Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Awesome-Cellular-Hacking — Awesome-Cellular-Hacking | Kitploit
Tools/GitHubGitHub/w00t3k/awesome-cellular-hacking
ReconnaissanceExploitationForensicsFuzzingWireless SecurityHardware & IoT SecurityPapers & ResearchLearning & EducationCurated Resources
GitHubw00t3k/awesome-cellular-hacking

Awesome-Cellular-Hacking

Awesome-Cellular-Hacking

4.0k6711613 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

Awesome Cellular Hacking

A comprehensive curated list of resources for 2G/3G/4G/5G cellular security research and analysis

This repository consolidates community knowledge in the cellular security space, including exploits, research papers, tools, and educational resources. The goal is to preserve and organize important security research that might otherwise become difficult to find.

Disclaimer: This information is intended for educational and defensive security research purposes only. Use responsibly and in compliance with applicable laws and regulations.

Table of Contents

  • Getting Started
  • Rogue Base Stations
  • Recent Updates (2024-2025)
  • Software and Tools
  • Hardware Setup
  • Testing and Research Methodologies
  • Attack Vectors
  • Conference Talks
  • Research Papers
  • Equipment and Hardware
  • Detection and Defense
  • Cellular IoT and NB-IoT Security
  • Satellite-Cellular Integration
  • Private 5G Network Security
  • Network Slicing and Edge Security
  • Automotive and Industrial Cellular
  • Forensics and Investigation
  • Vulnerability Disclosure
  • SIM Security
  • SS7 and Telecom Infrastructure
  • Surveillance Technology
  • Recent CVEs and Updates
  • International Research
  • Training and Education
  • Vendor-Specific Research
  • Roaming and Interconnect Security
  • Community
  • Resources

Getting Started

New to cellular security research? This section outlines the recommended path for building foundational skills.

Skill Levels

Beginner (passive listening only)

  • Hardware: RTL-SDR V3 or V4 ($35-$40), a laptop running Linux
  • Software: GNU Radio, GQRX, gr-gsm
  • First project: Scan and decode GSM frames passively using gr-gsm and Wireshark
  • Reading: NIST SP 800-187 LTE Security Guide

Intermediate (active research lab)

  • Hardware: HackRF One or LimeSDR Mini ($139-$350), programmable SIM cards (sysmoUSIM), a spare Android device
  • Software: srsRAN 4G, Open5GS or Free5GC, OsmocomBB
  • First project: Build a private LTE network in a Faraday cage and connect a test device
  • Reading: srsRAN documentation, Open5GS tutorials

Advanced (protocol fuzzing and baseband research)

  • Hardware: USRP B210 or BladeRF 2.0, multiple test devices
  • Software: 5GBaseChecker, LTEFuzz, BaseBridge, SigPloit
  • Focus areas: Baseband fuzzing, RAN-Core interface testing, SS7/Diameter signaling

Lab Setup Checklist

  • Linux host (Ubuntu 22.04 or 24.04 recommended)
  • UHD drivers installed and device recognized (uhd_find_devices)
  • Faraday cage or RF shielding for active transmissions
  • Programmable SIM cards (sysmoUSIM-SJA2 or similar)
  • Dedicated test devices (not your daily driver)
  • Isolated network environment (no production network access)

Key Concepts to Understand First

  • 3GPP Architecture Overview: how UE, eNodeB, MME, SGW, PGW fit together
  • IMSI, IMEI, TMSI: subscriber identity fundamentals
  • AKA Protocol: how authentication works in LTE

Rogue Base Stations

GSM/CDMA Traffic Impersonation and Interception

  • How To Build Your Own Rogue GSM BTS For Fun and Profit

    Guide to creating a portable GSM BTS for private networks or security testing. Covers technical setup using relatively inexpensive hardware.

  • How to Create an Evil LTE Twin / LTE Rogue BTS

    Tutorial for setting up a 4G/LTE Evil Twin base station using srsRAN and USRP SDR devices.

  • Practical Attacks Against GSM Networks: Impersonation

    Detailed analysis of GSM base station impersonation using SDR and open source tools.

  • Tutorial: Analyzing GSM with Airprobe and Wireshark

    Step-by-step guide for using RTL-SDR to analyze GSM signals with GR-GSM/Airprobe and Wireshark.

