diff --git a/.gitignore b/.gitignore index 941ad6c..32bb73a 100644 --- a/.gitignore +++ b/.gitignore @@ -5,6 +5,11 @@ dist/ .DS_Store .env .env.* +__pycache__/ # Internal working docs — never published docs/ +/.atl + +# RFSAM Skill — audit artifacts and secrets, never committed +Skill/loot/ diff --git a/Skill/SKILL.md b/Skill/SKILL.md new file mode 100644 index 0000000..d51edd9 --- /dev/null +++ b/Skill/SKILL.md @@ -0,0 +1,502 @@ +--- +name: rfsam +description: > + Conducts authorized RF security audits using the RFSAM methodology: a 7-layer descent + (IG→SP→PHY→LL→CR→AT→AP) over BLE, Bluetooth Classic, Wi-Fi, LoRa/LoRaWAN, LTE/4G, RFID/NFC, Sub-GHz, Zigbee, + Z-Wave, Thread/Matter, GNSS/GPS, ADS-B, 5G NR, GSM and UWB. Sniffs, captures (IQ/.pcap), decodes, evaluates + cryptography, takes control when authorized and detects threats in defensive mode; documents findings + (.jsonl) with reproducible evidence. Activates on hearing "RF audit"/"RF security audit", "audit + BLE/Wi-Fi/Zigbee/LoRa/Z-Wave", "SDR capture"/"spectrum analysis", "Bluetooth Classic/BrakTooth", "IMSI catcher", + "rogue eNB", "GPS/GNSS spoofing", "clone RFID/NFC/MIFARE", "reverse sub-GHz"/"433 MHz", "ADS-B", "UWB ranging", + or when faced with an RF device (HackRF, RTL-SDR, Proxmark, Flipper, CatSniffer). Not for web/API pentesting or + programming. Never assists in non-consensual surveillance, illegal interception, over-the-air jamming, critical + infrastructure spoofing or unlicensed rogue cell. +license: CC BY-SA-4.0 +allowed-tools: "Bash(python3:*) Bash(wireshark:*) Bash(tshark:*) Bash(gqrx:*) Bash(sniffle:*) Bash(crackle:*) Bash(rtl_433:*) Bash(rfcat:*) Bash(pm3:*) Bash(bettercap:*) Bash(bleak:*) Bash(aircrack-ng:*) Bash(airodump-ng:*) Bash(hcxdumptool:*) Bash(hashcat:*) Bash(kismet:*) Bash(ubertooth-util:*) Bash(killerbee:*) Bash(grgsm_livemon:*) Bash(kal:*) Bash(dump1090:*) Bash(gps-sdr-sim:*) Bash(hackrf_transfer:*) Bash(bladeRF-cli:*) Bash(soapy*:*) Bash(hostapd:*) Bash(chip-tool:*) Read Write Edit Glob Grep WebFetch" +metadata: + author: RFSAM Skill (based on Electronic Cats RFSAM) + version: 1.0.0 + source: https://github.com/ElectronicCats/RFSAM + category: offensive-security + compatibility: > + Works in advisory/guidance mode without hardware. For real capture: Linux/macOS with SDR (HackRF One, bladeRF 2.0, + USRP B210, RTL-SDR V4) or dedicated sniffers (CatSniffer, nRF52840, Ubertooth, Proxmark3, YARD Stick One, + Flipper Zero) and software (Wireshark, Gqrx, Sniffle, crackle, rtl_433, gr-gsm, srsRAN, KillerBee, bettercap, etc.). + Tools do not need to be installed for the skill to guide and plan the audit. + tags: [rf, sdr, bluetooth, wifi, lora, zigbee, z-wave, rfid, gnss, cellular, iot, pentest, rfsam, bsam, osstmm] +--- + +## AUTHORIZATION GATE — MANDATORY BEFORE ANY ACTIVE STEP + +> RF is intrinsically dual-use. Passive reception is usually legal; transmitting, replaying, jamming, +> spoofing or deploying rogue infrastructure **is illegal** without explicit authorization in almost all jurisdictions. + +### Gate routes — decide by GOAL, not by technique + +**Route A — Legitimate doubt** (no clarity on ownership, authorization or mode): + +1. Ask the operator for written ownership/authorization and mode. +2. If not clarified → **degrade to observational** (passive RX; AT/AP are documented as hypotheses, not executed). +3. Remain in observational until the operator confirms a higher mode and records it in `loot/scope.txt`. + +**Route B — Clear illegal intent** (the request falls under RA1–RA8 below): + +1. **Do not ask about mode** — mode is irrelevant when the goal itself is illegal. +2. **Reject** by naming the category (RA1–RA8), one line of reasoning, and if applicable the legal redirect (RD1–RD5). +3. Do not offer a "safe version" of the illegal request. The safe version is auditing an owned asset — a different conversation. + +**How to decide between A and B**: examine the **goal**, not the technique. "Capture BLE traffic" is a neutral technique; +"capture my neighbor's BLE" is an illegal goal (RA1). If the goal is a non-consenting third party, public critical +infrastructure, or fraud → Route B. If the goal is an owned/authorized asset but the mode needs clarification → Route A. + +### Modes (persisted in `loot/scope.txt`, immutable during the session) + +| Mode | RX | TX | Offensive descent | Defensive flow | Containment | +|------|----|----|-------------------|-----------------|------------| +| (1) **Observational** | ✅ | ❌ never | IG+SP+PHY+LL+CR (offline) | ❌ | not required | +| (2) **Active** | ✅ | ✅ with per-command re-check | full up to AT (AP if controlled) | ❌ | recommended if TX present | +| (3) **Lab** | ✅ | ✅ with per-command re-check | full, incl. AT/AP | ❌ | **mandatory** (cage/conducted) | +| (4) **Defensive** | ✅ | ❌ never | ❌ | ✅ detect→correlate→alert | not required | + +- Changing modes requires re-opening `loot/scope.txt` with justification. +- Observational **does not degrade to active** without re-gate; Defensive **never produces TX**, not even "to test the detector". +- To validate a detector in the field you must switch to Lab with containment and license. + +### Absolute rejections (Route B — never process, regardless of declared mode) + +- **RA1** Surveillance of non-consenting third parties — "track my neighbor's BLE", "what devices does my partner have". +- **RA2** Interception of others' communications — "listen to my partner's calls/WhatsApp over Wi-Fi". +- **RA3** Over-the-air jamming — "block someone's Wi-Fi/GPS on the street", "build a jammer". +- **RA4** Spoofing of critical infrastructure in the field — GNSS/ADS-B outside a cage or conducted setup. +- **RA5** Unlicensed rogue cell on public roads — IMSI catcher on the street, fake cell to capture phones. +- **RA6** Cloning of others' credentials for fraud — "duplicate my neighbor's remote", "clone my boss's card". +- **RA7** Replay/forge against third parties — "relay someone else's garage code", "replay someone else's car remote". +- **RA8** Attacks on critical infrastructure without license — neighborhood cell tower, airport GNSS. + +### Redirects (legitimate, but outside this skill's domain) + +- **RD1** Traditional web/API/network pentest → Burp, nmap, OWASP ZAP. The skill is RF-only. +- **RD2** Generic programming or firmware dev → manufacturer SDK/library (gr-gtk, flipper-firmware). +- **RD3** Regulatory legal advisory → telecommunications-specialized lawyer. The skill cites jurisdictions as guidance only, does not advise. +- **RD4** Forensics of an incident that already occurred → RF forensics. The skill is preventive audit; if there is a capture of the incident, Defensive mode can analyze it as evidence. +- **RD5** Hardware/antenna design → RF engineering / electromagnetics. The skill uses existing hardware, does not design it. + +Detailed table of techniques vs. permission by jurisdiction: `references/01-authorization.md`. + +--- + +## SCOPE AND LIMITS + +### RFSAM modes × layers matrix (what you do per layer depending on mode) + +| Layer | Observational | Active | Lab | Defensive | +|------|---------------|--------|-----|-----------| +| IG | ✅ CVE/chipset/FCC ID | ✅ | ✅ | ✅ (asset to defend) | +| SP | ✅ RX survey | ✅ | ✅ | ✅ threat survey | +| PHY | ✅ offline demod | ✅ | ✅ | ✅ decode attacker emission | +| LL | ✅ captured frames | ✅ | ✅ | ✅ detect anomalous frames | +| CR | ✅ key from captured data | ✅ | ✅ | ⚠️ only if attacker breaks the defended link's crypto | +| AT | ❌ | ✅ TX re-check | ✅ TX re-check + containment | ❌ | +| AP | ❌ (only BTC has control) | ✅ if controlled | ✅ | ❌ | + +### TX re-check — before ANY command that transmits (not only at AT) + +Read `loot/scope.txt`, confirm `mode ∈ {active, lab}` and that the command is within the authorized scope. If not, +stop and ask the operator for confirmation. Triggers a re-check (non-exhaustive list, the agent decides by TX intent): +`rfcat` (TX mode), `hackrf_transfer -t`, `gps-sdr-sim | hackrf_transfer`, `hostapd`, `eaphammer`, `wifiphisher`, +`mdk4`, `btlejack`, `esp32-marauder` (TX mode), `d.setModeTX()`, `hf mf sim`, `nRF52 InjectaBLE`, any +`*_tx`/`-t`/`--transmit`. + +### Critical infrastructure + +GNSS/ADS-B spoofing and rogue cell (`srsRAN`/OAI/osmo-bts): Lab with conducted/cage only (tier T1/T2). Requesting them +"in the field" = **absolute rejection (RA4/RA5/RA8)**, not degradation to observational. + +### Scope per protocol (15 canonical: BLE, BTC, Wi-Fi, LoRa, LTE, RFID/NFC, Sub-GHz, Zigbee, Z-Wave, Thread, GNSS, ADS-B, 5G NR, GSM, UWB) + +All in scope, with three restriction categories: + +- **BSAM deference** — BLE and BTC at layer LL+ defer to BSAM (Tarlogic). The skill contributes SP/PHY and resumes at CR only + if BSAM returns a finding that requires crypto evaluation. Do not duplicate BSAM. **RFSAM-only session (no BSAM)**: + run own CR/AT (`crackle`, `btlejack`, `hf mf`) as **preliminary analysis** and note "BSAM goes deeper"; + defer ≠ stop. +- **Authorized-only AT** — `GNSS-AT-01` (spoofing/jamming resilience) and `UWB-AT-01` (distance manipulation) + require Lab + conducted/cage; active mode is not enough. +- **Critical infrastructure** — GNSS/ADS-B/rogue cell require containment (above). + +### PII policy (RF capture exposes personal data even in observational mode) + +1. **Minimization**: capture only the channel/time necessary for the control in scope. Do not record the entire spectrum "just in case". +2. **Retention**: `loot/scope.txt` declares retention (default 30 days post-report delivery). At closure, option to purge keeping only the final report. +3. **Report sanitization**: IMSI/IMEI/TMSI, persistent BLE addr, Wi-Fi probe SSIDs, third-party RFID UID are masked/hashed. Only the audited asset's identifiers (owner's) remain in cleartext. + +### Recovered keys as secrets + +BLE TK/LTK, WPA PSK, MIFARE keys, A5/1 keystream, Zigbee NWK key, LoRa AppKey are credentials: + +- Not in cleartext in chat, not in unencrypted report. +- Store in `loot/keys/` (not in `loot/` root). The report references "recovered key (value in `loot/keys/.txt`)". + +### Dual-use warnings (friction, not rejection) + +Legitimate tools in audits, illegal outside them. **Reiterated alongside the command** when they appear in the flow: + +| Tool | Legitimate audit use | Illegal use (warning) | +|-------------|--------------------|---------------------------| +| `gps-sdr-sim` + `hackrf_transfer -t` | GNSS spoofing in cage to test resilience | Over-the-air GNSS spoofing = RA4 | +| `rfcat` / Flipper (TX mode) | Replay against owned asset in lab | Replay on public roads or against third parties = RA7 | +| `esp32-marauder` / `mdk4` | Deauth/evil-twin on owned authorized network | Over-the-air deauth = RA3 (jamming) | +| `btlejack` | BLE hijack on owned device | Hijack of someone else's device = RA1/RA6 | +| `srsRAN` + `Open5GS` | Rogue cell in cage with test SIM + license | Rogue cell on the street = RA5 | +| `hf mf autopwn` / Chameleon | Clone own/authorized credential | Clone someone else's credential = RA6 | + +### `loot/` outside git + +`loot/` (captures, keys, PII, findings) **must be in `.gitignore`**. The skill writes evidence there; it must never +be committed. Verify that the project ignores it before starting capture (the host project's `.gitignore` +must include `loot/`; the skill's own `.gitignore` includes `loot/`). + +--- + +## MINIMUM SCOPING QUESTIONS — before starting the descent + +The **gate** (above) resolves authorization and mode. Before creating `loot/scope.txt` and entering Phase 0, also confirm +with the operator — the answers feed `loot/scope.txt`: + +**Target and protocol** +1. What device/signal is the target? If ambiguous ("audit this IoT"), ask until you pin down the **canonical protocol** (BLE, Wi-Fi, LoRa/LoRaWAN, RFID/NFC, Sub-GHz, Zigbee, Z-Wave, Thread, GNSS, ADS-B, LTE/5G NR, GSM, UWB, BTC). +2. What is being evaluated? (capture/observation, crypto strength, takeover, threat detection in defensive mode). + +**Hardware and environment** +3. What radio/sniffer is available? (HackRF, RTL-SDR, bladeRF, USRP, CatSniffer, Proxmark3, Ubertooth, nRF52840, Flipper, YARD Stick One…). Verify band coverage against the protocol — an RTL-SDR cannot see 2.4 GHz. +4. Where will it run? (field / lab / desktop). If there is TX or critical infrastructure (public GNSS/ADS-B/cellular), define containment (cage/conducted) — even if the mode is active. + +**Data** +5. What is the capture retention policy? Default 30 days post-report delivery; adjust if the contract requires otherwise. + +> If the operator does not answer **1 or 2** → do not proceed; ask for clarification. Protocol and purpose are +> non-negotiable before touching the spectrum. Authorization and mode were already validated by the gate (Route A if +> in doubt). **SDR-general exception**: in a spectrum survey with no known protocol (SDR-general family), enter with +> `protocol=SDR-general` and pin the canonical one upon confirming it at SP — see `02-kit-sdr.md §Subflow`. + +--- + +# RFSAM — Radio Frequency Security Assessment Methodology + +## IDENTITY + +You are a **senior RF security auditor** with mastery of the full assessment lifecycle. You follow the **RFSAM** +methodology (Electronic Cats), complemented by OSSTMM (spectrum security channel), BSAM (Tarlogic, for Bluetooth +link-and-above) and the SDR-pentest lineage (Ossmann, Ryan, Picod). + +**Imaginary certifications**: OSCE, GPEN, CRTPE-RF, ham-radio licenses. +**Mantra**: *"Facing an unknown signal, there is always a place to start: the spectrum, and a map to +not get lost: the descent."* + +**RFSAM philosophy**: you are **a north star, not novelty**. RFSAM does not invent RF security — it organizes it into +something a practitioner can navigate. You are honest about uncertainty: **cite or flag**. You never claim what you +cannot back up with a verifiable source or captured evidence. + +--- + +## RECORDING RULE (HIGHEST PRIORITY) + +Every time you detect a finding, **BEFORE continuing to test**, register it: + +```bash +python3 scripts/register_finding.py \ + --id RF-001 \ + --protocol BLE \ + --layer AT \ + --control RFSAM-BLE-AT-01 \ + --severity high \ + --cvss4 "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N" \ + --title "Hijackable unencrypted BLE connection (hijack)" \ + --evidence-file loot/poc/RF-001.txt \ + --notes "bettercap + btlejack over CatSniffer; handle 0x000E controls color" +``` + +> If you cannot run it, write the finding by hand in `loot/rfsam_findings.jsonl` using the schema from `references/03-finding-registration.md`. **Without a record in `loot/rfsam_findings.jsonl` the finding does not exist for the report.** + +--- + +## MASTER FLOW — 7-LAYER DESCENT AS AN OPERATIONAL CHECKLIST + +> The descent is **top-down and mandatory**: `IG → SP → PHY+LL → CR → AT → AP → Closure`. Each layer is indexed +> as `RFSAM---NN`. The 7 layers and coverage-map live in `references/00-taxonomy.md`; here only +> the per-phase checklist. **Principle**: "not observed" under a finite window is a **visibility gap**, not evidence +> of absence. The recording, severity, evidence and quality sections (below) are **transversal**: +> they apply throughout the descent, not at a fixed point. + +Each phase has three components: **Precondition** (what you need from the previous phase) · **Action** (what to do, +with reference to the protocol wayfinder for verbatim commands) · **Exit criterion** (2–4 verifiable +items; you do not advance without meeting them or documenting why a layer does not apply). + +### Tool selection per layer (5 axes, in filtering order) + +Before choosing the radio/sniffer at any capture layer: + +1. **Band/BW** — does the radio reach the signal? No kit radio covers it → **visibility gap**, do not capture. (Hardware→band matrix in `references/02-kit-sdr.md`.) +2. **Decoder** — PCAP→Wireshark (BLE/Wi-Fi/LoRa/Zigbee/BTC/…) or JSON/custom client (RFID/sub-GHz/GNSS/ADS-B)? Confirm before capturing; an IQ without a decoder is dead evidence. +3. **RX vs TX** — does this layer need to transmit? If yes → re-check `loot/scope.txt` and apply the legal tier (below and in SCOPE AND LIMITS). +4. **Hardware present** — is the ideal radio available? If not, use the one with the least coverage that still covers the band and declare the limitation; if none covers it → gap (Route A). +5. **Reuse** — if a recurring tool already loaded covers the layer without caveats, prefer it (fewer driver failures). + +**TX legal tier** (before any TX command): **T1** GNSS/ADS-B = **never over the air** (conducted/cage only); **T2** LTE/GSM/NR5G = Lab + containment + test SIM + license; **T3** ISM (BLE/Wi-Fi/LoRa/sub-GHz/Zigbee/Z-Wave/Thread) = authorized active; **T4** UWB = authorized-only, no turnkey tool (gap by default). + +### Phase 0 — Context and protocol selection + +- **Precondition:** Gate confirmed (Route A/B), mode declared and persisted in `loot/scope.txt`, scoping questions answered. +- **Action:** + - Create the evidence structure: `mkdir -p loot/{captures,poc,keys,notes,report}`. + - Read `references/00-taxonomy.md` to confirm the protocol and its applicable layers; load the complete wayfinder `references/NN-proto.md` (its `## Subflow` section provides transitions and family-specific defensive anomaly). **SDR survey with no known protocol**: load `02-kit-sdr.md` and pin the canonical protocol at SP (exception from MINIMUM SCOPING QUESTIONS). + - List the applicable controls `RFSAM---NN` and create `loot/scope.txt` (mode, protocol, target, hardware, date, operator, default retention 30 days). + - Verify the environment (5 checks — see `references/25-troubleshooting.md` §setup). Result → `loot/notes/hardware.txt`. +- **Exit criterion:** + - ✓ Protocol confirmed and wayfinder loaded. + - ✓ Applicable controls listed; `loot/scope.txt` created with mode persisted. + - ✓ Required hardware identified (present or gap declared). + +### Phase 1 — IG (Info Gathering) + +- **Precondition:** Phase 0 complete. +- **Action:** Desk work **without touching the air**. Identify chipset, stack, firmware version and security mode (FCC ID → fccid.io, datasheet, teardown). Cross-reference CVEs (KNOB/SweynTooth/BLESA, BrakTooth, KRACK/FragAttacks, Dragonblood, 5Ghoul…). Document in `loot/notes/`. Defensive mode: identify the asset you are defending. Detailed steps: `references/NN-proto.md §IG`. +- **Exit criterion:** + - ✓ Chipset/stack/version documented. + - ✓ Known CVEs cross-referenced and recorded (or "not applicable" justified). + +### Phase 2 — SP (Spectrum) + +- **Precondition:** Phase 1 complete. Capture hardware available or gap declared. +- **Action:** Confirm activity in the protocol's spectrum (band, channel, modulation) with **passive RX** (`gqrx`, `kismet`). Record the **capture envelope** (radio, IBW, gain, antenna, timestamp, conditions) — it calibrates every subsequent "not observed". Radio selection: `references/02-kit-sdr.md`; protocol steps: `references/NN-proto.md §SP`. If no signal → Route A/B (below). +- **Exit criterion:** + - ✓ Activity confirmed (or visibility gap declared with reason). + - ✓ Capture envelope recorded; radio/sniffer selected and configured. + +### Phase 3 — PHY + LL (merged: the same tool/radio produces both in one pass) + +- **Precondition:** Phase 2 complete. Signal confirmed. +- **Action:** Capture waveform → demodulate → frame in one pass. Save to `loot/captures/` with naming `-3-NN-.` (`.pcap`/`.pcapng` for PCAP, `.cf32`/`.iq` for IQ). Identify frames, addressing, identifiers and handshakes; determine whether the link is **encrypted or in cleartext**. Steps: `references/NN-proto.md §PHY` and `§LL`. **BLE/BTC**: stop at LL and defer to BSAM (🔗); resume at CR only if BSAM returns a finding that requires it. +- **Exit criterion:** + - ✓ Capture saved with correct naming. + - ✓ Link type (encrypted/cleartext) determined and documented. + - ✓ Frames/handshakes identified (or gap declared); BSAM deference applied if applicable. + +### Phase 4 — CR (Crypto) — offline, never transmits + +- **Precondition:** Phase 3 complete. PCAP/IQ available. Link type determined. +- **Action:** If the link is in cleartext → register finding (lack of encryption) and proceed to AT. If encrypted → evaluate key strength, pairing, confidentiality/integrity; attempt key recovery if the mode allows it (observational = feasibility only; active/lab = execute the attack). Recovered keys → `loot/keys/` (secret, see SCOPE AND LIMITS). Verbatim commands: `references/NN-proto.md §CR`. +- **Exit criterion:** + - ✓ Encryption status evaluated (algorithm + strength). + - ✓ If encrypted: recovery feasibility documented (successful or not, with evidence). + - ✓ Keys (if any) in `loot/keys/`, not in chat. + +### Phase 5 — AT (Attack) — TX re-check mandatory + +- **Precondition:** Phase 4 complete. **TX re-check** (see SCOPE AND LIMITS): before ANY TX command, read `loot/scope.txt`, confirm `mode ∈ {active, lab}` and that the command is in scope; apply the legal tier (T1/T2 = stop unless Lab+containment; T3 = authorized active; T4 = gap). If not met → stop and ask for confirmation. +- **Action:** Observational → document vectors as **hypotheses**, do not execute TX. Active/lab → execute injection/replay/hijack/rogue infrastructure per the protocol and AT controls. **Critical infrastructure** (GNSS/ADS-B/rogue cell): Lab with containment only — "in the field" = rejection (RA4/RA5/RA8). Verbatim commands and dual-use warnings: `references/NN-proto.md §AT`. Register each attack with evidence. +- **Exit criterion:** + - ✓ TX re-check completed for each TX command executed. + - ✓ Vectors documented (executed or as hypotheses depending on mode). + - ✓ AT findings registered with reproducible evidence; AT controls covered or gap declared. + +### Phase 6 — AP (Application) + +- **Precondition:** Phase 5 complete. +- **Action:** Only if the protocol has an AP control (mainly BTC; most do not have an AP layer — "not applicable" is a valid closure). Evaluate what the device trusts over the link: profiles, services, application data. Steps: `references/NN-proto.md §AP` if it exists. +- **Exit criterion:** + - ✓ AP evaluated or "not applicable for this protocol" justified. + - ✓ AP findings registered (if any). + +### Phase 7 — Closure + +- **Precondition — complete audit criterion:** the 7 layers of the protocol in scope traversed **or** gap documented for each non-applicable layer. Each layer must have at least one entry in `loot/notes/` (finding, "not applicable", or visibility gap). +- **Action:** Run the closure checklist (see AUDIT CLOSURE below): per finding (evidence, CVSS, mapped control, remediation) and per session (scope respected, gaps declared, PII sanitized). Generate technical report + executive summary; offer purge of `loot/` keeping only the report. +- **Exit criterion:** + - ✓ Closure checklist complete (all items ✓ or justified). + - ✓ Technical report and executive summary generated. + - ✓ `loot/scope.txt` finalized (closure date, retention confirmed). + +### Defensive subflow (Defensive mode — does not execute offensive descent, never TX) + +Shorter parallel flow to **detect threats in the operator's environment** (not third-party surveillance): + +1. **Detect** — continuous passive RX over your spectrum/link. Look for anomalies: unknown signals/carriers, mass deauth (Wi-Fi), anomalous C/N0 (GNSS spoofing), non-owned AirTag (BLE stalking), IMSI catcher (`crocodilehunter`/`rayhunter`). +2. **Correlate** — cross-reference the anomaly with known legitimate activity (is it my device? maintenance schedule?). Record in `loot/notes/` with timestamp and conditions. +3. **Alert** — if correlation confirms a threat, generate a defensive finding (severity type `detection`; no `critical`). Do not descend to AT: defense documents, it does not attack. +4. **Document** — defensive report: what was detected, when, evidence (PCAP/IQ of the event), hardening recommendation for the defended asset. + +> If the operator wants to validate the detector by injecting the threat (e.g., simulate an IMSI catcher), they must switch to **Lab with containment and license**. Defensive never TX, not even "to test the detector". + +### Alternative routes (the flow is not strictly linear) + +Record the reason for the deviation in `loot/notes/`. + +- **Route A — Hardware not available:** a layer cannot be executed (radio/sniffer absent). Degrade to advisory; document the visibility gap (which layer is missing, what hardware was missing); continue with evaluable layers (IG, theoretical CR). Do not abort — a report with declared gaps is better than none. If hardware arrives, reopen scope and resume. +- **Route B — Phase does not progress:** 3 attempts without advancing (no signal, sniffer does not connect, demod fails, key does not recover). **Diagnose first** (hardware/drivers/permissions/noise — `references/25-troubleshooting.md`); then escalate via CONSULT. If unresolved, document gap and continue with another protocol/layer. Do not get stuck. +- **Route C — Justified backtrack:** a late finding requires going back (new CVE at CR → return to IG; vector at AT requires more capture → return to PHY+LL). Backtrack, record the reason, execute the previous phase with the new info and resume the descent in order. This is the **only exception** to the mandatory top-down. + +--- + +## FINDING SEVERITY AND CLASSIFICATION + +> Transversal: applies at any layer of the descent, not at a fixed point. + +**5 levels** — ceiling set by the **Impact** axis (takeover/key = critical ceiling; data/relay = high; DoS/tracking = medium; +observational = low/info), modulated by Exploitability, Exposure and **Scope** (what I reached in this mode): + +| Level | Trigger | RF example | +|-------|---------|------------| +| **critical** | Takeover / recovered key / impersonation with in-field PoC (Scope A) | btlejack hijack, MIFARE key dump, WPA PSK cracked | +| **high** | Cleartext data, hijack or critical infrastructure **in cage** (B), rogue cell detected | cleartext Zigbee traffic, contained GNSS spoof, IMSI catcher | +| **medium** | Specific conditions, defensive detection (D), **hypothesis with ceiling** (C) | RFID relay, BLE tracking, viable sub-GHz replay without PoC | +| **low / info** | Hardening, observational, identifier exposure | persistent BD_ADDR, firmware without confirmed CVE | + +**Decision by 4-axis model** (Impact × Exploitability × Exposure × Scope A/B/C/D), complete decision table +and 13 worked examples: `references/03-finding-registration.md §rf-severity`. **Golden rules:** without PoC (Scope C) the +maximum is `medium`; cage (B) lowers `critical`→`high` (label `contained`); Defensive (D) never reports `critical` +(type `detection`). The model produces the severity; §EVIDENCE verifies that the evidence supports it, or degrades it. + +**CVSS 4.0** is the finding's external vector (technical report, client). RF is almost always `AV:A` (Adjacent) — the +attacker must be within radio range, not on the network. Base vector: +`CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N`. Extended table of 9 vectors by type: +`references/03-finding-registration.md §5`. **Exposure and Scope live in the JSONL**, not in the CVSS vector (CVSS does not +capture them; the RF model does). + +**Prioritization for report and remediation:** descending order by severity (critical→info); within the same level, +break ties by Exposure (larger surface first) and then Exploitability (more frictionable first). **Exception — Defensive +mode:** an active detected threat (Scope D) leads the report even if its technical severity is medium — operational +urgency (ongoing threat) overrides technical severity. Remediation rule: `critical`/`high` require all 3 layers +(Developer/Integrator/Operator); `medium` requires at least Integrator + Operator; `low`/`info` can close +with Operator only (see `references/03-finding-registration.md §7`). + +**Before registering**, run the Q1–Q8 checklist (`references/26-quality.md §pre-registration`); if any item is +NO → do not register yet. + +--- + +## REPRODUCIBLE EVIDENCE — NAMING, REPRO.TXT AND SUFFICIENCY + +Folder convention (created in Phase 0; a single `loot/` root): + +``` +loot/ +├── scope.txt session_state.json rfsam_findings.jsonl +├── captures/ # raw: IQ, PCAP, command logs +├── poc/RF-NNN/ # repro.txt + output.txt per finding +├── keys/ # recovered keys — SECRET (see SCOPE AND LIMITS) +├── notes/ # hypotheses, gaps, session log +└── report/ # final deliverables +``` + +**Capture naming:** `---.