Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Awesome-Cellular-Hacking — Awesome-Cellular-Hacking | Kitploit
Tools/GitHubGitHub/w00t3k/awesome-cellular-hacking
ReconnaissanceExploitationForensicsFuzzingWireless SecurityHardware & IoT SecurityPapers & ResearchLearning & EducationCurated Resources
GitHubw00t3k/awesome-cellular-hacking

Awesome-Cellular-Hacking

Awesome-Cellular-Hacking

4.0k671441 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

Awesome Cellular Hacking

A comprehensive curated list of resources for 2G/3G/4G/5G cellular security research and analysis

This repository consolidates community knowledge in the cellular security space, including exploits, research papers, tools, and educational resources. The goal is to preserve and organize important security research that might otherwise become difficult to find.

Disclaimer: This information is intended for educational and defensive security research purposes only. Use responsibly and in compliance with applicable laws and regulations.

Table of Contents

  • Getting Started
  • Rogue Base Stations
  • Recent Updates (2024-2025)
  • Software and Tools
  • Hardware Setup
  • Testing and Research Methodologies
  • Attack Vectors
  • Conference Talks
  • Research Papers
  • Equipment and Hardware
  • Detection and Defense
  • Cellular IoT and NB-IoT Security
  • Satellite-Cellular Integration
  • Private 5G Network Security
  • Network Slicing and Edge Security
  • Automotive and Industrial Cellular
  • Forensics and Investigation
  • Vulnerability Disclosure
  • SIM Security
  • SS7 and Telecom Infrastructure
  • Surveillance Technology
  • Recent CVEs and Updates
  • International Research
  • Training and Education
  • Vendor-Specific Research
  • Roaming and Interconnect Security
  • Community
  • Resources

Getting Started

New to cellular security research? This section outlines the recommended path for building foundational skills.

Skill Levels

Beginner (passive listening only)

  • Hardware: RTL-SDR V3 or V4 ($35-$40), a laptop running Linux
  • Software: GNU Radio, GQRX, gr-gsm
  • First project: Scan and decode GSM frames passively using gr-gsm and Wireshark
  • Reading: NIST SP 800-187 LTE Security Guide

Intermediate (active research lab)

  • Hardware: HackRF One or LimeSDR Mini ($139-$350), programmable SIM cards (sysmoUSIM), a spare Android device
  • Software: srsRAN 4G, Open5GS or Free5GC, OsmocomBB
  • First project: Build a private LTE network in a Faraday cage and connect a test device
  • Reading: srsRAN documentation, Open5GS tutorials

Advanced (protocol fuzzing and baseband research)

  • Hardware: USRP B210 or BladeRF 2.0, multiple test devices
  • Software: 5GBaseChecker, LTEFuzz, BaseBridge, SigPloit
  • Focus areas: Baseband fuzzing, RAN-Core interface testing, SS7/Diameter signaling

Lab Setup Checklist

  • Linux host (Ubuntu 22.04 or 24.04 recommended)
  • UHD drivers installed and device recognized (uhd_find_devices)
  • Faraday cage or RF shielding for active transmissions
  • Programmable SIM cards (sysmoUSIM-SJA2 or similar)
  • Dedicated test devices (not your daily driver)
  • Isolated network environment (no production network access)

Key Concepts to Understand First

  • 3GPP Architecture Overview: how UE, eNodeB, MME, SGW, PGW fit together
  • IMSI, IMEI, TMSI: subscriber identity fundamentals
  • AKA Protocol: how authentication works in LTE

Rogue Base Stations

GSM/CDMA Traffic Impersonation and Interception

  • How To Build Your Own Rogue GSM BTS For Fun and Profit

    Guide to creating a portable GSM BTS for private networks or security testing. Covers technical setup using relatively inexpensive hardware.

  • How to Create an Evil LTE Twin / LTE Rogue BTS

    Tutorial for setting up a 4G/LTE Evil Twin base station using srsRAN and USRP SDR devices.

  • Practical Attacks Against GSM Networks: Impersonation

    Detailed analysis of GSM base station impersonation using SDR and open source tools.

  • Tutorial: Analyzing GSM with Airprobe and Wireshark

    Step-by-step guide for using RTL-SDR to analyze GSM signals with GR-GSM/Airprobe and Wireshark.

  • GSM/GPRS Traffic Interception for Penetration Testing

    NCC Group research on GSM/GPRS interception capabilities for penetration testing engagements.


Recent Updates (2024-2025)

New Research (2025)

  • RANsacked: 100+ Flaws in LTE and 5G Implementations — University of Florida / NC State, Jan 2025

    Researchers disclosed 119 vulnerabilities (97 CVEs) across seven LTE and three 5G implementations including Open5GS, Magma, OpenAirInterface, Athonet, SD-Core, srsRAN. Every flaw can be used to persistently disrupt city-wide cellular communications. Some require no SIM card — a single unauthenticated packet can crash an MME or AMF.

  • CITesting: Context Integrity Violations in LTE Core Networks — KAIST, ACM CCS 2025 (Distinguished Paper)

    KAIST researchers identified a new class of uplink attacks against LTE core networks. Unlike traditional downlink attacks, these work through legitimate base stations and can affect anyone in the same MME coverage area. All four tested implementations (Open5GS, srsRAN, Amarisoft, Nokia) were vulnerable.

  • Uncovering Hidden Paths in 5G: Protocol Tunneling and Network Boundary Bridging — ACM CCS 2025

    New research on exploiting protocol tunneling in 5G networks to cross network boundaries and reach components that should be isolated.

  • BaseBridge: Over-the-Air and Emulation Testing for Cellular Baseband Firmware — IEEE S&P 2025

    Bridges the gap between over-the-air and emulation-based testing for cellular baseband firmware analysis.

  • 5G Network Slicing: Security Challenges, Attack Vectors, and Mitigation — PMC, July 2025

    Comprehensive classification of attacks across orchestration, virtualization, and inter-slice communication layers in 5G.

  • Survey on 5G Physical Layer Security Threats and Countermeasures — MDPI Sensors, 2024

    In-depth review of PHY layer attack surface in 4G/5G: jamming, spoofing, eavesdropping, pilot contamination, and current SDR-based research tooling.

Base Station Software and Tools (Updated)

Download Tool