  • GSM/GPRS Traffic Interception for Penetration Testing

    NCC Group research on GSM/GPRS interception capabilities for penetration testing engagements.


Recent Updates (2024-2025)

New Research (2025)

  • RANsacked: 100+ Flaws in LTE and 5G Implementations — University of Florida / NC State, Jan 2025

    Researchers disclosed 119 vulnerabilities (97 CVEs) across seven LTE and three 5G implementations including Open5GS, Magma, OpenAirInterface, Athonet, SD-Core, srsRAN. Every flaw can be used to persistently disrupt city-wide cellular communications. Some require no SIM card — a single unauthenticated packet can crash an MME or AMF.

  • CITesting: Context Integrity Violations in LTE Core Networks — KAIST, ACM CCS 2025 (Distinguished Paper)

    KAIST researchers identified a new class of uplink attacks against LTE core networks. Unlike traditional downlink attacks, these work through legitimate base stations and can affect anyone in the same MME coverage area. All four tested implementations (Open5GS, srsRAN, Amarisoft, Nokia) were vulnerable.

  • Uncovering Hidden Paths in 5G: Protocol Tunneling and Network Boundary Bridging — ACM CCS 2025

    New research on exploiting protocol tunneling in 5G networks to cross network boundaries and reach components that should be isolated.

  • BaseBridge: Over-the-Air and Emulation Testing for Cellular Baseband Firmware — IEEE S&P 2025

    Bridges the gap between over-the-air and emulation-based testing for cellular baseband firmware analysis.

  • 5G Network Slicing: Security Challenges, Attack Vectors, and Mitigation — PMC, July 2025

    Comprehensive classification of attacks across orchestration, virtualization, and inter-slice communication layers in 5G.

  • Survey on 5G Physical Layer Security Threats and Countermeasures — MDPI Sensors, 2024

    In-depth review of PHY layer attack surface in 4G/5G: jamming, spoofing, eavesdropping, pilot contamination, and current SDR-based research tooling.

Base Station Software and Tools (Updated)

  • OpenBTS 2024 Reloaded — Updated for modern UHD drivers and Ubuntu 22.04/24.04
  • OpenAirInterface (OAI) — Complete 3GPP Release-15+ implementation with active 5G development
  • LimeNET CrowdCell — Network-in-a-box with integrated LimeSDR for small cell deployments
  • Amarisoft LTEENB/gNB — Professional-grade LTE/5G NR base station software
  • DragonOS — Ubuntu-based SDR distro with cellular tools pre-installed
  • Magma Core Network — Meta's distributed packet core, now under the Linux Foundation
  • 5GBaseChecker — Automated 5G baseband vulnerability detection tool

Software and Tools

Base Station Software

Configuration Guides

  • BladeRF and YateBTS Configuration
  • srsRAN Project Documentation
  • srsRAN 4G Documentation

Analysis Tools

  • LTE-Cell-Scanner — LTE cell detection and analysis
  • gr-gsm — GSM analysis with GNU Radio
  • IMSI-Catcher Detector — Android app for detecting IMSI catchers
  • QCSuper — Capture 2G-4G traffic using Qualcomm phones
  • 5GBaseChecker — Automated 5G baseband vulnerability detection (Penn State, 2024)
  • FALCON LTE — Fast analysis of LTE control channels in real-time
  • Kalibrate — GSM base station scanner and frequency calibration
  • LTE Sniffer — Open-source LTE downlink/uplink eavesdropper
  • OsmocomBB — Free firmware for mobile phone baseband processors
  • Modmobmap — Mobile network mapping
  • Modmobjam — Mobile jamming research tool
  • CITesting — Systematic testing of context integrity violations in LTE core networks (KAIST, 2025)
  • SigPloit — SS7/Diameter/GTP/SIP signaling security testing framework
  • LTEFuzz — LTE protocol fuzzer from KAIST, predecessor to CITesting; generates malformed NAS/RRC messages
  • Crocodile Hunter — EFF open-source tool for detecting rogue cell towers by wardriving

Hardware Setup

USRP Installation on Linux

root@kitploit:~
# Add Ettus Research repository
sudo add-apt-repository ppa:ettusresearch/uhd
sudo apt-get update