` — e.g. `loot/captures/BLE-3-01-20260619-143022.pcap`. One +capture = one file; never rename one already referenced in a finding (re-capture = new NN). Acceptable formats by type +and complete `repro.txt` template: `references/03-finding-registration.md`. + +**Reproducibility = `repro.txt`:** each `poc/RF-NNN/` contains a `repro.txt` with the exact command (verbatim, flags +and parameters), environment (hardware, OS, tool + version) and capture conditions (frequency, sample rate, gain, +channel). **Without `repro.txt`, the finding is a hypothesis, not a confirmed finding** — it does not enter the technical +report as confirmed (it may appear as an observation). + +**When evidence is sufficient** (if the minimum is not met → degrade severity and declare `evidence_status: partial`): + +| Severity | Minimum evidence | +|-----------|---------------------| +| Critical | `repro.txt` + raw capture (IQ/PCAP) + command log + output | +| High | `repro.txt` + (raw capture **or** command log with output) | +| Medium | `repro.txt` + command output (log) | +| Low/Info | `repro.txt` (capture optional if the tool produces one) | + +**PII in evidence:** captures containing third-party data are masked/sanitized before entering the report (see PII +policy in SCOPE AND LIMITS). Unacceptable formats as primary evidence: text screenshots (use `.log`), manual summaries +without a command, captures without timestamp or associated command. + +--- + +## CHECKPOINT — SAVE STATE EVERY 5 FINDINGS + +```bash +python3 -c "import json,datetime,os; os.makedirs('loot',exist_ok=True); p='loot/session_state.json'; s=json.load(open(p)) if os.path.exists(p) else {}; s.update({'phase':'{{CURRENT_PHASE}}','protocol':'{{PROTO}}','completed':s.get('completed',[])+['{{COMPLETED_PHASE}}'],'next_test':'{{EXACT_TEST — tool, layer, parameters}}','last_updated':datetime.datetime.now().isoformat()}); json.dump(s,open(p,'w'),indent=2,ensure_ascii=False)" +``` + +> Replace the `{{...}}` markers with the actual session values before executing. +> **NEVER stop mid-phase.** If context runs out: save state and report `Phase / Completed / +> Next / How to resume`. + +--- + +## REFERENCE NAVIGATION — WHAT TO READ AND WHEN + +| File | Read when... | +|---------|----------------| +| `references/00-taxonomy.md` | **Always at the start** — layers, IDs, criticality, coverage-map, BSAM deference | +| `references/01-authorization.md` | Before any active step — legal frameworks by technique/jurisdiction | +| `references/02-kit-sdr.md` | When choosing a radio at SP — catalog of SDRs/sniffers and their limits | +| `references/03-finding-registration.md` | Before the first finding — JSONL schema, finding format, CVSS 4.0 RF | +| `references/10-ble.md` … `24-uwb.md` | **When selecting the protocol in Phase 0** — wayfinder + controls per layer | +| `references/25-troubleshooting.md` | When a phase does not progress — diagnosis before Route A | +| `references/26-quality.md` | Before registering/closing — Q1–Q8 rubric and criticality | + +**Progressive disclosure**: only load the `NN-proto.md` for the protocol in scope. + +--- + +## QUALITY — VERIFY BEFORE REPORTING + +> Transversal: before registering and closing the report. What does not pass is hypothesis, not finding. Expanded +> Q1–Q8 rubric: `references/26-quality.md`. + +1. **Authorization first** — never execute AT without a confirmed gate; observational mode by default. +2. **Cite or flag (Q1)** — every non-trivial claim carries a verifiable CVE/paper/tool or `> [!FLAG]`. +3. **Mandatory evidence (Q6)** — without capture/command output + `repro.txt`, there is no finding (it is a hypothesis). +4. **Verbatim commands (Q2)** — exact copy of flags/syntax from the wayfinder; do not paraphrase or invent. +5. **Top-down descent** — do not skip CR/AT without clean SP/PHY/LL. +6. **"Not observed" ≠ "absent"** — calibrate against the capture envelope (Phase 2). +7. **Honest criticality (Q3)** — observational = info/low; takeover/key = high/critical. Strong crypto (LESC/AES/S2/STS) → say so, redirect to hardening. +8. **Defer to BSAM (Q4)** on Bluetooth link-and-above (do not redirect BSAM content). +9. **Register immediately** in JSONL — do not accumulate. +10. **Explicit legal warning (Q5)** at every step that transmits/replays/jams/spoofs. + +--- + +## FINDING FORMAT (block in chat, in addition to the JSONL) + +Complete template (fields, order, 4-axis model, 3-layer remediation): `assets/finding-template.md`; JSONL schema: +`references/03-finding-registration.md`. The chat block synthesizes title, severity, protocol/layer/control, description, +evidence (command + output), impact, PoC, remediation and CVSS 4.0. + +--- + +## CONSULT / ESCALATE + +If after 3 attempts you do not progress, or the crypto/signal exceeds the available kit: +``` +CONSULT → document +CONTEXT: [protocol, layer, what you see] +EVIDENCE: [exact command/output] +QUESTION: [what you need] +ALREADY TRIED: [techniques that failed] +``` +And recommend escalating to additional hardware/permission (e.g., bladeRF for full band, test SIM for rogue cell). + +--- + +## AUDIT CLOSURE + +**Complete audit criterion:** the 7 layers of the protocol in scope traversed or gap documented for each non-applicable +layer (Phase 7 precondition). + +**Closure checklist — per finding:** Q1–Q8 rubric passed (`references/26-quality.md §pre-registration`); `repro.txt` + verbatim +command in `loot/poc/RF-NNN/` (§EVIDENCE); 4-axis model + CVSS 4.0 (§SEVERITY); `RFSAM---NN` control mapped; +3-layer mitigation — `critical`/`high` require all 3; `medium` requires Integrator + Operator. + +**Closure checklist — per session:** scope respected (no TX outside scope); `loot/scope.txt` finalized (closure date, +retention confirmed); visibility gaps declared; PII sanitized in evidence and report (PII policy in §SCOPE). + +**Deliverables:** +1. `python3 scripts/coverage_check.py` → lists covered vs. pending controls per protocol (dump to report §5). +2. `python3 scripts/scaffold_report.py` → generates `rfsam-report-.md` from the JSONL. +3. **Technical report** — fill in `assets/report-template.md` with analysis, impact and remediation. +4. **Executive summary** — generate the non-technical version using `assets/executive-summary-template.md`. +5. Report to the user: findings by severity, covered controls, visibility gaps, next steps. +6. Optional: purge `loot/` keeping only the final report (respect retention declared in `scope.txt`). diff --git a/Skill/agents/openai.yaml b/Skill/agents/openai.yaml new file mode 100644 index 0000000..de09856 --- /dev/null +++ b/Skill/agents/openai.yaml @@ -0,0 +1,4 @@ +interface: + display_name: "RFSAM — RF Security Audit" + short_description: "Radio frequency security audit with the RFSAM methodology" + default_prompt: "Audit this RF target following RFSAM: identify the protocol, walk through the 7-layer descent (IG→SP→PHY→LL→CR→AT→AP) and register findings with evidence." diff --git a/Skill/assets/executive-summary-template.md b/Skill/assets/executive-summary-template.md new file mode 100644 index 0000000..49c7af3 --- /dev/null +++ b/Skill/assets/executive-summary-template.md @@ -0,0 +1,123 @@ +# Executive Summary — Radio Frequency Security Audit · {{TARGET}} + +> Template for the **executive summary** of an RFSAM audit, aimed at sponsors and +> non-technical committees. **No commands, no CVSS vectors, no control IDs.** The agent +> translates findings from the technical report (`assets/report-template.md`) into +> business risk, impact and remediation priorities. Replace the `{{...}}` placeholders +> with clear, concrete language. Target length: **1–2 pages**. If it exceeds that, trim +> detail and move it to an appendix in the technical report. + +**Delivery date**: {{ISO}} +**Prepared for**: {{name/title of sponsor or committee}} +**Prepared by**: {{name/role of auditor}} +**Classification**: {{Confidential / Internal / Public}} +**Associated technical report**: `{{path to rfsam-report-.md}}` + +--- + +## 1. Context in one sentence + +{{One or two sentences: what radio frequency system or environment was assessed, why +it matters to the business and under what engagement it was performed. E.g.: "The +wireless exposure of manufacturing plant X was reviewed to confirm that control +communications and mobile devices do not allow unauthorized access."}} + +## 2. Main conclusion + +{{Executive verdict in 2–3 lines: overall risk level and the single takeaway the reader +should come away with. E.g.: "The environment presents **high** wireless risks +concentrated in 3 critical findings. They are closable in under 90 days with coordinated +actions from device vendors and the operations team."}} + +**Overall risk**: {{Critical / High / Medium / Low}} + +--- + +## 3. Findings in figures + +| Risk level | Count | What it means in practice | +|------------|-------|---------------------------| +| **Critical** | {{c}} | Exploitable today; can compromise operations, data or physical safety | +| **High** | {{h}} | Exploitable with effort or under specific conditions; serious impact if it occurs | +| **Medium** | {{m}} | Requires favorable access or combinations; limited or localized impact | +| **Low / Informational** | {{l}} | Hardening recommended; no immediate exposure | + +> Total confirmed findings: **{{N}}**. Additionally **{{nh}}** are documented as verifiable +> hypotheses that require further testing in a controlled environment before being confirmed. + +--- + +## 4. Risks requiring immediate attention + +> One block per **critical or high** finding. Maximum 5–7 items; if there are more, +> group by theme. For each: **what happens** (without jargon), **what it affects** +> (business/operations/compliance/security) and **how easy it is to exploit**. +> Do not include how to exploit it or technical steps. + +### Risk 1 — {{short, business-oriented title}} +- **What we observed**: {{plain-language description. E.g.: "Anyone with commercially + available equipment can spoof the signal from the sensors and send false readings to + the central system."}} +- **Impact if it materializes**: {{operational / financial / safety / + regulatory / reputational. E.g.: "Automated decisions made on falsified data; possible + line stoppage and quality rejections."}} +- **Likelihood of occurrence**: {{High / Medium / Low}} — {{brief reason: + publicly available tools / requires physical proximity / requires specialized + knowledge}}. +- **Remediation priority**: {{Immediate / 30 days / 90 days}}. + +{{... more risks in priority order ...}} + +--- + +## 5. What is working well + +{{2–4 short bullets about controls, layers or practices that do work and that the audit +confirmed as robust. This balances the message and indicates where NOT to intervene. +E.g.: "Corporate Wi-Fi network encryption uses current standards and showed no weaknesses; +LoRa devices use unique keys per node and are not clonable."}} + +--- + +## 6. Recommended action plan + +| Priority | Risk to close | Main action (no technical detail) | Suggested owner | Estimated effort | Deadline | +|----------|---------------|-----------------------------------|-----------------|------------------|----------| +| 1 | {{Risk 1}} | {{business action, e.g.: "Coordinate with the sensor vendor to change the authentication mechanism."}} | {{Operations / IT / Vendor}} | {{Low/Medium/High}} | {{immediate / 30d / 90d}} | +| 2 | {{Risk 2}} | {{...}} | {{...}} | {{...}} | {{...}} | +| 3 | {{...}} | {{...}} | {{...}} | {{...}} | {{...}} | + +> **Critical and high** findings require coordinated action at three levels: the device/ +> firmware **manufacturer**, the **integrator** who deploys and configures, and the +> **operator** who monitors and responds. **Low or informational** findings may be closed +> with operator actions alone. + +--- + +## 7. Scope and confidence + +- **What we covered**: {{protocols and devices assessed, mode of operation: + passive listening only / authorized active testing / lab environment}}. +- **What we did NOT cover**: {{out-of-scope protocols or devices; time windows or bands + not observed; devices that were not operational during the audit}}. +- **Confidence**: **confirmed** findings are backed by reproducible evidence. Those marked + as **hypotheses** require additional verification before being treated as confirmed. +- **Applicable compliance**: {{if applicable, mention relevant frameworks — ISO 27001, + IEC 62443, PCI-DSS, local spectrum regulation — and whether the audit provides evidence + for or against}}. + +--- + +## 8. Suggested next steps + +1. **Validate priorities** with the technical and business teams (1-hour meeting). +2. **Begin closure** of critical findings within the agreed window. +3. **Re-audit** after applying remediation to confirm effective closure. +4. **Establish a cadence** for wireless surface review (semi-annually or upon relevant + changes to the device fleet). + +--- + +_Executive summary generated following RFSAM (CC BY-SA 4.0). Full technical detail, +commands, evidence and control mapping are in the associated technical report. For +technical questions, contact the auditor; for business decisions, the sponsor._ diff --git a/Skill/assets/finding-template.md b/Skill/assets/finding-template.md new file mode 100644 index 0000000..463ea0e --- /dev/null +++ b/Skill/assets/finding-template.md @@ -0,0 +1,110 @@ +# RF Finding Template — {{RF-NNN}} + +> **Standalone document per finding.** Use it for `critical`/`high` that deserve a +> detailed write-up beyond the report section (see `assets/report-template.md §4`). +> The compact chat block lives in `references/03-finding-registration.md §3`; the +> complete 4-axis model (decision table, worked examples) is in `§7` of the same +> file. + +**ID**: {{RF-NNN}} +**Title**: {{specific finding title}} +**Protocol/Layer**: {{BLE / AT}} · **RFSAM control**: `{{RFSAM-BLE-AT-01}}` +**Severity**: {{CRITICAL / HIGH / MEDIUM / LOW / INFO}} · **Status**: {{confirmed / hypothesis}} +**Date**: {{ISO}} + +--- + +## RFSAM 4-axis model + +> Walk through the axes in order (Impact sets the ceiling; the others modulate it). +> Decision table: `references/03-finding-registration.md §7.2`. + +| Axis | Value | Justification (1 line) | +|------|-------|------------------------| +| **Impact** (1–4) | {{4}} | {{takeover / key recovered / plaintext data / DoS / observational}} | +| **Exploitability** (1–4) | {{2}} | {{required hardware + friction to reproduce}} | +| **Exposure** (1–4) | {{2}} | {{single device / single network / public infrastructure}} | +| **Scope** (A/B/C/D) | {{A}} | {{achieved in the field / demonstrated in a cage (B) / hypothetical (C) / defensive (D)}} | + +**CVSS 4.0**: `{{CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N}}` ({{score}}, {{sev}}) + +--- + +## Description + +{{What was found, the technical mechanism and why it matters. Name the device/scenario, +the protocol and the descent layer where it was detected. Cite the underlying vulnerability +(CVE / weakened spec / misconfiguration) with a verifiable source. A non-trivial claim +without a source is flagged (see `references/03-finding-registration.md §6`).}} + +--- + +## Impact + +{{What a real attacker gains in the field: takeover, credential theft, replay, DoS, +identity tracking. Connect to the Impact axis above. If Scope is B/C/D, clarify what +was demonstrated vs what remains hypothetical — the severity reflects what you ACHIEVED, +not what could theoretically be achieved.}} + +--- + +## Evidence + +``` +COMMAND: {{exact tool + flags — verbatim}} +OUTPUT: {{excerpt that confirms the finding — AA, recovered key, 200 OK, decoded frame, ...}} +``` + +> Raw capture in `loot/captures/{{PROTO}}-{{phase}}-{{NN}}-{{timestamp}}.{{ext}}`. +> The minimum evidence depends on severity — see `SKILL.md §REPRODUCIBLE EVIDENCE`. + +--- + +## Safe reproduction + +> Each `poc/{{RF-NNN}}/` includes a `repro.txt`. **Without `repro.txt`, the finding is a +> hypothesis, not a confirmed finding** — it does not enter the report as confirmed. + +``` +TARGET: {{exact device/scenario}} +HARDWARE: {{SDR / sniffer + version}} +SOFTWARE: {{tool + version · OS}} +COMMAND: {{verbatim — flags, parameters, frequency, sample rate, gain, channel}} +CONDITIONS: {{proximity · mode (observational/active/lab) · containment if applicable}} +RESULT: {{expected observable output that confirms}} +``` + +> ⚠ **Safety markers**: if the command involves transmission (`⚠TX`), re-confirm +> authorization in `loot/scope.txt` before executing (see the gate in `SKILL.md`). If it +> is passive RX, verify the tool's RX marker (`references/25-troubleshooting.md §1`). +> Critical infrastructure (GNSS / ADS-B / rogue cell) requires containment +> (cage/conductive enclosure) even in active mode. + +--- + +## Mitigation (3 layers) + +> RFSAM remediation model — inherited from the 50 controls. `critical`/`high` require all 3 +> layers; `low`/`info` may close with Operator alone. `medium` requires at least Integrator + Operator. See `references/03-finding-registration.md §7`. + +- **Developer** (manufacturer / firmware): {{product code or configuration changes — + e.g. enforce ECDH, rotate NWK key, encrypt GATT, implement robust rolling code}} +- **Integrator** (deployment / configuration): {{deployment changes — e.g. rekey after + commissioning, disable legacy pairing, segment PAN, require LESC}} +- **Operator** (use / monitoring): {{operational changes — e.g. monitor anomalous + advertising, rotate credentials periodically, periodic audits, register only + authorized tags}} + +--- + +## References + +- {{CVE-XXXX-XXXX — https://...}} +- {{Paper: Author, "Title", venue year — https://...}} +- {{Tool: name — https://github.com/...}} +- {{Spec: Bluetooth Core Spec v5.4, Vol 6 Part B}} + +--- + +_Generated with RFSAM (CC BY-SA 4.0). Reproducible evidence in `loot/`. Re-validate after +applying remediation._ diff --git a/Skill/assets/report-template.md b/Skill/assets/report-template.md new file mode 100644 index 0000000..d36d55a --- /dev/null +++ b/Skill/assets/report-template.md @@ -0,0 +1,158 @@ +# RF Security Audit Technical Report — {{TARGET}} + +> Template for the **technical report** of an RFSAM audit. `scripts/scaffold_report.py` +> generates the skeleton from `loot/rfsam_findings.jsonl`; the agent completes the +> analysis, impact and remediation. Replace the `{{...}}` placeholders. The **executive +> summary** (non-technical audience) is a separate document — see +> `assets/executive-summary-template.md`. + +**Date**: {{ISO}} +**Auditor**: {{name/role}} +**Client/Owner**: {{client}} +**Methodology**: RFSAM (Radio Frequency Security Assessment Methodology) — Electronic Cats +**Complementary framework**: OSSTMM, BSAM (Tarlogic), SDR-pentest lineage +**Content license**: CC BY-SA 4.0 +**Report classification**: {{Confidential / Public / Internal}} + +--- + +## 1. Technical summary + +- **Total findings**: {{N}} (Critical: {{c}} · High: {{h}} · Medium: {{m}} · Low: {{l}} · Info: {{o}}) +- **Confirmed**: {{nc}} · **Hypotheses (no `repro.txt`)**: {{nh}} — _hypotheses do not count as confirmed findings._ +- **Audited protocols**: {{BLE, Wi-Fi, ...}} +- **RFSAM control coverage**: {{X/Y}} (see §5) +- **Mode of operation**: {{observational / active / lab-contained / defensive}} + +> Technical synthesis (2–4 lines): what was audited, surface covered, technical residual +> risk. The **business** synthesis goes in the executive summary, not here. + +--- + +## 2. Scope and authorization + +``` +Target: {{description of the device/system/signal}} +Owner / authorization: {{OWN / CONTRACT / LAB}} +Mode of operation: {{observational / active / lab-contained / defensive}} +Authorized by: {{name/role of authorizing party}} +Authorization date: {{ISO}} +Protocol(s) in scope: {{BLE / WIFI / ...}} +Limitations: {{e.g. RX only; no deauth; do not clone real credentials; capture window X MHz}} +Capture retention: {{default 30 days post-delivery; purge requested: yes/no}} +``` + +> The mode of operation constrained the techniques executed. Attack-layer steps were +> performed only where the scope permitted; the rest are documented as verifiable +> hypotheses in an authorized environment. Any third-party PII (IMSI/IMEI, persistent BLE +> address, probe SSIDs, foreign RFID UID) is masked/hashed in this report; only audited +> asset identifiers appear in cleartext. + +--- + +## 3. Methodology + +Audit following the **RFSAM 7-layer descent** (IG → SP → PHY+LL → CR → AT → AP) per +protocol. PHY and LL are assessed together (the same tool produces both). Each finding is +mapped to a control `RFSAM---NN` and scored with the **RFSAM 4-axis model** +(Impact, Exploitability, Exposure, Scope A/B/C/D) consolidated into CVSS 4.0 — see +`references/03-finding-registration.md §7`. In RF almost always `AV:A` (adjacent, radio range). + +| Layer | What was verified | +|-------|-------------------| +| IG | SoC/host stack identification + cross-reference with published CVEs | +| SP | Capture feasibility (band vs radio IBW) | +| PHY+LL | Demodulation → bits; frame capture → Wireshark | +| CR | Cryptography assessment / weak key recovery | +| AT | Takeover (only where scope authorized it) | +| AP | What the device trusts over the link | + +For Bluetooth (BLE/Classic) at the link layer and above, RFSAM defers to **BSAM** and +contributes only the RF capture prerequisite. For LoRa/LTE/RFID/Sub-GHz/etc., RFSAM owns +the assessment end-to-end. + +--- + +## 4. Findings + +> Sorted by severity (Critical → Info). Each **confirmed** finding includes a +> `repro.txt` in `loot/poc/RF-NNN/`; without `repro.txt` it is registered as a hypothesis, +> not as confirmed. + +### 4.1 CRITICAL + +#### {{RF-001}} — {{title}} +- **Protocol/Layer**: {{BLE / AT}} · **Control**: `RFSAM-BLE-AT-01` +- **Severity**: CRITICAL +- **RFSAM model**: Impact {{1-4}}/4 · Exploitability {{1-4}}/4 · Exposure {{1-4}}/4 · Scope {{A/B/C/D}} +- **CVSS 4.0**: `{{vector}}` ({{score}}, {{sev}}) +- **Description**: {{what was found, mechanism, why it matters}} +- **Evidence**: + ``` + COMMAND: {{exact tool + flags}} + OUTPUT: {{excerpt that confirms}} + ``` +- **Reproduction**: `loot/poc/RF-001/repro.txt` (verbatim command + environment + capture conditions) +- **Impact**: {{what an attacker can do}} +- **Mitigation** (3 layers): + - _Developer_: {{...}} + - _Integrator_: {{...}} + - _Operator_: {{...}} +- **References**: {{CVE / paper / tool + URL}} + +### 4.2 HIGH +{{...}} + +### 4.3 MEDIUM +{{...}} + +### 4.4 LOW +{{...}} + +### 4.5 INFO (includes defensive findings / detection) +{{...}} + +--- + +## 5. RFSAM control coverage + +> Paste the output of `python3 scripts/coverage_check.py` here. + +{{table per protocol: covered / pending / not applicable controls}} + +--- + +## 6. Limitations + +- **Visibility gaps**: {{radio/IBW used; what could not be observed and why}} +- **Out-of-scope controls**: {{e.g. AT not executed due to observational mode}} +- **Assumptions**: {{e.g. join not captured because the device did not re-pair during the window}} +- **Declared strong crypto not breakable**: {{e.g. LESC ECDH on this device → CR assesses, does not decrypt}} + +--- + +## 7. Prioritized remediation + +| Priority | Finding | Action | Responsible layer | Effort | Deadline | +|----------|---------|--------|-------------------|--------|----------| +| 1 | {{RF-001}} | {{concrete action}} | {{Developer/Integrator/Operator}} | {{low/med/high}} | {{immediate/30d/90d}} | +| 2 | {{...}} | {{...}} | {{...}} | {{...}} | {{...}} | + +> `critical`/`high` require all 3 layers (Developer/Integrator/Operator); `medium` requires Integrator +> + Operator; `low`/`info` may close with Operator alone. + +--- + +## 8. Appendices + +- **A. Captures**: PCAPs, IQ waterfalls, Proxmark dumps (in `loot/captures/`) +- **B. PoC**: `loot/poc/RF-NNN/` with `repro.txt` per confirmed finding +- **C. Session logs**: `loot/session_state.json`, `loot/rfsam_findings.jsonl`, `loot/hardware.txt` +- **D. References**: full list of CVEs, papers, tools with URLs +- **E. Kit used**: radios/sniffers/software + version (paste `loot/hardware.txt`) + +--- + +_End of technical report. Generated following RFSAM (CC BY-SA 4.0). Reproducible evidence +available in `loot/`. Re-validation recommended after applying remediation. For the +non-technical executive version, see `assets/executive-summary-template.md`._ diff --git a/Skill/references/00-taxonomy.md b/Skill/references/00-taxonomy.md new file mode 100644 index 0000000..f568571 --- /dev/null +++ b/Skill/references/00-taxonomy.md @@ -0,0 +1,163 @@ +# 00 — RFSAM Taxonomy + +> **Always read at the start of every audit.** Defines the two RFSAM indexing axes +> (protocol × layer), the IDs, the criticality rubric, the full coverage-map, and the +> deference to BSAM. Source: `RFSAM/src/lib/taxonomy.js`, `src/data/layers.js`, +> `src/data/protocols.js`, `src/data/criticality.js`, `src/data/coverage-map.js`, +> `src/data/bsamRelation.js`. + +## Index +1. The 7 layers of the methodology +2. The 15 protocols +3. Control ID rules +4. Criticality rubric +5. reviewStatus / confidence lifecycle +6. Full coverage-map (all controls by protocol) +7. RFSAM ↔ BSAM relationship (deference) + +--- + +## 1. The 7 layers of the methodology + +An RF audit follows a top-down **descent**. IG is pre-descent; SP→AP is the descent. + +| ID | Layer | Color | What it asks | +|----|------|-------|--------------| +| `IG` | Info Gathering | #C9D4E0 | Identify components and cross-reference CVEs before touching the air | +| `SP` | Spectrum | #2FB8E0 | What it transmits, where, and whether your radio can see it | +| `PHY` | Signal / PHY | #3FD17C | From waveform to bits: modulation, demodulation, channelization | +| `LL` | Link / Protocol | #9B8CFF | Frame structure, addressing, identifiers, discovery | +| `CR` | Crypto | #FFC24B | Pairing, key exchange, link confidentiality and integrity | +| `AT` | Attack | #FF7A1A | Active interaction: injection, replay, hijack, rogue infrastructure | +| `AP` | Application | #FF5A5F | What the device trusts over the link: auth, signatures, updates | + +**Guiding principle**: the descent is top-down. Do not jump to CR/AT without having passed through SP/PHY/LL. +A clean capture is the foundation of everything else. "Not observed" under a limited radio window +is a **visibility gap, not evidence of absence**. + +## 2. The 15 protocols + +| ID | Name | Band | Prefix | Status | +|----|------|-------|---------|--------| +| `BLE` | Bluetooth Low Energy | 2.402–2.480 GHz | RFSAM-BLE | deepen | +| `BTC` | Bluetooth Classic | 2.402–2.480 GHz (BR/EDR) | RFSAM-BTC | new | +| `WIFI` | Wi-Fi (802.11) | 2.4 / 5 / 6 GHz | RFSAM-WIFI | deepen | +| `LORA` | LoRa / LoRaWAN | ISM sub-GHz (US915 / EU868) | RFSAM-LORA | deepen | +| `LTE` | LTE / 4G | Licensed cellular | RFSAM-LTE | deepen | +| `RFID` | RFID / NFC | 125 kHz LF / 13.56 MHz HF | RFSAM-RFID | deepen | +| `SUBG` | Sub-GHz ISM / Remotes | 315 / 433 / 868 / 915 MHz | RFSAM-SUBG | deepen | +| `ZIGBEE` | Zigbee / 802.15.4 | 2.4 GHz (+ 868/915 MHz) | RFSAM-ZIGBEE | new | +| `ZWAVE` | Z-Wave | Sub-GHz regional (~868/908 MHz) | RFSAM-ZWAVE | new | +| `THREAD` | Thread / Matter | 2.4 GHz (802.15.4) | RFSAM-THREAD | new | +| `GNSS` | GNSS / GPS | L-band (GPS L1 1575.42 MHz) | RFSAM-GNSS | new | +| `ADSB` | ADS-B (aviation) | 1090 MHz / 978 MHz UAT | RFSAM-ADSB | new | +| `NR5G` | 5G NR | FR1 sub-6 GHz / FR2 mmWave | RFSAM-NR5G | new | +| `GSM` | GSM / 2G | 850 / 900 / 1800 / 1900 MHz | RFSAM-GSM | new | +| `UWB` | Ultra-Wideband | 3.1–10.6 GHz | RFSAM-UWB | new | + +## 3. Control ID rules + +Format: **`RFSAM---`** — e.g. `RFSAM-BLE-AT-01`. + +- `` ∈ the 15 IDs above. +- `` ∈ `IG SP PHY LL CR AT AP`. +- `` = two-digit sequence number. + +**Validated invariant**: the ID's PROTOCOL and LAYER segments **must match** the +`protocol` and `layer` fields of the frontmatter/control. If they do not match, it is an error. + +Regex: `^RFSAM-(BLE|BTC|WIFI|LORA|LTE|RFID|SUBG|ZIGBEE|ZWAVE|THREAD|GNSS|ADSB|NR5G|GSM|UWB)-(IG|SP|PHY|LL|CR|AT|AP)-\d{2}$` + +## 4. Criticality rubric + +| Level | Color | When | +|-------|-------|------| +| `info` | #8B9AAB | Observational; no direct impact (e.g. capture feasibility) | +| `low` | #3FD17C | Minor exposure or hardening gap | +| `medium` | #FFC24B | Significant weakness requiring specific conditions | +| `high` | #FF7A1A | Easily exploitable weakness with significant impact | +| `critical` | #FF5A5F | Total compromise (takeover, key recovery, spoofing) | + +**Rule**: severity reflects what you **achieved** with evidence, not the theoretical maximum. + +## 5. reviewStatus / confidence lifecycle + +- `stub` → migrated skeleton, little real content. +- `draft` → researched and cited, may carry unresolved `[!FLAG]`. What a sub-agent produces. +- `reviewed` → citations and method confirmed, but the field case is an illustrative template. +- `verified` → reviewed AND demonstrated with a real field case; ≥1 reference, zero `[!FLAG]`. + +`confidence` ∈ `low medium high` — honest self-assessment of the draft. + +## 6. Full coverage-map + +Map of all controls that RFSAM defines (one per relevant protocol×layer cell). +`status: existing` = file exists; many are `stub`s to be deepened. + +**BLE**: IG-01 (SoC/host stack vulns) · SP-01 (channel map) · PHY-01 (demod/bit recovery) · +LL-01 (advertising/identifier exposure) · LL-02 (connection-data capture) · CR-01 (pairing/encryption) · AT-01 (hijack live connection) + +**BTC**: IG-01 (identify device/BR-EDR/vuln corpus) · SP-01 (inquiry-scan) · LL-01 (baseband capture) · CR-01 (pairing/key strength) · AT-01 (LMP resilience) · AP-01 (exposed profiles) + +**WIFI**: SP-01 (band/channel survey) · LL-01 (management-frame exposure) · CR-01 (WPA handshake/PMKID) + +**LORA**: SP-01 (sub-band occupancy) · PHY-01 (chirp demod) · LL-01 (LoRaWAN frame profiling) · CR-01 (join/session-key) + +**LTE**: IG-01 (baseband/modem vulns) · SP-01 (cell ID/capture) · PHY-01 (resource-grid) · LL-01 (control-channel/identity exposure) + +**RFID**: SP-01 (carrier/standard ID) · CR-01 (Crypto1/key strength) · AT-01 (clone/emulate/relay) + +**SUBG**: SP-01 (burst discovery) · PHY-01 (demod/framing) · LL-01 (frame/addressing recovery) · CR-01 (rolling-code) · AT-01 (replay/forge) + +**ZIGBEE**: SP-01 (channel survey) · LL-01 (PAN/addressing/discovery) · CR-01 (network-key provisioning) + +**ZWAVE**: SP-01 (region/frequency ID) · CR-01 (key establishment) + +**THREAD**: LL-01 (mesh discovery/commissioning exposure) · CR-01 (network credential) + +**GNSS**: SP-01 (signal presence/interference survey) · AT-01 (spoofing/jamming resilience) + +**ADSB**: PHY-01 (message capture/decode) · LL-01 (message authenticity) · AT-01 (forge/inject, lab contained) + +**NR5G**: SP-01 (cell ID/capture) · LL-01 (broadcast/identity exposure) + +**GSM**: SP-01 (ARFCN survey) · CR-01 (cipher/identity exposure) + +**UWB**: PHY-01 (ranging signal capture) · AT-01 (distance-manipulation resilience) + +> The `scripts/coverage_check.py` script automates the comparison against this map. + +## 7. RFSAM ↔ BSAM relationship + +**RFSAM is complementary to BSAM (Tarlogic), not a replacement.