← Back to Tools Directory

srsRAN 4G & 5G

5G NR / 4G LTE

Open-source SDR 4G and 5G software radio suite implementing eNodeB, gNodeB, and User Equipment (UE) stacks for over-the-air RF testing.

Domain / CategorySoftware Defined Radio Base Station & UE
Required HardwareUSRP B210 / BladeRF / LimeSDR
Primary Binarysrsenb

srsRAN — 4G LTE & 5G NR Software Radio Suite

srsRAN (formerly srsLTE) provides a modular, high-performance C++ software radio implementation of 3GPP cellular networks. In TelcoChisel, srsRAN is linked against the PREEMPT_RT realtime kernel and pre-tuned UHD drivers to prevent USB buffer dropouts during high-throughput 5G NR transmissions.

Use Cases & Security Audits

  • Rogue Base Station (IMSI-Catching): Spin up private eNodeBs to audit UE attach procedures, encryption cipher negotiation (EEA0 vs EEA2), and emergency broadcast spoofing.
  • 5G SA gNodeB Air Interface: Interconnect directly with Open5GS or free5GC cores over standard N2/N3 interfaces using USRP B210 or X310 SDRs.
  • Cipher Downgrade Testing: Test mobile device fallback from 5G to 4G/2G under RF jamming conditions.

Pre-installed TelcoChisel Cheatsheet

1. Check Connected SDR Hardware

# Verify USRP UHD detection and bandwidth calibration
uhd_usrp_probe --args="type=b200"

2. Launch 4G eNodeB with Live Spectrum

# Start eNodeB transmitting on LTE Band 7 (2.6 GHz)
sudo srsenb /etc/srsran/enb.conf --enb.n_prb=50 --rf.device_name=uhd

3. Launch 5G NR gNodeB (srsRAN 5G Project)

# Start 5G Standalone gNodeB in SA Mode
sudo gnb -c /etc/srsran/gnb_sa.yml

Practice in TelcoSec Cloud Academy

To learn how to operate SDR hardware and simulate rogue cellular base stations safely: 👉 Access the Cellular Radio RF Lab at App.TelcoSec.Net

Cloudflare D1 Verified

Community Test Notes & Field Feedback

No community field notes posted yet. Be the first telecom engineer to leave feedback!