# Install UHD drivers and tools
sudo apt-get install libuhd-dev libuhd003 uhd-host

# Find connected devices
uhd_find_devices

# Download firmware images
cd /usr/lib/uhd/utils/
./uhd_images_downloader.py

# Test device connection
sudo uhd_usrp_probe

SDR Hardware Options

Common SDR Issues and Troubleshooting

IssuePossible Causes
Device not detectedImproper firmware, USB connection issues
Poor signal qualityIncorrect antennas, wrong frequency configuration
Connection failuresWrong SIM, incorrect MCC/MNC codes
Performance issuesVirtualized platform limitations, wrong SDR firmware

Testing and Research Methodologies

Modern Baseband Fuzzing (2024-2025)

  • Budget-Friendly Baseband Fuzzing Setup — DefCon 32, Janne Taponen

    Covers building cost-effective baseband fuzzing rigs using SDRs, using LLMs to accelerate protocol parser development, and testing automotive ECUs, payment terminals, and mobile devices.

  • RANsacked Fuzzing Framework — University of Florida / NC State, ACM CCS 2024

    Domain-informed fuzzing approach targeting RAN-Core interfaces. Discovered 119 vulnerabilities across ten network implementations.

  • BaseBridge — IEEE S&P 2025

    Framework that bridges over-the-air and emulation-based testing for cellular baseband firmware.

Vulnerability Research Tools

  • 5GBaseChecker — Automated 5G baseband vulnerability detection
  • CITesting — Context integrity violation testing for LTE core networks
  • certmitm — TLS implementation testing tool

Attack Vectors

Radio Jamming Attacks

From NIST SP 800-187:

  • Smart Jamming — Targeted channel interference timed to avoid detection
  • Dumb Jamming — Broadband noise across frequency ranges
  • UE Interface Jamming — Preventing UE signaling to eNodeB
  • eNodeB Interface Jamming — Disrupting base station communications

5G Security Research

  • Privacy Attacks on 4G/5G Paging Protocols — NDSS 2019
  • European 5G Security in the Wild — 2023
  • 5G Threat Modeling Framework
  • ENISA 5G Threat Landscape
  • 5GReasoner Analysis Framework
  • 5G NR Jamming, Spoofing, and Sniffing
  • New Privacy Threat on 3G, 4G, and 5G AKA Protocols
  • Insecure Connection Bootstrapping in Cellular Networks
  • Protecting 4G and 5G Cellular Paging Protocols
  • Uncovering Hidden Paths in 5G: Protocol Tunneling — ACM CCS 2025
  • 5G Network Slicing Attack Classification — MDPI, July 2025

LTE/4G Security Research

  • LTRACK: Stealthy Mobile Phone Tracking — USENIX Security 2022
  • Detecting Fake 4G Base Stations in Real Time — Black Hat 2020
  • BaseSAFE: Baseband Fuzzing
  • LTE Public Warning System Attacks
  • Signal Overshadowing Attacks — USENIX Security 2019
  • Breaking LTE on Layer Two
  • LTE/LTE-A Jamming, Spoofing, and Sniffing
  • LTE Protocol Exploits
  • Practical Attacks Against Privacy and Availability
  • LTE Security Assessment
  • LTE Security Disabled: Misconfiguration in Commercial Networks
  • All The 4G Modules Could Be Hacked — Black Hat 2019
  • Paging Storm Attacks Against 4G/LTE Networks
  • Analysis of the LTE Control Plane — IEEE S&P 2019
  • — WOOT 2012

Conference Talks

ACM CCS 2025

  • CITesting: Systematic Testing of Context Integrity Violations in LTE Core Networks — KAIST (Distinguished Paper)

    New class of uplink attacks against LTE core networks that work through legitimate base stations — no rogue BTS required. All four tested implementations were vulnerable, including commercial systems from Nokia and Amarisoft.

  • Uncovering Hidden Paths in 5G: Exploiting Protocol Tunneling and Network Boundary Bridging

    Demonstrates how attackers can use protocol tunneling to traverse network boundaries and reach isolated 5G components.

IEEE S&P 2025

  • BaseBridge: Bridging Over-the-Air and Emulation Testing for Cellular Baseband Firmware

    New framework for cellular baseband firmware security testing that combines emulation and OTA testing approaches.

