"className":3380,"code":3381,"language":117,"meta":8},[115],"# Install a SIM Toolkit test applet from compiled CAP file\nshadysim -i \u002Fopt\u002Fshadysim\u002Fapplets\u002Fstk-intercept.cap -r 0\n",[3383],{"type":20,"tag":120,"props":3384,"children":3385},{"__ignoreMap":8},[3386],{"type":26,"value":3381},{"type":20,"tag":105,"props":3388,"children":3390},{"id":3389},"_3-delete-applet-from-sim",[3391],{"type":26,"value":3392},"3. Delete Applet from SIM",{"type":20,"tag":112,"props":3394,"children":3397},{"className":3395,"code":3396,"language":117,"meta":8},[115],"# Remove a previously installed applet by AID\nshadysim -d A0000000620001 -r 0\n",[3398],{"type":20,"tag":120,"props":3399,"children":3400},{"__ignoreMap":8},[3401],{"type":26,"value":3396},{"type":20,"tag":47,"props":3403,"children":3404},{"id":156},[3405],{"type":26,"value":159},{"type":20,"tag":29,"props":3407,"children":3408},{},[3409,3410],{"type":26,"value":164},{"type":20,"tag":33,"props":3411,"children":3412},{},[3413],{"type":20,"tag":169,"props":3414,"children":3416},{"href":15,"rel":3415},[172],[3417],{"type":26,"value":3418},"Launch SIM Security Lab on App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":3420},[3421,3422,3427],{"id":49,"depth":177,"text":52},{"id":100,"depth":177,"text":103,"children":3423},[3424,3425,3426],{"id":3359,"depth":183,"text":3362},{"id":3374,"depth":183,"text":3377},{"id":3389,"depth":183,"text":3392},{"id":156,"depth":177,"text":159},"content:tools:shadysim.md","tools\u002Fshadysim.md","tools\u002Fshadysim",{"_path":3432,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":3433,"description":3434,"name":3433,"protocol":3435,"category":1245,"hardware":1246,"command":3436,"academyLab":15,"body":3437,"_type":187,"_id":3556,"_source":189,"_file":3557,"_stem":3558,"_extension":192},"\u002Ftools\u002Fsigdigger","SigDigger","Free digital signal processing software for exploratory SDR analysis, audio demodulation, and burst signal inspection.","RF \u002F DSP \u002F Digital IQ","sigdigger",{"type":17,"children":3438,"toc":3548},[3439,3445,3460,3464,3497,3501,3507,3516,3522,3531,3535],{"type":20,"tag":21,"props":3440,"children":3442},{"id":3441},"sigdigger-exploratory-digital-signal-analyzer",[3443],{"type":26,"value":3444},"SigDigger — Exploratory Digital Signal Analyzer",{"type":20,"tag":29,"props":3446,"children":3447},{},[3448,3452,3454,3458],{"type":20,"tag":33,"props":3449,"children":3450},{},[3451],{"type":26,"value":3433},{"type":26,"value":3453}," is a powerful DSP-based graphical application for analyzing radio frequency spectrums in real time and examining offline recorded captures. In ",{"type":20,"tag":33,"props":3455,"children":3456},{},[3457],{"type":26,"value":43},{"type":26,"value":3459},", SigDigger is equipped with multi-format audio and digital demodulators (ASK, FSK, PSK, GFSK) and automatic burst detection for reverse-engineering wireless telecommunication protocols.",{"type":20,"tag":47,"props":3461,"children":3462},{"id":1274},[3463],{"type":26,"value":1277},{"type":20,"tag":54,"props":3465,"children":3466},{},[3467,3477,3487],{"type":20,"tag":58,"props":3468,"children":3469},{},[3470,3475],{"type":20,"tag":33,"props":3471,"children":3472},{},[3473],{"type":26,"value":3474},"Automatic Burst & Preamble Detection",{"type":26,"value":3476},": Identify transient wireless packet bursts and extract their precise duration and modulation type.",{"type":20,"tag":58,"props":3478,"children":3479},{},[3480,3485],{"type":20,"tag":33,"props":3481,"children":3482},{},[3483],{"type":26,"value":3484},"Constellation Diagrams & Phase Space Analysis",{"type":26,"value":3486},": Real-time IQ constellation display for evaluating signal-to-noise ratios and modulation quality.",{"type":20,"tag":58,"props":3488,"children":3489},{},[3490,3495],{"type":20,"tag":33,"props":3491,"children":3492},{},[3493],{"type":26,"value":3494},"Built-in Channel Decoders",{"type":26,"value":3496},": Decodes FSK, PSK, and GFSK streams into ASCII \u002F Hex payloads on the fly.",{"type":20,"tag":47,"props":3498,"children":3499},{"id":1313},[3500],{"type":26,"value":1316},{"type":20,"tag":105,"props":3502,"children":3504},{"id":3503},"_1-launch-sigdigger",[3505],{"type":26,"value":3506},"1. Launch SigDigger",{"type":20,"tag":112,"props":3508,"children":3511},{"className":3509,"code":3510,"language":117,"meta":8},[115],"sigdigger\n",[3512],{"type":20,"tag":120,"props":3513,"children":3514},{"__ignoreMap":8},[3515],{"type":26,"value":3510},{"type":20,"tag":105,"props":3517,"children":3519},{"id":3518},"_2-live-burst-spectrum-inspection",[3520],{"type":26,"value":3521},"2. Live Burst Spectrum