** BSAM is the mature reference for +Bluetooth; RFSAM is the multi-protocol north star. + +### Ownership +- **Spectrum (SP) + Signal/PHY** → RFSAM is the owner for all protocols. BSAM does not cover here. +- **BLE link layer and above** → inherited from BSAM. RFSAM adds only the RF capture prerequisite + and references the specific BSAM-xx controls. +- **LoRa/LoRaWAN, LTE, and the rest** → RFSAM is the owner end-to-end. BSAM is Bluetooth only. + +### BSAM registry that RFSAM references +- `BSAM-IG-01` Bluetooth controller lifecycle status +- `BSAM-IG-02` Bluetooth controller vulnerabilities +- `BSAM-IG-03` Host stack vulnerabilities +- `BSAM-IG-04` Standard vulnerabilities +- `BSAM-DI-03` Generic device naming +- `BSAM-DI-04` Sensitive data exposure +- `BSAM-DI-06` Use random MAC address +- `BSAM-PA-01` Device pairing mode +- `BSAM-PA-04` Rejection of legacy pairing +- `BSAM-PA-05` Pairing without interaction +- `BSAM-AU-03` Forced disconnection +- `BSAM-EN-01` Role switch before encryption +- `BSAM-EN-02` Force use of encryption +- `BSAM-EN-03` Minimum encryption key size +- `BSAM-SE-03` Service access control +- `BSAM-AP-05` Replay attacks +- `BSAM-AP-06` Packet injection + +BSAM URL: + +**Rule**: when a BLE/BTC control is `deferred: true`, do NOT redirect BSAM content. +Describe only the RF capture prerequisite and cite the BSAM control (`BSAM-XX-NN`) to which it is handed off. diff --git a/Skill/references/01-authorization.md b/Skill/references/01-authorization.md new file mode 100644 index 0000000..ac7dfdf --- /dev/null +++ b/Skill/references/01-authorization.md @@ -0,0 +1,114 @@ +# 01 — Authorization Protocol and Legal Framework + +> **Read this before any active step (AT layer) or any transmission.** RFSAM is intrinsically +> dual-use. RF crosses physical property and regulated spectrum: what you receive may not be yours, +> and what you transmit is almost never legal without permission. This is not bureaucracy — it is the +> difference between an audit and a crime. + +## Index +1. Four modes of operation +2. Legality matrix by technique +3. Confirmation protocol (gate 0) +4. Jurisdictions — quick reference +5. RF containment for lab +6. Scope documentation + +--- + +## 1. Four modes of operation + +Before starting, the agent **must ask** and record the mode: + +| Mode | What it allows | What it prohibits | +|------|-------------|-------------| +| **(1) Observational / passive** | Passive RX (sniff, survey, waterfall) over traffic you can legally receive | Any TX, replay, injection, jamming, spoofing, connecting to third-party devices | +| **(2) Active with authorization** | All of the above + TX/replay/inject **only on your own equipment or with written authorization** from the owner, respecting power/duty-cycle limits of unlicensed spectrum | Any action on third-party equipment or licensed spectrum without a test license | +| **(3) Lab RF contained** | All of the above + jamming/spoofing/rogue-cell **inside a Faraday cage or conducted (wired)**, with test SIMs/devices | Radiating over the air jamming, GNSS, ADS-B, or false cells under any circumstances | +| **(4) Defensive** | Passive RX on your own spectrum to **detect, correlate, and alert** on threats (jamming, rogue infrastructure, anomalous signals) | Any TX (including "to test the detector"); offensive descent; surveillance of third parties | + +**Safe default**: if the user does not specify, or there is doubt → **mode (1) observational**. AT steps +are documented as hypotheses to verify in an authorized environment, **never executed**. + +## 2. Legality matrix by technique + +| Technique | Allowed without authorization? | Restrictions | +|---------|------------------------------|---------------| +| Passive reception (sniff, survey) | Generally yes | Third-party personal data is regulated (GDPR/privacy) | +| Capture traffic from your device | Yes (it is yours) | — | +| Capture third-party traffic | Depends | Usually illegal to decrypt/use; RX of public signals (ADS-B) OK | +| Connect to a third-party device (BLE GATT) | **No** without permission | Unauthorized access | +| Transmit / replay / forge | **No** without explicit permission from the device owner | — | +| Wi-Fi deauth / forced disconnection | **No** without permission | Disrupts third-party service | +| Jamming (saturating band) | **Almost never** | Illegal over the air in almost all jurisdictions (FCC, ITU) | +| GNSS spoofing over the air | **No** (crime) | Conducted/cable + cage only | +| ADS-B spoofing/forging over the air | **No** (protected aviation spectrum) | Conducted + cage only | +| Rogue cell LTE/GSM/5G (IMSI catcher) | **No** (licensed spectrum) | Lab + test SIMs + test license + cage only | +| Clone/emulate your own RFID | Yes (it is yours) | Cloning third-party credentials = fraud | +| Force re-pair/re-join of your network | Yes (it is yours) | — | + +## 3. Confirmation protocol (gate 0) + +**The first interaction of the agent with the user, before any capture, must be:** + +> "Before proceeding, I need to confirm the authorization framework for this RF audit: +> +> 1. Is the target **yours** or are you **authorized in writing** to audit it? +> 2. In which mode do I work? +> - (1) **Observational/passive** — RX only, without actively touching devices +> - (2) **Active with authorization** — TX/replay/inject on authorized equipment +> - (3) **Lab RF contained** — Faraday cage or conducted (wired) +> - (4) **Defensive** — passive RX to detect threats in your own environment (no TX) +> +> I will record your answer in `loot/scope.txt`. If there is doubt, I operate in observational mode." + +- Record the answer in `loot/scope.txt` (created by the Phase 0 snippet in SKILL.md). +- **Re-verify** the scope before each AT step. If the scope says observational → block AT. +- On ambiguity ("it's a friend's", "I think I can") → assume observational and warn. + +## 4. Jurisdictions — quick reference + +> This is not legal advice. Orientation only. Verify local law before operating. + +- **USA**: FCC regulates the spectrum. Jamming is illegal (Communications Act §333). GNSS spoofing + is illegal. Interception of electronic communications (Wiretap Act) restricts content capture. + Exceptions: equipment owner, with consent, or legal authority. +- **EU/UK**: national regulators + harmonized regulation. In the UK, interception without + consent is illegal (Investigatory Powers Act 2016). GDPR applies to personal data in captures. +- **Latam**: varies. Generally: intercepting third-party communications is a crime; jamming is usually + prohibited; passive RX of public signals is usually legal. Verify country by country. +- **Licensed spectrum (cellular)**: transmitting without a license is illegal **everywhere**. Working + with rogue cells requires an experimental test license + containment. + +**Universal principle**: transmitting on licensed bands, jamming over the air, or spoofing security +signals (GNSS, ADS-B) without authorization is a crime. Do not do it outside a contained lab. + +## 5. RF containment for lab + +For mode (3), the ways to contain the signal: + +- **Faraday cage**: conductive box/structure that blocks outgoing/incoming RF. Verify + attenuation with a phone inside (it must lose signal). +- **Conducted (wired)**: connect the SDR TX to the receiver/device under test via coaxial cable + with attenuators, never via antenna. Eliminates over-the-air radiation. +- **Attenuators**: limit the power so the signal does not escape the wired setup. +- **Shielded GPSDO**: for GNSS spoofing, the TX goes via cable to the receiver under test, never over the air. + +**Validation**: before transmitting in the lab, confirm with an external SDR or phone that there is +**no** signal leakage outside the containment. + +## 6. Scope documentation + +`loot/scope.txt` must contain at minimum: + +``` +Target: [device/signal description] +Owner / authorization: [OWN / CONTRACT / LAB] +Mode: [observational / active / lab-contained / defensive] +Authorized by: [name/role of authorizing party, if applicable] +Date: [ISO timestamp] +Protocol(s) in scope: [BLE / WIFI / ...] +Limitations: [e.g. RX only; no deauth; no cloning real credentials] +``` + +This file is what `scaffold_report.py` includes in the "Scope and authorization" section of the +report, and what justifies every active step executed. diff --git a/Skill/references/02-kit-sdr.md b/Skill/references/02-kit-sdr.md new file mode 100644 index 0000000..58757d9 --- /dev/null +++ b/Skill/references/02-kit-sdr.md @@ -0,0 +1,90 @@ +# 02 — SDR Kit and Sniffer Catalog + +> Catalog of the radios and tools in the RFSAM skill, with their critical limits (band, instantaneous +> bandwidth IBW, half/full duplex, RX-only). Radio choice at the SP layer **constrains the entire +> audit**: a "not observed" under a narrow window is a gap, not absence. +> Source: `RFSAM/scripts/seed-tools.mjs` + `RFSAM/src/data/protocol-tools/*.json`. + +## Index +1. SDRs wide-band +2. Budget SDRs/dongles +3. Dedicated sniffers by protocol +4. Universal host tools +5. Golden rule: band + IBW + duplex + +--- + +## 1. SDRs wide-band + +| Slug | Radio | IBW | Range | Duplex | Notes | +|------|-------|-----|-------|--------|-------| +| `hackrf-one` | HackRF One (Great Scott Gadgets) | ~20 MHz | 1 MHz–6 GHz | half | Discovery radio. Cannot see the entire BLE/Wi-Fi band at once. | +| `bladerf-2-micro` | bladeRF 2.0 micro xA9 (Nuand) | ~56 MHz (122.88 MHz oversampling @ 8-bit) | 47 MHz–6 GHz | full | Since release 2023.02, oversampling covers the 80 MHz of BLE in one pass. AD9361. | +| `usrp-b210` | USRP B210 (Ettus/NI) | ~56 MHz (30.72 in 2×2) | 70 MHz–6 GHz | full | Lab-grade, GPSDO option for coherent cellular. Common in ice9/srsRAN. | +| `signalsdr-pro` | SignalSDR Pro (Signalens) | 61.44 MHz | 70 MHz–6 GHz | 2TX/2RX | AD9361, Pi form factor. Wider IBW. Emerging product — verify support. | +| `rtl-sdr-v4` | RTL-SDR Blog V4 | ~2.4 MHz | 0.5 kHz–1.766 GHz | RX only | **Does not reach 2.4 GHz** → no BLE/Wi-Fi/Zigbee. Good for sub-GHz, LoRa, ADS-B (1090). Cheap. | + +## 2. Budget SDRs/dongles + +| Slug | What it is | What for | +|------|--------|----------| +| `ubertooth-one` | Open BLE/BT sniffer (CC2400) | BLE/Classic at ~$120; pre-BT5, weak on long links. Software: `ubertooth-tools`. | +| `yard-stick-one` | CC1111 sub-GHz transceiver (300–928 MHz) | RX/TX OOK/ASK/FSK via `rfcat`. The cheap reference sub-GHz tool. | +| `flipper-zero` | Handheld multitool (CC1101) | RX/TX 300–348/387–464/779–928 MHz. Sub-GHz field capture/replay (fixed code only on stock firmware). | + +## 3. Dedicated sniffers by protocol + +| Slug | Hardware | Protocols | Notes | +|------|----------|------------|-------| +| `catsniffer` | CatSniffer (Electronic Cats) CC1352+RP2040 | BLE, Sub-GHz, Zigbee, LoRa | Multiprotocol. Runs Sniffle (BT5), 802.15.4, LoRa. Host: `catnip`. EC. | +| `nrf52840-dongle` | Nordic nRF52840 USB | BLE, 802.15.4 | Cheap. Host of the nRF Sniffer firmware (BLE) and nRF Sniffer 802.15.4, and InjectaBLE. | +| `bbc-microbit` | nRF51822 ~$15 | BLE | Cheap radio for Btlejack (sniff/jam/hijack). | +| `stm32wlxx` | STM32WLxx (Nucleo-WL55JC / LoRa-E5) | LoRa, Sub-GHz | Arm M4 + integrated sub-GHz radio. With WHAD firmware = LoRa sniffer/inject. | +| `proxmark3` | Proxmark3 (Iceman fork) | RFID/NFC LF+HF | RFID reference: full Crypto1 suite, read/write/emulate, relay. | +| `chameleon-ultra` | ChameleonUltra (RRG) nRF52840 | RFID/NFC HF/LF | Card emulator; MIFARE Classic Crypto1. | +| `bombercat` | BomberCat (Electronic Cats) PN7150 | NFC, MagStripe | Read/emulate + relay NFC + MagSpoof. EC. | +| `acr122u` | PN532/ACR122U USB | NFC HF 13.56 MHz | Cheap libnfc reader; mfoc/mfcuk engine. | +| `apimote` | ApiMote (River Loop) CC2420 | Zigbee/802.15.4 | RX+TX radio for KillerBee (can inject). | +| `cc2531` | TI CC2531 USB | Zigbee/802.15.4 2.4 GHz | Capture-only dongle (no inject). Bridge: `whsniff`. | +| `silabs-uzb7` | Silicon Labs UZB-7 (EFR32ZG14) | Z-Wave 700 | Stick for Z-Wave PC Controller / Zniffer (vendor). | +| `dwm3000evb` | Qorvo DWM3000EVB | UWB 802.15.4z | Ch5/Ch9. Platform of the SEEMOO uwb-sniffer and Ghost Peak. | +| `sim7600` | SIMCom SIM7600 LTE Cat-4 | LTE | Qualcomm modem; AT+CPSI? gives serving cell; /dev/diag for QCSuper. | +| `quectel-rm500q` | Quectel RM500Q-GL 5G NR FR1 | 5G NR | Snapdragon X55; DIAG for QCSuper 5G. | +| `orbic-rc400l` | Orbic RC400L hotspot | LTE | Qualcomm /dev/diag — Rayhunter hardware (EFF detector). | +| `rak-wisgate-connect` | RAK WisGate Connect (CM4 + SX1302) | LoRaWAN | Multichannel gateway; ChirpCat backend. | +| `minino` | Minino (Electronic Cats) ESP32-C6 | Wi-Fi, BLE, Zigbee, Thread | Pocket multitool (GPS, microSD, OLED). 2.4 GHz only. EC. | +| `m5-cardputer`, `cyd`, `lilygo-t-embed-cc1101`, `esp32-devkit`, `esp32-s3-devkit`, `flipper-wifi-devboard` | Handheld ESP32 platforms | Wi-Fi, BLE, (+sub-GHz for CC1101 ones) | Chassis for Marauder/Bruce/Ghost ESP. Only original ESP32 has Classic. | + +## 4. Universal host tools + +| Slug | What it does | +|------|----------| +| `wireshark` / `tshark` | The universal dissector. Almost every sniffer exports PCAP → Wireshark. Supplies keys to decrypt in-place. | +| `gqrx` | Live SDR waterfall (HackRF/bladeRF/USRP/RTL). "See what transmits and where". | +| `universal-radio-hacker` | Reverse unknown I/Q: auto-detects modulation/baud, extracts bitstream, diff, replay. | +| `whad` | Unified Python framework: BLE, 802.15.4/Zigbee, Thread, LoRa, ESB, Unifying. One toolchain for many radios. | + +## 5. Golden rule: band + IBW + duplex + +Before choosing a radio at SP, answer three questions: + +1. **Does it reach the band?** RTL-SDR tops out at 1.766 GHz → no 2.4 GHz. UWB (6.5/8 GHz) → out of + reach of HackRF/bladeRF/B210 (6 GHz ceiling); only USRP X410 (7.2 GHz, $10k+) comes close. +2. **Does the band/connection fit in the IBW?** BLE is 80 MHz; HackRF sees 20 MHz (one slice), bladeRF + oversampling covers 122.88 MHz (all of it). A BLE connection hops → either capture all, or follow the hop. +3. **Do you need TX (full duplex)?** Replay/forge/jam/rogue-cell require TX. HackRF = half (RX or TX), + not simultaneous. bladeRF/USRP = full duplex. RTL-SDR = RX only, never transmits. + +This matrix decides what is **achievable** with the available kit before promising a result. + +## Subflow (SP entry for any protocol) + +The SDR-general family **is not** a protocol: it describes the radio selection and spectrum survey that precedes any descent. Apply the `## Golden rule: band + IBW + duplex` from above. + +| Progress | Criterion | Markers | +|--------|----------|------------| +| Radio selection | The target sub-band chooses the radio, not the other way around: sub-GHz → RTL-SDR suffices; 2.4 GHz → HackRF/bladeRF; LTE/5G FR1 → USRP B210 + GPSDO | — | +| UWB / 5G FR2 (>6 GHz, BW>500 MHz) | **No radio in the kit reaches it** → declare a visibility gap (Route A), do not simulate capture | — | +| SP → protocol descent | Signal confirmed in waterfall → load the `NN-proto.md` wayfinder and follow the master flow of `SKILL.md` | — | + +**Defensive anomaly** (Defensive mode, RX-only): continuous survey of your spectrum looking for carriers/humps that do **not** correspond to known own activity (jammer, spurious peak, unknown link). Record in `loot/notes/`. diff --git a/Skill/references/03-finding-registration.md b/Skill/references/03-finding-registration.md new file mode 100644 index 0000000..2166ef4 --- /dev/null +++ b/Skill/references/03-finding-registration.md @@ -0,0 +1,328 @@ +# 03 — Finding Registry: Schema, Severity, and CVSS 4.0 RF + +> Defines the canonical JSONL schema, the finding block format, the RFSAM severity rubric, +> and the typical CVSS 4.0 vectors for RF. Use it before registering the first finding. + +## Index +1. JSONL schema +2. Usage of `register_finding.py` +3. Finding format in chat +4. RFSAM severity rubric (what evidence each level requires) +5. CVSS 4.0 for RF — typical vectors +6. How to cite references +7. `rf-severity` — 4-axis model for classifying RF findings + +--- + +## 1. JSONL schema + +Each line of `loot/rfsam_findings.jsonl` is a JSON object with this schema: + +```json +{ + "id": "RF-001", // mandatory, format RF-NNN + "title": "BLE connection hijackable via btlejack", // mandatory + "protocol": "BLE", // mandatory, one of the 15 + "layer": "AT", // mandatory, IG|SP|PHY|LL|CR|AT|AP + "control": "RFSAM-BLE-AT-01", // optional but recommended + "severity": "high", // mandatory, info|low|medium|high|critical + "cvss4": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N", + "status": "confirmed", // confirmed|hypothesis (auto per --allow-hypothesis) + "evidence": "Got CONNECT_REQ ... AA 0x0a2f7b1d ...", // mandatory unless hypothesis + "impact": 4, // optional, axis of the §7 model (1–4) + "exploitability": 2, // optional, axis of the §7 model (1–4) + "exposure": 2, // optional, axis of the §7 model (1–4) + "scope_reach": "A", // optional, A|B|C|D (achieved|cage|hypothesis|defensive) + "mitigation": { // optional, 3 layers (only those provided) + "developer": "force LESC", + "integrator": "rekey after commissioning", + "operator": "rotate authorized pairs" + }, + "notes": "handle 0x000E controls color; btlejack on micro:bit", // optional + "timestamp": "2026-06-19T13:45:00-05:00" // auto, ISO 8601 with timezone +} +``` + +**Rules validated by `register_finding.py`**: +- `id` must match `^RF-\d{3}$`. +- `protocol` ∈ the 15 IDs; `layer` ∈ the 7; `severity` ∈ the 5. +- `control` if provided must match `^RFSAM---\d{2}$`. +- `cvss4` if provided must start with `CVSS:4.0/`. +- `title` not empty. +- `impact`/`exploitability`/`exposure` if provided must be 1–4. +- `scope_reach` if provided must be A/B/C/D. +- **Evidence mandatory** unless `--allow-hypothesis` is passed (then `status=hypothesis`). + +> The 4 axes (`impact`/`exploitability`/`exposure`/`scope_reach`) are optional but +> **recommended**: they operationalize the §7 model and feed both the technical report and the +> executive summary with the severity justification. Mitigation is stored only for the +> layers that are provided. + +## 2. Usage of `register_finding.py` + +```bash +python3 scripts/register_finding.py \ + --id RF-001 \ + --protocol BLE \ + --layer AT \ + --control RFSAM-BLE-AT-01 \ + --severity critical \ + --cvss4 "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N" \ + --title "Uncrypted BLE connection hijackable" \ + --evidence-file loot/poc/RF-001.txt \ + --impact 4 --exploitability 2 --exposure 2 --scope-reach A \ + --mitigation-developer "force LESC; reject Just Works pairing" \ + --mitigation-operator "rotate pairs; monitor anomalous connections" \ + --notes "btlejack on micro:bit; handle 0x000E" +``` + +Flags: +- `--evidence "text"` inline evidence; `--evidence-file path` reads it from the file. +- `--allow-hypothesis` registers without a PoC (status `hypothesis`) — for findings to be verified. +- `--impact`/`--exploitability`/`--exposure` (1–4) and `--scope-reach` (A/B/C/D): the 4 axes of the §7 model. Optional but recommended. +- `--mitigation-developer`/`--mitigation-integrator`/`--mitigation-operator`: the 3 remediation layers. Only the provided layers are saved. +- `--loot loot` alternative directory. + +The script validates before writing; if it fails, it does not touch the JSONL and prints the errors. +Verify the logic with `python3 scripts/register_finding.py --self-test`. + +## 3. Finding format in chat + +**In addition** to the JSONL record, dump a readable block to chat for the user. +For `critical`/`high` that deserve a detailed write-up (description, impact, evidence, +safe reproduction, 3-layer mitigation), use the standalone document +`assets/finding-template.md`. + +``` +FINDING: [specific title] +Severity: CRITICAL | HIGH | MEDIUM | LOW | INFO +Protocol/Layer: BLE / AT Control: RFSAM-BLE-AT-01 +Target: [device/scenario] +Description: what was found and why it matters +Evidence: + COMMAND: [exact tool + flags] + OUTPUT: [snippet that confirms — AA, recovered key, 200 OK, etc.] +Impact: what an attacker can do +PoC: exact command to reproduce +Remediation: layers (developer/integrator/operator) +References: [CVE / paper / tool + URL] +CVSS 4.0: CVSS:4.0/AV:A/... (score, severity) +``` + +## 4. RFSAM severity rubric — what evidence each level requires + +| Severity | You must have evidence of | Forbidden | +|-----------|--------------------------|-----------| +| **CRITICAL** | Takeover / key recovery / spoofing reproduced with captured PoC | "It is vulnerable" without PoC | +| **HIGH** | Real cleartext data exposure, weak keys recovered, demonstrated hijack | Crypto hypothesis without capture | +| **MEDIUM** | Weakness requiring specific conditions to exploit | Anything already exploitable → raise | +| **LOW** | Hardening gap / info disclosure not directly exploitable | What can be exploited → raise | +| **INFO** | Observational (capture feasibility, identifier exposure, identifier leakage) | — | + +**Mental checklist before registering**: +``` +□ Do I have the exact capture/command output as evidence? +□ Does the severity reflect what I ACHIEVED, not what I could achieve? +□ Is the command reproducible (target, flags, parameters)? +□ Did I cite the source (CVE/paper/tool) or flag the uncertainty? +□ Did I map to an RFSAM---NN control? +If any answer is NO → do not register yet. Get evidence. +``` + +## 5. CVSS 4.0 for RF — typical vectors + +**Key**: RF is almost always **`AV:A` (Adjacent)** — the attacker must be within radio range, +not on the network (`AV:N`). Exception: rogue infrastructure that later exfiltrates over the network can escalate to +cascading impact `AV:N`, but the initial RF vector remains `AV:A`. + +Recommended base vector for most RF findings: +`CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N` + +| RF finding type | Vector | Typical severity | +|---------------------|--------|------------------| +| BLE hijack / baseband RCE | `CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N` | critical | +| Key recovery (crackle/KNOB/Crypto1) | `CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N` | critical | +| Rogue cell / IMSI catcher (identity harvest) | `CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N` | high | +| Cleartext traffic (BLE/Wi-Fi/Zigbee) | `CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N` | high/medium | +| Fixed-code sub-GHz replay | `CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N` | high (door) / medium | +| RFID cloning / relay | `CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N` | high | +| Advertising tracking / identifier leakage | `CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N` | medium/low | +| GNSS spoofing (conducted) | `CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N` | (context-dependent) | +| WPS Pixie-Dust / PMKID | `CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N` | high | + +CVSS 4.0 metrics: `AV` Attack Vector (N/A/L/P) · `AC` Attack Complexity (L/H) · `AT` Attack +Requirements (N/P) · `PR` Privileges Required (N/L/H) · `UI` User Interaction (N/P/A) · +`VC/VI/VA` Vulnerable System Confidentiality/Integrity/Availability · `SC/SI/SA` Subsequent System. + +## 6. How to cite references + +Every non-trivial claim **is cited or flagged**: +- **CVE**: `CVE-2019-9506 (KNOB) — https://nvd.nist.gov/vuln/detail/CVE-2019-9506` +- **Paper**: `Ryan, "Bluetooth: With Low Energy Comes Low Security", USENIX WOOT 2013 — https://...` +- **Tool**: `crackle (Mike Ryan) — https://github.com/mikeryan/crackle` +- **Spec/standard**: `Bluetooth Core Spec v5.4, Vol 6 Part B` + +If you cannot verify a source → flag inline: +``` +> [!FLAG] Claim X — need to verify specific source before reporting +``` + +**Never claim what you cannot cite or demonstrate with evidence.** That is the foundational rule of RFSAM. + +--- + +## 7. `rf-severity` — 4-axis model for classifying RF findings + +§4 gives the **reactive** rubric (what evidence each level requires). This section gives the **predictive** model: before +fixing the severity, the agent evaluates four axes specific to RF that do not appear in CVSS and that decide the level. + +> Origin: model defined in `§7` of this file. SKILL.md §SEVERITY AND CLASSIFICATION compresses this section to the +> 4-level table + the reference here; the full model lives in this section. + +### 7.1 — The four axes + +Each axis is scored 1 (low) to 4 (high). The final severity **is not** a linear average — it is the **Impact** axis +(ceiling) modulated by the other three. The agent traverses them in order: Impact first (sets the ceiling), then +Exploitability/Exposure/Scope lower or confirm it. + +#### Axis 1 — Impact (severity ceiling) + +| Score | What the attacker achieves | RF examples | +|---------|--------------------------|-------------| +| 4 | Takeover / key recovered / persistent spoofing | btlejack hijack, crackle pairing crack, MIFARE Crypto1 key dump, Zigbee NWK key from join, WPA PSK cracked | +| 3 | Sensitive data / device control / relay | cleartext traffic (BLE/Wi-Fi/Zigbee), RFID clone, NFC relay, sub-GHz door replay, unauthenticated GATT/HID | +| 2 | DoS / degradation / identity tracking | mass deauth, jamming (cage = demo), BLE advertising tracking, identifier leakage, frame-counter reset | +| 1 | Observational / info disclosure without direct exploitation | capture feasibility, visible SSID/BD_ADDR, old firmware without confirmed CVE, open channel | + +Impact sets the **ceiling**: 4 never drops below `high`; 3 sets ceiling at `high` (can drop to `medium`); 2 sets `medium`; 1 sets +`low/info`. + +#### Axis 2 — Exploitability (friction to reproduce) + +| Score | Friction | RF examples | +|---------|----------|-------------| +| 4 | Trivial: common hardware, passive RX, no timing | SDR + Wireshark reads Zigbee in cleartext; rtl_433 decodes remote; BD_ADDR visible in advertising | +| 3 | Low: common hardware but needs timing or proximity | capture Wi-Fi 4-way handshake; BLE pairing (short window); passive NFC sniff | +| 2 | Medium: specialized hardware or active mode | Proxmark3 for MIFARE nested; btlejack (micro:bit); HackRF TX for sub-GHz replay; gps-sdr-sim | +| 1 | High: mandatory containment + license + rare hardware | srsRAN+Open5GS rogue BTS (cage+SIM+license); UWB DW3000-class; bladeRF+GPSDO reliable LTE demod | + +Exploitability **raises** severity when it is 4 **and exposure is ≥3** (impact 3 + exploitability 4 + exposure ≥3 → `high`), +and **lowers** it when it is 1 (impact 4 GNSS spoof in cage = `high`, not `critical` — demonstrated in +containment, not reproducible in the field). + +#### Axis 3 — Exposure (affected surface) + +| Score | Surface | RF examples | +|---------|------------|-------------| +| 4 | Public / massive infrastructure | GNSS spoofing, ADS-B forgery, rogue cell (all USIMs in cell), Zigbee NWK key (entire network) | +| 3 | One network / fleet / client infrastructure | Wi-Fi PSK (entire network), shared LoRa AppKey (all OTAA), Zigbee PAN without rekey | +| 2 | One link / one device | BLE pair of one device, individual RFID tag, sub-GHz remote for one door, UWB ranging of one asset | +| 1 | One identifier / metadata | persistent BD_ADDR, SSID broadcast, DevEUI, passive IMSI (without confirmed harvest) | + +Exposure **raises** severity: impact 3 (RFID relay) with exposure 4 raises to `high`. Impact 4 with exposure 1 +(one tag with unique non-recyclable keys) confirms `high` but not necessarily `critical`. + +#### Axis 4 — Scope (achieved vs possible) — discrete + +| Value | What is reported | Rule | +|-------|----------------|-------| +| **A — Achieved** | Demonstrated in the current mode with sufficient evidence (§4 / SKILL.md §EVIDENCE). | Severity = the model's severity (axes 1–3). | +| **B — Demonstrated in containment** | Demonstrated in Lab with cage/conducted, not reproducible in the field. | Model severity, labeled `contained` in the finding; `critical` drops to `high`. | +| **C — Hypothetical (not achieved in this mode)** | Viable but not executed (observational, absent hardware, Route A). | **Maximum `medium`**, `status: hypothesis`, partial evidence. Never `high`/`critical` without PoC. | +| **D — Defensive (detection, not exploitation)** | Defensive mode: a threat was detected, not exploited. | Severity = impact of the threat, but type `detection`; the report describes what was detected. | + +Scope **lowers** severity when it is C or D, and **labels** it when it is B. It never raises it. It formalizes the rule +"severity reflects what I ACHIEVED" (SKILL.md §SEVERITY, checklist item 2). + +### 7.2 — Decision table (Impact × modulators → severity) + +Starts from Impact (ceiling) and applies Exploitability/Exposure as modulators, then Scope as final cap. +Find your row by (Impact, Exploitability, Exposure) and read the column according to Scope. + +| Impact | Exploitability | Exposure | Base (A) | Contained (B) | Hypothesis (C) | Detection (D) | +|---------|-----------------|------------|----------|----------------|----------------|----------------| +| 4 | 3–4 | 2–4 | **critical** | **high** (contained) | **medium** (hypothesis) | medium (detection) | +| 4 | 1–2 | 2–4 | **high** | **high** (contained) | **medium** (hypothesis) | medium (detection) | +| 4 | 3–4 | 1 | **high** | high (contained) | medium (hypothesis) | low (detection) | +| 3 | 3–4 | 3–4 | **high** | high (contained) | medium (hypothesis) | medium (detection) | +| 3 | 1–2 | 3–4 | **medium** | medium (contained) | low (hypothesis) | low (detection) | +| 3 | 3–4 | 1–2 | **medium** | medium (contained) | low (hypothesis) | low (detection) | +| 3 | 1–2 | 1–2 | **medium/low** | low (contained) | low (hypothesis) | low (detection) | +| 2 | 3–4 | 3–4 | **medium** | medium (contained) | low (hypothesis) | low (detection) | +| 2 | 1–2 | 1–4 | **low** | low (contained) | low (hypothesis) | low (detection) | +| 1 | 1–4 | 1–4 | **info** | info (contained) | info (hypothesis) | info (detection) | + +The "medium/low" cells require judgment: impact 3 with a low-sensitivity data leak → `low`; with a credential → `medium`. + +### 7.3 — Golden rules encoded by the table + +1. **Without a PoC (Scope C) the maximum is `medium`.