Telecommunications Security Engineering & Virtual RF Labs
Hands-on training, air-interface offensive engineering, baseband RTOS reverse engineering, and 5G Core signaling defense. Access virtualized SDR testbeds running Open5GS, srsRAN, and live Layer-3 protocol harnesses.
Training Tracks & Certification Curriculums
5G NR & LTE Air-Interface Red Teaming
Comprehensive training on Software Defined Radio (SDR) hardware, Open5GS 5G Standalone core simulation, rogue gNodeB rogue base station deployment, and RRC null-cipher stripping attacks.
- SDR transceivers configuration (BladeRF, USRP, HackRF)
- False Base Station (FBS / IMSI-Catcher) architecture & SIB spoofing
- 5G Standalone cipher downgrade (NEA0 / EEA0 null ciphering)
- Type-0 Silent SMS interception and baseband paging tracking
Cellular Baseband RTOS & Protocol Layer-3 Fuzzing
Reverse engineer Qualcomm Hexagon DSP and MediaTek baseband firmware, hook modem RTOS memory segments, and construct automated Layer-3 NAS/RRC signaling fuzzers.
- Modem firmware unpack & symbol recovery in Ghidra/IDA Pro
- Qualcomm DIAG interface protocol tracing & QXDM logging
- NAS / RRC ASN.1 message corruption & heap exploitation
- Emulated baseband test harness setup via QEMU
SS7, Diameter & 5G Core Inter-Carrier Exploitation
Audit inter-operator roaming links, simulate rogue STP/DRA routing, analyze MAP/CAP subscriber location queries, and test telecom core signaling firewalls.
- SS7 MAP / CAP message injection & SMS-C interception
- Diameter S6a / Cx protocol vulnerabilities in 4G/5G EPS
- GTP-C and GTP-U tunnel encapsulation & user data hijacking
- Signaling firewall policy validation and bypass mechanisms
UICC / eSIM Security & STK Sandboxing
Hardware smartcard security, JavaCard applet decompilation, BIP (Bearer Independent Protocol) channel attacks, S@T Browser 0-days, and GSMA eSIM profile auditing.
- SIM Application Toolkit (STK) proactive command auditing
- Over-The-Air (OTA) SMS-PP cryptographic payload attacks
- GSMA SGP.22 eSIM architecture & Remote SIM Provisioning (RSP)
- APDU command fuzzing & SIM sandbox escape defenses