Inspection",{"type":20,"tag":112,"props":3523,"children":3526},{"className":3524,"code":3525,"language":117,"meta":8},[115],"# Connect SDR device (e.g., HackRF One) -> Set center frequency -> Enable Audio & Constellation scopes\n",[3527],{"type":20,"tag":120,"props":3528,"children":3529},{"__ignoreMap":8},[3530],{"type":26,"value":3525},{"type":20,"tag":47,"props":3532,"children":3533},{"id":156},[3534],{"type":26,"value":159},{"type":20,"tag":29,"props":3536,"children":3537},{},[3538,3539],{"type":26,"value":164},{"type":20,"tag":33,"props":3540,"children":3541},{},[3542],{"type":20,"tag":169,"props":3543,"children":3545},{"href":15,"rel":3544},[172],[3546],{"type":26,"value":3547},"Access SDR & DSP Signal Analysis Labs at App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":3549},[3550,3551,3555],{"id":1274,"depth":177,"text":1277},{"id":1313,"depth":177,"text":1316,"children":3552},[3553,3554],{"id":3503,"depth":183,"text":3506},{"id":3518,"depth":183,"text":3521},{"id":156,"depth":177,"text":159},"content:tools:sigdigger.md","tools\u002Fsigdigger.md","tools\u002Fsigdigger",{"_path":3560,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":3561,"description":3562,"name":3561,"protocol":3563,"category":3564,"hardware":3565,"command":3566,"academyLab":15,"body":3567,"_type":187,"_id":3789,"_source":189,"_file":3790,"_stem":3791,"_extension":192},"\u002Ftools\u002Fsigploit","SigPloit","Comprehensive telecom signaling exploitation framework targeting SS7 (MAP\u002FCAMEL\u002FISUP), Diameter (S6a\u002FCx\u002FRo\u002FGy), and GTP-C (v1\u002Fv2) networks.","SS7 \u002F Diameter \u002F GTP","Telecom Signaling Exploitation Framework","Ethernet \u002F SCTP Interface \u002F VPN Gateway","sigploit",{"type":17,"children":3568,"toc":3780},[3569,3575,3586,3592,3713,3717,3723,3732,3738,3747,3753,3762,3766],{"type":20,"tag":21,"props":3570,"children":3572},{"id":3571},"sigploit-telecom-signaling-exploitation-framework",[3573],{"type":26,"value":3574},"SigPloit — Telecom Signaling Exploitation Framework",{"type":20,"tag":29,"props":3576,"children":3577},{},[3578,3580,3584],{"type":26,"value":3579},"SigPloit is the premier dedicated penetration testing framework for telecommunication signaling networks. In ",{"type":20,"tag":33,"props":3581,"children":3582},{},[3583],{"type":26,"value":43},{"type":26,"value":3585},", SigPloit is pre-compiled with updated SCTP kernel socket libraries, LibSS7, and modern Diameter dictionary definitions.",{"type":20,"tag":47,"props":3587,"children":3589},{"id":3588},"key-telecom-attack-modules",[3590],{"type":26,"value":3591},"Key Telecom Attack Modules",{"type":20,"tag":54,"props":3593,"children":3594},{},[3595,3629,3655,3680],{"type":20,"tag":58,"props":3596,"children":3597},{},[3598,3603,3605,3611,3613,3619,3621,3627],{"type":20,"tag":33,"props":3599,"children":3600},{},[3601],{"type":26,"value":3602},"Location Tracking",{"type":26,"value":3604},": Send MAP ",{"type":20,"tag":120,"props":3606,"children":3608},{"className":3607},[],[3609],{"type":26,"value":3610},"SendRoutingInfoForSM",{"type":26,"value":3612}," (SRI-SM), ",{"type":20,"tag":120,"props":3614,"children":3616},{"className":3615},[],[3617],{"type":26,"value":3618},"ProvideSubscriberInfo",{"type":26,"value":3620}," (PSI), and ",{"type":20,"tag":120,"props":3622,"children":3624},{"className":3623},[],[3625],{"type":26,"value":3626},"AnyTimeInterrogation",{"type":26,"value":3628}," (ATI) to pinpoint subscriber cell IDs and geographic coordinates.",{"type":20,"tag":58,"props":3630,"children":3631},{},[3632,3637,3639,3645,3647,3653],{"type":20,"tag":33,"props":3633,"children":3634},{},[3635],{"type":26,"value":3636},"SMS & Voice Interception",{"type":26,"value":3638},": Execute ",{"type":20,"tag":120,"props":3640,"children":3642},{"className":3641},[],[3643],{"type":26,"value":3644},"UpdateLocation",{"type":26,"value":3646}," (UL) and ",{"type":20,"tag":120,"props":3648,"children":3650},{"className":3649},[],[3651],{"type":26,"value":3652},"InsertSubscriberData",{"type":26,"value":3654}," (ISD) to hijack inbound SMS verification codes and 2FA tokens.",{"type":20,"tag":58,"props":3656,"children":3657},{},[3658,3663,3664,3670,3672,3678],{"type":20,"tag":33,"props":3659,"children":3660},{},[3661],{"type":26,"value":3662},"Denial of Service (DoS)",{"type":26,"value":3638},{"type":20,"tag":120,"props":3665,"children":3667},{"className":3666},[],[3668],{"type":26,"value":3669},"PurgeMS",{"type":26,"value":3671}," and ",{"type":20,"tag":120,"props":3673,"children":3675},{"className":3674},[],[3676],{"type":26,"value":3677},"CancelLocation",{"type":26,"value":3679}," to detach subscribers from cellular operator