We audit what nobody can see.
Every other part of your product gets reviewed. The radio link gets a datasheet and the benefit of the doubt. That gap is where we work, and it is the one an attacker reaches without touching your network.
Where we get in.
An abridged list of the technologies we assess and what usually turns out to be wrong with them. If your stack is on it, we have broken one before.
| Technology | What usually fails |
|---|---|
| 2G / 3G / 4G / 5G networks | Downgrade paths left open, core interfaces exposed to subscriber traffic, filtering that differs from one operator to the next |
| Private 5G and OpenRAN | Flat trust between radio and core, management APIs reachable from the radio side |
| Wi-Fi (WPA2, WPA3, EAP) | Enterprise EAP misconfiguration, evil-twin credential capture, crashes under stack fuzzing |
| Bluetooth and BLE | Pairing shortcuts, unauthenticated GATT writes, devices that trust anything already bonded |
| RFID and NFC access control | Cloneable credentials, replayed opens, readers that verify nothing at all |
| LoRa and industrial radio | Plaintext telemetry, forged commands, join procedures with no rate limiting |
| Automotive and V2X | Bus access reached over a radio path, key-fob relay, abuse of the charging-station link |
| Firmware and hardware | Debug ports left live, unsigned updates, secrets sitting in flash |
Two ways to hire us, and a catalogue of kit.
Have it tested
We attack the system the way someone else would, from the outside in, and give your engineers the exact path we took.
Train your team
Twelve hands-on courses taught by the author of RF Swift. Live with hardware, on demand, or built around your own stack.
The tools are public. So is the research.
Penthertz was founded by Sébastien Dudek, a trainer since 2009 and the author of RF Swift, the open-source SDR toolbox we run on every engagement. The published work covers 5G and OpenRAN security, baseband fuzzing, interception and mapping, and power-line communication in electric vehicles and charging stations.
- Founded
- Penthertz Consulting, France. RCS Nanterre 881 000 079
- Training centre
- Officially registered, ID 11788588278. Invoices are fundable
- Open source
- RF Swift, the SDR toolbox behind our assessments and courses
- Teaching since
- 2009, across RFID, Wi-Fi, SDR and industrial communications
Seen in public, 2026.
Trainings you can book a seat at, and the talks that come out of the same research.
All trainings| Nov 16-18, 2026 | Hardwear.io NL 2026SDR Hacking Advanced: reversing and exploiting wireless communications |
Latest from the blog.
All posts →Welcome to WordPress. This is your first post. Edit or delete it, then start writing!
Without proper routing and filtering of subscriber communications, sensitive assets on an operator infrastructure stay exposed, core network services among them. Operators…
The platforms we tested and the TEACHertz infrastructure behind high-definition remote courses for radio and hardware work.
Tell us what transmits. We will tell you what it leaks.
One call to scope it, a fixed proposal after. Intrusion tests, vulnerability hunting, fuzzing, testbeds, trainings. Offices near Paris, Mon to Fri 09:00 to 19:00.