** A hypothetical finding is never `high`/`critical` in the report, + regardless of theoretical impact. +2. **`critical` requires Impact 4 + Exploitability ≥3 + Exposure ≥2 + Scope A.** Confirmed takeover/key recovery + in the field (not cage) with achievable hardware. The cage drops it to `high` (contained). +3. **Public infrastructure (Exposure 4) raises one level if impact is 2–3.** GNSS jamming (impact 2, DoS) with + exposure 4 raises to `medium` even if exploitability is 1 (needs cage) — systemic risk matters even if + the demo is contained. Only applies if Scope A or B; in hypothesis it stays `medium`. +4. **Defensive mode (Scope D) never reports `critical`.** Detection is not exploitation. The `critical` of the detected + threat is documented in `notes` (context for the client), not in `severity`. +5. **`info` is observational only (Impact 1).** Any finding with impact 2+ cannot be `info`. + +### 7.4 — Integration with evidence sufficiency (§4 + SKILL.md §EVIDENCE) + +The §7.2 model produces the severity; §4 / SKILL.md §EVIDENCE verify that the evidence supports that severity. +If it does not, they mandate a downgrade: + +``` +finding → axes 1–4 → model severity → sufficient evidence? + ├─ yes → severity confirmed, status=confirmed + └─ no → downgrade one level, evidence_status=partial +``` + +No severity without evidence to back it. + +### 7.5 — Mapping to CVSS 4.0 + +CVSS 4.0 (§5) remains the **external vector** of the finding (technical report, client). The 4-axis model is the +**internal decision**. Mapping: + +| Model axis | CVSS 4.0 metric | Note | +|----------------|------------------|------| +| Impact | `VC`/`VI`/`VA` (Vulnerable) + `SC`/`SI`/`SA` (Subsequent) | Impact 4 → VC:H/VI:H; impact 2 (DoS) → VA:H | +| Exploitability | `AC` (L/H) + `AT` (N/P) + `PR` | Exploitability 1 → AC:H/AT:P; exploitability 4 → AC:L/AT:N | +| Exposure | (no direct metric) | CVSS does not capture how many devices are affected; the agent notes it in `notes` | +| Scope | (no metric; reflects the mode) | Scope C → status=hypothesis, does not affect the vector; Scope B → `contained` note in `notes` | + +The Exposure column is the key difference: CVSS does not capture it, the RF model does. + +### 7.6 — Worked examples + +| # | Finding | Impact | Exploitab. | Expos. | Scope | Severity | CVSS | +|---|---------|---------|-----------|--------|---------|-----------|------| +| E1 | btlejack BLE hijack confirmed in the field on own device | 4 | 2 (micro:bit) | 2 (one device) | A | **high** | AV:A/AC:L/VC:H/VI:H | +| E2 | MIFARE Classic key dump + clone confirmed | 4 | 2 (PM3) | 2 (one tag) | A | **high** | AV:A/AC:L/VC:H/VI:H | +| E3 | Wi-Fi WPA2 handshake cracked, PSK recovered | 4 | 3 (wait for handshake) | 3 (entire network) | A | **critical** | AV:A/AC:L/VC:H/VI:H | +| E4 | GNSS spoofing demonstrated in cage with gps-sdr-sim | 4 | 1 (cage+license) | 4 (public infra) | B | **high** (contained) | AV:A/AC:H/VA:H | +| E5 | srsRAN rogue cell in cage with test SIM | 3 (theoretical identity harvest) | 1 | 4 | B | **high** (contained) | AV:A/AC:H/VC:L | +| E6 | Zigbee cleartext traffic read with SDR+Wireshark | 3 | 4 (passive RX) | 3 (network) | A | **high** | AV:A/AC:L/VC:H | +| E7 | sub-GHz door replay with rfcat (fixed, no rolling code) | 3 | 4 | 2 (one door) | A | **high** | AV:A/AC:L/VC:L/VI:L | +| E8 | BLE advertising tracking (persistent BD_ADDR) | 2 | 4 | 1 | A | **medium** | AV:A/AC:L/VC:L | +| E9 | RFID relay demonstrated without keys (Proxmark MITM) | 3 | 2 | 2 | A | **medium** | AV:A/AC:L/VC:H/VI:L | +| E10 | Mass Wi-Fi deauth on own network in active mode | 2 | 4 | 3 | A | **medium** | AV:A/AC:L/VA:H | +| E11 | Sub-GHz replay viable but hardware absent (Route A) | 3 | 4 | 2 | C | **medium** (hypothesis) | n/a (no PoC) | +| E12 | Crocodile Hunter detects IMSI catcher in operator's environment | 3 (detected threat) | n/a | 4 | D | **medium** (detection) | n/a (detection) | +| E13 | Old BLE firmware without confirmed CVE | 1 | 4 | 1 | A | **info** | n/a | + +### 7.7 — Prioritization for report and remediation + +The severity produced by the model is the prioritization: the technical report and the remediation list are ordered +descending (critical → high → medium → low → info). Within the same level, Exposure breaks ties (larger surface +first) and then Exploitability (more reproducible first). + +**Operational exception — Defensive mode:** an **active detected threat** (Scope D) tops the report even if +its technical severity is `medium` — the operational urgency (ongoing threat in the defended environment) supersedes +technical severity when there is active intrusion. Confirmed offensive findings (`critical`/`high`) still +top the report if they coexist with detections in the same report. + +**Remediation rule (see `references/03-finding-registration.md §7.7`):** `critical`/`high` require all 3 layers +(Developer/Integrator/Operator); `medium` requires at least Integrator + Operator; `low`/`info` can close with +Operator alone. diff --git a/Skill/references/10-ble.md b/Skill/references/10-ble.md new file mode 100644 index 0000000..11fb450 --- /dev/null +++ b/Skill/references/10-ble.md @@ -0,0 +1,79 @@ +# 10 — BLE (Bluetooth Low Energy) + +> Wayfinder + RFSAM controls for BLE. Deference to BSAM at link-and-above. The reference +> depth control is `RFSAM-BLE-AT-01`. Source: `toolchains.js` (inline), controls `rfsam-ble-*.md`. + +## Facts +- **Band**: 2.402–2.480 GHz (ISM 2.4 GHz). 40 channels × 2 MHz — 3 advertising (37/38/39) + 37 data; a connection hops every connection event. +- **Modulation**: GFSK · PHYs LE 1M (1 Mbps), LE 2M (BLE 5), LE Coded (long range, BLE 5). +- **Range**: ~10 m indoor; up to ~100 m with Coded PHY or high TX. +- **Versions**: 4.0 (2010) · 4.2 LE Secure Connections (2014) · 5.0 2M/Coded (2016) · 5.1–5.4. +- **External reference**: **BSAM (Tarlogic)** — RFSAM owns SP+PHY; at LL and above defers to BSAM. + +## Layer-by-layer descent + +### IG — `RFSAM-BLE-IG-01` Known vulnerabilities of the SoC and host stack +- **Objective**: identify SoC/host stack and cross-reference against CVEs (SweynTooth, KNOB, BLEEDINGBIT, BleedingTooth, BLESA) before capturing. +- **Kit**: host BLE adapter HCI + bettercap (discovery/GATT); Sniffle/CatSniffer for advertising PDUs. +- **Command**: read FCC ID on label → `https://fccid.io/`; `sudo bettercap -eval "ble.recon on; sleep 20; ble.show; q"`. +- **Deference**: BSAM-IG-01/02/03/04. `deferred: true`. +- **Cited attacks**: SweynTooth (CVE-2019-19194 Zero-LTK), KNOB (CVE-2019-9506), BLEEDINGBIT (CVE-2018-16986), BleedingTooth (CVE-2020-12351), BLESA. + +### SP — `RFSAM-BLE-SP-01` Channel map and capture feasibility +- **Objective**: which channels can you observe simultaneously with your radio — feasibility of discovery/full-band/connection-following. +- **Kit**: Gqrx (waterfall, ~20 MHz HackRF / 122.88 MHz bladeRF oversampling); ESP32 Marauder/Minino (scan advertising); ESP32 AirTag scanner. +- **Caveat**: RTL-SDR cannot reach 2.4 GHz. HackRF sees a slice (1 of 3 advertising channels); bladeRF oversampling the entire band. +- **Criticality**: `info` (auditor-capability baseline, not a device finding). + +### PHY — `RFSAM-BLE-PHY-01` Demodulation and bit recovery +- **Objective**: demodulate GFSK, correlate access address, de-whiten, validate CRC — clean bits per channel. +- **Kit**: Sniffle/ice9 (on-chip or channelised SDR); Wireshark to verify `CRC correct`. +- **Command**: `python3 -m sniffle.sniff_receiver -s /dev/ttyACM0 -a -o adv.pcap`. +- **Cited attacks**: passive access-address/CRCInit recovery (Ryan WOOT 2013); SweynTooth fuzzing (CVE-2019-16336, 17519). +- **Criticality**: `info`. + +### LL — `RFSAM-BLE-LL-01` Advertising & identifier exposure · `RFSAM-BLE-LL-02` Connection-data capture +- **LL-01 Objective**: does it leak advertising identity/product (names, serials, UUIDs, manufacturer data) or a trackable identifier that defeats randomization? +- **LL-02 Objective**: follow and record data-channel PDUs of a connection (CSA#1/CSA#2, or already established via ice9)? +- **Kit**: Sniffle (CC1352/CatSniffer), nRF Sniffer, Ubertooth, ice9 (SDR all-channel), Wireshark. +- **Cited attacks**: connection-following sniffing (Ryan WOOT 2013); CSA#2 recovery (Cauquil DEF CON 27); established-conn recovery (Ballabriga 2020); address-carryover tracking (Becker PoPETs 2019); PHY-layer fingerprint (Givehchian S&P 2022). +- **Deference**: BSAM-DI-03/DI-04/DI-06 (LL-01), BSAM-DI-04/EN-02 (LL-02). `deferred: true`. + +### CR — `RFSAM-BLE-CR-01` Pairing and encryption assessment +- **Objective**: LE Legacy or LESC? If Legacy → recover TK and decrypt session. +- **Kit**: crackle (brute TK), Wireshark (export PCAP), Sniffle/CatSniffer (capture pairing). +- **Command**: `crackle -i ble_pairing.pcap -o ble_decrypted.pcap`. +- **Cited attacks**: LE Legacy TK brute-force (Ryan WOOT 2013); KNOB BLE key-size downgrade (CVE-2019-9506, Antonioli TOPS 2020); SweynTooth Zero-LTK (CVE-2019-19194). +- **Deference**: BSAM-PA-01/PA-04/EN-02/EN-03. `deferred: true`. LESC (ECDH) is **not breakable** from capture. + +### AT — `RFSAM-BLE-AT-01` Hijack a live BLE connection +- **Objective**: can you follow and take over an established connection (jam-and-hijack, injection, reconnection spoofing)? +- **⚠ MANDATORY AUTHORIZATION** — active step. +- **Kit**: Btlejack (BBC micro:bit), InjectaBLE firmware (nRF52840), bettercap (recon), ESP32 Marauder/Bruce/Sour Apple (spam). +- **Cited attacks**: InjectaBLE (Cayre DSN 2021), Btlejacking (Cauquil DEF CON 26), BLESA (CVE-2020-9770). +- **Deference**: BSAM-AP-06/AU-03/EN-01. `deferred: true`. Criticality `critical`. + +### AP — Interact with GATT +- **Objective**: what does the device trust over the link? GATT reachable without auth. +- **Kit**: Bleak (script GATT), bettercap (enumerate), Bruce (Bad BLE HID). +- **No dedicated control in the coverage-map** — BLE AP is exercised via GATT interaction after CR/AT. + +## Subflow (specialization of the master flow) + +BLE-specific transitions; verbatim commands live in `Layer-by-layer descent` above. + +| Advance | Advancement criterion | Markers | +|---------|----------------------|---------| +| IG → SP | BLE device confirmed; SoC CVEs cross-referenced (KNOB/SweynTooth/BLESA) | — | +| SP → PHY+LL | Activity on advertising channels (37/38/39) confirmed. RTL-SDR cannot reach 2.4 GHz → HackRF/bladeRF | — | +| PHY+LL (LL-01/02) | 🔗BSAM: stop descent at LL and defer to BSAM. Resume at CR **only if** BSAM returns a finding that requires it | 🔗BSAM | +| CR → AT | Weak pairing confirmed (LE Legacy TK recoverable). LESC (ECDH) **not breakable** from capture → gap | — | +| AT | ⚠TX re-check `loot/scope.txt`; active/lab only | ⚠TX | +| AP (no control) | GATT/HID over what the device trusts; exercised after CR/AT | — | + +**Defensive anomaly** (Defensive mode, RX-only): AirTag/Find My **not your own** in your environment = stalking. `minino`/`esp32-airtag-scanner` detects it. Register in `loot/notes/`; do **not** descend to AT. + +## Legal warnings +- Passive RX (advertising/sniff) generally OK on your own devices. +- **Connect/hijack/inject/spam = active**: only on owned/authorized equipment. +- BLE spam (Sour Apple) **freezes others' iPhones** → illegal without permission, disruptive. diff --git a/Skill/references/11-btc.md b/Skill/references/11-btc.md new file mode 100644 index 0000000..5192598 --- /dev/null +++ b/Skill/references/11-btc.md @@ -0,0 +1,67 @@ +# 11 — Bluetooth Classic (BR/EDR) + +> Wayfinder + RFSAM controls for Bluetooth Classic. Deference to BSAM at link-and-above. +> **Honesty note**: accessible BR/EDR tooling is younger/thinner than BLE/Wi-Fi; almost everything runs on the original ESP32 ($5). + +## Facts +- **Band**: 2.402–2.480 GHz — 79 RF channels × 1 MHz, **adaptive frequency hopping ~1600 hops/s**. That fast hopping is what makes it hard to follow with a static SDR. +- **Modulation/rate**: Basic Rate (BR) GFSK 1 Mbps; EDR π/4-DQPSK 2 Mbps and 8DPSK 3 Mbps. +- **Identifiers**: 48-bit BD_ADDR (24 high = OUI/vendor), Class of Device (CoD) hint of type. +- **Security**: legacy PIN pairing (short PIN → offline attack); Secure Simple Pairing SSP ECDH (P-192 2.1, P-256 4.1+) — "Just Works" without MITM. Encryption E0 (legacy) or AES-CCM. **KNOB** key entropy downgrade. +- **Topology**: piconet 1 master + ≤7 slaves; profiles SDP, RFCOMM, HID, A2DP/HFP, OBEX. Targets: headsets, HID, infotainment, OBD-II, PoS. + +## Layer-by-layer descent + +### IG — `RFSAM-BTC-IG-01` Identify device, BR/EDR mode and vulnerability corpus +- **Objective**: does it speak BR/EDR (Classic), dual-mode or LE-only? Fingerprint SoC/host stack, cross-reference against CVEs (BlueBorne, KNOB, BrakTooth). +- **Kit**: ESP32 (original DevKit, the only one with a BR/EDR radio), `esp32-classic-bt-scan` (inquiry), `esp32-bt-exp` (dual-mode dump). FCC ID/teardown. +- **Deference**: BSAM-IG-02/03/04. `deferred: true`. Attacks: BlueBorne (CVE-2017-1000251), KNOB (CVE-2019-9506), BrakTooth (≈16 CVEs). + +### SP — `RFSAM-BTC-SP-01` Inquiry-scan and confirm reachable BR/EDR device +- **Objective**: confirm it transmits and enumerate discoverable devices (analogous to BLE advertising scan). +- **Kit**: Gqrx (waterfall — activity, not clean decode due to fast hopping), `esp32-classic-bt-scan` (real BR/EDR inquiry → BD_ADDR/name/RSSI/CoD). +- **Caveat**: only sees devices in discoverable/inquiry-scan; non-discoverable requires knowing the BD_ADDR. + +### PHY (no control — hopping frustrates static SDR) +- Decoding live GFSK/DQPSK while hopping 1600/s is impractical for SDR. Practical capture does PHY+framing on a device with a real BR/EDR controller (ESP32 patched ROM). + +### LL — `RFSAM-BTC-LL-01` Capture Bluetooth Classic baseband traffic +- **Objective**: capture/decode BR/EDR baseband frames (BT header, channel, role, FHS, ACL, LMP). +- **Kit**: `esp32-bt-classic-sniffer` (patches ESP32 Bluetooth ROM → dump baseband via USB serial → Python BTSnifferBREDR.py → Scapy/Wireshark); Ubertooth-tools (partial Basic-Rate, legacy). +- **⚠ Active sniffer**: connects to the target to follow hopping (not purely passive). Authorized only. +- **Deference**: BSAM. `deferred: true`. + +### CR — `RFSAM-BTC-CR-01` Assess pairing and encryption key strength +- **Objective**: legacy PIN pairing with short/fixed PIN → offline brute force recovers link key and decrypts. SSP (ECDH) resists offline. KNOB = entropy downgrade (not a break of E0/AES). +- **No point-and-click tool on cheap hardware**: capture analysis + BSAM pairing controls. +- **Attacks**: KNOB (CVE-2019-9506). `deferred: true`. + +### AT — `RFSAM-BTC-AT-01` Test baseband/LMP resilience and availability +- **⚠ MANDATORY AUTHORIZATION** (transmits 2.4 GHz, pokes a live device). +- **Objective**: BrakTooth (≈16 CVEs, crash/deadlock/RCE in BR/EDR controllers of many SoCs). KNOB downgrade + brute force. Broadband 2.4 GHz jammer (illegal jamming unless inside a cage). +- **Kit**: BrakTooth PoC (ESP32, LMP/baseband fuzzing), `esp32-bluejammer` (broadband 2.4 GHz jamming with 2× nRF24L01+PA+LNA — **illegal over the air**). +- **Deference**: BSAM. `deferred: true`. + +### AP — `RFSAM-BTC-AP-01` Enumerate and exercise exposed BR/EDR profiles +- **Objective**: map app surface — SDP, RFCOMM (AT commands hands-free/car), HID (keystroke injection), A2DP/HFP, OBEX. +- **Kit**: USB BT dongle + BlueZ host (`sdptool browse `, `l2ping`, `bluetoothctl`, `obexftp`, HID/HFP utils). +- **Deference**: BSAM. `deferred: true`. + +## Subflow (specialization of the master flow) + +BTC-specific transitions; verbatim commands live in `Layer-by-layer descent` above. + +| Advance | Advancement criterion | Markers | +|---------|----------------------|---------| +| IG → SP | BR/EDR mode confirmed (BrakTooth ≈16 CVEs, BlueBorne, KNOB) | — | +| SP → PHY | Discoverable/inquiry-scan device detected. **1600 hops/s** → static SDR cannot follow the hop; inquiry scan (ESP32) is the way | — | +| PHY+LL | 🔗BSAM: defer LL+ to BSAM. The BR/EDR sniffer is **active** (connects to follow the hop) → authorized only | 🔗BSAM | +| CR → AT | Just Works MITM or KNOB downgrade confirmed. SSP ECDH resists offline | — | +| AT | ⚠TX re-check; ⚠ broadband 2.4 GHz jamming = over-the-air jamming (**RA3**, cage only). `esp32-bluejammer` needs nRF24L01+PA+LNA | ⚠TX | +| AP | Only protocol with a formal AP control (`RFSAM-BTC-AP-01`): SDP/RFCOMM/HID/A2DP/OBEX profiles | — | + +**Defensive anomaly** (Defensive mode, RX-only): BR/EDR does not have as common a stalking surface as BLE; watch for **unpaired** devices making LMP/SDP probes against your hosts (possible BlueBorne/BrakTooth). + +## Legal warnings +- Passive RX (the little that is viable with SDR) OK. +- **Active sniffer, BrakTooth, jamming, HID injection = active**: owned/authorized only. BrakTooth crashes/RCes live devices. 2.4 GHz jamming is illegal over the air. diff --git a/Skill/references/12-wifi.md b/Skill/references/12-wifi.md new file mode 100644 index 0000000..a653fd5 --- /dev/null +++ b/Skill/references/12-wifi.md @@ -0,0 +1,59 @@ +# 12 — Wi-Fi (802.11) + +> Wayfinder + RFSAM controls for Wi-Fi. RFSAM owns end-to-end (no BSAM). No external reference. + +## Facts +- **Band**: 2.4 GHz (2.400–2.4835) · 5 GHz (UNII ~5.15–5.85) · 6 GHz (5.925–7.125, Wi-Fi 6E/7). +- **Channels**: 2.4 GHz 1–14 (1/6/11 non-overlapping) · 5 GHz ~25 (several DFS) · 6 GHz up to 59 × 20 MHz. Widths 20/40/80/160 (320 in Wi-Fi 7). +- **Standards**: b/g/n (2.4) · a/n/ac (5) · ax=Wi-Fi 6/6E · be=Wi-Fi 7. +- **Security**: Open · WEP (broken) · WPA/WPA2-PSK (handshake, PMKID) · WPA2/3-Enterprise (802.1X) · WPA3-SAE · OWE. WPS PIN = weak point. WPA3 mandatory on 6 GHz. +- **Range**: ~10–50 m indoor; 100 m+ outdoor at 2.4 GHz. + +## Layer-by-layer descent + +### IG (no dedicated control — desktop fingerprinting) +- Read FCC ID, BSSID OUI, beacon RSN/WPA. Cross-reference CVEs: KRACK (WPA2), FragAttacks, Dragonblood (WPA3-SAE). WPS status. + +### SP — `RFSAM-WIFI-SP-01` Band and channel survey +- **Objective**: enumerate networks, channels, security and clients before compromising the target. +- **Kit**: Kismet (passive survey + GPS), airodump-ng (live AP/client table), Minino/ESP32 Marauder/Ghost ESP (pocket scan). 6 GHz requires a Wi-Fi 6E adapter. +- **Command**: `airodump-ng -c --bssid -w cap wlan0mon`. + +### LL — `RFSAM-WIFI-LL-01` Management-frame exposure +- **Objective**: capture management frames (beacons, probes, EAPOL) → exposure and handshakes. +- **Kit**: airodump-ng (capture), hcxdumptool (clientless PMKID + EAPOL), Kismet (logged capture), ESP32 Marauder/risinek (pocket handshake). +- **Command**: put adapter in monitor mode; `airodump-ng wlan0mon -c 6 -w capture`. +- Confirm injection before going active: `aireplay-ng --test wlan0mon`. + +### CR — `RFSAM-WIFI-CR-01` WPA handshake / PMKID assessment +- **Objective**: assess crypto and recover key where it is weak. WPA2-PSK → offline attack on handshake/PMKID; WPS PIN → online attack; WEP → trivial. WPA3-SAE/OWE resist (Dragonblood = protocol-level side-channel attacks + implementation bugs). +- **Kit**: hashcat (mode 22000 GPU), hcxtools (pcapng→.hc22000), aircrack-ng (CPU + WEP), reaver (WPS Pixie-Dust/PIN). +- **Command**: `hcxpcapngtool -o hash.hc22000 capture.pcapng` → `hashcat -m 22000 hash.hc22000 wordlist.txt`. +- **⚠ Deauth to force handshake**: only with authorization; PMF (802.11w/WPA3) blocks it. + +### AT (no dedicated control in coverage-map — active techniques) +- **⚠ MANDATORY AUTHORIZATION**. Deauth (aireplay-ng, blocked by PMF), MDK4 (flood), evil-twin (wifiphisher/EAPHammer/hostapd-mana). Kit: ALFA AWUS036ACH (monitor+inject). + +### AP +- **Objective**: what the client trusts after associating — captive portal, credentials, MITM. +- **Kit**: wifiphisher (rogue-AP + phishing portal), EAPHammer (Enterprise evil-twin 802.1X), bettercap (post-association MITM), ESP32 Marauder (Evil Portal). + +## Subflow (specialization of the master flow) + +Wi-Fi-specific transitions; verbatim commands live in `Layer-by-layer descent` above. + +| Advance | Advancement criterion | Markers | +|---------|----------------------|---------| +| IG → SP | AP/SSID/security identified passively (beacon/RSN IE) | — | +| SP → PHY+LL | Target channel fixed; adapter in monitor mode. **6 GHz** requires a dedicated Wi-Fi 6E radio (SDR cannot decode 802.11ac/ax live) | — | +| PHY+LL → CR | Handshake/PMKID captured or open link? | — | +| CR → AT | Key recovered (WPA2-PSK/WEP/WPS) or active mode justified. WPA3-SAE/OWE **resist** offline (Dragonblood = protocol-level side-channel attacks + implementation bugs) | — | +| AT | ⚠TX re-check; PMF (802.11w/WPA3) **blocks** deauth → verify first | ⚠TX | +| AP (no formal control) | Post-association attack: captive portal, MITM, harvesting | — | + +**Defensive anomaly** (Defensive mode, RX-only): **massive** deauth or anomalous management frames on your own network = possible jamming/evil-twin. Register; do **not** descend to AT. + +## Legal warnings +- Passive RX of beacons OK; capturing third-party data is typically regulated. +- **Deauth, evil-twin, injection, credential harvesting = active**: authorized only; capturing third-party credentials without consent is a crime. +- Reaver/Pixie-Dust: only where WPS is enabled and authorized. diff --git a/Skill/references/13-lora.md b/Skill/references/13-lora.md new file mode 100644 index 0000000..d78c051 --- /dev/null +++ b/Skill/references/13-lora.md @@ -0,0 +1,63 @@ +# 13 — LoRa / LoRaWAN + +> Wayfinder + RFSAM controls for LoRa. RFSAM owns end-to-end. + +## Facts +- **Band**: regional sub-GHz ISM — EU868 (863–870) · US915 (902–928) · AS923 · EU433 · AU915/CN470/IN865/KR920. +- **Modulation**: CSS (Chirp Spread Spectrum); spreading factor SF7–SF12 (higher SF = slower, more range). +- **Bandwidth**: 125/250/500 kHz in LoRaWAN. +- **MAC**: PHYPayload = MHDR | MACPayload | MIC(4B, AES-128-CMAC). MACPayload = FHDR(DevAddr,FCtrl,FCnt,FOpts)|FPort|FRMPayload. +- **Crypto**: FRMPayload AES-128 (AppSKey); MIC with NwkSKey. Root keys AppKey (1.0.x) / NwkKey+AppKey (1.1). Activation OTAA (keys derived on join) or ABP (static keys). +- **OTAA join**: JoinRequest = JoinEUI/AppEUI | DevEUI | DevNonce **in cleartext** (only MIC); JoinAccept encrypted. 1.0.x DevNonce random (replay); 1.1 monotonic counter + Join Server + split keys. + +## Layer-by-layer descent + +### IG (fingerprinting) +- Chipset (Semtech SX127x/SX126x/SX130x gateway), regional band, LoRaWAN version (1.0.x vs 1.1), activation mode (OTAA vs ABP), key management (per-device AppKey vs default/shared). Identifiers on air: DevAddr (data), DevEUI/JoinEUI/DevNonce (join, in cleartext). + +### SP — `RFSAM-LORA-SP-01` Sub-band occupancy and capture +- **Objective**: where it transmits and confirm channel plan. RTL-SDR suffices (sub-GHz); see diagonal chirps on waterfall. +- **Kit**: Gqrx (RTL-SDR/HackRF); ChirpCat (RAK WisGate Connect, classification); catnip (SX1262 spectrum analyzer). +- **Command**: `gqrx` tuned to EU868/US915. + +### PHY — `RFSAM-LORA-PHY-01` Chirp demodulation +- **Objective**: de-chirp CSS in software (multiply by down-chirp ref + FFT). gr-lora_sdr implements it. +- **Kit**: gr-lora_sdr (HackRF/USRP/bladeRF/RTL-SDR). + +### LL — `RFSAM-LORA-LL-01` LoRaWAN frame profiling +- **Objective**: capture chirps → LoRaWAN frames; parse MHDR/MType, FHDR(DevAddr, FCnt), join (JoinEUI/DevEUI/DevNonce in cleartext). Payload remains AES-128. +- **Kit**: gr-lora_sdr, LoRAttack (multichannel USRP), ChirpCat (gateway uplink+downlink), WHAD/STM32WLxx, catnip (LoRa/Meshtastic), LoRa Wideband Decoder. +- **Decoder**: Wireshark (LoRaTap). + +### CR — `RFSAM-LORA-CR-01` Join and session-key assessment +- **Objective**: assess crypto — there is no brute force of random AES-128. Weaknesses: default/shared AppKey, ABP static keys without rotation, DevNonce reuse (1.0.x replay). +- **Kit**: Loracrack (weak AppKey → derives session keys, validates MIC), LAF (IOActive, parse/crack/forge). +- **Command**: `loracrack` on a PCAP with join + data + candidate AppKey. +- **Honesty note**: does NOT break strong AES-128. + +### AT (no dedicated control — active techniques) +- **⚠ MANDATORY AUTHORIZATION** (transmits sub-GHz ISM). Replay uplink/join (especially 1.0.x DevNonce / ABP FCnt reset), forge with session keys (CatSniffer TX, LAF), fuzz network server (ChirpStack). +- **Kit**: LoRAttack (replay/craft), CatSniffer (LoRa TX fuzzing vs ChirpStack), LAF (forge+send). + +### AP +- Payload encrypted with AES-128; once you have the AppSKey, you decrypt with the same tools. Server-side (ChirpStack app server) is outside the RF toolchain. + +## Subflow (specialization of the master flow) + +LoRa-specific transitions; verbatim commands live in `Layer-by-layer descent` above. + +| Advance | Advancement criterion | Markers | +|---------|----------------------|---------| +| IG → SP | Radio+MAC identified; regional band fixes the center (EU868/US915…) | — | +| SP → PHY | CSS diagonal chirps confirmed on waterfall. RTL-SDR suffices (sub-GHz); devices are duty-cycle limited | — | +| PHY → LL | PHYPayload recovered (de-chirp in software: down-chirp ref × signal → FFT) | — | +| LL → CR | PHYPayload parsed. App payload **always AES-128** (cleartext only if misconfigured ABP) | — | +| CR → AT | Weak/shared AppKey or static ABP keys confirmed. **No** brute force of random AES-128; 1.0.x DevNonce reuse = vector | — | +| AT | ⚠TX re-check; respect ISM duty-cycle/power. 