VLRs.",{"type":20,"tag":58,"props":3681,"children":3682},{},[3683,3688,3689,3695,3697,3703,3705,3711],{"type":20,"tag":33,"props":3684,"children":3685},{},[3686],{"type":26,"value":3687},"Diameter 4G\u002FLTE Attacks",{"type":26,"value":3638},{"type":20,"tag":120,"props":3690,"children":3692},{"className":3691},[],[3693],{"type":26,"value":3694},"ULR",{"type":26,"value":3696}," (Update-Location-Request), ",{"type":20,"tag":120,"props":3698,"children":3700},{"className":3699},[],[3701],{"type":26,"value":3702},"CLR",{"type":26,"value":3704}," (Cancel-Location-Request), and ",{"type":20,"tag":120,"props":3706,"children":3708},{"className":3707},[],[3709],{"type":26,"value":3710},"PUR",{"type":26,"value":3712}," (Purge-UE-Request) across S6a interfaces.",{"type":20,"tag":47,"props":3714,"children":3715},{"id":740},[3716],{"type":26,"value":743},{"type":20,"tag":105,"props":3718,"children":3720},{"id":3719},"_1-launch-sigploit-cli",[3721],{"type":26,"value":3722},"1. Launch SigPloit CLI",{"type":20,"tag":112,"props":3724,"children":3727},{"className":3725,"code":3726,"language":117,"meta":8},[115],"# Launch SigPloit interactive console\nsigploit\n",[3728],{"type":20,"tag":120,"props":3729,"children":3730},{"__ignoreMap":8},[3731],{"type":26,"value":3726},{"type":20,"tag":105,"props":3733,"children":3735},{"id":3734},"_2-configure-local-remote-sctp-signatures",[3736],{"type":26,"value":3737},"2. Configure Local & Remote SCTP Signatures",{"type":20,"tag":112,"props":3739,"children":3742},{"className":3740,"code":3741,"language":117,"meta":8},[115],"# Within SigPloit console:\nsigploit > use ss7\u002Ftracking\u002Fpsi\nsigploit (ss7\u002Ftracking\u002Fpsi) > set LocalIP 192.168.1.100\nsigploit (ss7\u002Ftracking\u002Fpsi) > set RemoteIP 10.10.20.1\nsigploit (ss7\u002Ftracking\u002Fpsi) > set RemotePort 2905\nsigploit (ss7\u002Ftracking\u002Fpsi) > set TargetIMSI 001010123456789\nsigploit (ss7\u002Ftracking\u002Fpsi) > run\n",[3743],{"type":20,"tag":120,"props":3744,"children":3745},{"__ignoreMap":8},[3746],{"type":26,"value":3741},{"type":20,"tag":105,"props":3748,"children":3750},{"id":3749},"_3-diameter-s6a-location-tracking",[3751],{"type":26,"value":3752},"3. Diameter S6a Location Tracking",{"type":20,"tag":112,"props":3754,"children":3757},{"className":3755,"code":3756,"language":117,"meta":8},[115],"# Execute Diameter User-Authorization \u002F Location check\nsigploit > use diameter\u002Ftracking\u002Fulr\nsigploit (diameter\u002Ftracking\u002Fulr) > set TargetIMSI 208950000000001\nsigploit (diameter\u002Ftracking\u002Fulr) > set DestinationHost hss.mnc095.mcc208.3gppnetwork.org\nsigploit (diameter\u002Ftracking\u002Fulr) > run\n",[3758],{"type":20,"tag":120,"props":3759,"children":3760},{"__ignoreMap":8},[3761],{"type":26,"value":3756},{"type":20,"tag":47,"props":3763,"children":3764},{"id":776},[3765],{"type":26,"value":779},{"type":20,"tag":29,"props":3767,"children":3768},{},[3769,3771],{"type":26,"value":3770},"To practice SS7\u002FDiameter attacks against isolated carrier STP\u002FHSS nodes in private cloud testbeds:\n👉 ",{"type":20,"tag":33,"props":3772,"children":3773},{},[3774],{"type":20,"tag":169,"props":3775,"children":3777},{"href":15,"rel":3776},[172],[3778],{"type":26,"value":3779},"Access the SS7\u002FDiameter Signaling Lab at App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":3781},[3782,3783,3788],{"id":3588,"depth":177,"text":3591},{"id":740,"depth":177,"text":743,"children":3784},[3785,3786,3787],{"id":3719,"depth":183,"text":3722},{"id":3734,"depth":183,"text":3737},{"id":3749,"depth":183,"text":3752},{"id":776,"depth":177,"text":779},"content:tools:sigploit.md","tools\u002Fsigploit.md","tools\u002Fsigploit",{"_path":3793,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":3794,"description":3795,"name":3794,"protocol":3796,"category":1820,"hardware":3797,"command":3798,"academyLab":15,"body":3799,"_type":187,"_id":3919,"_source":189,"_file":3920,"_stem":3921,"_extension":192},"\u002Ftools\u002Fsipp","SIPp","High-performance SIP protocol generator and traffic fuzzer for testing VoLTE, VoNR, IMS, and telecom PBX security.","SIP \u002F IMS \u002F VoLTE","Ethernet \u002F IP Interface","sipp -sn uac 10.0.0.1",{"type":17,"children":3800,"toc":3911},[3801,3807,3822,3828,3861,3865,3871,3880,3886,3895,3899],{"type":20,"tag":21,"props":3802,"children":3804},{"id":3803},"sipp-sip-ims-volte-traffic-generator-security-fuzzer",[3805],{"type":26,"value":3806},"SIPp — SIP, IMS & VoLTE Traffic Generator & Security Fuzzer",{"type":20,"tag":29,"props":3808,"children":3809},{},[3810,3814,3816,3820],{"type":20,"tag":33,"props":3811,"children":3812},{},[3813],{"type":26,"value":3794},{"type":26,"value":3815}," is the industry-standard performance testing, traffic