Black Hat USA 2024

  • 5G Baseband Vulnerabilities — Penn State University

    Researchers disclosed 12 vulnerabilities in 5G basebands from Samsung, MediaTek, and Qualcomm, affecting devices from Google, OPPO, OnePlus, Motorola, and Samsung. Accompanied by the release of the 5GBaseChecker tool.

DefCon 32 (2024)

  • Economizing Mobile Network Warfare: Budget-Friendly Baseband Fuzzing — Janne Taponen

    Making baseband fuzzing accessible with affordable SDR hardware. Covers LLM-assisted protocol parser development and vulnerability discovery across automotive ECUs, payment terminals, and cellular modems.

Black Hat USA 2022

  • Attacks from a New Front Door in 4G and 5G Networks

Black Hat USA 2021

  • Over The Air Baseband Exploit: 5G RCE — White Paper

Black Hat USA 2020

  • Detecting Fake 4G Base Stations in Real Time

Additional Conference Resources

  • NSA PLAYSET GSM — DEF CON 22
  • VoLTE Phreaking — Ralph Moonen
  • RF Exploitation: IoT/OT Hacking with SDR — HITB 2019
  • Bye-Bye IMSI Catchers: Security Enhancements in 5G — HITB 2018
  • Side Channel Attacks in 4G and 5G — Black Hat Europe 2019
  • Dirty Use of USSD Codes in Cellular Networks — TROOPERS 2013, Ravi Borgaonkar
  • Hacking LTE Public Warning Systems — HITB 2019

Research Papers

2025

  • CITesting: Systematic Testing of Context Integrity Violations in LTE Core Networks — ACM CCS 2025 (Distinguished Paper Award)

    KAIST's CITesting tool runs thousands of test cases against LTE core implementations, dwarfing the 31-case coverage of prior tooling (LTEFuzz). All four tested implementations contained CIV vulnerabilities.

  • Uncovering Hidden Paths in 5G: Protocol Tunneling and Network Boundary Bridging — ACM CCS 2025

  • 5G Network Slicing: Security Challenges, Attack Vectors, and Mitigation Approaches — MDPI, July 2025

  • Starshields for iOS: Navigating the Security Cosmos in Satellite Communication — NDSS 2025

    First comprehensive security analysis of Apple's satellite communication features. Researchers reverse-engineered the proprietary protocol, demonstrated restriction bypasses, and built a simulation testbed covering Emergency SOS, Find My, roadside assistance, and iMessage over satellite.

2024

  • RANsacked: A Domain-Informed Approach for Fuzzing LTE and 5G RAN-Core Interfaces — ACM CCS 2024

    119 vulnerabilities, 97 CVEs, across ten implementations. Any one of them enables city-wide disruption of cellular communications.

  • Survey on 5G Physical Layer Security Threats and Countermeasures — MDPI Sensors 2024

    Comprehensive review of PHY-layer attack surface covering eavesdropping, jamming, spoofing, pilot contamination, and SDR-based research frameworks.

  • 5GBaseChecker Tool Release — Penn State University

    Open-source tool for detecting vulnerabilities in 5G baseband implementations. Used to find 12 critical bugs in Samsung, MediaTek, and Qualcomm chipsets.

2019-2023

  • Privacy Attacks on 4G/5G Paging Protocols — NDSS 2019

  • New Vulnerabilities in 4G and 5G Cellular Access Network Protocols — WiSec 2019

    Three new attack classes exploiting unprotected device capability information: identification, bidding-down, and battery drain.

  • New Privacy Threat on 3G, 4G, and Upcoming 5G AKA Protocols

  • BaseSAFE: Baseband SAnitized Fuzzing through Emulation

  • European 5G Security in the Wild — 2023


Equipment and Hardware

Research Equipment Used in "Over The Air Baseband Exploit"


Detection and Defense

Protection from Stingrays and IMSI Catchers

  • CellGuard — SEEMOO Lab, 2024

    iOS app that detects rogue base stations by analyzing baseband packets in real-time. Integrates with the Apple Cell Location Database for anomaly detection. Website — TestFlight Beta

IMSI Catcher Detection and Research

  • SeaGlass: City-Wide IMSI-Catcher Detection — UW
  • SeaGlass Research Paper — PETS 2017
  • Evaluating IMSI Catcher Detectors — Oxford
  • IMSI-Catcher Detector (Android)

