5G Radio and Core Networks Hacking
Three days on 5G NSA and SA security: assessing devices, the current and Next-Generation Core Network, and the attack surface OpenRAN brings. Private 5G on unlicensed bands puts campuses and companies on the air, and this course covers the new risks that come with it.
- Tell 5G NSA and SA apart and their new security mechanisms
- Downgrade security mechanisms
- Set up an entire 5G lab and testbed
- Assess 5G-NR devices safely and hunt for vulnerabilities
- Attack current and Next-Generation Core Networks from outside and inside
- Understand OpenRAN architecture and its attack surface
- Mobile operators and private-5G owners
- Device and infrastructure makers
- Red teamers and researchers on the mobile core
Three parts, radio to core to OpenRAN.
Radio first, then the core network, then the OpenRAN surface.
5G radio
5G core networks
OpenRAN
What every attendee takes home.
Attendees keep the kit, the tooling and the captures.
- RF kit
- bladeRF 2.0 mini, kept by the attendee
- Virtual machine
- Preconfigured lab and tools
- Slides and tools
- Full deck and the tools used in class
- Captures
- Cleared for teaching
Prerequisites.
A laptop running Linux
8 GB of RAM minimum
Linux administration
Required
Radio knowledge is a plus
Not mandatory
Your trainer.
Published research on 5G security, Open RAN, baseband fuzzing, interception and mapping, and power-line communication in electric vehicles and charging stations. Practical work across Wi-Fi, RFID and other wireless systems.
Publications →Run it privately for your team.
Quoted per group, not per seat, and the content adapts to your stack. Remote live, on your site, or at our offices near Paris.