Everything we have published, in one list.
Papers, conference material and the tooling released alongside them. Filter by area, or take the whole list. Nothing here is behind a form.
Cite the venue and the year as printed. For a preprint or a dataset that is not linked here, write to us and we will send it.
Request a paper Tools on GitHub →Hacking 5G: from radio security to the APIs
Where the 5G attack surface has moved now that service-based architecture puts APIs behind the radio, and what a device on the air can still reach.
LoRaPWN: from custom and industrial radio to drone hacking
Attacks on LoRa and proprietary industrial links, from plaintext telemetry to forged commands, extended to airborne platforms.
RF Swift: a reproducible SDR environment
The design of the containerised toolbox behind our assessments and courses, and why reproducibility matters more than features here.
Open RAN: disaggregation and the interfaces it exposes
Trust boundaries in a disaggregated radio access network, and where the management plane ends up addressable from the radio side.
Power-line communication in electric vehicles and charging stations
HomePlug AV in domestic plugs, vehicles and chargers: what a party on the same line observes, and what it can inject.
RFID access control in the wild
A survey of credential and reader failures met on physical intrusion engagements, with the mitigations that actually held afterwards.
Subscriber-side routing and filtering in operator networks
What a subscriber context can reach when routing and filtering are missing or partial, and how much the mechanisms differ per operator.
Tell us what transmits. We will tell you what it leaks.
One call to scope it, a fixed proposal after. Intrusion tests, vulnerability hunting, fuzzing, testbeds, trainings. Offices near Paris, Mon to Fri 09:00 to 19:00.