← Back to Tools Directory

free5GC

5G NR

Open-source 5G Core Network (3GPP Release 15/16) written in Go, designed for research and telecom security auditing.

Domain / Category5G Core Network & Evolved Packet Core
Required HardwareUSRP B210 / LimeSDR / BladeRF
Primary Binary./run.sh

free5GC — 5G Standalone Core Security Platform

free5GC is a widely adopted open-source 5G Core Network written natively in Go. Within TelcoChisel, free5GC is packaged with modular network function configurations, MongoDB persistence, and real-time SBI tracing scripts.

Key Capabilities & Security Vectors

  • Go-based 5G SBA Functions: Complete implementations of NSSF, NRF, UDR, UDM, AUSF, N3IWF, AMF, PCF, SMF, and UPF.
  • N2/N3 Interface Auditing: Test gNodeB SCTP signaling to AMF and GTP-U data tunnel encapsulation to UPF.
  • Non-3GPP Interworking (N3IWF): Test untrusted Wi-Fi access integration, IKEv2 / IPsec tunnel establishment, and authentication bypasses.
  • Microservice Isolation & Policy Auditing: Fuzz HTTP/2 Service-Based Interfaces (SBI) between NFs to discover privilege escalation paths.

TelcoChisel Execution Cheatsheet

1. Run Complete free5GC Core

# Launch free5GC core network functions with default logging
cd /opt/free5gc && sudo ./run.sh

2. Inspect 5G Core Web Management Console

# Start free5GC webconsole on port 5000
cd /opt/free5gc/webconsole && ./bin/webconsole
# Open in browser: http://localhost:5000 (admin / free5gc)

3. Fuzz SBA API Endpoints

# Verify NRF registration endpoint via curl
curl -k -X GET http://127.0.0.10:8000/nnrf-disc/v1/nf-instances?nf-type=AMF

Practice in TelcoSec Academy

👉 Launch 5G Core Security Lab on App.TelcoSec.Net

Cloudflare D1 Verified

Community Test Notes & Field Feedback

No community field notes posted yet. Be the first telecom engineer to leave feedback!