generation, and fuzzing tool for the Session Initiation Protocol (SIP). In ",{"type":20,"tag":33,"props":3817,"children":3818},{},[3819],{"type":26,"value":43},{"type":26,"value":3821},", SIPp comes bundled with specialized XML scenarios for fuzzing VoLTE (Voice over LTE) and VoNR (Voice over New Radio) IMS network components including P-CSCF, S-CSCF, and I-CSCF proxies.",{"type":20,"tag":47,"props":3823,"children":3825},{"id":3824},"key-telecom-security-use-cases",[3826],{"type":26,"value":3827},"Key Telecom Security Use Cases",{"type":20,"tag":54,"props":3829,"children":3830},{},[3831,3841,3851],{"type":20,"tag":58,"props":3832,"children":3833},{},[3834,3839],{"type":20,"tag":33,"props":3835,"children":3836},{},[3837],{"type":26,"value":3838},"VoLTE & VoNR IMS Core Fuzzing",{"type":26,"value":3840},": Test SIP invite message handling, header parsing vulnerabilities, and buffer overflows.",{"type":20,"tag":58,"props":3842,"children":3843},{},[3844,3849],{"type":20,"tag":33,"props":3845,"children":3846},{},[3847],{"type":26,"value":3848},"SIP Authentication Bypass Testing",{"type":26,"value":3850},": Verify nonce validation, digest authentication, and registration spoofing.",{"type":20,"tag":58,"props":3852,"children":3853},{},[3854,3859],{"type":20,"tag":33,"props":3855,"children":3856},{},[3857],{"type":26,"value":3858},"Telecom DoS & Flooding Simulation",{"type":26,"value":3860},": Simulate high-velocity call invite storms to evaluate IMS SBC (Session Border Controller) rate-limiting thresholds.",{"type":20,"tag":47,"props":3862,"children":3863},{"id":1313},[3864],{"type":26,"value":1316},{"type":20,"tag":105,"props":3866,"children":3868},{"id":3867},"_1-execute-default-volte-user-agent-client-uac-scenario",[3869],{"type":26,"value":3870},"1. Execute Default VoLTE User Agent Client (UAC) Scenario",{"type":20,"tag":112,"props":3872,"children":3875},{"className":3873,"code":3874,"language":117,"meta":8},[115],"# Send 10 calls per second to target IMS P-CSCF\nsipp -sn uac -r 10 -l 50 192.168.100.10:5060\n",[3876],{"type":20,"tag":120,"props":3877,"children":3878},{"__ignoreMap":8},[3879],{"type":26,"value":3874},{"type":20,"tag":105,"props":3881,"children":3883},{"id":3882},"_2-run-custom-malformed-sip-invite-fuzzing-scenario",[3884],{"type":26,"value":3885},"2. Run Custom Malformed SIP Invite Fuzzing Scenario",{"type":20,"tag":112,"props":3887,"children":3890},{"className":3888,"code":3889,"language":117,"meta":8},[115],"# Execute XML scenario injecting malformed headers\nsipp -sf \u002Fopt\u002Ftelcochisel\u002Fscenarios\u002Fvolte_fuzz.xml 192.168.100.10:5060 -trace_err\n",[3891],{"type":20,"tag":120,"props":3892,"children":3893},{"__ignoreMap":8},[3894],{"type":26,"value":3889},{"type":20,"tag":47,"props":3896,"children":3897},{"id":156},[3898],{"type":26,"value":159},{"type":20,"tag":29,"props":3900,"children":3901},{},[3902,3903],{"type":26,"value":164},{"type":20,"tag":33,"props":3904,"children":3905},{},[3906],{"type":20,"tag":169,"props":3907,"children":3909},{"href":15,"rel":3908},[172],[3910],{"type":26,"value":1935},{"title":8,"searchDepth":177,"depth":177,"links":3912},[3913,3914,3918],{"id":3824,"depth":177,"text":3827},{"id":1313,"depth":177,"text":1316,"children":3915},[3916,3917],{"id":3867,"depth":183,"text":3870},{"id":3882,"depth":183,"text":3885},{"id":156,"depth":177,"text":159},"content:tools:sipp.md","tools\u002Fsipp.md","tools\u002Fsipp",{"_path":3923,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":3924,"description":3925,"name":3926,"protocol":2234,"category":3927,"hardware":3928,"command":3929,"academyLab":15,"body":3930,"_type":187,"_id":4072,"_source":189,"_file":4073,"_stem":4074,"_extension":192},"\u002Ftools\u002Fsrsran","srsRAN 4G & 5G","Open-source SDR 4G and 5G software radio suite implementing eNodeB, gNodeB, and User Equipment (UE) stacks for over-the-air RF testing.","srsRAN","Software Defined Radio Base Station & UE","USRP B210 \u002F BladeRF \u002F LimeSDR","srsenb \u002Fetc\u002Fsrsran\u002Fenb.conf",{"type":17,"children":3931,"toc":4063},[3932,3938,3957,3963,3996,4000,4006,4015,4021,4030,4036,4045,4049],{"type":20,"tag":21,"props":3933,"children":3935},{"id":3934},"srsran-4g-lte-5g-nr-software-radio-suite",[3936],{"type":26,"value":3937},"srsRAN — 4G LTE & 5G NR Software Radio Suite",{"type":20,"tag":29,"props":3939,"children":3940},{},[3941,3943,3947,3949,3955],{"type":26,"value":3942},"srsRAN (formerly srsLTE) provides a modular, high-performance C++ software radio implementation of 3GPP cellular networks. In ",{"type":20,"tag":33,"props":3944,"children":3945},{},[3946],{"type":26,"value":43},{"type":26,"value":3948},", srsRAN is linked against the ",{"type":20,"tag":120,"props":3950,"children":3952},{"className":3951},[],[3953],{"type":26,"value":3954},"PREEMPT_RT",{"type":26,"value":3956}," realtime kernel and pre-tuned UHD drivers to prevent USB buffer dropouts during high-throughput 5G NR transmissions.",{"type":20,"tag":47,"props":3958,"children":3960},{"id":3959},"use-cases-security-audits",[3961],{"type":26,"value":3962},"Use Cases & Security Audits",{"type":20,"tag":54,"props":3964,"children":3965},{},[3966,3976,3986],{"type":20,"tag":58,"props":3967,"children":3968},{},[3969,3974],{"type":20,"tag":33,"props":3970,"children":3971},{},[3972],{"type":26,"value":3973},"Rogue Base Station (IMSI-Catching)",{"type":26,"value":3975},": Spin up private eNodeBs to audit UE attach procedures, encryption cipher negotiation (EEA0 vs EEA2), and emergency broadcast spoofing.",{"type":20,"tag":58,"props":3977,"children":3978},{},[3979,3984],{"type":20,"tag":33,"props":3980,"children":3981},{},[3982],{"type":26,"value":3983},"5G SA gNodeB Air Interface",{"type":26,"value":3985},": Interconnect directly with Open5GS or free5GC cores over standard N2\u002FN3 interfaces using USRP B210 or X310 SDRs.",{"type":20,"tag":58,"props":3987,"children":3988},{},[3989,3994],{"type":20,"tag":33,"props":3990,"children":3991},{},[3992],{"type":26,"value":3993},"Cipher Downgrade Testing",{"type":26,"value":3995},": Test mobile device fallback from 5G to 4G\u002F2G under RF jamming conditions.",{"type":20,"tag":47,"props":3997,"children":3998},{"id":740},[3999],{"type":26,"value":743},{"type":20,"tag":105,"props":4001,"children":4003},{"id":4002},"_1-check-connected-sdr-hardware",[4004],{"type":26,"value":4005},"1. Check Connected SDR Hardware",{"type":20,"tag":112,"props":4007,"children":4010},{"className":4008,"code":4009,"language":117,"meta":8},[115],"# Verify USRP UHD detection and bandwidth calibration\nuhd_usrp_probe --args=\"type=b200\"\n",[4011],{"type":20,"tag":120,"props":4012,"children":4013},{"__ignoreMap":8},[4014],{"type":26,"value":4009},{"type":20,"tag":105,"props":4016,"children":4018},{"id":4017},"_2-launch-4g-enodeb-with-live-spectrum",[4019],{"type":26,"value":4020},"2. Launch 4G eNodeB with Live Spectrum",{"type":20,"tag":112,"props":4022,"children":4025},{"className":4023,"code":4024,"language":117,"meta":8},[115],"# Start eNodeB transmitting on LTE Band 7 (2.6 GHz)\nsudo srsenb \u002Fetc\u002Fsrsran\u002Fenb.conf --enb.n_prb=50 --rf.device_name=uhd\n",[4026],{"type":20,"tag":120,"props":4027,"children":4028},{"__ignoreMap":8},[4029],{"type":26,"value":4024},{"type":20,"tag":105,"props":4031,"children":4033},{"id":4032},"_3-launch-5g-nr-gnodeb-srsran-5g-project",[4034],{"type":26,"value":4035},"3. Launch 5G NR gNodeB (srsRAN 5G Project)",{"type":20,"tag":112,"props":4037,"children":4040},{"className":4038,"code":4039,"language":117,"meta":8},[115],"# Start 5G Standalone gNodeB in SA Mode\nsudo gnb -c \u002Fetc\u002Fsrsran\u002Fgnb_sa.yml\n",[4041],{"type":20,"tag":120,"props":4042,"children":4043},{"__ignoreMap":8},[4044],{"type":26,"value":4039},{"type":20,"tag":47,"props":4046,"children":4047},{"id":776},[4048],{"type":26,"value":779},{"type":20,"tag":29,"props":4050,"children":4051},{},[4052,4054],{"type":26,"value":4053},"To learn how to operate SDR hardware and simulate rogue cellular base stations safely:\n👉 ",{"type":20,"tag":33,"props":4055,"children":4056},{},[4057],{"type":20,"tag":169,"props":4058,"children":4060},{"href":15,"rel":4059},[172],[4061],{"type":26,"value":4062},"Access the Cellular Radio RF Lab at App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":4064},[4065,4066,4071],{"id":3959,"depth":177,"text":3962},{"id":740,"depth":177,"text":743,"children":4067},[4068,4069,4070],{"id":4002,"depth":183,"text":4005},{"id":4017,"depth":183,"text":4020},{"id":4032,"depth":183,"text":4035},{"id":776,"depth":177,"text":779},"content:tools:srsran.md","tools\u002Fsrsran.md","tools\u002Fsrsran",{"_path":4076,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":4077,"description":4078,"name":4077,"protocol":4079,"category":4080,"hardware":4081,"command":4082,"academyLab":15,"body":4083,"_type":187,"_id":4219,"_source":189,"_file":4220,"_stem":4221,"_extension":192},"\u002Ftools\u002Fss7maper","SS7MAPer","Fast SS7 MAP (Mobile Application Part) scanner and network topology mapper for telecommunications security audits.","SS7 \u002F SIGTRAN","SS7 \u002F SIGTRAN Signaling Auditing","None (IP \u002F SCTP Interface)","python3 ss7maper.py --target-gt 123456789",{"type":17,"children":4084,"toc":4211},[4085,4091,4100,4106,4160,4164,4170,4179,4185,4194,4198],{"type":20,"tag":21,"props":4086,"children":4088},{"id":4087},"ss7maper-ss7-map-reconnaissance-network-scanner",[4089],{"type":26,"value":4090},"SS7MAPer — SS7 MAP Reconnaissance & Network Scanner",{"type":20,"tag":29,"props":4092,"children":4093},{},[4094,4098],{"type":20,"tag":33,"props":4095,"children":4096},{},[4097],{"type":26,"value":4077},{"type":26,"value":4099}," is an automated reconnaissance and network topology mapping engine for telecom SS7\u002FSIGTRAN signaling backbones. It probes target carrier Global Titles (GT) and Point Codes (PC) to discover active HLRs, MSCs, VLRs, and SMSCs while testing MAP protocol message filtering rules.",{"type":20,"tag":47,"props":4101,"children":4103},{"id":4102},"core-telecom-vectors",[4104],{"type":26,"value":4105},"Core Telecom Vectors",{"type":20,"tag":54,"props":4107,"children":4108},{},[4109,4119,4150],{"type":20,"tag":58,"props":4110,"children":4111},{},[4112,4117],{"type":20,"tag":33,"props":4113,"children":4114},{},[4115],{"type":26,"value":4116},"Global Title Scanning & Resolution",{"type":26,"value":4118},": Discover active network nodes across target Mobile Country Codes (MCC) and Mobile Network Codes (MNC).",{"type":20,"tag":58,"props":4120,"children":4121},{},[4122,4127,4129,4135,4137,4142,4143,4148],{"type":20,"tag":33,"props":4123,"children":4124},{},[4125],{"type":26,"value":4126},"MAP Operation Probing",{"type":26,"value":4128},": Test whether target carrier nodes respond to unauthorized MAP messages (",{"type":20,"tag":120,"props":4130,"children":4132},{"className":4131},[],[4133],{"type":26,"value":4134},"SendRoutingInfo",{"type":26,"value":4136},", ",{"type":20,"tag":120,"props":4138,"children":4140},{"className":4139},[],[4141],{"type":26,"value":3626},{"type":26,"value":4136},{"type":20,"tag":120,"props":4144,"children":4146},{"className":4145},[],[4147],{"type":26,"value":3618},{"type":26,"value":4149},").",{"type":20,"tag":58,"props":4151,"children":4152},{},[4153,4158],{"type":20,"tag":33,"props":4154,"children":4155},{},[4156],{"type":26,"value":4157},"Signaling Firewall Fingerprinting",{"type":26,"value":4159},": Identify and classify carrier SMS\u002FMAP firewalls and SMS Routers.",{"type":20,"tag":47,"props":4161,"children":4162},{"id":1313},[4163],{"type":26,"value":1316},{"type":20,"tag":105,"props":4165,"children":4167},{"id":4166},"_1-scan-carrier-global-title-range",[4168],{"type":26,"value":4169},"1. Scan Carrier Global Title Range",{"type":20,"tag":112,"props":4171,"children":4174},{"className":4172,"code":4173,"language":117,"meta":8},[115],"# Scan a range of GTs to identify active HLR \u002F VLR nodes\npython3 \u002Fopt\u002Fss7maper\u002Fss7maper.py -r 33600000000-33600000100 --op SRI_SM\n",[4175],{"type":20,"tag":120,"props":4176,"children":4177},{"__ignoreMap":8},[4178],{"type":26,"value":4173},{"type":20,"tag":105,"props":4180,"children":4182},{"id":4181},"_2-fingerprint-hlr-response-behavior",[4183],{"type":26,"value":4184},"2. Fingerprint HLR Response Behavior",{"type":20,"tag":112,"props":4186,"children":4189},{"className":4187,"code":4188,"language":117,"meta":8},[115],"# Send targeted SRI_SM query to check for subscriber IMSI exposure\npython3 \u002Fopt\u002Fss7maper\u002Fss7maper.py -t 447700900000 --imsi-probe\n",[4190],{"type":20,"tag":120,"props":4191,"children":4192},{"__ignoreMap":8},[4193],{"type":26,"value":4188},{"type":20,"tag":47,"props":4195,"children":4196},{"id":156},[4197],{"type":26,"value":159},{"type":20,"tag":29,"props":4199,"children":4200},{},[4201,4202],{"type":26,"value":164},{"type":20,"tag":33,"props":4203,"children":4204},{},[4205],{"type":20,"tag":169,"props":4206,"children":4208},{"href":15,"rel":4207},[172],[4209],{"type":26,"value":4210},"Launch SS7 Attack & Reconnaissance Labs on App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":4212},[4213,4214,4218],{"id":4102,"depth":177,"text":4105},{"id":1313,"depth":177,"text":1316,"children":4215},[4216,4217],{"id":4166,"depth":183,"text":4169},{"id":4181,"depth":183,"text":4184},{"id":156,"depth":177,"text":159},"content:tools:ss7maper.md","tools\u002Fss7maper.md","tools\u002Fss7maper",{"_path":4223,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":4224,"description":4225,"name":4224,"protocol":197,"category":4226,"hardware":4227,"command":4228,"academyLab":15,"body":4229,"_type":187,"_id":4386,"_source":189,"_file":4387,"_stem":4388,"_extension":192},"\u002Ftools\u002Fueransim","UERANSIM","State-of-the-art open source 5G NR User Equipment (UE) and gNodeB (gNB) simulator for testing 5G Standalone SA Core networks.","Radio Access Network & UE Emulation","USRP B210 \u002F LimeSDR \u002F Pure Software Emulation","nr-gnb -c \u002Fetc\u002Fueransim\u002Fgnb.yaml",{"type":17,"children":4230,"toc":4377},[4231,4237,4252,4258,4309,4315,4321,4330,4336,4345,4351,4360,4364],{"type":20,"tag":21,"props":4232,"children":4234},{"id":4233},"ueransim-5g-nr-ue-gnodeb-emulator",[4235],{"type":26,"value":4236},"UERANSIM — 5G NR UE & gNodeB Emulator",{"type":20,"tag":29,"props":4238,"children":4239},{},[4240,4244,4246,4250],{"type":20,"tag":33,"props":4241,"children":4242},{},[4243],{"type":26,"value":4224},{"type":26,"value":4245}," is a high-performance open-source 5G SA Radio Access Network (RAN) and User Equipment (UE) simulator. In ",{"type":20,"tag":33,"props":4247,"children":4248},{},[4249],{"type":26,"value":43},{"type":26,"value":4251},", UERANSIM allows security researchers to simulate hundreds of rogue 5G UEs and fake gNodeBs without requiring physical RF hardware.",{"type":20,"tag":47,"props":4253,"children":4255},{"id":4254},"key-security-audit-capabilities",[4256],{"type":26,"value":4257},"Key Security Audit Capabilities",{"type":20,"tag":54,"props":4259,"children":4260},{},[4261,4271,4281,4299],{"type":20,"tag":58,"props":4262,"children":4263},{},[4264,4269],{"type":20,"tag":33,"props":4265,"children":4266},{},[4267],{"type":26,"value":4268},"Simulated 5G UE Registration & NAS Security",{"type":26,"value":4270},": Test 5G-GUTI allocation, AKA authentication, and NAS-5GS security mode command enforcement.",{"type":20,"tag":58,"props":4272,"children":4273},{},[4274,4279],{"type":20,"tag":33,"props":4275,"children":4276},{},[4277],{"type":26,"value":4278},"Rogue gNodeB Injection",{"type":26,"value":4280},": Establish unauthorized SCTP associations to test AMF admission control and NGAP malformed message handling.",{"type":20,"tag":58,"props":4282,"children":4283},{},[4284,4289,4291,4297],{"type":20,"tag":33,"props":4285,"children":4286},{},[4287],{"type":26,"value":4288},"5G PDU Session Establishment & Traffic Hijacking",{"type":26,"value":4290},": Create ",{"type":20,"tag":120,"props":4292,"children":4294},{"className":4293},[],[4295],{"type":26,"value":4296},"uesimtun0",{"type":26,"value":4298}," virtual network interfaces to send arbitrary TCP\u002FUDP packets through 5G UPF data plane tunnels.",{"type":20,"tag":58,"props":4300,"children":4301},{},[4302,4307],{"type":20,"tag":33,"props":4303,"children":4304},{},[4305],{"type":26,"value":4306},"Multi-UE Denial-of-Service Fuzzing",{"type":26,"value":4308},": Spin up concurrent simulated UEs to stress-test 5G Core registration throttling and resource exhaustion.",{"type":20,"tag":47,"props":4310,"children":4312},{"id":4311},"telcochisel-cheatsheet",[4313],{"type":26,"value":4314},"TelcoChisel Cheatsheet",{"type":20,"tag":105,"props":4316,"children":4318},{"id":4317},"_1-start-simulated-5g-gnodeb",[4319],{"type":26,"value":4320},"1. Start Simulated 5G gNodeB",{"type":20,"tag":112,"props":4322,"children":4325},{"className":4323,"code":4324,"language":117,"meta":8},[115],"# Start gNodeB connecting to local AMF at 127.0.0.1\nsudo nr-gnb -c \u002Fetc\u002Fueransim\u002Fopen5gs-gnb.yaml\n",[4326],{"type":20,"tag":120,"props":4327,"children":4328},{"__ignoreMap":8},[4329],{"type":26,"value":4324},{"type":20,"tag":105,"props":4331,"children":4333},{"id":4332},"_2-connect-simulated-5g-ue",[4334],{"type":26,"value":4335},"2. Connect Simulated 5G UE",{"type":20,"tag":112,"props":4337,"children":4340},{"className":4338,"code":4339,"language":117,"meta":8},[115],"# Launch UE with pre-configured SUPI, Key, and OPc\nsudo nr-ue -c \u002Fetc\u002Fueransim\u002Fopen5gs-ue.yaml\n",[4341],{"type":20,"tag":120,"props":4342,"children":4343},{"__ignoreMap":8},[4344],{"type":26,"value":4339},{"type":20,"tag":105,"props":4346,"children":4348},{"id":4347},"_3-verify-5g-tunnel-data-plane-pdu-session",[4349],{"type":26,"value":4350},"3. Verify 5G Tunnel Data Plane (PDU Session)",{"type":20,"tag":112,"props":4352,"children":4355},{"className":4353,"code":4354,"language":117,"meta":8},[115],"# Ping external target via the simulated 5G tun interface\nping -I uesimtun0 8.8.8.8\n",[4356],{"type":20,"tag":120,"props":4357,"children":4358},{"__ignoreMap":8},[4359],{"type":26,"value":4354},{"type":20,"tag":47,"props":4361,"children":4362},{"id":156},[4363],{"type":26,"value":159},{"type":20,"tag":29,"props":4365,"children":4366},{},[4367,4368],{"type":26,"value":164},{"type":20,"tag":33,"props":4369,"children":4370},{},[4371],{"type":20,"tag":169,"props":4372,"children":4374},{"href":15,"rel":4373},[172],[4375],{"type":26,"value":4376},"Access 5G UE & RAN Emulation Labs at