Security Advisories

  • CERT Alert: VoLTE Implementation Vulnerabilities

Cellular IoT and NB-IoT Security

  • NB-IoT Security Analysis Framework — Narrowband IoT security research
  • Cat-M1/LTE-M Attack Vectors — GSMA IoT security guidelines
  • Monitoring 5G Core Networks Vulnerabilities With eBPF — IEEE Networking Letters 2025

Satellite-Cellular Integration

  • Starshields for iOS: Satellite Communication Security — NDSS 2025
  • 3GPP Non-Terrestrial Networks (NTN) Security — Official 5G satellite integration specs
  • LEO Satellite Cellular Vulnerabilities — Low Earth Orbit security research

Private 5G Network Security

  • O-RAN Security Research — Open RAN security specifications
  • Private 5G Penetration Testing Guide — Enterprise private network testing
  • Campus 5G Security Assessment — NIST private 5G security guidance

Network Slicing and Edge Security

  • 5G Network Slicing Attack Research — MDPI, July 2025
  • Multi-Access Edge Computing (MEC) Vulnerabilities — ETSI MEC security specs
  • Network Function Virtualization (NFV) Attacks — Virtual network function security

Automotive and Industrial Cellular

  • V2X Security Research — Vehicle-to-everything communications
  • Cellular-V2X Attack Vectors — Automotive cellular security
  • BMW Security Assessment using OpenBTS — Keen Lab / Tencent

Forensics and Investigation

  • XRY Mobile Forensics — Commercial cellular forensics platform
  • Cellebrite UFED — Mobile device extraction tools
  • NIST Mobile Forensics Guidelines — NIST SP 800-101r1

Vulnerability Disclosure

  • Android Security Bulletins — Regular Android/baseband patches
  • Qualcomm Security Bulletins — Snapdragon security updates
  • Samsung Mobile Security — Galaxy security research program
  • Apple Security Research — iOS/baseband security program

SIM Security

  • Rooting SIM Cards — Black Hat 2013, Karsten Nohl
  • SIM Port Hack Case Study
  • Cloning 3G/4G SIM Cards With a PC and an Oscilloscope — Black Hat 2015

SS7 and Telecom Infrastructure

SS7 Attack Research

  • Bypassing GSMA SS7 Recommendations — Kirill Puzankov
  • Attacking SS7 Networks — HES 2010
  • SS7: Locate. Track. Manipulate. — 31C3 2014, Tobias Engel; live demonstration of cross-network subscriber tracking
  • SS7 Map — P1 Security; map of SS7 exposure across global carriers
  • Diameter Vulnerabilities Exposure — GSMA FS.07; official Diameter security guidance for 4G roaming
  • GSMA FS.11 SS7 Security — GSMA baseline SS7 network security requirements

SS7/Diameter Testing Tools

  • SigPloit — Modular testing framework for SS7, Diameter, GTP, and SIP; covers location tracking, call/SMS interception, and DoS scenarios
  • ss7map — Automated SS7 network topology and exposure mapper
  • SCTP scanner — Discovers SCTP-based SS7 endpoints on IP networks

Surveillance Technology

Stingray / IMSI Catchers

  • DHS Stingray Surveillance — Wired
  • Stingray Cost Analysis — Vice
  • NYCLU Stingray Information
  • EFF: Cell Site Simulators / IMSI Catchers
  • WiFi IMSI Catcher — Black Hat Europe 2016

Recent CVEs and Updates

  • NVD CVE Search — Search for cellular-related CVEs
  • Google Project Zero — Ongoing mobile security research
  • Samsung Security Bulletins — Regular baseband updates
  • SIMjacker Research — SIM-based attack evolution

International Research

  • ENISA 5G Reports — EU 5G security assessments
  • KAIST SysSec Lab — Leading cellular security research group (CITesting, LTEFuzz, LTESniffer)
  • Japanese 5G Security Guidelines — Japan national cybersecurity strategy

Training and Education

  • SANS Mobile Security — Professional mobile security courses
  • Offensive Security Mobile Testing — Advanced mobile penetration testing
  • OpenAirInterface Lab Setup — Open-source 5G lab environment
  • GNU Radio / SDR University Courses — SDR educational materials

