Back to updates
UpdatedAug 5, 2026

Mr.SIP — Updated!

SIP Security Assessment Framework for VoIP Pentesters. Presented at DEFCON, BlackHat & Offzone.

Share
Mr.SIP

SIP Security, Attack and Audit Framework

License CI

Black Hat Arsenal Black Hat Arsenal Black Hat Arsenal Black Hat Arsenal Offzone Moscow DEF CON 28 Black Hat Arsenal Securi-Tay 2023 Black Hat MEA 2022 Black Hat Arsenal


Mr.SIP is a simple, console-based SIP audit and attack tool. It was originally developed for academic work on novel SIP-based DDoS attacks, and evolved into a fully functional SIP-based penetration testing tool. It has since been cited in several academic papers and journal articles, and can also be used as a SIP client simulator and traffic generator.

This public repository ships 3 modules — network scanning, user enumeration, and DoS attack simulation. Mr.SIP Pro extends this with more modules and a web GUI.

Documentation

  • Installation — Linux/macOS setup differences, virtual environment setup, when root is actually required
  • Lab Guide — Building a local test target: Docker (PJSIP) and VM (classic chan_sip/Trixbox) labs, generalizing to other Asterisk-based PBXs
  • Usage Guide — Full command reference, what each --mt message type actually does, --if/--pps/--mtu in depth, ngrep, debug mode, architecture/data-flow diagram
  • Mr.SIP Pro comparison — Full public-vs-Pro breakdown, module-by-module
  • CHANGELOG.md — Full version history and technical rationale for each change

Public Version Modules

ModulePurpose
SIP-NES (Network Scanner)Detects SIP components on a network, along with manufacturer/product/version information.
SIP-ENUM (Enumerator)Identifies valid SIP users and their authentication requirements.
SIP-DAS (DoS Attack Simulator)Performs TDoS-based attacks, with a powerful IP-spoofing engine.

Competitive features across all three: high-performance multithreading, IP spoofing, and smart SIP message generation.

This is the public, 3-module version — see what Mr.SIP Pro adds below.

Mr.SIP Pro

Mr.SIP Pro is the most comprehensive attack-oriented VoIP product available — 10 modules across 3 categories (Information Gathering, Vulnerability Scanning, Offensive), plus IP spoofing/message-generation helper components and a GUI, versus this repo's 3 console-only modules.

→ Full Public vs. Pro comparison · mrsip.pro · Pricing · Request a demo

Quick Start

pip install -r requirements.txt

python3 mr.sip.py --help
python3 mr.sip.py --nes  --tn=<target_IP> --mt=options --from=<ext> --to=<ext>
python3 mr.sip.py --enum --from=<wordlist_file> [--tn=<target_IP>]
python3 mr.sip.py --das  --mt=invite -c <count> --tn=<target_IP> [-r|-s|-m --il=<file>]

See the Installation Guide for OS-specific setup and the Usage Guide for the full command/flag reference.

SIP-NES scan output

Development

This repo has a real test suite and CI - see CHANGELOG.md for the full technical history of fixes and hardening work.

pip install -r tests/requirements-dev.txt
pytest              # 262 tests, network-free, runs in a couple seconds
ruff check src/ tests/ mr.sip.py

Recognition

Mr.SIP started as academic research into novel SIP-based DDoS attacks and grew into a tool presented at some of the industry's largest security conferences, cited across peer-reviewed literature, and recognized in national innovation competitions.

Global Stage Recognition

Categories