SigTrace
signaling
Signaling trace analysis across SS7, Diameter, GTP, SIP, and 2G–5G RAN.
Ingests tshark NDJSON into an ELK pipeline to give analysts searchable, dashboardable views over SS7, Diameter, GTP, SIP, and 2G–5G RAN traces.
A P1 Security tool for signaling trace analysis with broad protocol coverage, SS7, Diameter, GTP, SIP/SDP, 2G/3G/4G RAN, and core IP protocols. Ingests tshark NDJSON and processes it through an ELK pipeline for search, dashboards, and analyst-driven investigation.
What it does
- Ingests tshark NDJSON and indexes it into ELK for search and dashboards.
- Parses and normalises signaling across SS7, Diameter, GTP, SIP/SDP, and 2G–5G RAN.
- Reconstructs dialogs and transactions for case-driven investigation.
- Surfaces anomalies, malformed messages, and suspicious patterns.
- Supports analyst workflows during fraud, security, and incident response work.
Best for
- Telecom security analysts investigating signaling abuse.
- Fraud teams correlating signaling with case data.
- Researchers studying real-world signaling pathologies across SS7, Diameter, GTP, and RAN.
Protocols: IPv4, IPv6, DNS, BGP, HTTP, HTTP/2, SS7, MTP3, M3UA, SCCP, TCAP, MAP, CAMEL, ISUP, BICC, Diameter, GTP, SIP, SDP, GSMTAP, GSM A-DTAP, GSM RLC/MAC, RRC, LTE-RRC, NAS-EPS
Inputs: tshark NDJSON, PCAP, Signaling traces
Outputs: ELK indices and dashboards, Reconstructed dialogs, Anomaly markers, Analyst-ready reports