App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":4378},[4379,4380,4385],{"id":4254,"depth":177,"text":4257},{"id":4311,"depth":177,"text":4314,"children":4381},[4382,4383,4384],{"id":4317,"depth":183,"text":4320},{"id":4332,"depth":183,"text":4335},{"id":4347,"depth":183,"text":4350},{"id":156,"depth":177,"text":159},"content:tools:ueransim.md","tools\u002Fueransim.md","tools\u002Fueransim",{"_path":4390,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":4391,"description":4392,"name":4393,"protocol":4394,"category":4395,"hardware":4396,"command":4397,"academyLab":15,"body":4398,"_type":187,"_id":4516,"_source":189,"_file":4517,"_stem":4518,"_extension":192},"\u002Ftools\u002Furh","Universal Radio Hacker (URH)","Complete wireless protocol reverse-engineering suite for recording, demodulating, decoding, and fuzzing custom RF signals and cellular bursts.","URH","RF \u002F Wireless Signaling \u002F SDR","Signal Reverse-Engineering & Protocol Decoder","HackRF \u002F RTL-SDR \u002F USRP \u002F BladeRF \u002F LimeSDR","urh",{"type":17,"children":4399,"toc":4508},[4400,4406,4417,4423,4456,4460,4466,4475,4481,4490,4494],{"type":20,"tag":21,"props":4401,"children":4403},{"id":4402},"universal-radio-hacker-urh-rf-protocol-analysis-suite",[4404],{"type":26,"value":4405},"Universal Radio Hacker (URH) — RF Protocol Analysis Suite",{"type":20,"tag":29,"props":4407,"children":4408},{},[4409,4411,4415],{"type":26,"value":4410},"Universal Radio Hacker (URH) is a complete software suite for wireless protocol analysis with direct SDR transceiver support. In ",{"type":20,"tag":33,"props":4412,"children":4413},{},[4414],{"type":26,"value":43},{"type":26,"value":4416},", URH includes pre-loaded modulation decoders (FSK, ASK, PSK, QAM), cellular burst decoders, and integrated signal replay engines.",{"type":20,"tag":47,"props":4418,"children":4420},{"id":4419},"key-features",[4421],{"type":26,"value":4422},"Key Features",{"type":20,"tag":54,"props":4424,"children":4425},{},[4426,4436,4446],{"type":20,"tag":58,"props":4427,"children":4428},{},[4429,4434],{"type":20,"tag":33,"props":4430,"children":4431},{},[4432],{"type":26,"value":4433},"Raw I\u002FQ Signal Demodulation",{"type":26,"value":4435},": Visually inspect analog I\u002FQ spectrum waterfalls, detect symbol rates, and calculate carrier offsets.",{"type":20,"tag":58,"props":4437,"children":4438},{},[4439,4444],{"type":20,"tag":33,"props":4440,"children":4441},{},[4442],{"type":26,"value":4443},"Bit-Level Protocol Analysis",{"type":26,"value":4445},": Automatically detect preamble patterns, synchronization words, and packet lengths in captured cellular and wireless transmissions.",{"type":20,"tag":58,"props":4447,"children":4448},{},[4449,4454],{"type":20,"tag":33,"props":4450,"children":4451},{},[4452],{"type":26,"value":4453},"RF Packet Injection & Fuzzing",{"type":26,"value":4455},": Transmit crafted packets and altered frames directly through supported full-duplex SDR hardware (HackRF, USRP, BladeRF).",{"type":20,"tag":47,"props":4457,"children":4458},{"id":740},[4459],{"type":26,"value":743},{"type":20,"tag":105,"props":4461,"children":4463},{"id":4462},"_1-launch-urh-graphical-interface",[4464],{"type":26,"value":4465},"1. Launch URH Graphical Interface",{"type":20,"tag":112,"props":4467,"children":4470},{"className":4468,"code":4469,"language":117,"meta":8},[115],"# Launch URH with native Qt hardware acceleration\nurh\n",[4471],{"type":20,"tag":120,"props":4472,"children":4473},{"__ignoreMap":8},[4474],{"type":26,"value":4469},{"type":20,"tag":105,"props":4476,"children":4478},{"id":4477},"_2-capture-wireless-signal-from-cli",[4479],{"type":26,"value":4480},"2. Capture Wireless Signal from CLI",{"type":20,"tag":112,"props":4482,"children":4485},{"className":4483,"code":4484,"language":117,"meta":8},[115],"# Record 10 seconds of raw I\u002FQ data on 868 MHz using HackRF\nurh_cli --device HackRF --frequency 868M --sample-rate 2M --gain 20 --duration 10s --output \u002Ftmp\u002Fcapture.complex\n",[4486],{"type":20,"tag":120,"props":4487,"children":4488},{"__ignoreMap":8},[4489],{"type":26,"value":4484},{"type":20,"tag":47,"props":4491,"children":4492},{"id":776},[4493],{"type":26,"value":779},{"type":20,"tag":29,"props":4495,"children":4496},{},[4497,4499],{"type":26,"value":4498},"To practice RF signal demodulation and protocol fuzzing in hands-on cloud labs:\n👉 ",{"type":20,"tag":33,"props":4500,"children":4501},{},[4502],{"type":20,"tag":169,"props":4503,"children":4505},{"href":15,"rel":4504},[172],[4506],{"type":26,"value":4507},"Access the RF & Signal Analysis Lab at App.TelcoSec.Net",{"title":8,"searchDepth":177,"depth":177,"links":4509},[4510,4511,4515],{"id":4419,"depth":177,"text":4422},{"id":740,"depth":177,"text":743,"children":4512},[4513,4514],{"id":4462,"depth":183,"text":4465},{"id":4477,"depth":183,"text":4480},{"id":776,"depth":177,"text":779},"content:tools:urh.md","tools\u002Furh.md","tools\u002Furh",1790363493770]