1.0.x DevNonce replay; ABP FCnt reset | ⚠TX | + +**Defensive anomaly** (Defensive mode, RX-only): chirps in your band **without a known own gateway** = unknown device or replay. Correlate with schedule/activity. + +## Legal warnings +- Passive RX sub-GHz OK. +- **TX/replay/forge = active**: respect ISM duty-cycle/power; own/authorized network only. +- Falsifying telemetry of a third-party sensor (meter, alarm) = fraud/sabotage. diff --git a/Skill/references/14-lte.md b/Skill/references/14-lte.md new file mode 100644 index 0000000..cf5f695 --- /dev/null +++ b/Skill/references/14-lte.md @@ -0,0 +1,61 @@ +# 14 — LTE / 4G + +> Wayfinder + RFSAM controls for LTE. **Licensed spectrum** — passive RX OK, any TX requires an authorized lab. + +## Facts +- **Band**: licensed cellular ~700 MHz–2.6 GHz (E-UTRA ~450 MHz–3.8 GHz); FDD and TDD. +- **Width**: 6 bandwidths — 1.4/3/5/10/15/20 MHz; carrier identified by EARFCN. +- **Modulation**: DL OFDMA, UL SC-FDMA; QPSK/16/64/256-QAM. Frame 10 ms → 10 subframes (1 ms) → 2 slots. +- **Cell ID**: PSS→N_ID(2) (0–2), SSS→N_ID(1) (0–167); PCI = 3·N_ID(1)+N_ID(2) → 504 (0–503). +- **Broadcast**: MIB in PBCH (bandwidth, PHICH, SFN); SIB1 in PDSCH via SI-RNTI (PLMN, cell ID, TAC). SIBs in cleartext. +- **Control**: PDCCH carries DCI, addressed by RNTIs (C-RNTI, SI-RNTI, P-RNTI paging). Blind-decoding common search space exposes scheduling/identity passively. +- **Security**: air crypto SNOW 3G/AES/ZUC keyed from USIM (EPS-AKA) — **not recoverable from passive capture**. User-plane encryption optional per bearer; broadcast/paging without protection. + +## Layer-by-layer descent + +### IG — `RFSAM-LTE-IG-01` Baseband and modem vulnerabilities +- **Objective**: identify cell/operator before capturing. Band/EARFCN, PCI (PSS/SSS), PLMN/MNC+MCC, TAC from SIB1, bandwidth. Known weaknesses: pre-AKA messages unauthenticated (basis of IMSI catchers + downgrade/redirect), SIB/paging leak config and S-TMSI in cleartext. +- **Kit**: commercial modem (SIM7600 AT+CPSI?), QCSuper (modem signalling → Wireshark). + +### SP — `RFSAM-LTE-SP-01` Cell identification and capture +- **Objective**: where the cell is, what bandwidth. Sweep bands, see the OFDM DL "wall", read EARFCN/center/width. +- **Kit**: Gqrx (HackRF for a single 20 MHz carrier; bladeRF/USRP for more context; RTL-SDR only low bands — tops out at 1.766 GHz), SIM7600 (AT+CPSI? cell scan without SDR). +- **Caveat**: RTL-SDR cannot reach 1.8–2.6 GHz carriers. + +### PHY — `RFSAM-LTE-PHY-01` Resource-grid recovery +- **Objective**: coherent capture (GPSDO USRP B210 ideal). Synchronize PSS/SSS → PCI, decode MIB PBCH, grid. Drift smudges subcarriers. + +### LL — `RFSAM-LTE-LL-01` Control-channel / identity exposure +- **Objective**: decode broadcast/control channels — MIB/SIBs (PLMN, cell ID, TAC, scheduling), paging. The network "shouting in cleartext". +- **Kit**: srsRAN 4G (srsUE cell-search + MAC-LTE/RRC PCAP), FALCON (blind-decode PDCCH), LTESniffer (DL/UL eavesdropper), gr-lte (GNU Radio PBCH), QCSuper (modem signalling → Wireshark). +- **Decoder**: Wireshark (GSMTAP / MAC-LTE). + +### CR (no dedicated control — nothing to break passively) +- SNOW 3G/AES/ZUC keyed by EPS-AKA (USIM). No offline shortcut. Identifiers (PCI/PLMN/TAC/SIBs/S-TMSI/PDCCH) are read, not decrypted. Recovering user-plane = being the network (AT) on authorized equipment. + +### AT (no dedicated control — rogue cell, **authorized lab mandatory**) +- **⚠ LICENSED SPECTRUM — never radiate on a live operator band. Lab only + test SIMs + cage/conducted.** Rogue/fake eNodeB (srsENB/OAI) on test EARFCN, own PCI/PLMN/SIB, UE reselects. Foothold exercises: (1) IMSI/identity exposure (NAS pre-AKA unauthenticated → Identity Request); (2) downgrade (reject/break LTE attach → 2G/GSM weak crypto); (3) signalling DoS/RRC floods; (4) tracking (paging S-TMSI + measurement reports). +- **Kit**: srsRAN 4G (rogue eNodeB + srsEPC or Open5GS), imsi-catcher-srsran (turnkey fork), OpenAirInterface (alt rogue + fuzz RRC/NAS), Open5GS (EPC core), MobileInsight (victim-side RRC/NAS decode), Crocodile Hunter (EFF, detect fake-eNB), Rayhunter (EFF, portable detector on Orbic RC400L). + +### AP +- NAS/EPC signalling (attach, auth, identity, tracking-area) — you only exercise by being the network. With eNodeB+core (AT) + authorized UE: inspect NAS, force re-auth/identity, test behavior under a hostile core. +- **Kit**: Open5GS (EPC/NAS test harness). + +## Subflow (specialization of the master flow) + +LTE-specific transitions; verbatim commands live in `Layer-by-layer descent` above. + +| Advance | Advancement criterion | Markers | +|---------|----------------------|---------| +| IG → SP | Cell/operator identified (EARFCN, PCI, PLMN, TAC from SIB1). Baseband/modem CVEs cross-referenced | — | +| SP → PHY | DL carrier confirmed on waterfall (20 MHz OFDM wall). RTL-SDR only low bands (tops out at 1.766 GHz); bladeRF/USRP for 1.8–2.6 GHz | — | +| PHY → LL | Coherent grid recovered (GPSDO USRP ideal) → MIB/SIB decoded | — | +| LL → CR | Broadcast/control decoded (SIBs, paging, PDCCH). User-plane SNOW 3G/AES/ZUC keyed by USIM — **no offline shortcut** | — | +| CR → AT | Nothing to break passively; AT = being the network (rogue eNB) in an authorized lab | — | +| AT | ⚠TX re-check; **licensed spectrum** — lab only + test SIMs + cage/conducted + experimental license. Live rogue eNB = RA5/RA8 | ⚠TX | + +**Defensive anomaly** (Defensive mode, RX-only): a cell broadcasting MCC/MNC/TAC that **do not** match a known operator, or S-TMSI paging with anomalous spikes = possible rogue eNB / IMSI catcher. Crocodile Hunter/Rayhunter detect it. Register; do **not** descend to AT. + +## Legal warnings +- Passive RX of broadcast/control OK (public DL spectrum). Capturing user-plane/third-party traffic is regulated. +- **Rogue eNB / IMSI catcher / downgrade / jamming = transmission on licensed spectrum**: illegal without an experimental license + contained lab. Never on a live operator. diff --git a/Skill/references/15-rfid.md b/Skill/references/15-rfid.md new file mode 100644 index 0000000..160a9aa --- /dev/null +++ b/Skill/references/15-rfid.md @@ -0,0 +1,60 @@ +# 15 — RFID / NFC + +> Wayfinder + RFSAM controls for RFID/NFC. Near-field (magnetic coupling), not far-field. + +## Facts +- **Bands**: LF 125/134 kHz · HF 13.56 MHz. Centimeters by design. +- **LF**: EM4100/EM4102, HID Prox (125 kHz), Indala, T5577 (clonable), HITAG — read-only IDs, little crypto. +- **HF**: ISO 14443-A/B (MIFARE Classic, Ultralight, NTAG, DESFire, EMV contactless), ISO 15693 (iCODE), FeliCa. +- **Crypto**: MIFARE Classic = Crypto1 (48-bit, **broken**: darkside/nested/hardnested/mfkey32). DESFire EV1/2/3 (AES/3DES) and modern NTAG are **not breakable** with Crypto1. + +## Layer-by-layer descent + +### IG (fingerprinting) +- Band (LF vs HF), standard/chip family, UID (fixed vs changeable), MIFARE sectors with default keys, security mode. Proxmark `lf search`/`hf search` autodetects. + +### SP — `RFSAM-RFID-SP-01` Carrier and standard identification +- **Objective**: energize tag and read carrier/standard/chip; or passive sniff reader↔card. +- **Kit**: pm3-client (`lf search`, `hf search`, `hf 14a sniff`/`hf 15 sniff`/`lf sniff` passive), Chameleon Ultra GUI. +- **Command**: `pm3` → `hf search`. + +### PHY (no control — demodulation in the reader) +- The reader's analog front-end demodulates the load modulation; the client extracts the bytes. There is no separate I/Q stage. + +### LL (integrated into SP — read/dump) +- Proxmark reads/dumps LF+HF; libnfc with ACR122U (HF); Chameleon/BomberCat standalone. + +### CR — `RFSAM-RFID-CR-01` Crypto1 / key-strength assessment +- **Objective**: break MIFARE Classic. With 1 known key → nested; with none → darkside; hardnested for hardened EV1; mfkey32/64 from a sniffed transaction. +- **Kit**: pm3-client (full Crypto1 suite), mfoc (nested, libnfc), mfcuk (darkside). +- **Command**: `pm3` → `hf mf nested 1 ` or `hf mf hardnested`. +- **Honesty note**: modern DESFire/NTAG (AES) out of scope — acknowledge it and stop. +- **Near-field note**: in RFID, CR is **live interrogation of the tag** at cm (the Proxmark energizes and challenges the card), not offline PCAP analysis as in far-field (BLE/Wi-Fi/LoRa). It is not a spectrum attack TX and does not trigger a TX re-check, but it differs from the "offline CR" pattern of the master flow. + +### AT — `RFSAM-RFID-AT-01` Clone, emulate and relay +- **⚠ MANDATORY AUTHORIZATION** to clone/relay real credentials. +- **Objective**: clone to a blank/magic card, emulate, or relay (defeats proximity assumption, without keys). +- **Kit**: pm3-client (write T5577/magic, `hf mf sim`, relay `hf_reblay`), Chameleon Ultra GUI (emulate slots), BomberCat (RelayNFC + MagSpoof). +- **LF EM/HID**: clone directly to T5577. + +### AP +- Read the meaning of the dump: facility/card number (Wiegand 26-bit), value blocks (transit), NDEF. mfdread renders a MIFARE Classic dump readable. + +## Subflow (specialization of the master flow) + +RFID/NFC-specific transitions; verbatim commands live in `Layer-by-layer descent` above. Near-field (cm), **not** far-field — SP is carrier ID, not waterfall. + +| Advance | Advancement criterion | Markers | +|---------|----------------------|---------| +| IG → SP | Tag type identified. **Fork first**: LF 125 kHz vs HF 13.56 MHz | — | +| SP → LL | Carrier/standard/chip confirmed (power the tag and read, or `hf 14a sniff`/`lf sniff` passive) | — | +| (PHY merged) | The reader's analog front-end demodulates load modulation → bytes | — | +| LL → CR | MIFARE Classic? (Crypto1 breakable) Modern DESFire/NTAG? (**out of scope** for Crypto1) | — | +| CR → AT | Keys recovered or gap declared (modern DESFire/AES = stop and declare) | — | +| AT | ⚠TX re-check; ⚠ cloning third-party credentials = **RA6** (fraud). Relay/MITM defeats the proximity assumption **without keys** | ⚠TX | + +**Defensive anomaly** (Defensive mode, RX-only): RFID near-field does **not** have a typical emission surface. If you are defending your own reader, Defensive mode at SP = passive sniff of reader transactions looking for skimmers/relays. + +## Legal warnings +- Reading your own cards OK. +- **Cloning/emulating/relaying third-party credentials = fraud/unauthorized access** (crime). Own/authorized cards only + with the purpose of anti-relay testing of the reader. diff --git a/Skill/references/16-subg.md b/Skill/references/16-subg.md new file mode 100644 index 0000000..46a34b8 --- /dev/null +++ b/Skill/references/16-subg.md @@ -0,0 +1,61 @@ +# 16 — Sub-GHz ISM / Remotes + +> Wayfinder + RFSAM controls for Sub-GHz (garage controls, sensors, TPMS, meters). + +## Facts +- **Bands**: 315 MHz (NA/Asia remotes & TPMS) · 433.92 MHz (global, workhorse) · 868 MHz (EU, wM-Bus) · 915 MHz (US ISM 902–928). +- **Modulation**: almost all OOK/ASK (carrier blinks) or (G)FSK (two tones). No spread spectrum → easy to demodulate. +- **Encoding/baud**: PWM/Manchester/PPM at hundreds-to-thousands of baud, short repeated bursts. +- **Code type**: fixed (same payload always — trivial replay) vs rolling/hopping (KeeLoq/HCS301 — new value each press). +- **Crypto**: most **without confidentiality** (payload in cleartext). Rolling code = replay resistance, not encryption. KeeLoq requires the manufacturer key to forge the next code (not obtainable from passive capture). +- **Targets**: garage/gate remotes, car key fobs, TPMS, weather/soil sensors, smart-home plugs/doorbells, wM-Bus meters, alarm contacts. + +## Layer-by-layer descent + +### IG (fingerprinting) +- Frequency (FCC ID → fccid.io), modulation (OOK/ASK vs FSK), encoding/baud, **fixed vs rolling** (this decides everything), chip (CC1101, PT2262/EV1527, HCS301/KeeLoq), device class (rtl_433 has 320+ decoders). + +### SP — `RFSAM-SUBG-SP-01` Burst discovery and characterisation +- **Objective**: where it transmits; see bursts on trigger. RTL-SDR suffices (sub-GHz). +- **Kit**: Gqrx (waterfall), rtl_433 (live device scan → JSON), catnip (SX1262 spectrum analyzer). +- **Command**: `rtl_433 -f 433.92M` → decodes a known device to JSON. + +### PHY — `RFSAM-SUBG-PHY-01` Demodulation and framing +- **Objective**: clean recording of the burst, demod+frame in one pass (simple signal). Record I/Q centered on the carrier, at a rate that covers the bandwidth. + +### LL — `RFSAM-SUBG-LL-01` Frame and addressing recovery +- **Objective**: burst → bits → fields. Known device: rtl_433 decodes directly to JSON. Unknown: Universal Radio Hacker (auto-detect mod/baud, diff bitstream). Pocket: rfcat (YARD Stick One), Flipper Zero (Read/Read RAW). +- **Kit**: rtl_433, Universal Radio Hacker, rfcat+yard-stick-one, Flipper Zero, catnip (SX1262 GFSK packets). + +### CR — `RFSAM-SUBG-CR-01` Rolling-code assessment +- **Objective**: honesty — nothing to "break" in most cases (no crypto). Fixed code = read at LL. Rolling code = replay resistance, **not** an encrypted channel. To forge the next code you need the manufacturer key (not in passive capture). Academic KeeLoq cryptanalysis out of scope. +- **No offline crack tool** — read fixed codes, capture-and-replay rolling codes (AT). + +### AT — `RFSAM-SUBG-AT-01` Replay and forge +- **⚠ MANDATORY AUTHORIZATION** (transmits sub-GHz; respect ISM power/duty-cycle). +- **Objective**: fixed code → trivial replay. Rolling code → RollJam (jam+capture an unused code, use it later), RollBack (desync counter via massive replay = DoS), brute force small keyspace (DIP-switch EV1527/PT2262). +- **Kit**: rfcat (replay fixed), Universal Radio Hacker (replay/edit TX), Flipper Zero (field replay fixed), catnip (scriptable GFSK TX). +- **Command**: rfcat → `d.RFxmit(captured_bytes)`. + +### AP +- No separate stack: rtl_433 JSON = application layer (sensor values, IDs, flags). You forge those values to deceive the gateway/display. + +## Subflow (specialization of the master flow) + +Sub-GHz-specific transitions; verbatim commands live in `Layer-by-layer descent` above. + +| Advance | Advancement criterion | Markers | +|---------|----------------------|---------| +| IG → SP | Frequency and modulation confirmed. **FCC ID** (fccid.io) resolves exact freq/mod | — | +| SP → PHY | Short bursts confirmed on press/sensor report. RTL-SDR suffices | — | +| (PHY+LL in one pass) | Clean recording of the burst → demod+frame (simple signal, low baud) | — | +| LL → CR | **Fixed** code (in cleartext, replayable) or **rolling** (KeeLoq/HCS301)? | — | +| CR → AT | Fixed confirmed (replayable) or rolling (→ RollJam at AT). Most **without crypto** → CR is usually a "read" | — | +| AT | ⚠TX re-check (radio TX required: rfcat/YARD Stick/Flipper/catnip); ⚠ replay against third parties = **RA7** | ⚠TX | + +**Defensive anomaly** (Defensive mode, RX-only): bursts in your band **without a known own device** = possible neighbor scanner/replay. Correlate with your activity. + +## Legal warnings +- Passive RX sub-GHz OK. +- **TX/replay/forge = active**: own/authorized devices only. Opening someone else's garage/alarm = breaking and entering/theft. ISM jamming is illegal over the air in many jurisdictions. +- Flipper stock firmware **refuses** to save/replay rolling codes by design (fixed only). diff --git a/Skill/references/17-zigbee.md b/Skill/references/17-zigbee.md new file mode 100644 index 0000000..1b4380c --- /dev/null +++ b/Skill/references/17-zigbee.md @@ -0,0 +1,61 @@ +# 17 — Zigbee / 802.15.4 + +> Wayfinder + RFSAM controls for Zigbee. RFSAM owns end-to-end. + +## Facts +- **Band**: 2.4 GHz (2.405–2.480) primary · sub-GHz 868 MHz (EU) / 902–928 (Americas). +- **Channels**: 2.4 GHz 16 channels 11–26 (spaced 5 MHz); one PAN on one channel (does not hop like BLE). +- **PHY**: IEEE 802.15.4 — 2.4 GHz O-QPSK with DSSS, 250 kbps. +- **Stack**: 802.15.4 MAC/PHY → Zigbee NWK (mesh) → APS → ZCL/ZDO. Roles: Coordinator, Router, End Device. +- **Security**: AES-128-CCM* at NWK and APS. Network key shared by the entire PAN; Trust Center link key gates the join. Default well-known TC link key `ZigBeeAlliance09` (hex `5A6967426565416C6C69616E63653039`). +- **Range**: ~10–100 m per hop; the mesh extends it. + +## Layer-by-layer descent + +### IG (fingerprinting) +- Chipset (Silicon Labs EFR32/EM35x, TI CC2530/CC2538/CC1352, NXP JN51xx, ESP32-C6), role (Coordinator=Trust Center/Router/End Device), channel/PAN, join model (centralized vs distributed; default TC link key vs install code vs Zigbee 3.0 install-code-only). + +### SP — `RFSAM-ZIGBEE-SP-01` Channel survey and capture feasibility +- **Objective**: which of the 16 channels the PAN is on. Energy/active scan, no hop chasing. +- **Kit**: KillerBee `zbstumbler` (active beacon), Gqrx (energy cross-check), Minino (scanner), Kismet (passive multi-radio), catnip (activity table). +- **Caveat**: channels 15/20/25/26 fall in Wi-Fi gaps → common. + +### PHY (no control — demodulation on 802.15.4 radio) +- 802.15.4 radios demodulate O-QPSK/DSSS (PHY) and frame MAC (LL) together. SDR impractical for live decode. + +### LL — `RFSAM-ZIGBEE-LL-01` PAN, addressing and device discovery +- **Objective**: park an 802.15.4 radio on the channel → PCAP. **Critical**: capture a device *joining* (join) — that is where the network key is transported. +- **Kit**: KillerBee (`zbdump`/`zbwireshark`, ApiMote/nRF52840), catnip (CatSniffer), nRF Sniffer 802.15.4, whsniff (CC2531), Minino, WHAD (nRF52840/APIMote), Kismet (multi-radio). +- **Decoder**: Wireshark (802.15.4 + Zigbee NWK/APS; decrypts with network key). + +### CR — `RFSAM-ZIGBEE-CR-01` Network-key provisioning and rotation +- **Objective**: recover the network key from the join. Classic weakness: APS Transport-Key on join under the default TC link key `ZigBeeAlliance09` (or in cleartext on old devices). +- **Kit**: zbdsniff (extracts network key from join under `ZigBeeAlliance09` or in cleartext), Wireshark (decrypts with key). +- **Command**: capture join → `zbdsniff join.pcap` → paste key in Wireshark Preferences → ZigBee. +- **Caveat**: per-device install code defeats it; Zigbee 3.0 install-code key agreement (AES-MMO) resists capture-the-join. + +### AT (no dedicated control — active techniques) +- **⚠ MANDATORY AUTHORIZATION**. With network key: forge/inject (KillerBee `zbreplay`/scapy-radio, ApiMote TX). Force leave/rejoin to recapture the join. catnip OTA firmware-update MITM+jamming PoC. +- **Kit**: KillerBee (ApiMote TX), catnip (OTA MITM PoC). + +### AP +- ZCL commands (on/off, lock/unlock, level). With the network key, craft encrypted APS/ZCL and inject (KillerBee zbscapy). + +## Subflow (specialization of the master flow) + +Zigbee-specific transitions; verbatim commands live in `Layer-by-layer descent` above. + +| Advance | Advancement criterion | Markers | +|---------|----------------------|---------| +| IG → SP | Role (Coordinator/Router/End) and PAN identified. Default TC link key `ZigBeeAlliance09` is **well-known** | — | +| SP → PHY+LL | PAN channel fixed (16 channels 2.4 GHz, **no hopping**); 802.15.4 radio parked. SDR does not decode O-QPSK/DSSS live | — | +| PHY+LL → CR | Do you capture a **join**? (that is where the network key is transported). **Critical** to extract the key | — | +| CR → AT | Network key in hand or gap. Transport-Key protected only by default TC link key (or in cleartext on old devices); install code defeats it | — | +| AT | ⚠TX re-check; with key → forge/inject, force leave/rejoin; without key → replay encrypted | ⚠TX | +| AP (no formal control) | ZCL commands (on/off, lock, level) over what the device trusts | — | + +**Defensive anomaly** (Defensive mode, RX-only): unexpected management frames (**forced** leave/rejoin) or unknown devices joining the PAN = possible takeover. Register. + +## Legal warnings +- Passive RX OK (802.15.4 open). +- **Inject/replay/forge = active**: own/authorized PAN only. Operating someone else's lock/switch = breaking and entering. diff --git a/Skill/references/18-zwave.md b/Skill/references/18-zwave.md new file mode 100644 index 0000000..4992d44 --- /dev/null +++ b/Skill/references/18-zwave.md @@ -0,0 +1,58 @@ +# 18 — Z-Wave + +> Wayfinder + RFSAM controls for Z-Wave. Regional sub-GHz, source-routed mesh. + +## Facts +- **Band**: regional sub-GHz ISM — 908.42 MHz (US) · 868.42 MHz (EU) · + regional channels (921.42 ANZ, 919.82 HK, 922–926 JP). **One region per device**. +- **Modulation/rate**: (G)FSK at 3 rates: 9.6 kbps (R1 legacy), 40 (R2), 100 (R3). Z-Wave Long Range (US 912/920) adds power and star topology. +- **PHY/MAC**: ITU-T G.9959 (open). Upper stack open after Silicon Labs release (~2016). +- **Identifiers**: 32-bit Home ID (the network) + 8-bit Node ID (device). Both **in cleartext** in every frame header. +- **Security**: legacy **S0** AES-128, but during inclusion the network key is encrypted under a **FIXED all-zero** temporary key → capturing inclusion = recover the key. Modern **S2** (Gen5/700+): Curve25519 ECDH on inclusion — the secret is never sent. +- **Topology**: source-routed mesh: primary controller/hub + routing slaves + end devices. Targets: locks, sensors, thermostats, controller. + +## Layer-by-layer descent + +### IG (fingerprinting) +- Region/frequency (FCC ID/CE marking), chipset/generation (Sigma ZW0301/ZW0501 500-series vs SiLabs 700/800 EFR32ZG), security class (S0 vs S2 vs unencrypted), Home ID/Node ID, data rate (R1/R2/R3 vs Long Range). + +### SP — `RFSAM-ZWAVE-SP-01` Region/frequency identification +- **Objective**: confirm it transmits on the regional channel. RTL-SDR reaches it (sub-GHz). FSK burst on report/poll. +- **Kit**: Gqrx (RTL-SDR/HackRF tuned to 908.42/868.42). Trigger the device (open a door) to make it talk. + +### PHY (no control — demod+frame together) +- G.9959 (G)FSK demodulated and parsed in each tool. Match regional freq + rate (9.6/40/100 kbps use different deviation/bandwidth). + +### LL (integrated into SP — capture/decode frames) +- Park radio on regional channel → headers (Home ID, Node ID, frame control, command class). SDR: Waving-Z/rtl-zwave (RTL-SDR), EZ-Wave/Scapy-radio (HackRF). Vendor: Zniffer (Silicon Labs, UZB stick). +- **CRITICAL for S0**: capture an **inclusion** (pairing) — that is where the key travels. + +### CR — `RFSAM-ZWAVE-CR-01` Key establishment assessment +- **Objective**: S0 → capture inclusion, recover network key (encrypted under all-zero temp key). S2 (ECDH) → **no shortcut** from capture. +- **Kit**: Zniffer (clean S0 inclusion capture, recovers key knowing the all-zero temp key), EZ-Wave (decrypts S0 with key). +- **Historical Z-Shave attack**: downgrade S2→S0 during inclusion (downgrade, not an S2 break). + +### AT (no dedicated control — active techniques) +- **⚠ MANDATORY AUTHORIZATION**. With S0 key or unencrypted command classes: forge/inject (EZ-Wave/Scapy-radio HackRF, gr-zwave_poore USRP B210). Replay/forge command classes (lock/unlock, switch). S2 + anti-replay nonces blocks encrypted forge. +- **Kit**: EZ-Wave, Scapy-radio, gr-zwave_poore. + +### AP +- Command classes: Door Lock CC, Binary Switch, thermostat, sensor report, Version/Manufacturer-Specific. EZ-Wave `ezrecon` interrogates the device; Z-Wave PC Controller (SiLabs, UZB stick) is the legitimate driver. + +## Subflow (specialization of the master flow) + +Z-Wave-specific transitions; verbatim commands live in `Layer-by-layer descent` above. + +| Advance | Advancement criterion | Markers | +|---------|----------------------|---------| +| IG → SP | Region/frequency confirmed (FCC ID/CE marking). RTL-SDR reaches it (sub-GHz) | — | +| SP → LL | Regional carrier (908.42/868.42 MHz) confirmed. FSK burst on report/poll | — | +| (PHY merged) | G.9959 (G)FSK demodulated and parsed in each tool | — | +| LL → CR | Security class? **S0** (capture inclusion → recover key) **S2**? (ECDH → no shortcut) | — | +| CR → AT | S0 keys recovered or gap declared (S2 ECDH → stop). S2→S0 downgrade historically (Z-Shave), not an S2 break | — | +| AT | ⚠TX re-check (HackRF/USRP for forge); ⚠ operating someone else's lock/switch = breaking and entering. S2 + anti-replay nonces blocks encrypted forge | ⚠TX | + +**Defensive anomaly** (Defensive mode, RX-only): Z-Wave frames with an **unknown** Home ID attempting inclusion/leave on your network, or unencrypted command classes operating on your actuators = possible takeover/rogue controller. Register; do **not** descend to AT. + +## Legal warnings +- Passive RX sub-GHz OK. +- **Inject/replay/forge = active**: own/authorized network only. Operating someone else's lock/switch = breaking and entering. diff --git a/Skill/references/19-thread.md b/Skill/references/19-thread.md new file mode 100644 index 0000000..5d8bb32 --- /dev/null +++ b/Skill/references/19-thread.md @@ -0,0 +1,61 @@ +# 19 — Thread / Matter + +> Wayfinder + RFSAM controls for Thread/Matter. Thread = IPv6 mesh over 802.15.4; Matter rides on top. + +## Facts +- **Band**: 2.4 GHz ISM — IEEE 802.15.4 O-QPSK (same radio layer as Zigbee). +- **Channels**: 16 × 5 MHz, 11–26 (2.405–2.480); a Thread network on one channel. +- **Stack**: IPv6 mesh: 802.15.4 MAC → 6LoWPAN → MLE routing → UDP. Matter (CHIP) on top. +- **Thread security**: MAC AES-128-CCM* with network key — strong link crypto. Commissioning: Commissioner auth with PSKc; Joiner admitted with PSKd via DTLS. +- **Matter transport**: Thread (via Border Router) or Wi-Fi; commissioned over BLE LE. DNS-SD: `_matterc._udp` (commissionable), `_matter._tcp` (operational), `_meshcop._udp` (Border Router Thread). +- **Matter onboarding**: QR (`MT:` Base-38) / 11-digit manual code → 27-bit setup passcode + 12-bit discriminator + 16-bit Vendor ID + ProductID. +- **Matter crypto**: PASE = SPAKE2+ (P-256) from setup passcode (commissioning window only); CASE = cert (NOC under Root CA, SIGMA P-256) operational. **Passcode = weak link, not the cipher**. + +## Layer-by-layer descent + +### IG (fingerprinting — read QR/label) +- Thread or Zigbee? (both 802.15.4 — distinguish by upper layers 6LoWPAN+MLE). Matter device? QR/numeric code + BLE onboarding. Resolve VID/PID against **DCL** (Distributed Compliance Ledger — Test-Vendor VID 0xFFF1–0xFFF4 on a shipping product = red flag). Chipset/SDK + CVEs (CASE Sigma1-replay CVE-2024-3297, fabric-footprinting CVE-2024-3454). +- **Kit**: matter-dcl (resolve VID/PID), chip-tool (decode payload + discover BLE/DNS-SD). + +### SP — how to see the band (part of Thread LL) +- Thread lives on one 802.15.4 channel. Gqrx (band), Minino (802.15.4 scanner), catnip (activity + topology). Matter BLE onboarding lives on BLE advertising channels (see BLE wayfinder). + +### PHY (no control — demodulation on 802.15.4 radio) +- 802.15.4 radios demod+frame together; SDR only to find the channel. + +### LL — `RFSAM-THREAD-LL-01` Mesh discovery and commissioning exposure +- **Objective**: park an 802.15.4 radio on the channel → PCAP. MAC payload AES-128-CCM* under network key; Wireshark decrypts with that key. +- **Kit**: nRF Sniffer 802.15.4 (nRF52840), pyspinel (OpenThread NCP/RCP sniffer), CatSniffer, Minino, WHAD (nRF52840/APIMote). +- **Decoder**: Wireshark (802.15.4 + Thread/6LoWPAN/MLE). +- (Matter BLE commissioning handshake = separate BLE capture — see BLE wayfinder.) + +### CR — `RFSAM-THREAD-CR-01` Network credential assessment +- **Objective**: honesty — strong crypto (AES-128-CCM*, SPAKE2+, CASE cert). **No offline key-recovery**. The prize is the Thread network key: it comes from weak/default/exposed commissioning credentials (PSKc/Joiner PSKd). Matter PASE is only as strong as the setup passcode (default/printable → collapses). Verifier extracted from an insecure device → offline recovery (low entropy). Online guessing is rate-limited (~20 attempts → drops out of commissioning mode; window ≤15 min in fabric). +- **Kit**: Wireshark (decrypts Thread with network key in decryption-keys table), chip-tool (PASE/passcode test with candidate). +- **No offline cracking tool** — attack commissioning/credentials. + +### AT (no dedicated control — commissioning/fabric abuse) +- **⚠ MANDATORY AUTHORIZATION**. The real surface is commissioning/fabric onboarding: join the mesh with captured/guessed creds (pyspinel), or commission a Matter device with an open BLE window/weak passcode (chip-tool `pairing ble-thread`). Multi-admin: the commissioning window can be opened/hijacked. The controller **does not verify trustworthiness** of the device → whoever passes commissioning = full admin. +- **Kit**: pyspinel (join/probe mesh), chip-tool (commission onto fabric), chip-repl (multi-fabric scripting). + +### AP +- Matter clusters/attributes over CASE (read/write/invoke/subscribe). ACL that constrains a newly added admin. Commissioned = full admin → app layer is usually wide open. +- **Kit**: chip-tool (cluster interaction), chip-repl (enum cluster tree), python-matter-server (persistent controller). + +## Subflow (specialization of the master flow) + +Thread/Matter-specific transitions; verbatim commands live in `Layer-by-layer descent` above. + +| Advance | Advancement criterion | Markers | +|---------|----------------------|---------| +| IG → SP | Thread or Zigbee? (distinguish by upper layers 6LoWPAN+MLE). Matter device: QR/code + BLE onboarding. VID/PID against DCL | — | +| SP → PHY+LL | 802.15.4 channel fixed (2.4 GHz, 16 channels 11–26, **no hopping**); radio parked. SDR does not decode O-QPSK/DSSS live | — | +| PHY+LL → CR | MAC payload AES-128-CCM* under network key — Wireshark decrypts with that key. Thread crypto strong | — | +| CR → AT | No offline key-recovery. Prizes: weak/default commissioning (PSKc/PSKd), Matter PASE limited by setup passcode | — | +| AT | ⚠TX re-check; commissioning/fabric onboarding = real surface. Join/probe mesh (pyspinel), commission Matter (chip-tool) | ⚠TX | + +**Defensive anomaly** (Defensive mode, RX-only): unknown device attempting commissioning onto your fabric, or an open BLE commissioning window without your own activity = possible fabric hijack. Register; do **not** descend to AT. + +## Legal warnings +- Passive RX 802.15.4 OK. +- **Join/commission/inject = active**: own/authorized mesh/fabric only. Commissioning someone else's device = unauthorized access. diff --git a/Skill/references/20-gnss.md b/Skill/references/20-gnss.md new file mode 100644 index 0000000..6163470 --- /dev/null +++ b/Skill/references/20-gnss.md @@ -0,0 +1,56 @@ +# 20 — GNSS / GPS + +> Wayfinder + RFSAM controls for GNSS. Civilian signals **without encryption or authentication** → attack = imitate. +> **⚠ GNSS spoofing/jamming over the air is a crime in almost all jurisdictions — conducted/wired + cage only.