Vendor-Specific Research

  • Ericsson Security Research
  • Nokia Bell Labs Security
  • Qualcomm Security Bulletins
  • MediaTek Product Security

Roaming and Interconnect Security

  • GRX/IPX Security Research — GSMA roaming security
  • Diameter Protocol Security — 4G/5G signaling security
  • GSMA FS.19 IPX Security — Security requirements for IPX providers handling roaming traffic
  • Roaming Attacks via Diameter — P1 Security analysis of Diameter-based roaming attack surface
  • GTP Vulnerabilities in 4G/5G Roaming — GTP-C and GTP-U attack surface at the roaming interface
  • AdaptiveMobile SS7 Firewall Research — Carrier-grade SS7/Diameter firewall bypass techniques

Resources

Development and Analysis Tools

  • RTL-SDR Community — SDR resources and tutorials
  • MCC-MNC Database — Mobile Country/Network Code reference
  • RFSec-ToolKit — RF security testing tools
  • cellularsecurity.org — Community resource for cellular security research

Research Collections

  • RF Security Documentation
  • USENIX Security Papers — Security conference proceedings
  • ACM Digital Library — ACM research papers
  • IEEE Xplore — IEEE research database

Legal and Regulatory

  • FCC Equipment Authorization Rules — US cellular equipment regulations
  • CISA 5G Security Guidance — US critical infrastructure guidance
  • NIST 5G Cybersecurity — NIST cellular security frameworks

Additional Reading

  • Analyzing GSM Downlink with USRP
  • AT&T Microcell Analysis
  • LTE Recon — DefCon 23
  • LTE Security Guide — NIST SP 800-187
  • LTE Pwnage: Core Network Elements — HITB 2013

Community

Mailing Lists and Forums

  • Osmocom Mailing Lists — Active developer and user lists for OpenBTS, OsmocomBB, srsRAN topics
  • srsRAN Discussions — GitHub Discussions for the srsRAN Project
  • OpenAirInterface Forum — OAI issue tracker and community support
  • Reddit r/RTLSDR — Active SDR community covering cellular scanning and analysis
  • Reddit r/cellmapper — Cell tower mapping and analysis community

IRC and Chat

  • Osmocom IRC — #osmocom on libera.chat; real-time support for Osmocom tools
  • DEF CON RF Village — Annual RF hacking community track at DEF CON

Conferences to Follow

  • DEF CON — RF Village, Wireless Village, and main track cellular talks
  • Black Hat USA/Europe — Regular cellular/baseband research presentations
  • WiSec — ACM Conference on Security and Privacy in Wireless and Mobile Networks
  • IEEE S&P / CCS / USENIX Security — Top-tier academic venue for cellular security papers
  • HITB — Regular telecom security talks

Contributing

Fork the repo, add resources with descriptions, verify links are active, and submit a pull request with context on what was added.

Legal Notice

This repository is for educational and research purposes only. Users are responsible for complying with all applicable laws and regulations. The maintainers do not endorse or encourage illegal activities.


Last Updated: March 2026 Maintainer: @W00t3k

Broken links or new resources? Open an issue or submit a PR.

