← Back to Tools Directory
GNU Radio Telecom OOT
RF / 2G-5GGNU Radio with telecom-specific out-of-tree (OOT) modules for cellular signal processing, LTE/5G channel estimation, custom demodulation, and RF fingerprinting.
GNU Radio Telecom OOT — Cellular SDR Signal Processing
GNU Radio is the foundational SDR signal processing framework, extended in TelcoChisel with telecom-specific out-of-tree (OOT) modules for LTE/5G waveform generation, cellular channel estimation, OFDM subcarrier manipulation, and RF device fingerprinting. Pre-installed OOT blocks include gr-lte, gr-gsm, gr-cellurar, gr-rds, and custom TelcoChisel telecom flow graphs.
Key Capabilities & Security Vectors
- Custom LTE/5G Waveform Generation: Build arbitrary OFDM waveforms matching 3GPP physical layer specifications for protocol-level RF testing.
- Channel Estimation Attacks: Exploit pilot signal knowledge to perform channel estimation on encrypted LTE/5G downlink for passive RF fingerprinting.
- OFDM Subcarrier Injection: Target specific OFDM subcarriers carrying control information (PDCCH, PBCH) for selective signal manipulation.
- RF Device Fingerprinting: Analyze transmitter-specific imperfections (I/Q imbalance, carrier leakage, phase noise) to identify and track individual SDR devices.
TelcoChisel Execution Cheatsheet
1. Launch GNU Radio Companion
# Open the graphical flow graph editor
gnuradio-companion
# Load telecom flow graphs from: /opt/telcochisel/gnuradio-flows/
2. Run LTE Cell Search Flow Graph
# Execute headless LTE cell search using gr-lte blocks
python3 /opt/telcochisel/gnuradio-flows/lte_cell_search.py --freq 1842.5e6 --gain 40
3. Record Wideband Cellular Spectrum
# Capture 20 MHz wideband IQ samples for offline analysis
python3 /opt/telcochisel/gnuradio-flows/wideband_recorder.py --freq 2140e6 --rate 20e6 --duration 30 --output /tmp/capture.cf32
No community field notes posted yet. Be the first telecom engineer to leave feedback!