P1 Arsenal

Open telecom security tools and research utilities for signaling analysis, PCAP inspection, log parsing, and mobile network research.

Tools

  • Telco Attack Surface Matrix
    analysis
    Confidential attack-surface assessment for mobile network operators.
  • Signaling Firewall (SigFW)
    signaling
    Signaling firewall for SS7, Diameter, GTP-C/U, and 5G SBA traffic.
  • File Analyzer
    analysis
    Client-side file forensics with WebGPU visualisation and ML-based triage.
  • Logs Analyzer
    logs
    Browser-based log analytics with DuckDB WASM, Lucene search, and six anomaly-detection methods.
  • PCAP Anonymizer
    pcap
    Browser-based PCAP anonymisation using Wiregasm dissection, SHAKE256 hashing, and field masking.
  • PCAP Editor
    pcap
    Browser-based PCAP editor with Wireshark dissection and a Python (Scapy / Pycrate) editor.
  • PCAP Visualizer
    pcap
    Browser-based PCAP visualisation with time-series traffic charts, dissection, and field discovery.
  • Tshark OpenSearch
    analysis
    Dockerised stack that indexes tshark NDJSON into OpenSearch + Dashboards, with optional simple-NIDS live capture.
  • JSON2PCAP
    research
    Reconstructs and modifies PCAPs from tshark JSON using a position-based hex overlay.
  • SigTrace
    signaling
    Signaling trace analysis across SS7, Diameter, GTP, SIP, and 2G–5G RAN.
  • Pycrate
    signaling
    Python library of encoders and decoders for telecom protocols and file formats.
  • pysctp
    signaling
    SCTP transport bindings for Python.
  • QCSuper
    research
    Capture raw 2G/3G/4G radio frames from Qualcomm-based phones and modems.
  • hermes-dec
    research
    Reverse-engineering tool for React Native Hermes bytecode.
  • corenet
    research
    Minimal 3G and LTE/EPC core network for home-NodeBs and eNodeBs.
  • CryptoMobile
    signaling
    Python toolkit for 3G and LTE mobile cryptography and authentication.
  • pcapview
    pcap
    Fast browser-based viewer and filter for SS7, Diameter and 5G HTTP/2 SBA PCAPs.

What's inside the Arsenal

The Arsenal groups signaling firewall and policy tooling (SS7 / Diameter / GTP filters aligned with GSMA FS.11 / FS.19 / FS.36), PCAP and traffic inspection utilities for SIGTRAN, GTP-C, Diameter and SIP, log-analysis helpers for correlating operator-side events, and research utilities for SEPP / PRINS interoperability testing and roaming due-diligence.

How teams use the Arsenal

Common workflows: pre-audit signaling reconnaissance, drafting SS7/Diameter firewall rules against real traffic, incident triage on suspected SIM-swap or location-tracking events, roaming partner due-diligence before signing IPX contracts, and hands-on training for SOC analysts new to telecom protocols.