>>> Research Division
Research
Intelligence
Protocol-level vulnerability analysis across 3GPP signaling stacks, core network interfaces, and radio access layers. Every vector catalogued. Every procedure animated.
Per-protocol vulnerability catalogues, animated call-flow procedures, and attack taxonomies. SS7 through 5G SBA.
Published talks, papers, and CVEs the team investigates and reproduces — with full attribution to the original researchers.
Endpoint and subscriber-equipment audits — baseband firmware, UE capability profiling, SIM/eSIM provisioning, and mobile app surface review.
Hardware attack-surface analysis for identity modules and Massive IoT — UICC/APDU internals and NB-IoT / LTE-M protocol auditing.
GSM Air Interface
2GUm air interface - IMSI catchers, A5/0 cipher downgrade, COMP128v1 SIM cloning, unauth backhaul.
SS7 / MAP
2G · 3GLegacy TDM signaling - geolocation, call intercept, SMS hijack via MAP operations.
CAMEL / CAP
2G · 3GIntelligent Network protocol - prepaid bypass, call redirect, VLR manipulation via CAP.
Diameter
4G · IMSS6a/Cx/Gx interfaces - auth vector theft, subscriber tracking, QoS manipulation.
SIP / VoLTE
4G · VoLTEVoLTE signaling - REGISTER hijack, SDP media redirect, INVITE flooding, CLI spoofing.
GTP-C / GTP-U
3G · 4G · 5GTunnelling protocol - Create Session spoofing, TEID injection, IMSI enumeration.
SIGTRAN / SCTP
3G · 4GSS7-over-IP transport - ASP registration abuse, OPC spoofing, SCTP ABORT floods.
4G EPC
4G LTEMME, SGW, PGW architecture - S1-AP abuse, bearer session manipulation.
IMS Core
4G · VoLTEHSS, P/I/S-CSCF architecture - VoLTE interception, registration storm attacks.
5G SBA
5G NRService-Based Architecture - NF spoofing, network slicing bypass, SBI HTTP/2 attacks.
RAN Structure
4G · 5GRadio Access Network - X2/Xn handover abuse, F1-AP protocol exposure, NGAP attacks.