Download Tool
SoftwareDescriptionLink
OpenBTS (2024 Reloaded)Updated Linux SDR-based GSM air interface for modern systemsGitHub
OpenBTS (Original)Range Networks implementationSourceForge
YateBTSGSM/GPRS radio access network implementationWebsite
srsRAN ProjectOpen-source 5G O-RAN CU/DU software suiteGitHub
srsRAN 4GOpen-source 4G software radio suiteGitHub
OpenAirInterfaceComplete 4G/5G protocol stackWebsite
Free5GCOpen-source 5G core network implementationGitHub
KamailioOpen-source SIP server used in IMS/VoLTE labsWebsite
  • SCAT — Signaling Collection and Analysis Tool; captures diagnostic logs from Qualcomm and Samsung basebands
  • ss7map — SS7 network exposure mapping by P1 Security
  • Diameter EAP Tool (DET) — Diameter protocol fuzzing and testing
  • Osmocom Suite — Complete open-source GSM/GPRS stack: osmo-nitb, osmo-bts, osmo-sgsn, osmo-msc and more
  • HardwareFrequency RangeBandwidthPrice RangeUse CaseLink
    Ettus Research (USRP)
    USRP B21070 MHz - 6 GHz61.44 MHz$2,100Professional development, 2x2 MIMOEttus
    USRP B200mini70 MHz - 6 GHz61.44 MHz$775Compact USRP B-seriesEttus
    USRP N210DC - 6 GHz25 MHz$1,700High-performance networked SDREttus
    USRP N3201 MHz - 6 GHz200 MHz$8,000Networked 2x2 MIMOEttus
    USRP X310DC - 6 GHz160 MHz$6,000High-performance desktop/rackEttus
    USRP X4101 MHz - 7.2 GHz400 MHz$15,000Latest high-performance 4x4 MIMOEttus
    USRP X44030 MHz - 4 GHz1.6 GHz$25,000+Latest 8x8 MIMO RFSoC platformEttus
    USRP E32070 MHz - 6 GHz56 MHz$4,000Embedded 2x2 MIMO SDREttus
    Nuand (BladeRF)
    BladeRF 2.0 xA447 MHz - 6 GHz61.44 MHz$420Budget 2x2 MIMO developmentNuand
    BladeRF 2.0 xA947 MHz - 6 GHz61.44 MHz$720High FPGA resources, 2x2 MIMONuand
    BladeRF x40 (Legacy)300 MHz - 3.8 GHz40 MHz$400Entry-level legacy modelNuand
    Great Scott Gadgets
    HackRF One1 MHz - 6 GHz20 MHz$350Budget TX/RX developmentGSG
    YARD Stick One300-348, 391-464, 782-928 MHz2.5 MHz$110Sub-GHz IoT frequenciesGSG
    Lime Microsystems
    LimeSDR USB100 kHz - 3.8 GHz61.44 MHz$289Open-source 2x2 MIMOLime Micro
    LimeSDR Mini10 MHz - 3.5 GHz30.72 MHz$139Compact LimeSDR variantLime Micro
    LimeSDR Mini 2.010 MHz - 3.5 GHz30.72 MHz$169Updated with ECP5 FPGALime Micro
    LimeSDR X3Various bandsUp to 61.44 MHz$3,000+Professional 3x transceiver PCIeLime Micro
    Analog Devices
    PlutoSDR325 MHz - 3.8 GHz20 MHz$150Education and learning platformAnalog Devices
    RTL-SDR Blog
    RTL-SDR V3500 kHz - 1.75 GHz3.2 MHz$35Ultra-budget RX-only scannerRTL-SDR
    RTL-SDR V4500 kHz - 1.75 GHz3.2 MHz$40Latest with R828D tunerRTL-SDR
    Airspy
    Airspy R224 MHz - 1.8 GHz10 MHz$200High-performance VHF/UHF scannerAirspy
    Airspy Mini24 MHz - 1.8 GHz6 MHz$99Compact Airspy in dongle formatAirspy
    Airspy HF+ Discovery9 kHz - 31 MHz, 60-260 MHz768 kHz$169Dedicated HF receptionAirspy
    SDRplay
    RSP1A1 kHz - 2 GHz10 MHz$119Wideband general purposeSDRplay
    RSPdx1 kHz - 2 GHz10 MHz$299Professional features, dual antennaSDRplay
    Red Pitaya
    STEMlab 125-14DC - 60 MHz50 MHz$600HF transceiver, lab instrumentRed Pitaya
    STEMlab 122-16DC - 50 MHzVariable$625High-resolution HF SDR/scopeRed Pitaya
    Baseband Attacks: Remote Exploitation of Memory Corruptions
  • CITesting: Context Integrity Violations in LTE Core Networks — ACM CCS 2025 (Distinguished Paper)
  • New Vulnerabilities in 4G and 5G Cellular Access Network Protocols — WiSec 2019
  • ComponentPurposeLink
    Ettus USRP B210Software Defined RadioProduct Page
    srsENB4G/5G Base Station SoftwareGitHub
    Open5GS5G Core NetworkGitHub
    sysmo-usim-toolSIM ProgrammingProject Page
    pysimSIM Analysis ToolGitHub
    CoIMSVoLTE TestingPlay Store
    Docker Open5GSContainerized CoreTutorial