What we publish is what we practise.
The work that ends up in a client report is the same work that ends up on a conference stage. Papers, write-ups, recorded talks and the tooling, all in public. Read it before you hire us.
Conference and journal material on mobile, radio and embedded security.
Read the papers →Findings from live engagements and lab work, in enough detail to reproduce.
Read the blog →Where the research goes.
Subject areas we have published in, and the systems each one applies to.
All publications| Area | Applies to |
|---|---|
| 5G security, NSA and SA | Handsets, IoT modules, private networks, operator cores |
| Open RAN | Disaggregated radio access, management interfaces, vendor integration |
| Baseband fuzzing | Modems in phones, vehicles, routers and industrial gateways |
| Interception and mapping | Coverage analysis, rogue infrastructure, subscriber exposure |
| Power-line communication | HomePlug AV, domestic PLC, electric vehicles and charging stations |
| RFID and physical access | Badge systems, gates, controllers, credential lifecycles |
| Wi-Fi and short-range radio | Enterprise wireless, BLE devices, LoRa and proprietary links |
RF Swift, the toolbox behind all of it.
A containerised SDR toolchain that gets a working radio environment up in one command, instead of an afternoon of dependency archaeology. We wrote it for our own engagements, we teach from it, and it is public.
Latest from the blog.
All posts →Welcome to WordPress. This is your first post. Edit or delete it, then start writing!
Without proper routing and filtering of subscriber communications, sensitive assets on an operator infrastructure stay exposed, core network services among…
The platforms we tested and the TEACHertz infrastructure behind high-definition remote courses for radio and hardware work.
Tell us what transmits. We will tell you what it leaks.
One call to scope it, a fixed proposal after. Intrusion tests, vulnerability hunting, fuzzing, testbeds, trainings. Offices near Paris, Mon to Fri 09:00 to 19:00.