← Back to Tools Directory

Kraken

GSM 2G / A5/1

Fast GSM A5/1 encryption cracking tool utilizing rainbow tables to reverse-engineer 2G cellular bursts in sub-second timeframes.

Domain / CategoryRF & Baseband Reverse Engineering
Required HardwareHackRF One / RTL-SDR / USRP + SSD Storage
Primary Binarykraken

Kraken — GSM A5/1 Real-Time Cipher Cracker

Kraken is the famous open-source tool for finding 64-bit GSM A5/1 session encryption keys (Kc) in real time using pre-computed Berlin Rainbow Tables. Within TelcoChisel, Kraken is integrated alongside OsmocomBB and gr-gsm for analyzing 2G radio burst captures.

Key Telecom Security Capabilities

  • A5/1 Keystream Cracking: Reverse 114-bit keystreams extracted from encrypted GSM CCH (Control Channel) and TCH (Traffic Channel) bursts.
  • Interception Pipeline Integration: Feeds decrypted session keys directly into Wireshark / gr-gsm for real-time voice and SMS decoding.
  • Carrier Downward Compatibility Audits: Demonstrate why 2G legacy fallbacks remain critical attack surfaces on modern multi-mode smartphones.

Cheatsheet

1. Launch Kraken with Rainbow Tables

# Point Kraken to SSD-mounted A5/1 rainbow tables
cd /opt/kraken && sudo ./kraken /media/fast_ssd/kraken_tables/

2. Crack Keystream Sample

# Query Kraken with 114-bit keystream from gr-gsm
./find_kc 00101011100100100010101010010010110001001010100100101100010010101001001011000100101010010010110001001010100100101100

Practice in TelcoSec Academy

👉 Access GSM & 2G Interception Labs at App.TelcoSec.Net

Cloudflare D1 Verified

Community Test Notes & Field Feedback

No community field notes posted yet. Be the first telecom engineer to leave feedback!