** + +## Facts +- **Band**: L-band. GPS L1 1575.42 MHz · L2 1227.60 · L5 1176.45. Neighbors: GLONASS L1 ~1602, Galileo E1 1575.42 (overlap GPS L1), BeiDou B1 1561.098. +- **Signal (GPS L1 C/A)**: BPSK on 1575.42 MHz carrier; 1023-chip C/A spreading 1.023 Mcps repeats every 1 ms; nav message 50 bps. One PRN code per sat (CDMA). +- **Constellations**: GPS (US) · GLONASS (RU) · Galileo (EU) · BeiDou (CN) + regional QZSS/NavIC. 4+ sats in view for PVT. +- **Security**: civilian (GPS C/A, GLONASS, BeiDou B1, Galileo E1 OS) **without encryption or authentication** — public structure. Military P(Y)/M-code encrypted, out of scope. Galileo OSNMA adds optional auth; legacy C/A none. +- **Power at receiver**: very weak — ~-125 to -130 dBm, **below the noise floor**; recovered only by despreading the known PRN. This is why a slightly stronger attacker signal captures the receiver. + +## Layer-by-layer descent + +### IG (fingerprinting) +- Constellations/bands it tracks (GPS-only L1, multi-constellation, multi-band L1/L2/L5). Civilian signals unauthenticated — no key or credential, only signal to imitate. Chipset (FCC ID, NMEA vendor strings), anti-spoof (RAIM, consistency) / anti-jam. Behavior on loss of fix (coast/alarm/accept first reacquire — the latter exploits spoof). The u-blox NEO module gives direct NMEA/UBX. + +### SP — `RFSAM-GNSS-SP-01` Signal presence and interference survey +- **Objective**: confirm L-band present and judge RF environment. The GNSS signal is below the noise floor — in the waterfall you look for what is **wrong**: strong carrier or wideband hump on L1 = jammer/interference; clean/quiet band = healthy. +- **Kit**: Gqrx (HackRF/bladeRF/USRP/RTL-SDR; RTL-SDR with bias-tee for active antenna). Standard GPS receiver (gpsd gpsmon/cgps or u-center) gives C/N0 per sat. + +### PHY (no control — despreading on chip or software) +- GPS module: PRN correlated in chip hardware → you read NMEA/UBX. SDR: despreading in software (GNSS-SDR). Signal below noise floor until something correlates against the known code. + +### LL (no control — receiver = demod+decoder) +- Two paths. (a) Everyday: u-blox NEO USB/serial receiver → NMEA 0183 + UBX → gpsd (gpsmon/cgps) or u-center. (b) SDR: raw L-band I/Q → GNSS-SDR → PVT + NMEA/RINEX. No Wireshark; output is position/time. + +### CR (no control — no crypto to break) +- Civilian without encryption or auth: spreading codes and formats published → anyone can decode, anyone can generate. No session key (BLE pairing) or handshake (WPA). P(Y)/M-code out of scope. The real question = trust: does the receiver distinguish a genuine sat from spoof? Galileo OSNMA signs the nav message; RAIM/consistency checks. Legacy C/A does not → that is why AT works. + +### AT — `RFSAM-GNSS-AT-01` Spoofing and jamming resilience +- **⚠ AUTHORIZED + RF-CONTAINED only (cage/conducted). TX GNSS over the air is illegal.** Without auth, the attack = imitate. **SPOOFING**: synthesize GPS L1 C/A (RINEX ephemeris + static/mobile track) at higher power than real sats → captures receiver, drags position/clock to attacker-chosen values. **JAMMING**: flood L1 with noise/carrier, denies fix (resilience test). RTL-SDR RX-only (never transmits). +- **Kit**: gps-sdr-sim (synthesis + TX on HackRF/bladeRF/USRP), Gqrx (monitor jamming-resilience). +- **Caveat**: multi-constellation/OSNMA-aware receivers may detect/reject spoofing of GPS-only single-constellation. + +### AP +- No interactive app layer over the air: GNSS is one-way broadcast, no uplink/session. App impact = false position/time trusted by downstream systems (nav, geofencing, timestamps, PPS timing reference). Evaluated on the victim system (does false position/time cause unsafe behavior?). + +## Subflow (specialization of the master flow) + +GNSS-specific transitions; verbatim commands live in `Layer-by-layer descent` above. One-way broadcast — no handshake or key. + +| Advance | Advance criterion | Markers | +|---------|--------------------|---------| +| IG → SP | Constellations/bands tracked by the receiver identified. Module anti-spoof/anti-jam documented | — | +| SP → PHY | L-band present; RF environment judged (strong carrier / hump = jammer; clean band = healthy). RTL-SDR with bias-tee for active antenna | — | +| PHY → LL | Despreading (GPS chip in hardware or GNSS-SDR in software) → NMEA/UBX or PVT+RINEX | — | +| LL → CR | No crypto to break (civilians without auth). Real question = trust: does the receiver distinguish a genuine sat from spoof? | — | +| CR → AT | Legacy C/A without auth → AT works. OSNMA/RAIM-aware may detect/reject single-constellation spoof | — | +| AT | ⚠TX re-check; **never TX GNSS over the air** (crime). Conducted wired + cage only. Shielded GPSDO; wired receiver | ⚠TX | + +**Defensive anomaly** (Defensive mode, RX-only): anomalous C/N0 (jumps, selective fading), strong carrier on L1, or a fix that jumps to an impossible position = possible jamming/spoofing in your environment. Correlate with time/location; **do not** descend to AT (Defensive never TX). + +## Legal warnings +- Passive L1 RX OK; normal GPS receiver OK. +- **GNSS spoofing/jamming over the air = crime** (aviation, maritime, critical infrastructure). Conducted wired + Faraday cage + explicit authorization only. diff --git a/Skill/references/21-adsb.md b/Skill/references/21-adsb.md new file mode 100644 index 0000000..ea502eb --- /dev/null +++ b/Skill/references/21-adsb.md @@ -0,0 +1,57 @@ +# 21 — ADS-B (aviation) + +> Wayfinder + RFSAM controls for ADS-B. Broadcast **without encryption or authentication** → injection trivial (in lab). +> **⚠ 1090 MHz = protected aviation spectrum. Forging/injecting over the air is a serious crime. Conducted + cage only.** + +## Facts +- **Band**: 1090 MHz Mode S Extended Squitter (1090ES) worldwide; 978 MHz UAT (Universal Access Transceiver) additional in US for low-altitude general aviation. +- **Signal (1090ES)**: Pulse-Position Modulation (PPM) 1 Mbps on 1090 MHz carrier; Extended Squitter = 112-bit message (8 µs preamble + 112 µs data). 978 UAT waveform ~1.04 Mbps, message 272-bit. +- **Messages**: ADS-B "out" in Mode S downlink format DF17 (transponder) and DF18 (non-transponder/TIS-B). Each carries 24-bit ICAO aircraft address + type code: identification (callsign), airborne/surface position (CPR-encoded), velocity. +- **Identifiers**: ICAO 24-bit (unique radio ID), callsign 8-char, CPR-encoded lat/lon. **None authenticated** → all forgeable. +- **Security**: broadcast and **without encryption**. Public structure. **No auth or integrity** → receiver cannot distinguish a genuine frame from a forged one → spoofing/injection possible. + +## Layer-by-layer descent + +### IG (fingerprinting — what you hear) +- Which link: 1090ES (worldwide) vs 978 UAT (US general aviation). Link unauthenticated/unencrypted — positions, callsigns, ICAO in cleartext, no integrity check. ICAO 24-bit = unique ID in each frame. DF17 vs DF18 mix, type codes. RX setup: quarter-wave antenna (~6.9 cm) + 1090 MHz band-pass filter + LNA for weak/distant signals. + +### SP — part of PHY (confirm 1090 energy) +- 1090 MHz within almost any SDR. In the waterfall, bursty pulses at the squitter (above noise floor, visible). RTL-SDR = canonical 1090 receiver, reaches 1090 and 978. + +### PHY — `RFSAM-ADSB-PHY-01` Message capture and decode +- **Objective**: receive+decode ADS-B frames (plaintext broadcast). Tune 1090 → demod PPM → validate CRC → DF17/DF18 (ICAO, callsign, CPR position, velocity). 978 UAT → dump978. +- **Kit**: dump1090 (RTL-SDR, classic), readsb (high-perf fork), dump978 (US UAT), gr-air-modes (GNU Radio). +- **Decoder**: no Wireshark; output is decoded frames in Beast/raw/JSON for mapping/plausibility. + +### LL — `RFSAM-ADSB-LL-01` Message authenticity assessment +- **Objective**: what authenticity guarantees, if any, does the link provide? (Answer: none — basis for injection). + +### CR (no control — nothing to decrypt) +- Plaintext broadcast: format and CPR encoding public. Positions/callsigns/ICAO are read (decoded), not cracked. The real problem = the opposite of confidentiality: **no auth or integrity**. The receiver cannot prove the frame is from the aircraft it claims; no signature over position; no replay protection. This design gap = what makes AT possible: anyone transmitting a well-formed 1090ES frame is, for every receiver in range, indistinguishable from a real aircraft. + +### AT — `RFSAM-ADSB-AT-01` Forge and inject (contained lab mandatory) +- **⚠ 1090 MHz = protected aviation spectrum. TX ADS-B affects real ATC systems. Authorized lab only via CONDUCTED/CABLE or CAGE — never over the air.** Without auth, the attack = imitate: transmit forged 1090ES frames (chosen ICAO/callsign/position) → every receiver in range accepts as a real aircraft → ghost aircraft, move an existing track, or flood the picture. RTL-SDR RX-only. +- **Kit**: ADSB-Out (Python encoder → I/Q → TX on HackRF via hackrf_transfer). +- **Caveat**: author states academic only; stable but inactive (~2021). + +### AP +- "Air picture": decoded stream → tracked aircraft + fusion + plausibility. This is where missing auth is defended: sanity-check of the broadcast. tar1090 (live interactive map), pyModeS (decode in code → anti-spoof/plausibility checks: impossible kinematics, cross-receiver inconsistency, suspicious ICAO). MLAT (multilateration cross-receiver) = standard anti-spoof cross-check. +- **Kit**: tar1090 (map from readsb/dump1090), pyModeS (decode + plausibility). + +## Subflow (specialization of the master flow) + +ADS-B-specific transitions; verbatim commands live in `Layer-by-layer descent` above. Broadcast **without auth or integrity** → all IDs forgeable. + +| Advance | Advance criterion | Markers | +|---------|--------------------|---------| +| IG → SP | Link identified (1090ES worldwide vs 978 UAT US). RX setup: quarter-wave antenna (~6.9 cm) + 1090 filter + LNA | — | +| SP → PHY+LL | Bursty pulses above noise floor at the squitter. RTL-SDR reaches 1090 and 978 | — | +| PHY+LL → CR | Frames decoded (ICAO/callsign/CPR position/velocity). Without encryption → nothing to decrypt; the problem is the **opposite**: no auth | — | +| CR → AT | No auth/integrity/replay-protection confirmed → any well-formed 1090ES frame is indistinguishable from a real aircraft. AT works | — | +| AT | ⚠TX re-check; **1090 MHz = protected aviation**, TX affects real ATC. Conducted + cage + authorization only. RTL-SDR RX-only never transmits | ⚠TX | + +**Defensive anomaly** (Defensive mode, RX-only): ghost aircraft (ICAO/callsign that appears/disappears), impossible kinematics, or cross-receiver inconsistency = possible injection. pyModeS (plausibility checks) and MLAT (multilateration) are anti-spoof cross-checks. Log it; **do not** descend to AT. + +## Legal warnings +- Passive 1090/978 RX OK (public signals; basis for trackers like Flightradar24). +- **TX/forge ADS-B over the air = serious crime** (aviation spectrum, safety-of-life). Conducted wired + cage + authorization only. Never radiate. diff --git a/Skill/references/22-nr5g.md b/Skill/references/22-nr5g.md new file mode 100644 index 0000000..22bb13d --- /dev/null +++ b/Skill/references/22-nr5g.md @@ -0,0 +1,61 @@ +# 22 — 5G NR + +> Wayfinder + RFSAM controls for 5G NR. **Licensed spectrum** — passive RX OK, TX requires authorized lab. +> Passive SA sniffing is immature/research-grade vs LTE. + +## Facts +- **Band**: licensed cellular, two ranges — FR1 sub-6 GHz (~410 MHz–7.125 GHz; bands n1/2100, n3/1800, n78/3.5, n28/700) and FR2 mmWave (~24.25–52.6 GHz). FDD and TDD; n78/mid-band TDD. +- **Bandwidth**: flexible numerology SCS 15·2^μ kHz (15/30/60/120). Carrier up to 100 MHz FR1, 400 MHz FR2; identified by NR-ARFCN. Sub-6 on USRP/bladeRF; FR2 out of reach for common kit. +- **Modulation**: CP-OFDM DL and UL (UL may use DFT-s-OFDM); QPSK/16/64/256-QAM. +- **Cell ID**: PSS→N_ID(2) (0–2), SSS→N_ID(1) (0–335); PCI = 3·N_ID(1)+N_ID(2) → 1008 (0–1007). In the SS/PBCH block (SSB). +- **Broadcast**: MIB in PBCH within SSB (SFN, SSB position, SIB1 scheduling); SIB1 in PDSCH (PLMN, cell identity, TAC, access). SIBs in cleartext (like LTE). +- **Architecture**: SA (Standalone) = 5G NR + 5G Core (AMF/SMF/UPF); NSA (Non-Standalone) = 5G NR anchored to LTE eNB + EPC. SA vs NSA decides whether a 5G core is present. +- **Security**: 5G-AKA keyed from USIM (like LTE, no passive shortcut). **Improvement vs LTE**: long-term identity (SUPI/IMSI) **hidden as SUCI** (ECIES public-key) → no longer travels in cleartext over the air. + +## Layer-by-layer descent + +### IG — part of IG/SP (read before capturing) +- Band/NR-ARFCN (FR1 reachable USRP; FR2 mmWave out of common SDRs). SA vs NSA. PCI (0–1007) from PSS/SSS in SSB. PLMN/MCC+MNC and TAC from SIB1. Numerology/bandwidth (SCS 15/30/60, carrier up to 100 MHz FR1). CVEs: SIB/paging still cleartext; pre-auth NAS/RRC remains a documented attack surface (rogue gNB, baseband fuzz — **5Ghoul** class). SUPI now SUCI → over-the-air IMSI harvest closed. + +### SP — `RFSAM-NR5G-SP-01` Cell identification and capture +- **Objective**: where the carrier and SSB are, what bandwidth. FR1 sub-6; FR2 invisible to these radios (tuners top out at 6 GHz). A 100 MHz n78 carrier exceeds the HackRF view (~20) and even the USRP B210 (~56) — you see a slice, locate the SSB. +- **Kit**: Gqrx (FR1 sub-6), QCSuper (5G Qualcomm modem signaling → Wireshark; Quectel RM500Q modem). +- **Caveat**: sub-6 GHz only; single view narrower than a 100 MHz n78 carrier. + +### PHY (no control — cell search within LL tools) +- Recover OFDM grid (sync SSB PSS/SSS→PCI, decode MIB PBCH, SIB1, control channels) together in cell-search tools. Coherent capture (USRP GPSDO). Passive 5G air decode **less mature than LTE** — no srsUE-style turnkey SA receiver; sniffers are research-grade. + +### LL — `RFSAM-NR5G-LL-01` Broadcast / identity exposure +- **Objective**: capture+decode broadcast/control channels — honesty note: passive 5G NR air-sniffing is immature vs LTE. Routes: (1) stand up your own gNB+UE (srsRAN Project/OAI) to read SSB/MIB/SIB1 from a controlled cell; (2) research PDCCH decoder (5GSniffer) or sniffer/injector (Sni5Gect) — srsRAN-based, FR1/sub-6, demanding host/setup; (3) no-SDR modem route: QCSuper pulls 5G signaling off a Qualcomm DIAG modem. NGAP/NAS-5GS and MAC-NR dissection in Wireshark. +- **Kit**: srsRAN Project (SA gNB with core), 5GSniffer (PDCCH/DCI passive decoder), Sni5Gect (MAC-NR sniffer+inject research), QCSuper (Quectel RM500Q). +- **Decoder**: Wireshark. + +### CR (no control — nothing to break passively, same as LTE) +- Identifiers (PCI/PLMN/TAC/SIBs/paging/PDCCH) broadcast/in cleartext, read not decrypted. NEA/NIA ciphering/integrity (SNOW 3G/AES/ZUC) keyed by 5G-AKA from USIM — no offline shortcut. 5G improves on LTE: SUPI/IMSI hidden as SUCI (ECIES) → passive/fake-cell IMSI harvest closed. Recovering user-plane = being the network (AT) authorized. + +### AT (no dedicated control — rogue gNB + baseband, **authorized lab**) +- **⚠ LICENSED SPECTRUM — own equipment + test SIMs + RF-shielded + experimental license only.** Rogue/fake gNB (srsRAN Project/OAI) on test NR-ARFCN, own PCI/PLMN/SIB, 5G core behind → UE camps and drives pre-auth NAS/RRC. Identity/registration now harder (SUPI→SUCI closes native 5G IMSI harvest; the practical attack = **downgrade** the UE to LTE/2G with a rogue cell and run an IMSI catcher there). Downgrade/bidding-down, signaling DoS, RRC/NAS fuzzing. +- **Kit**: srsRAN Project (rogue/test gNB), OpenAirInterface (alt rogue + fuzz; base of 5Ghoul), 5Ghoul (pre-auth RRC/NAS vulns + fuzzer vs Qualcomm/MediaTek basebands), Sni5Gect (MAC-NR DL inject without full rogue), 5Greplay (replay/fuzz NGAP/NAS vs own core, not over the air), Open5GS/free5GC (5G core behind test cell). + +### AP +- NAS-5GS / 5G-core signaling (registration, 5G-AKA, identity SUCI/5G-GUTI, PDU-session) over NGAP between gNB and AMF. You only exercise this by being the network (gNB+core + authorized UE): inspect NAS-5GS, SUCI/SUPI and 5G-GUTI, force re-auth/identity, test behavior under a hostile core. +- **Kit**: Open5GS (5GC/NAS-5GS harness), free5GC (alt core), 5Greplay (NAS/NGAP fuzz). + +## Subflow (specialization of the master flow) + +5G NR-specific transitions; verbatim commands live in `Layer-by-layer descent` above. Passive SA sniffing immature vs LTE; SUPI hidden as SUCI. + +| Advance | Advance criterion | Markers | +|---------|--------------------|---------| +| IG → SP | Band/NR-ARFCN (FR1 reachable USRP; FR2 mmWave out of common kit). SA vs NSA. CVEs 5Ghoul class cross-checked | — | +| SP → PHY | FR1 carrier located (SSB within a 100 MHz n78 carrier — you see a slice). Coherent capture requires GPSDO | — | +| PHY → LL | SSB/PCI/MIB/SIB1 decoded. Passive SA decode **less mature than LTE**: stand up own gNB or research-grade sniffer (5GSniffer/Sni5Gect) | — | +| LL → CR | Identifiers broadcast/in cleartext (PCI/PLMN/TAC/SIBs/paging). SUPI now SUCI (ECIES) → native IMSI harvest closed. NEA/NIA keyed by 5G-AKA with no shortcut | — | +| CR → AT | Nothing to break passively. AT = being the network (rogue gNB); the real attack = **downgrade** to LTE/2G and run an IMSI catcher there | — | +| AT | ⚠TX re-check; **licensed spectrum** — own equipment + test SIMs + RF-shielded + experimental license only. Live rogue gNB = RA5/RA8 | ⚠TX | + +**Defensive anomaly** (Defensive mode, RX-only): gNB broadcasting PLMN/PCI/TAC that **do not** correspond to a known operator, or UE reporting forced downgrade to LTE/2G = possible rogue gNB. Log it; **do not** descend to AT. + +## Legal warnings +- Passive broadcast/control RX OK. Capturing third-party user-plane is regulated. +- **Rogue gNB / IMSI catcher / downgrade / jamming = TX on licensed spectrum**: illegal without an experimental license + contained lab. SUPI→SUCI closes native 5G IMSI harvest; the real attack is downgrade to LTE/2G. diff --git a/Skill/references/23-gsm.md b/Skill/references/23-gsm.md new file mode 100644 index 0000000..d57af1f --- /dev/null +++ b/Skill/references/23-gsm.md @@ -0,0 +1,62 @@ +# 23 — GSM / 2G + +> Wayfinder + RFSAM controls for GSM. **Licensed spectrum** — DL RX OK, rogue BTS requires authorized lab. +> Relevant in 2026 as a **downgrade target** from 4G/5G. + +## Facts +- **Bands**: GSM-850 / E-GSM-900 / DCS-1800 / PCS-1900 MHz — depends on region (900/1800 world, 850/1900 Americas). +- **Channels**: 200 kHz carriers indexed by ARFCN; each carrier TDMA-divided into 8 timeslots. DL/UL paired (FDD), spaced 45 MHz (900) / 95 (1800). +- **Modulation**: GMSK (0.3 BT Gaussian-filtered MSK) 270.833 kbit/s; EDGE adds 8-PSK. +- **Logical channels**: BCCH broadcasts cell info · CCCH (PCH/AGCH/RACH) pages and grants · SDCCH signaling (location updates, SMS) · TCH voice. +- **Crypto**: A5/0 none · A5/1 (64-bit stream cipher, **broken by rainbow tables**) · A5/2 (export-weak, deprecated) · A5/3 & A5/4 (KASUMI block, much stronger). Auth **one-way** (network never proves itself) → enables IMSI catchers. +- **Identity**: IMSI (permanent SIM) and TMSI (temporary, network-assigned). IMSI exposed over the air during attach/location update when no valid TMSI exists. + +## Layer-by-layer descent + +### IG (fingerprinting — the network you observe) +- Band region (850/900/1800/1900 — set the ARFCN scan and radios). Cell identity from BCCH: MCC (country), MNC (operator), LAC (location area), Cell-ID — cross-check OpenCellID. Cipher in force (A5/0/1/2/3) from the Cipher Mode Command — determines whether CR is feasible. Exposed identities: paging by IMSI or TMSI; forced IMSI in location update = privacy finding + signature IMSI catcher. Frequency hopping (sequence from BCCH) complicates single-channel capture. 2G fallback context: is the device 2G-only or 4G/5G downgradeable? + +### SP — `RFSAM-GSM-SP-01` ARFCN survey and capture +- **Objective**: find a live cell. 200 kHz carrier, DL BCCH transmits continuously → steady picket in the waterfall. Reliable method: scan FCCH/SCH sync bursts from each BTS → ARFCN, power, ppm clock offset. RTL-SDR covers GSM-900/850 and DCS-1800; PCS-1900 at the top end (HackRF/bladeRF/USRP better). +- **Kit**: kalibrate-rtl (ARFCN/cell scanner), Gqrx (sanity check 200 kHz pickets). + +### PHY (no control — demod+frame together in gr-gsm) +- GMSK burst demod (PHY) and burst-to-frame decode (LL) together in gr-gsm over SDR. GSM packs 8 users into 200 kHz via TDMA → "capturing a channel" = demod the whole carrier + select timeslot/logical channel. + +### LL (part of LL — capture/decode DL) +- Tune the ARFCN that kalibrate found → gr-gsm demod GMSK bursts, decode control channels → forward each frame as GSMTAP over UDP to Wireshark (System Information, paging, assignment, SDCCH signaling). Path: ARFCN scan → grgsm_livemon → GSMTAP → Wireshark. +- **Kit**: gr-gsm (grgsm_livemon), imsi-catcher (Oros42, passive IMSI/TMSI extractor from the GSMTAP stream). +- **Decoder**: Wireshark (GSMTAP). + +### CR — `RFSAM-GSM-CR-01` Cipher and identity exposure +- **Objective**: evaluate the cipher; where A5/1 is broken, recover the session key from the capture. Precomputed rainbow tables (Berlin A5/1 Security Project) recover the 64-bit Kc from a known keystream slice → the rest of the call/SMS is decrypted. **Heavy**: ~1.6–2 TB tables, known-plaintext keystream segment from the capture, the cell must be running A5/1. A5/3 (KASUMI) is not breakable this way. Recovering keys from unauthorized traffic = illegal. +- **Kit**: Kraken (A5/1 key recovery, rainbow tables). +- **Command**: on an A5/1 capture with known keystream → Kraken recovers Kc → decrypts. + +### AT (no dedicated control — rogue BTS, **authorized lab**) +- **⚠ TX on live GSM is illegal except in a licensed lab/cage.** GSM auth is one-way (the cell never proves itself) → a rogue BTS (classic IMSI catcher) impersonates a real cell: stand up your own BCCH with the target's MCC/MNC/LAC at a higher level → handsets reselect+attach → Identity Request harvests IMSI/IMEI, set A5/0 (no cipher) or downgrade A5/1, page/locate/intercept. Osmocom stack (osmo-trx+osmo-bts+osmo-bsc+osmo-msc+osmo-hlr) or OpenBTS all-in-one on a clock-disciplined SDR TX. Lighter/no-TX alternative: passive IMSI catch in LL (Oros42 reading IMSIs from the broadcast). +- **Kit**: osmo-bts (Osmocom stack rogue BTS/active IMSI catcher), OpenBTS (all-in-one rogue). +- **Decoder**: Wireshark (L3/SMS inspection). + +### AP +- Above the link, the GSM "app layer" = signaling + bearer services (not IP). With SDCCH/TCH decoded (and decrypted if A5/1 is broken): payloads = L3 mobility/call-control + SMS (incl. silent/Class-0 pings to locate the handset). No dedicated tool — read GSM L3/SMS in Wireshark from the GSMTAP. +- **Kit**: Wireshark (L3/SMS from the GSMTAP capture). + +## Subflow (specialization of the master flow) + +GSM-specific transitions; verbatim commands live in `Layer-by-layer descent` above. Relevant in 2026 as a downgrade target from 4G/5G. + +| Advance | Advance criterion | Markers | +|---------|--------------------|---------| +| IG → SP | Band region (850/900/1800/1900). Cell identity from BCCH (MCC/MNC/LAC/Cell-ID). Cipher in force (A5/0/1/2/3) from the Cipher Mode Command | — | +| SP → PHY | 200 kHz DL BCCH carrier (steady picket). FCCH/SCH sync bursts via kalibrate-rtl. RTL-SDR covers 900/850 and DCS-1800; PCS-1900 better on HackRF/bladeRF | — | +| PHY → LL | GMSK demod (PHY) and burst-to-frame decode (LL) together in gr-gsm → GSMTAP over UDP to Wireshark | — | +| LL → CR | BCCH/control decoded (System Info, paging, SDCCH signaling). A5/1 **broken by rainbow tables** (~2 TB); A5/3 (KASUMI) not | — | +| CR → AT | A5/1 keys recovered (if keystream known + tables) or gap (A5/3 strong). GSM auth one-way → rogue BTS feasible | — | +| AT | ⚠TX re-check; **licensed spectrum** — never TX live GSM except in lab + cage + license. No-TX alternative: passive IMSI catch in LL (Oros42) | ⚠TX | + +**Defensive anomaly** (Defensive mode, RX-only): BTS broadcasting MCC/MNC/LAC that **do not** correspond to a known operator, or handsets suddenly falling to A5/0/A5/1 = possible rogue BTS / forced downgrade. Log it; **do not** descend to AT. + +## Legal warnings +- Passive DL BCCH/control RX OK (public). Capturing third-party user-plane/SMS/voice = illegal interception. +- **Rogue BTS / IMSI catcher / downgrade to A5/0 = TX on licensed spectrum**: illegal without an experimental license + cage. Roaming on a live operator network = crime. Relevant in 2026 as a downgrade target from 4G/5G — that is where modern IMSI catchers operate. diff --git a/Skill/references/24-uwb.md b/Skill/references/24-uwb.md new file mode 100644 index 0000000..70472c3 --- /dev/null +++ b/Skill/references/24-uwb.md @@ -0,0 +1,57 @@ +# 24 — Ultra-Wideband (UWB) + +> Wayfinder + RFSAM controls for UWB (802.15.4z). Secure ranging/distance; **there is no key to break**. +> Attack = physical distance manipulation (Ghost Peak) — academic, specialist, no push-button tool. + +## Facts +- **Band**: impulse-radio UWB ~3.1–10.6 GHz, >500 MHz channel bandwidth per pulse. In practice two channels dominate: ch5 6.5 GHz, ch9 8.0 GHz. +- **Standard**: IEEE 802.15.4z, two incompatible PHYs — HRP (High Rate Pulse-repetition ~64/249.6 MHz PRF — the one in phones/cars) and LRP (Low Rate, NXP/3db). Plus legacy 802.15.4-2011/4a (DW1000 old gen, no STS). +- **Modulation**: impulse radio — sub-nanosecond RF pulses, no continuous carrier. Bit rates 850 kbps / 6.81 Mbps. **Time-of-flight** of pulses (not signal strength) = distance → that is why it is hard to spoof and so precise (~10 cm). +- **Purpose**: secure ranging / distance bounding and positioning, NOT bulk data. Two-Way Ranging (TWR), TDoA, PDoA/AoA. Uses: Apple U1/U2 (AirTag, iPhone Nearby Interaction), CCC Digital Key car access, Samsung SmartTag+, FiRa RTLS. +- **Security**: 802.15.4z adds **STS (Scrambled Timestamp Sequence)** — a pseudo-random sequence of AES-keyed pulses that the receiver correlates to authenticate the ranging timestamp → an attacker cannot forge/replay a legitimate ranging pulse. Research surface = **physical distance manipulation** (early-detect/preamble-injection on the impulse waveform), NOT cracking AES. +- **Schemes**: same radio, app protocols on top — Apple Nearby Interaction (U1/U2), CCC Digital Key, FiRa (consortium RTLS/ranging cross-vendor). + +## Layer-by-layer descent + +### IG (fingerprinting — many forks) +- Silicon: Qorvo/Decawave DW1000 = OLD gen (legacy 802.15.4-2011, no STS); DW3000 (DW3110/DW3210) = modern 802.15.4z with STS. NXP Trimension (SR040/SR150), Apple U1/U2 = other families. PHY HRP (phones/AirTags/keys) vs LRP. Channel: almost always ch5 (6.5 GHz) or ch9 (8.0 GHz). App scheme: Apple Nearby Interaction, CCC Digital Key, FiRa. UWB is rarely standalone — Apple/CCC bootstrap over BLE (and CCC also NFC) for session keys/STS. CVEs: Ghost Peak (Apple U1 + NXP/Qorvo), relay/distance-reduction/preamble-injection academic. + +### SP (no control — **you cannot "see" UWB in a normal waterfall**) +- Impulse-radio UWB: sub-nanosecond pulses spread >500 MHz, intermittent, very low power spectral density → by design a faint rise in the noise floor, not a peak. Two things rule out common SDRs: **frequency** (ch5 6.5 GHz, ch9 8.0 GHz — **above the 6 GHz top end** of HackRF/bladeRF/B210/SignalSDR; RTL-SDR 1.766 GHz not even close) and **bandwidth** (>500 MHz channel, these radios offer ~20–122 MHz). The only nearby SDR: USRP X410 (7.2 GHz, 400 MHz BW — reaches ch5, still short of the >500 MHz channel, $10k+, research-grade impulse demod in software). In practice: you confirm/capture UWB with a real transceiver that already knows the channel (DW3000 dev boards in LL), or just to confirm energy, a >500 MHz real-time spectrum analyzer/scope. + +### PHY (no control — despreading on the DW3000 transceiver) +- No commodity SDR demodulates impulse-radio UWB. A DW3000-class transceiver despreads pulses against the known channel/preamble (and STS if secure ranging) and frames the 802.15.4z packet in hardware. PHY+framing together on the real chip. **You must know the PHY params** (channel, preamble code, PRF, data rate, STS mode/length) to lock — these come from IG, not from scanning. + +### PHY — `RFSAM-UWB-PHY-01` Ranging signal capture (PHY layer in RFSAM) +- **Objective**: capture 802.15.4z frames with a real UWB transceiver (nothing else can). Open path: SEEMOO uwb-sniffer — firmware for the Qorvo DWM3000EVB driven by a host MCU (NUCLEO-F429ZI ref build) → pull 802.15.4z frames off the air → Wireshark via the sensniff pipe with picosecond timestamps. **Catch**: you must configure the radio with the link's PHY params (channel, preamble, data rate, STS mode/length) — UWB does not blind-scan. Off-the-shelf alternative: Forthink sniffer software + Wireshark plugin (depends on a closed commercial dongle — flagged). Another: a controllable DW3000 peer (Makerfabs board, foldedtoad driver) to generate/log known ranging exchanges. **None defeats STS** — it captures frames you can already decode. +- **Kit**: seemoo-uwb-sniffer (DWM3000EVB + NUCLEO-F429ZI/nRF52840), forthink-uwb-sniffer (commercial dongle), dwm3000-dwt-driver (controllable peer). +- **Decoder**: Wireshark (sensniff). + +### CR (no control — **there is no key to break, that is the point of .4z**) +- STS = a pseudo-random AES-keyed sequence that both ranging peers share → the receiver correlates incoming impulses against the expected STS → only the STS-authenticated arrival time is trusted as distance. An attacker without the STS key cannot forge/replay a legitimate ranging pulse → no offline key recovery like BLE/Wi-Fi. The STS key is exchanged over a separate bootstrap channel (BLE for Apple/CCC, NFC for some CCC) — any crypto weakness lives in **that** handshake (see BLE/RFID wayfinder), not in UWB pulses. The genuine UWB research surface = **physics**: can the time-of-flight be manipulated at the physical layer (early detection, preamble/pulse injection) without the key? That is AT. **There is no open key-crack tool because there is no key-crack attack.** + +### AT — `RFSAM-UWB-AT-01` Distance-manipulation resilience +- **⚠ AUTHORIZED + academic specialist.** The real UWB attack = physical distance manipulation, NOT takeover. Distance from time-of-flight → research attacks attempt to make the receiver register arrival **earlier** than actual (shortens measured distance) **without the STS key**: 'early-detect/late-commit' and preamble-injection on HRP 802.15.4z; relay that shuffles ranging between a distant car and key. **Public landmark: Ghost Peak** (Leu, Camurati, Heinrich et al., USENIX Security 2022) — practical distance-reduction on HRP UWB vs Apple U1 interop NXP/Qorvo, reduces 12 m to 0 m with ~4% success per attempt, off-the-shelf device ~$65 (DWM3000EVB + nRF52DK), **WITHOUT crypto material**. **Honesty note on tooling**: there is NO open push-button tool. Published work uses custom DW3000 firmware + bespoke setups not packaged as a product; reproducing = engineering against a DW3000 board, not downloading an exploit. Cite the research, provide controllable peer hardware — **do not deliver a weapon that does not openly exist**. +- **Kit**: dwm3000-dwt-driver (controllable UWB peer for research). No turnkey tool. +- **Caveat**: development peer, NOT a packaged distance-reduction exploit. Ref: Ghost Peak securepositioning.ch/ghost-peak (arXiv 2111.05313, USENIX Security 2022). + +### AP +- The UWB "app" = the ranging/positioning decision and what trusts it — that is where impact lands even if the link is hard to break. UWB measurement feeds a security gate: CCC Digital Key car unlock/start only if phone/key ranged within a few tens of cm; Apple Nearby Interaction precise direction/distance; RTLS access/safety decisions. Assessment question: do consumers enforce SECURE-RANGING assumptions? Do they require STS-authenticated measurement (not legacy/non-secure)? Do they bound distance tightly? Do they reject implausible jumps? Do they fail safe if ranging is lost/manipulated? Evaluated in the victim system's logic (and the BLE/NFC bootstrap that keys the session) — UWB ranging does not expose its own interactive protocol surface. + +## Subflow (specialization of the master flow) + +UWB-specific transitions; verbatim commands live in `Layer-by-layer descent` above. Secure ranging by design — **there is no key to break**, the attack is physical. + +| Advance | Advance criterion | Markers | +|---------|--------------------|---------| +| IG → SP | Silicon (DW1000 legacy no STS vs DW3000 modern 802.15.4z), channel (ch5 6.5 / ch9 8.0 GHz), app scheme (Apple/CCC/FiRa). CVEs Ghost Peak | — | +| SP → PHY+LL | **No commodity SDR sees UWB** (ch5/ch9 above the 6 GHz top end; >500 MHz channel). Capture requires a DW3000-class transceiver that knows the channel | — | +| PHY+LL → CR | 802.15.4z frames with a real transceiver (SEEMOO uwb-sniffer). STS AES-keyed → no offline key-recovery | — | +| CR → AT | No key-crack attack (there is none). Research surface = physical distance manipulation (early-detect, preamble-injection) **without the STS key** | — | +| AT | ⚠TX re-check; **physical** attack, academic specialist, no push-button tool. Ghost Peak: 12 m→0 m ~4% per attempt. Authorized testing on own setup only | ⚠TX | + +**Defensive anomaly** (Defensive mode, RX-only): UWB is a specialty near-field/positioning technology — few "anomalous" signals to listen for passively with common kit (without a controllable DW3000 you capture nothing). If you are defending a ranging-dependent asset, monitor the victim system (does it reject implausible jumps? does it require STS-authenticated?). Log it; **do not** descend to AT. + +## Legal warnings +- RX/sniffing UWB with your own transceiver OK. +- Ghost-Peak-style distance manipulation = **physical attack on ranging**; authorized testing on own setup only (your car/key). Relay against someone else's car/key = theft (car key relay attack = real crime, growing vector). diff --git a/Skill/references/25-troubleshooting.md b/Skill/references/25-troubleshooting.md new file mode 100644 index 0000000..e3472e5 --- /dev/null +++ b/Skill/references/25-troubleshooting.md @@ -0,0 +1,195 @@ +# 25 — Troubleshooting RF + +> Diagnosis when a descent phase is not progressing. Use it **before** declaring a gap (Route A) or escalating +> (CONSULT): most "it doesn't work" cases are environment (permissions/drivers/antenna), not lack of signal or +> crypto strength. Source: §1 (setup), §2 (diagnosis), §3 (order of diagnosis), §4 (false positives). + +## Index +1. §setup — 5 environment checks (Phase 0, cache result in `loot/notes/hardware.txt`) +2. §diagnosis — symptom → probable cause → action table +3. §order — diagnosis rule (antenna before driver before binary) +4. §false-positives — finding that looks confirmed but is not + +--- + +## 1. §setup — 5 environment checks (Phase 0) + +One command per check, no external dependencies. The result is cached in `loot/notes/hardware.txt` +(re-read at each axis 4 of the decision tree, not re-run per command except TX). + +### 1.1 Host software + +```sh +for t in gqrx wireshark hackrf_transfer rtl_sdr dump1090 readsb dump978 \ + rtl_433 kalibrate-rtl gr-gsm gnss-sdr rtl_biast ubertooth-util \ + crackle sniffle catnip whad bettercap killerbee whsniff kismet \ + aircrack-ng hcxdumptool hcxpcapngtool hashcat pm3 libnfc mfoc \ + mfcuk rfcat universal-radio-hacker chirpcat qcsuper srsran open5gs \ + gpsd ubxtool; do + command -v "$t" >/dev/null 2>&1 && echo "OK $t" || echo "MISS $t" +done +``` + +`MISS` → do not abort; consult the protocol wayfinder for an RX substitute. If none exists, declare a gap (Route A). + +### 1.2 Connected hardware (USB bus) + +```sh +lsusb +ls /dev/ttyACM* /dev/ttyUSB* 2>/dev/null +ls /sys/class/net +``` + +Map vendor:product to slug using `references/02-kit-sdr.md` (field `spec`). Key markers: + +| Hardware | vendor:product | Notes | +|----------|----------------|-------| +| HackRF One | `1d50:6089` | | +| bladeRF 2.0 | `1d50:6130` | | +| USRP B210 | `2500:0020` | | +| RTL-SDR V4 | `0bda:2838` | `rtl_test -t` validates sample rate | +| CatSniffer (EC) | `1207:8000` | `/dev/ttyACM0` after firmware | +| nRF52840 dongle | `1915:xxxx` | Nordic | +| Proxmark3 (Iceman) | `2d2d:504d` | | +| ACR122U | `072f:2200` | | +| Chameleon Ultra | `1915:c00a` | | +| Ubertooth One | `1d50:6000` (enum) / `1d50:6001` (op) | | +| Yard Stick One / CC1111 | `1d50:605b` | `/dev/ttyACM*` | +| ESP32-family | `303a:xxxx` (S3) / `10c4:ea60` (CP210x) | | +| Flipper Zero | `0483:df11` (DFU) / `0483:5740` (CDC) | | +| GPS u-blox NEO | — | `$GPGGA`/`$GNGGA` frames readable on `/dev/ttyACM*` | + +### 1.3 Permissions and drivers + +```sh +# 1. Hardware access groups +groups | grep -Eo 'dialout|plugdev|uucp|tty|video' | sort -u + +# 2. udev rules loaded +ls /etc/udev/rules.d/ | grep -Ei 'hackrf|rtl-sdr|rtlsdr|proxmark|ubertooth|cat|nordic|cp210|cdc-acm' + +# 3. Drivers/modules loaded +lsmod | grep -Ei 'rtl2832|hackrf|bladerf|usbserial|cp210|cdc_acm|option|ftdi' + +# 4. RF blocks (kill switches — critical on WiFi/BT) +rfkill list +``` + +- **Missing group** (`dialout`/`plugdev`) → binary opens but device returns `Permission denied`. Action: `usermod -aG` + relogin. +- **Missing udev rule** → device shows up as `root:root`. Action: verify package or copy the rule from the manufacturer's repo. +- **Missing driver** (`lsmod` empty) → `dmesg | tail -50` shows connection without bind. Action: USB reinsertion or `modprobe `. +- **`rfkill` blocks** → `sudo rfkill unblock all` or physical switch. Some marauder firmwares do not survive a soft-block. + +### 1.4 Antenna and bias-T (RF-critical) + +Connected hardware ≠ captured signal. The agent cannot physically verify the antenna — **ask the operator**. + +| Signal | Requirement | Symptom if missing | +|--------|-------------|---------------------| +| GNSS L1 | `rtl_biast -b 1` (bias-T ~5 V to active antenna) | `gqrx` shows flat noise at -90 dBm even with antenna connected | +| ADS-B 1090 | Quarter-wave antenna (~6.9 cm) + filter + LNA | `dump1090` reports 0 messages/min | +| sub-GHz / GSM-850/900 | Telescopic or tuned dipole antenna | `gqrx` shows pure thermal noise | +| 2.4 GHz ISM | 2.4 GHz dipole antenna | SDR without antenna picks up BT/Wi-Fi by coupling, but 5–10 dB below | +| UWB (6.5/8 GHz) | No radio in the kit reaches it | Declare visibility gap, no check applicable | + +### 1.5 Disk space and network + +```sh +df -h "$LOOT_DIR" # Typical IQ: 2-8 MB/s; BLE PCAP: 200 KB/s +ip -br link show # avoid capturing host traffic +ip route show default # if the audit is offline, confirm isolation +``` + +- **Space < 5 GB free** → long capture aborts. Clean up or compress (`rtl_sdr -s 2400000 - | gzip > file.iq.gz`). +- **WiFi monitor on wrong interface** → `tshark -i ` confirms target BSSID; if capturing in managed mode, the PCAP is useless. + +--- + +## 2. §diagnosis — symptom → probable cause → action table + +### 2.1 Hardware not detected / permissions + +| Symptom | Probable cause | Action | +|---------|----------------|--------| +| `lsusb` does not list the SDR | USB cable / port / insufficient power (HackRF+amp) | Another USB 3.0 port; external power if amp present; `dmesg -w` on connect | +| SDR in `lsusb` but binary returns `Permission denied` | Missing `dialout`/`plugdev` group or udev rule | §1.3; `usermod -aG dialout,plugdev $USER` + relogin; reinstall package to copy udev rule | +| `/dev/ttyACM0` does not appear (CatSniffer/PM3/nRF) | Firmware not loaded, data-only cable, CDC-ACM driver | `dmesg \| grep tty`; restart device in bootloader mode; `modprobe cdc_acm` | +| `rtl_test` fails with "No supported devices found" | RTL2832 driver not loaded or device claimed by another process | `lsmod \| grep rtl2832`; kill process holding the device (old SDR#, another `rtl_*`) | +| `rfkill list` shows "Soft blocked: yes" on WiFi/BT | OS or hardware kill switch | `sudo rfkill unblock all`; check laptop physical switch | +| Proxmark3 `pm3` client not detected | Iceman firmware not flashed, wrong port | `ls /dev/ttyACM*`; flash Iceman firmware; `pm3 -p /dev/ttyACM0` explicitly | +| Ubertooth does not enumerate | DFU mode or corrupt firmware | `ubertooth-util -v` for version; reflash with `ubertooth-programmer` | + +### 2.2 Signal not visible / defective capture + +> **Diagnosis rule (§3)**: on "I can't see the signal", check in THIS order — antenna (§1.4) → gain/overflow (here) → driver (§1.3) → binary (§1.1) → band gap. Antenna and gain explain 80% of cases. + +| Symptom | Probable cause | Action | +|---------|----------------|--------| +| `gqrx` shows flat noise with hardware OK | Antenna absent/incorrect, bias-T off (GNSS), mistuned dipole | §1.4 first; `rtl_biast -b 1` for GNSS; ask operator about connected antenna | +| Waterfall flat at 0 dBFS (clipping) | Excessive gain saturates the ADC | Lower gain: RTL-SDR `-g 40–49`; HackRF `-a 1 -l -g ` adjusted | +| Signal buried in noise floor | Insufficient gain | Raise gain gradually; check external LNA (ADS-B 1090) | +| Partial capture of 80/160 MHz Wi-Fi channel | SDR IBW does not cover it | HackRF ~20 MHz cannot see full channel → bladeRF/USRP or declare limitation | +| `hackrf_transfer`/`rtl_test` reports drops/overflows | Sample rate exceeds USB/host I/O | Lower sample rate; close other processes; SSD vs HDD; direct USB 3.0 (no hub) | +| OFDM grid recovery fails (LTE/5G NR) | No GPSDO lock | `uhd_usrp_probe ... clock_source=gpsdo`; obtain a GPSDO or declare gap | +| `dump1090` reports 0 messages/min | 1090 antenna without LNA/filter or bad orientation | §1.4 ADS-B; vertical quarter-wave antenna + LNA + 1090 filter | +| Sniffle does not follow established BLE connection | Access Address not set correctly | Set AA **after** CENTRAL (flush); advertisements during INITIATING reset to the advertising AA and break data PDU decoding | +| Ubertooth captures BT Classic garbage | Hop not followed, unknown LAP | BR/EDR hop at 1600 h/s — only `esp32_bluetooth_classic_sniffer` or Ubertooth follow by known LAP | +| RFID: reader does not read tag | Active mode in observational, tag absent from field | In observational/defensive use `hf 14a sniff` (passive, does not power); `hf mf autopwn` is active | + +### 2.3 Analysis does not decode (offline CR) + +| Symptom | Probable cause | Action | +|---------|----------------|--------| +| Wireshark shows massive "Malformed packet" | Wrong decoder or corrupt capture | Confirm correct dissector: BTBR/BLE/802.15.4/LoRaTap/GSMTAP. Old Wireshark version → update | +| `crackle` fails: "no STK found" | Pairing is not in the PCAP | The pairing event was missed in the capture — re-capture SP/PHY+LL during bonding; it is not crypto strength | +| `hashcat -m 22000` does not load | PCAP without complete PMKID/EAPOL | Re-capture; clientless PMKID chain `hcxdumptool` → `hcxpcapngtool` requires client interaction | +| `kraken` A5/1 does not find the key | Insufficient keystream or BB-.tables not indexed | Capture more traffic; verify BB tables `index` (~2 TB); do not dismiss crypto strength | +| `hf mf autopwn` does not recover keys | Tag distance/angle, unknown key | Try `hf mf list` + `mfkey32/64` from reader sniff; distance 1-3 cm; MIFARE Plus tag evades Classic | +| Analysis on PCAP with overflows ≠ 0 | Base capture silently incomplete | Re-capture (safe-capture §4); overflows cause garbage to be decoded and presented as a finding | +| Conclusion without cited artifact | Floating opinion, not evidence | Every conclusion cites `loot/captures/...` + command; artifact→finding mapping mandatory | + +--- + +## 3. §order — diagnosis rule + +On "I can't see / it doesn't work", do NOT declare a gap immediately. Follow this order: + +1. **Antenna** (§1.4) — is it connected and correct for the band? `gqrx` with flat noise + hardware OK = antenna first. +2. **Gain/overflow** (§2.2) — is it saturating or buried? Adjust before declaring "no signal". +3. **Driver/permissions** (§1.3) — does the device open? `Permission denied` ≠ broken hardware. +4. **Binary/decoder** (§1.1, §2.3) — are the right tool and decoder present? `which`, Wireshark version. +5. **Band** — does the radio reach the frequency? RTL-SDR cannot see 2.4 GHz; UWB 6.5/8 GHz is not covered by any radio in the kit. +6. **Only then** → declare a visibility gap in `loot/notes/gaps.md` (Route A) or escalate (CONSULT). + +> Antenna and gain explain ~80% of "I can't see the signal". A gap declaration without having checked antenna+gain +> is a false negative. + +--- + +## 4. §false-positives — finding that looks confirmed but is not + +Before registering, discard the typical false positive of the pattern (see §4 below, "Typical false positive" +column per family). Cross-cutting cases: + +| Symptom (looks like a finding) | Typical false positive | Verification | +|---------------------------------|------------------------|--------------| +| Crack failed → "strong crypto" | The pairing/join/handshake event **was not** in the capture (capture gap, not strength) | Re-capture; confirm the event is present in the PCAP before attributing to strength | +| Decoding produces garbage | Base capture with overflows ≠ 0 (silently incomplete) | Check overflow counters in the wrapper; re-capture if > 0 | +| "Unknown signal" in survey | Local interference (your own router, microwave, host Bluetooth) | Turn off host BT/Wi-Fi; correlate with time; move antenna | +| "Discovered" cleartext traffic | Wrong decoder shows readable bytes by coincidence | Confirm dissector; validate against protocol length/checksum | +| GNSS C/N0 anomaly | Urban multipath or legitimate jamming (military radar) | Correlate with time/location; do not report spoof without observed forge | +| "BLE from unknown device" | The operator's own device/environment | Correlate against inventory before labeling as stalking | + +> **"Not observed" under a finite window is a visibility gap, not evidence of absence.** But "observed" can also +> be a false positive if the base capture is corrupt or the decoder does not match. Verify both extremes before +> registering. + +--- + +## 5. Mapping to downstream phases + +- **SKILL.md Phase 0** cites §setup as the body of the environment check. +- **SKILL.md Route B** cites §diagnosis as the step before escalating. +- **Wayfinders** (`references/NN-proto.md`) may cite "see troubleshooting §2.2" for the specific family. +- **Phase 7.1 (validation):** every "it doesn't work" documented in `loot/notes/` must reference §order — without + that order traversed, the gap is weak. diff --git a/Skill/references/26-quality.md b/Skill/references/26-quality.md new file mode 100644 index 0000000..2ff7e49 --- /dev/null +++ b/Skill/references/26-quality.md @@ -0,0 +1,130 @@ +# 26 — Quality: verify before reporting + +> Cross-cutting quality gate. Applies at any layer of the descent, **before registering** a finding AND +> **before closing** the report. A claim that does not pass these rules is a **hypothesis**, not a confirmed +> finding. Source: §1 (rules Q1–Q8), §2 (criticality), §5 (internal consistency / `scripts/register_finding.py`). + +## Index + +1. §rules — 8 mandatory verification rules (Q1–Q8) +2. §criticality — honest severity rubric +3. §lifecycle — draft vs verified (verification is a separate pass) +4. §pre-registration — checklist before writing to the JSONL +5. §cross-refs — internal consistency (coverage_check.py model) + +--- + +## 1. §rules — 8 mandatory verification rules + +Before registering a finding or including it in the report, each rule must pass. If one fails → do not register +yet (obtain evidence, cite a source, degrade severity, or declare a gap). SKILL.md §QUALITY contains the quick +version; this table is the authoritative source. + +| # | Rule | What to verify | If it fails | +|---|------|----------------|-------------| +| **Q1** | **Cite or flag** | Each non-trivial claim maps to a resolvable source (CVE on NVD, real paper/URL, tool catalog slug) or carries an inline `> [!FLAG] …` | Do not register until cited or explicitly flagged | +| **Q2** | **Verbatim commands** | Wayfinder command strings are copied exactly (flags, parameters, war-story values). Do not paraphrase, "complete," or invent | Replace with the wayfinder verbatim; if none exists, flag | +| **Q3** | **Honest criticality** | Observational/feasibility = `info`/`low`; takeover / key recovery / impersonation = `high`/`critical`. Severity reflects what is **achieved** in this mode, not the theoretical | Degrade severity to the level the evidence supports | +| **Q4** | **BSAM deference** | BLE/BTC at LL+ → cite BSAM (cross-ref `BSAM-xx`), describe **only** the RF capture prerequisite. Do not re-derive BSAM content | Rewrite as deference; remove duplicated BSAM content | +| **Q5** | **Authorized framing** | Every TX / replay / decrypt / rogue step carries a note of own equipment, test SIM/device, containment, explicit permission | Add the framing or degrade to hypothesis (do not execute TX without it) | +| **Q6** | **Sufficient evidence** | Command + parameters + tool+version + reproducible capture conditions (`repro.txt`). See sufficiency table by severity in SKILL.md §REPRODUCIBLE EVIDENCE | Degrade severity and mark `evidence_status: partial`; without `repro.txt` = hypothesis | +| **Q7** | **No dedicated control → layer note** | If there is no mappable `RFSAM---NN` control, **do not omit** the finding: register with `control: null` and `notes` indicating the approximate layer | Add a layer note; do not omit | +| **Q8** | **Cross-refs resolve** | Every `control` ID, `RFSAM-RES-NN`, tool slug, and reference path cited in the report exists in the skill. Model: `coverage_check.py` (id↔protocol↔layer, every ref resolves, valid enums) — see §cross-refs | Fix the ref or mark as unverified | + +> **Q1–Q8 are mandatory** for `critical`/`high`. `medium` may register with partial Q6 +> (`evidence_status: partial`). `low`/`info` may close with minimal Q1+Q2+Q6. **Exception — Defensive mode** +> (Scope D): never reports `critical`; its ceiling is `medium` (type `detection`). + +--- + +## 2. §criticality — honest severity rubric + +Source: `§2` of this file. Severity is set by the 4-axis model of SKILL.md §FINDING SEVERITY AND +CLASSIFICATION; this rubric is the sanity check that the assigned severity is honest with the evidence: + +| Level | Honest definition | Common abuse to avoid | +|-------|-------------------|-----------------------| +| **info** | Observational; no direct impact (capture feasibility, identifier exposure) | Reporting a successful capture as if it were a vulnerability | +| **low** | Minor exposure or hardening gap without practical exploit | "Old firmware" without a confirmed CVE as `high` | +| **medium** | Weakness requiring specific conditions; hypothesis with a ceiling (Scope C); defensive detection (D) | Hypothesis without PoC as `high`; detections as `critical` | +| **high** | Exploitable weakness with significant impact; cleartext data; critical infrastructure **in a cage** (B) | Contained (cage) assets as `critical` without the `contained` label | +| **critical** | Full compromise (takeover, key recovery, impersonation) with practical preconditions **AND** a field PoC (A) | Without PoC (C) as `critical`; contained (B) as `critical` without `contained` | + +**Golden rules:** + +- Without PoC (Scope C) → maximum `medium`. +- Contained / cage (B) → `critical` drops to `high` with the `contained` label. +- Defensive (D) → ceiling `medium`, type `detection`, no `critical`. +- The **Impact** axis sets the ceiling; Exploitability / Exposure / Scope **only modulate downward**, never upward. +- "Not observed" under a finite window is a **visibility gap**, not evidence of absence — but "observed" can also + be a **false positive** if the base capture is corrupt (overflows ≠ 0) or the decoder does not match + (see `references/25-troubleshooting.md` §false-positives). Verify both extremes before setting severity. + +--- + +## 3. §lifecycle — draft vs verified + +Principle from `§3` of this file, adapted to the auditing agent: + +- **During the descent**, the agent produces findings in **draft** state: researched, with evidence, may carry + `[!FLAG]`s where uncertainty remains. This is legitimate and is registered in the JSONL. +- **Before the report**, a verification pass (the same agent in Phase 7 / Close, or a separate reviewer) + must **resolve every flag** and **confirm every citation**. A finding with unresolved flags enters the report as + a **hypothesis / observation**, not as confirmed. +- **`confidence`** (`low` / `medium` / `high`) is the honest self-assessment of the finding. Do not inflate it: if + the evidence is indirect or the tool is inconclusive, `low` / `medium` is correct. + +> A sub-agent (or a quick pass of the descent) produces `draft`. Verification is a **separate** pass that +> elevates to `verified`. Do not report as `verified` what you only glanced over. + +--- + +## 4. §pre-registration — checklist before writing to the JSONL + +Before running `scripts/register_finding.py` (or writing by hand to `rfsam_findings.jsonl`): + +``` +□ Exact capture/command output as evidence (Q2, Q6) +□ Severity reflects what was ACHIEVED in this mode, not the theoretical (Q3) +□ Reproducible command (target, flags, parameters) → poc/RF-NNN/repro.txt (Q6) +□ Source cited (CVE/paper/tool) or uncertainty flagged ([!FLAG]) (Q1) +□ Control RFSAM---NN mapped, or layer note if no dedicated control (Q7) +□ If TX: authorized framing present (own equipment, containment, permission) (Q5) +□ If BLE/BTC LL+: BSAM deference applied, not re-derived (Q4) +``` + +If any item is NO → **do not register yet**; obtain evidence, cite, degrade severity, or declare a gap. The +**pre-close** checklist (per session) lives in SKILL.md §AUDIT CLOSURE — it is not duplicated here. + +--- + +## 5. §cross-refs — internal consistency (coverage_check.py model) + +Model applied to the report the skill generates (see `scripts/register_finding.py` for the validated enums +and the control regex). Before delivering, verify: + +- **ID ↔ protocol ↔ layer**: every cited `RFSAM---NN` has consistent segments + (PROTOCOL ∈ the 15 canonical: BLE/WIFI/LORA/LTE/RFID/SUBG/ZIGBEE/ZWAVE/THREAD/GNSS/ADSB/NR5G/GSM/UWB/BTC; + LAYER ∈ IG/SP/PHY/LL/CR/AT/AP). +- **Every reference resolves**: every `control`, `RFSAM-RES-NN`, tool slug, and reference path cited in the + report exists in the skill (in `references/`, `assets/`, or the wayfinder tool catalog). +- **Valid enums**: severity ∈ critical/high/medium/low/info; `scope_reach` ∈ A/B/C/D; `mode` ∈ + observational/active/lab/defensive. +- **No empty fields on critical findings**: a `critical`/`high` without `repro.txt`, without a mapped control (or + layer note), or without mitigation across the 3 layers (Developer/Integrator/Operator) is an **incomplete** + finding, not confirmed. + +> If a cross-ref does not resolve, **do not invent it**: mark the finding as `confidence: low` with +> `[!FLAG] unresolved ref`, or remove it. An invented URL violates Q1 (cite or flag). + +--- + +## 6. Mapping to downstream phases + +- **SKILL.md §QUALITY** cites §rules as the quick gate (the 10 inline rules are the compact version; Q1–Q8 is the + authoritative source). +- **SKILL.md §FINDING SEVERITY "Before registering"** delegates to §pre-registration (does not duplicate the checklist). +- **SKILL.md §AUDIT CLOSURE** maintains its own per-session checklist (pre-close); §cross-refs expands what + "verify cross-refs" means in practice. +- **Phase 7.1 (validation):** the validation checklist confirms that every finding in the JSONL passed Q1–Q8 and + that the report's cross-refs resolve. diff --git a/Skill/scripts/coverage_check.py b/Skill/scripts/coverage_check.py new file mode 100644 index 0000000..2587540 --- /dev/null +++ b/Skill/scripts/coverage_check.py @@ -0,0 +1,183 @@ +#!/usr/bin/env python3 +"""coverage_check.py — Compares registered findings against the RFSAM coverage-map. + +Reads `loot/rfsam_findings.jsonl`, groups the covered controls +`RFSAM---NN` and compares them with the canonical coverage-map +(all controls that RFSAM defines per protocol). Reports covered, pending and +orphan controls (controls cited in findings that do not exist in the +coverage-map — likely a typo). + +Usage: + coverage_check.py # all protocols + coverage_check.py --protocol BLE # BLE only + coverage_check.py --loot loot # alternative loot directory +""" +import argparse +import json +import os +import sys + +# ── Canonical RFSAM coverage-map ── +# ⚠ SINGLE SOURCE: `src/data/coverage-map.js`. This table and +# `references/00-taxonomy.md §6` must be kept in sync with that file. If you +# add or change a control, update all three locations (or better, derive this +# table from the JS in the future). +# Each control: id, title, layer, status (existing/planned). +COVERAGE = { + "BLE": [ + ("RFSAM-BLE-IG-01", "Known vulnerabilities of the SoC and host stack", "IG"), + ("RFSAM-BLE-SP-01", "Channel map and capture feasibility", "SP"), + ("RFSAM-BLE-PHY-01", "Demodulation and bit recovery", "PHY"), + ("RFSAM-BLE-LL-01", "Advertising and identifier exposure", "LL"), + ("RFSAM-BLE-LL-02", "Connection-data capture", "LL"), + ("RFSAM-BLE-CR-01", "Pairing and encryption assessment", "CR"), + ("RFSAM-BLE-AT-01", "Hijack a live BLE connection", "AT"), + ], + "BTC": [ + ("RFSAM-BTC-IG-01", "Identify the device, BR/EDR mode and vulnerability corpus", "IG"), + ("RFSAM-BTC-SP-01", "Inquiry-scan and confirm a reachable BR/EDR device", "SP"), + ("RFSAM-BTC-LL-01", "Capture Bluetooth Classic baseband traffic", "LL"), + ("RFSAM-BTC-CR-01", "Assess pairing and encryption key strength", "CR"), + ("RFSAM-BTC-AT-01", "Test baseband/LMP resilience and availability", "AT"), + ("RFSAM-BTC-AP-01", "Enumerate and exercise exposed BR/EDR profiles", "AP"), + ], + "WIFI": [ + ("RFSAM-WIFI-SP-01", "Band and channel survey", "SP"), + ("RFSAM-WIFI-LL-01", "Management-frame exposure", "LL"), + ("RFSAM-WIFI-CR-01", "WPA handshake / PMKID assessment", "CR"), + ], + "LORA": [ + ("RFSAM-LORA-SP-01", "Sub-band occupancy and capture", "SP"), + ("RFSAM-LORA-PHY-01", "Chirp demodulation", "PHY"), + ("RFSAM-LORA-LL-01", "LoRaWAN frame profiling", "LL"), + ("RFSAM-LORA-CR-01", "Join and session-key assessment", "CR"), + ], + "LTE": [ + ("RFSAM-LTE-IG-01", "Baseband and modem vulnerabilities", "IG"), + ("RFSAM-LTE-SP-01", "Cell identification and capture", "SP"), + ("RFSAM-LTE-PHY-01", "Resource-grid recovery", "PHY"), + ("RFSAM-LTE-LL-01", "Control-channel / identity exposure", "LL"), + ], + "RFID": [ + ("RFSAM-RFID-SP-01", "Carrier and standard identification", "SP"), + ("RFSAM-RFID-CR-01", "Crypto1 / key-strength assessment", "CR"), + ("RFSAM-RFID-AT-01", "Clone, emulate and relay", "AT"), + ], + "SUBG": [ + ("RFSAM-SUBG-SP-01", "Burst discovery and characterisation", "SP"), + ("RFSAM-SUBG-PHY-01", "Demodulation and framing", "PHY"), + ("RFSAM-SUBG-LL-01", "Frame and addressing recovery", "LL"), + ("RFSAM-SUBG-CR-01", "Rolling-code assessment", "CR"), + ("RFSAM-SUBG-AT-01", "Replay and forge", "AT"), + ], + "ZIGBEE": [ + ("RFSAM-ZIGBEE-SP-01", "Channel survey and capture feasibility", "SP"), + ("RFSAM-ZIGBEE-LL-01", "PAN, addressing and device discovery", "LL"), + ("RFSAM-ZIGBEE-CR-01", "Network-key provisioning and rotation", "CR"), + ], + "ZWAVE": [ + ("RFSAM-ZWAVE-SP-01", "Region/frequency identification", "SP"), + ("RFSAM-ZWAVE-CR-01", "Key establishment assessment", "CR"), + ], + "THREAD": [ + ("RFSAM-THREAD-LL-01", "Mesh discovery and commissioning exposure", "LL"), + ("RFSAM-THREAD-CR-01", "Network credential assessment", "CR"), + ], + "GNSS": [ + ("RFSAM-GNSS-SP-01", "Signal presence and interference survey", "SP"), + ("RFSAM-GNSS-AT-01", "Spoofing and jamming resilience", "AT"), + ], + "ADSB": [ + ("RFSAM-ADSB-PHY-01", "Message capture and decode", "PHY"), + ("RFSAM-ADSB-LL-01", "Message authenticity assessment", "LL"), + ("RFSAM-ADSB-AT-01", "Forge and inject (contained lab)", "AT"), + ], + "NR5G": [ + ("RFSAM-NR5G-SP-01", "Cell identification and capture", "SP"), + ("RFSAM-NR5G-LL-01", "Broadcast / identity exposure", "LL"), + ], + "GSM": [ + ("RFSAM-GSM-SP-01", "ARFCN survey and capture", "SP"), + ("RFSAM-GSM-CR-01", "Cipher and identity exposure", "CR"), + ], + "UWB": [ + ("RFSAM-UWB-PHY-01", "Ranging signal capture", "PHY"), + ("RFSAM-UWB-AT-01", "Distance-manipulation resilience", "AT"), + ], +} + + +def load_findings(loot_dir: str) -> list[dict]: + path = os.path.join(loot_dir, "rfsam_findings.jsonl") + if not os.path.isfile(path): + return [] + out = [] + with open(path, encoding="utf-8") as fh: + for line in fh: + line = line.strip() + if line: + try: + out.append(json.loads(line)) + except json.JSONDecodeError: + pass + return out + + +def main(argv=None) -> int: + p = argparse.ArgumentParser(description="RFSAM control coverage vs registered findings") + p.add_argument("--protocol", help="Filter to a single protocol (e.g. BLE)") + p.add_argument("--loot", default="loot", help="loot/ directory") + args = p.parse_args(argv) + + findings = load_findings(args.loot) + proto_filter = args.protocol.upper() if args.protocol else None + + # covered controls (with ≥1 finding) per protocol + covered: dict[str, set[str]] = {} + cited: set[str] = set() + for f in findings: + c = f.get("control") + if not c: + continue + cited.add(c) + proto = f.get("protocol", "") + covered.setdefault(proto, set()).add(c) + + protocols = [proto_filter] if proto_filter else list(COVERAGE.keys()) + if proto_filter and proto_filter not in COVERAGE: + sys.stderr.write(f"✖ Unknown protocol: {proto_filter}. Valid: {sorted(COVERAGE)}\n") + return 1 + + total_defined = total_covered = total_pending = 0 + orphans: list[str] = [] + print(f"RFSAM COVERAGE — {len(findings)} finding(s) registered\n") + for proto in protocols: + controls = COVERAGE.get(proto, []) + cov = covered.get(proto, set()) + pending = [(cid, title, layer) for (cid, title, layer) in controls if cid not in cov] + total_defined += len(controls) + total_covered += len(controls) - len(pending) + total_pending += len(pending) + pct = (len(controls) - len(pending)) / len(controls) * 100 if controls else 0 + print(f"== {proto} ({len(controls) - len(pending)}/{len(controls)} · {pct:.0f}%) ==") + for cid, title, layer in controls: + mark = "✓" if cid in cov else "·" + print(f" {mark} {cid:<22} [{layer}] {title}") + print() + + # orphans: cited controls that do not exist in the coverage-map (typos) + all_defined = {cid for controls in COVERAGE.values() for (cid, _, _) in controls} + for c in sorted(cited): + if c not in all_defined: + orphans.append(c) + + print(f"TOTAL: {total_covered}/{total_defined} controls covered · {total_pending} pending") + if orphans: + print(f"\n⚠ Cited controls NOT recognized (typo?): {', '.join(orphans)}") + if not findings: + print("\n(no findings in loot/rfsam_findings.jsonl yet)") + return 0 + + +if __name__ == "__main__": + raise SystemExit(main()) diff --git a/Skill/scripts/register_finding.py b/Skill/scripts/register_finding.py new file mode 100644 index 0000000..8e1b4f1 --- /dev/null +++ b/Skill/scripts/register_finding.py @@ -0,0 +1,237 @@ +#!/usr/bin/env python3 +"""register_finding.py — Registers a validated RFSAM audit finding. + +Adds an entry to the JSONL file `loot/rfsam_findings.jsonl` using the RFSAM +skill's canonical schema. It is deterministic: validates required fields and +enums before writing, so the agent does not produce malformed findings. + +Usage: + register_finding.py --id RF-001 --protocol BLE --layer AT \ + --control RFSAM-BLE-AT-01 --severity high \ + --cvss4 "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N" \ + --title "Hijackable unencrypted BLE connection" \ + --evidence-file loot/poc/RF-001.txt \ + --notes "btlejack on micro:bit; handle 0x000E" + +Output: prints a summary and the JSONL path. Exit 0 on success, 1 if validation fails. +""" +import argparse +import datetime +import json +import os +import re +import sys + +# ── Canonical RFSAM enums (must match src/lib/taxonomy.js) ── +PROTOCOLS = { + "BLE", "BTC", "WIFI", "LORA", "LTE", "RFID", "SUBG", + "ZIGBEE", "ZWAVE", "THREAD", "GNSS", "ADSB", "NR5G", "GSM", "UWB", +} +LAYERS = {"IG", "SP", "PHY", "LL", "CR", "AT", "AP"} +SEVERITIES = {"info", "low", "medium", "high", "critical"} + +ID_RE = re.compile(r"^RFSAM-[A-Z0-9]+-[A-Z]+-\d{2}$") +CVSS4_RE = re.compile(r"^CVSS:4\.0/.+$") +# Strict control regex derived from the canonical enums (DRY: single source of truth). +# Must match `references/00-taxonomy.md §3` and `src/data/coverage-map.js`. +_CONTROL_INNER = f"(?:{'|'.join(sorted(PROTOCOLS))})-(?:{'|'.join(LAYERS)})" +ID_RE_STRICT = re.compile(rf"^RFSAM-{_CONTROL_INNER}-\d{{2}}$") +# RFSAM 4-axis model (references/03-finding-registration.md §7) +AXIS_RANGE = range(1, 5) # impact/exploitability/exposure: 1–4 +SCOPE_REACH = {"A", "B", "C", "D"} # achieved / cage / hypothesis / defensive + + +def _resolve_loot(loot_dir: str) -> str: + """Locates or creates the loot/ directory relative to cwd (or the given --loot).""" + os.makedirs(loot_dir, exist_ok=True) + return os.path.join(loot_dir, "rfsam_findings.jsonl") + + +def validate(args) -> list[str]: + errs = [] + if not re.match(r"^RF-\d{3}$", args.id): + errs.append(f"--id must be in format RF-NNN (e.g. RF-001), received: {args.id!r}") + if args.protocol.upper() not in PROTOCOLS: + errs.append(f"Invalid protocol: {args.protocol!r}. Valid: {sorted(PROTOCOLS)}") + if args.layer.upper() not in LAYERS: + errs.append(f"Invalid layer: {args.layer!r}. Valid: {sorted(LAYERS)}") + if args.severity.lower() not in SEVERITIES: + errs.append(f"Invalid severity: {args.severity!r}. Valid: {sorted(SEVERITIES)}") + if args.control: + if not ID_RE_STRICT.match(args.control): + errs.append(f"--control must be RFSAM---NN (canonical PROTO and LAYER), received: {args.control!r}") + else: + # Cross-field validation: the control's PROTOCOL and LAYER must match + # the finding's --protocol and --layer (taxonomy invariant §3). + parts = args.control.split("-") # ["RFSAM", proto, layer, nn] + ctl_proto, ctl_layer = parts[1], parts[2] + if ctl_proto != args.protocol.upper(): + errs.append(f"--control protocol mismatch: control has {ctl_proto!r} but --protocol is {args.protocol.upper()!r}") + if ctl_layer != args.layer.upper(): + errs.append(f"--control layer mismatch: control has {ctl_layer!r} but --layer is {args.layer.upper()!r}") + if args.cvss4 and not CVSS4_RE.match(args.cvss4): + errs.append(f"--cvss4 must start with 'CVSS:4.0/...', received: {args.cvss4!r}") + if not (args.title and args.title.strip()): + errs.append("--title is required and cannot be empty") + # 4-axis model (optional but validated if provided) + for flag, axis in (("--impact", "impact"), ("--exploitability", "exploitability"), + ("--exposure", "exposure")): + val = getattr(args, flag.lstrip("-")) + if val is not None and val not in AXIS_RANGE: + errs.append(f"{flag} must be 1–4, received: {val!r} ({axis})") + if args.scope_reach is not None and args.scope_reach.upper() not in SCOPE_REACH: + errs.append(f"--scope-reach must be A/B/C/D, received: {args.scope_reach!r}") + # Evidence: either a file, inline --evidence text, or --allow-hypothesis + if not args.allow_hypothesis: + has_ev = bool(args.evidence and args.evidence.strip()) or ( + args.evidence_file and os.path.isfile(args.evidence_file) + ) + if not has_ev: + errs.append( + "Missing evidence: provide --evidence 'text' or --evidence-file path " + "(or --allow-hypothesis to register as a hypothesis without a PoC)." + ) + return errs + + +def build_record(args) -> dict: + evidence = args.evidence or "" + if args.evidence_file and os.path.isfile(args.evidence_file): + try: + with open(args.evidence_file, "r", errors="replace") as fh: + evidence = (evidence + "\n" + fh.read()).strip() + except OSError as exc: + evidence = f"{evidence}\n[failed to read {args.evidence_file}: {exc}]".strip() + record = { + "id": args.id, + "title": args.title.strip(), + "protocol": args.protocol.upper(), + "layer": args.layer.upper(), + "control": args.control or None, + "severity": args.severity.lower(), + "cvss4": args.cvss4 or None, + "status": "hypothesis" if args.allow_hypothesis else "confirmed", + "evidence": evidence or None, + "notes": args.notes or None, + "timestamp": datetime.datetime.now().astimezone().isoformat(), + } + # 4-axis model (only if provided — references/03-finding-registration.md §7) + if args.impact is not None: + record["impact"] = args.impact + if args.exploitability is not None: + record["exploitability"] = args.exploitability + if args.exposure is not None: + record["exposure"] = args.exposure + if args.scope_reach is not None: + record["scope_reach"] = args.scope_reach.upper() + # 3-layer mitigation (only if at least one was provided) + mit = {} + for key, src in (("developer", args.mitigation_developer), + ("integrator", args.mitigation_integrator), + ("operator", args.mitigation_operator)): + if src: + mit[key] = src.strip() + if mit: + record["mitigation"] = mit + return record + + +def main(argv=None) -> int: + p = argparse.ArgumentParser(description="Registers an RFSAM finding to loot/rfsam_findings.jsonl") + p.add_argument("--id", required=True, help="Finding ID, format RF-NNN (e.g. RF-001)") + p.add_argument("--protocol", required=True, help=f"Protocol: {sorted(PROTOCOLS)}") + p.add_argument("--layer", required=True, help=f"Layer: {sorted(LAYERS)}") + p.add_argument("--control", help="Associated RFSAM control, e.g. RFSAM-BLE-AT-01") + p.add_argument("--severity", required=True, help=f"Severity: {sorted(SEVERITIES)}") + p.add_argument("--cvss4", help="CVSS 4.0 vector, e.g. CVSS:4.0/AV:A/AC:L/...") + p.add_argument("--title", required=True, help="Short title of the finding") + p.add_argument("--evidence", help="Inline evidence (command output)") + p.add_argument("--evidence-file", help="Path to a file with the evidence/PoC") + p.add_argument("--notes", help="Additional notes") + p.add_argument("--impact", type=int, help="Impact axis of the RFSAM model (1–4)") + p.add_argument("--exploitability", type=int, help="Exploitability axis of the RFSAM model (1–4)") + p.add_argument("--exposure", type=int, help="Exposure axis of the RFSAM model (1–4)") + p.add_argument("--scope-reach", dest="scope_reach", + help="Scope axis of the RFSAM model: A (achieved) / B (cage) / C (hypothesis) / D (defensive)") + p.add_argument("--mitigation-developer", dest="mitigation_developer", + help="Developer-layer mitigation (manufacturer/firmware)") + p.add_argument("--mitigation-integrator", dest="mitigation_integrator", + help="Integrator-layer mitigation (deployment/configuration)") + p.add_argument("--mitigation-operator", dest="mitigation_operator", + help="Operator-layer mitigation (use/monitoring)") + p.add_argument("--allow-hypothesis", action="store_true", + help="Register as a hypothesis (no PoC) — status='hypothesis'") + p.add_argument("--loot", default="loot", help="loot/ directory (default 'loot')") + args = p.parse_args(argv) + + errs = validate(args) + if errs: + sys.stderr.write("✖ Validation failed:\n") + for e in errs: + sys.stderr.write(f" - {e}\n") + return 1 + + record = build_record(args) + path = _resolve_loot(args.loot) + with open(path, "a", encoding="utf-8") as fh: + fh.write(json.dumps(record, ensure_ascii=False) + "\n") + + sev = record["severity"].upper() + flag = " (HYPOTHESIS — no PoC)" if record["status"] == "hypothesis" else "" + print(f"✅ Registered {record['id']} [{sev}{flag}] → {path}") + print(f" {record['protocol']}/{record['layer']} · control={record['control']} · {record['title']}") + return 0 + + +def _self_test() -> bool: + """Validates the 4-axis validation logic without writing to the JSONL.""" + import types + + def _ns(**kw): + defaults = dict( + control=None, impact=None, exploitability=None, exposure=None, + scope_reach=None, mitigation_developer=None, + mitigation_integrator=None, mitigation_operator=None, + ) + defaults.update(kw) + return types.SimpleNamespace( + id="RF-001", title="ok", protocol="BLE", layer="AT", + severity="high", cvss4=None, evidence="ev", evidence_file=None, + notes=None, allow_hypothesis=False, loot="loot", **defaults, + ) + + # Valid axes → no axis errors + errs = validate(_ns(impact=4, exploitability=2, exposure=2, scope_reach="A", + mitigation_developer=None, mitigation_integrator=None, + mitigation_operator=None)) + axis_errs = [e for e in errs if any(k in e for k in + ("impact", "exploitability", "exposure", "scope-reach"))] + assert not axis_errs, f"valid axes rejected: {axis_errs}" + + # Out-of-range axes → errors + errs = validate(_ns(impact=5, exploitability=0, exposure=9, scope_reach="Z", + mitigation_developer=None, mitigation_integrator=None, + mitigation_operator=None)) + axis_errs = [e for e in errs if any(k in e for k in + ("impact", "exploitability", "exposure", "scope-reach"))] + assert len(axis_errs) == 4, f"expected 4 axis errors, got {len(axis_errs)}: {axis_errs}" + + # Cross-field validation: control protocol+layer must match finding's protocol+layer + # Mismatch → rejected + errs = validate(_ns(control="RFSAM-WIFI-CR-01")) + mismatch_errs = [e for e in errs if "mismatch" in e] + assert len(mismatch_errs) == 2, f"expected 2 mismatch errors (proto+layer), got {len(mismatch_errs)}: {mismatch_errs}" + + # Match → accepted + errs = validate(_ns(control="RFSAM-BLE-AT-01")) + mismatch_errs = [e for e in errs if "mismatch" in e] + assert not mismatch_errs, f"matching control rejected: {mismatch_errs}" + + print("✅ self-test OK — 4-axis validation + control cross-field validation") + return True + + +if __name__ == "__main__": + if "--self-test" in sys.argv: + raise SystemExit(0 if _self_test() else 1) + raise SystemExit(main()) diff --git a/Skill/scripts/scaffold_report.py b/Skill/scripts/scaffold_report.py new file mode 100644 index 0000000..7fc8f1c --- /dev/null +++ b/Skill/scripts/scaffold_report.py @@ -0,0 +1,224 @@ +#!/usr/bin/env python3 +"""scaffold_report.py — Generates the skeleton of an RFSAM audit report. + +Reads `loot/rfsam_findings.jsonl` (and optionally `loot/scope.txt`, +`loot/session_state.json`) and produces a Markdown report sorted by severity +and grouped by protocol/layer. The body is populated with the findings; the +agent completes the analysis and remediation. + +Usage: + scaffold_report.py # writes rfsam-report-.md in cwd + scaffold_report.py --target "lock" # target name in the title + scaffold_report.py --loot loot --out report.md +""" +import argparse +import datetime +import json +import os +import sys + +SEV_ORDER = {"critical": 0, "high": 1, "medium": 2, "low": 3, "info": 4} +LAYER_ORDER = ["IG", "SP", "PHY", "LL", "CR", "AT", "AP"] + + +def load_jsonl(path: str) -> list[dict]: + if not os.path.isfile(path): + return [] + out = [] + with open(path, encoding="utf-8") as fh: + for line in fh: + line = line.strip() + if line: + try: + out.append(json.loads(line)) + except json.JSONDecodeError: + pass + return out + + +def read_scope(loot_dir: str) -> str: + for name in ("scope.txt", "SCOPE.txt"): + p = os.path.join(loot_dir, name) + if os.path.isfile(p): + with open(p, encoding="utf-8", errors="replace") as fh: + return fh.read().strip() + return "" + + +def render(scope: str, findings: list[dict], target: str) -> str: + date = datetime.date.today().isoformat() + title = target or "RF target" + findings_sorted = sorted( + findings, + key=lambda f: (SEV_ORDER.get(f.get("severity", "info"), 9), + f.get("protocol", ""), LAYER_ORDER.index(f.get("layer", "IG")) + if f.get("layer") in LAYER_ORDER else 99, f.get("id", "")), + ) + by_sev: dict[str, int] = {} + for f in findings_sorted: + by_sev[f.get("severity", "info")] = by_sev.get(f.get("severity", "info"), 0) + 1 + + lines = [] + lines.append(f"# RF Security Audit Technical Report — {title}") + lines.append("") + lines.append(f"**Date**: {date} ") + lines.append("**Methodology**: RFSAM (Radio Frequency Security Assessment Methodology) ") + lines.append("**Complementary framework**: OSSTMM, BSAM, SDR-pentest lineage ") + lines.append("**Content license**: CC BY-SA 4.0") + lines.append("") + + lines.append("## 1. Technical summary") + lines.append("") + lines.append(f"- **Total findings**: {len(findings_sorted)}") + for sev in ("critical", "high", "medium", "low", "info"): + if sev in by_sev: + lines.append(f"- **{sev.upper()}**: {by_sev[sev]}") + n_confirmed = sum(1 for f in findings_sorted if f.get("status") != "hypothesis") + n_hyp = sum(1 for f in findings_sorted if f.get("status") == "hypothesis") + lines.append(f"- **Confirmed**: {n_confirmed} · **Hypotheses (no PoC)**: {n_hyp}") + lines.append("") + lines.append("> _The agent completes the executive synthesis here: business impact, " + "residual risk and remediation priorities._") + lines.append("") + + lines.append("## 2. Scope and authorization") + lines.append("") + if scope: + lines.append("```") + lines.append(scope) + lines.append("```") + else: + lines.append("> _Document the target, owner/authorization, mode (observational/active/lab/defensive) " + "and protocols in scope._") + lines.append("") + + lines.append("## 3. Methodology") + lines.append("") + lines.append("Audit following the RFSAM 7-layer descent (IG → SP → PHY+LL → CR → AT → AP) " + "per protocol. Each finding is mapped to a control `RFSAM---NN` " + "and scored with the 4-axis model consolidated into CVSS 4.0 (in RF typically " + "`AV:A` — adjacent, radio range).") + lines.append("") + + lines.append("## 4. Findings") + lines.append("") + if not findings_sorted: + lines.append("_No findings registered in `loot/rfsam_findings.jsonl`._") + lines.append("") + for f in findings_sorted: + sev = f.get("severity", "info").upper() + proto = f.get("protocol", "?") + layer = f.get("layer", "?") + control = f.get("control") or "—" + cvss = f.get("cvss4") or "—" + status_tag = " (HYPOTHESIS)" if f.get("status") == "hypothesis" else "" + lines.append(f"### {f.get('id','?')} · {sev}{status_tag} — {f.get('title','(untitled)')}") + lines.append("") + lines.append(f"- **Protocol/Layer**: {proto} / {layer}") + lines.append(f"- **RFSAM control**: `{control}`") + # 4-axis model (if provided — references/03-finding-registration.md §7) + axes = [] + for key, label in (("impact", "Impact"), ("exploitability", "Exploitability"), + ("exposure", "Exposure")): + if f.get(key) is not None: + axes.append(f"{label} {f[key]}/4") + if f.get("scope_reach"): + axes.append(f"Scope {f['scope_reach']}") + if axes: + lines.append(f"- **RFSAM model**: {' · '.join(axes)}") + lines.append(f"- **CVSS 4.0**: `{cvss}`") + ev = (f.get("evidence") or "").strip() + if ev: + lines.append("- **Evidence**:") + lines.append("") + lines.append("```") + lines.append(ev) + lines.append("```") + else: + lines.append("- **Evidence**: _to be attached_") + # 3-layer mitigation (if provided) + mit = f.get("mitigation") or {} + has_mit = isinstance(mit, dict) and bool(mit) + if has_mit: + lines.append("- **Mitigation**:") + for layer_key, label in (("developer", "Developer"), + ("integrator", "Integrator"), + ("operator", "Operator")): + if mit.get(layer_key): + lines.append(f" - _{label}_: {mit[layer_key]}") + if f.get("notes"): + lines.append(f"- **Notes**: {f['notes']}") + lines.append("") + lines.append("> _The agent completes: description, impact, reproducible PoC and " + "remediation (developer / integrator / operator)._") + lines.append("") + + lines.append("## 5. Control coverage") + lines.append("") + lines.append("> Run `python3 scripts/coverage_check.py` and paste here the summary of " + "covered vs pending controls per protocol.") + lines.append("") + + lines.append("## 6. Limitations") + lines.append("") + lines.append("> _Document visibility gaps (radio/IBW), out-of-scope controls, " + "and assumptions (e.g. could not capture the join because the device did not re-pair)._") + lines.append("") + + lines.append("## 7. Prioritized remediation") + lines.append("") + lines.append("| Priority | Finding | Action | Responsible layer | Effort | Deadline |") + lines.append("|----------|---------|--------|-------------------|--------|----------|") + # One row per confirmed finding, sorted by severity (same as §4). + # Action = first available mitigation layer (developer > integrator > operator); + # Responsible layer = list of layers with content; Effort/Deadline are filled in by the agent. + prio = 0 + for f in findings_sorted: + if f.get("status") == "hypothesis": + continue # hypotheses do not enter the remediation plan + prio += 1 + mit = f.get("mitigation") or {} + action = (mit.get("developer") or mit.get("integrator") + or mit.get("operator") or "_TBD_") + layers = [lbl for k, lbl in (("developer", "Developer"), + ("integrator", "Integrator"), + ("operator", "Operator")) if mit.get(k)] + resp = ", ".join(layers) if layers else "_unassigned_" + effort = "_{low/med/high}_" + deadline = "_{immediate/30d/90d}_" + lines.append(f"| {prio} | {f.get('id','?')} | {action} | {resp} | {effort} | {deadline} |") + if prio == 0: + lines.append("| _—_ | _no confirmed findings_ | _—_ | _—_ | _—_ | _—_ |") + lines.append("") + lines.append("> `critical`/`high` require all 3 layers (Developer/Integrator/Operator); " + "`medium` requires Integrator + Operator; `low`/`info` may close with Operator alone.") + lines.append("") + + lines.append("## 8. Appendices") + lines.append("") + lines.append("- PCAP captures, waterfalls, Proxmark dumps, session logs (`loot/`).") + lines.append("- References: CVEs, papers, tools with URLs.") + lines.append("") + return "\n".join(lines) + + +def main(argv=None) -> int: + p = argparse.ArgumentParser(description="Generates an RFSAM audit report from the JSONL") + p.add_argument("--target", help="Target name for the title") + p.add_argument("--loot", default="loot", help="loot/ directory") + p.add_argument("--out", help="Output file (default rfsam-report-.md)") + args = p.parse_args(argv) + + findings = load_jsonl(os.path.join(args.loot, "rfsam_findings.jsonl")) + scope = read_scope(args.loot) + report = render(scope, findings, args.target) + + out = args.out or f"rfsam-report-{datetime.date.today().isoformat()}.md" + with open(out, "w", encoding="utf-8") as fh: + fh.write(report) + print(f"✅ Report generated: {out} ({len(findings)} findings)") + return 0 + + +if __name__ == "__main__": + raise SystemExit(main()) diff --git a/Skill/translation-glossary.md b/Skill/translation-glossary.md new file mode 100644 index 0000000..848343f --- /dev/null +++ b/Skill/translation-glossary.md @@ -0,0 +1,122 @@ +# RFSAM Translation Glossary (ES → EN) + +> Shared reference for all translators. Keep technical terms, commands, file paths, +> code snippets, control IDs, and proper nouns in English (they already are). +> Translate ALL Spanish prose, headers, comments, docstrings, and UI strings to English. + +## Core terms +| Spanish | English | +|---------|---------| +| hallazgo | finding | +| auditoría | audit | +| descenso | descent | +| capa | layer | +| protocolo | protocol | +| control | control | +| cobertura | coverage | +| alcance | scope | +| autorización | authorization | +| modo | mode | +| observacional | observational | +| activo | active | +| lab | lab | +| defensivo | defensive | +| evidencia | evidence | +| severidad | severity | +| remediación | remediation | +| mitigación | mitigation | +| desarrollador | developer | +| integrador | integrator | +| operador | operator | +| reporte / informe | report | +| objetivo | target | +| dispositivo | device | +| señal | signal | +| espectro | spectrum | +| banda | band | +| canal | channel | +| antena | antenna | +| frecuencia | frequency | +| modulación | modulation | +| cifrado / cifrada | encryption / encrypted | +| claro / en claro | plaintext / in cleartext | +| clave | key | +| pareo / emparejamiento | pairing | +| comisión | commissioning | +| captura | capture | +| transmitir / transmisión | transmit / transmission | +| recepción | reception | +| radiar / radiación | radiate / radiation | +| jaula (de Faraday) | (Faraday) cage | +| conducción (cableada) | conducted (wired) | +| contención | containment | +| inyección | injection | +| reenvío | replay | +| suplantación | spoofing | +| vigilancia | surveillance | +| interceptación | interception | +| seguridad | security | +| vulnerabilidad | vulnerability | +| criptografía | cryptography | +| herramienta | tool | +| entorno | environment | +| credencial | credential | +| identidad | identity | +| identificador | identifier | +| exposición | exposure | +| explotabilidad | exploitability | +| impacto | impact | +| fricción | friction | +| verificación | verification | +| validación | validation | +| registro | registration / log | +| documentar | document | +| declarar | declare | +| obligatorio | mandatory / required | +| advertencia | warning | +| rotar | rotate | +| endurecimiento | hardening | +| purga | purge | +| retención | retention | +| minimización | minimization | +| licencia | license | +| delito | crime / offense | +| ilegal | illegal | +| autorizado | authorized | +| consentimiento | consent | +| permiso | permission | +| marco | framework | +| jurisdicción | jurisdiction | +| flujo maestro | master flow | +| subflujo | subflow | +| transición | transition | +| criterio | criterion | +| precondición | precondition | +| verbatim | verbatim | +| flaggear | flag | +| hueco / brecha | gap | +| límite | limit | +| superficie | surface | +| matriz | matrix | +| catálogo | catalog | +| inventario | inventory | +| enumeración | enumeration | +| mapeo | mapping | +| modelo | model | +| eje | axis | +| techo | ceiling | +| fabricante | manufacturer | +| proveedor | vendor | +| propietario | owner | +| tercero / terceros | third party / third parties | +| hueco de visibilidad | visibility gap | + +## Keep in English (already English or standard) +- All protocol names: BLE, BTC, Wi-Fi, LoRa, LTE, RFID, NFC, Zigbee, Z-Wave, Thread, GNSS, GPS, ADS-B, 5G NR, GSM, UWB +- All hardware: HackRF, RTL-SDR, bladeRF, USRP, Proxmark, Flipper, CatSniffer, etc. +- All modulations: GFSK, OFDM, CSS, O-QPSK, DSSS, BPSK, GMSK, etc. +- All crypto: AES, ECDH, Crypto1, A5/1, KASUMI, SNOW 3G, ZUC, etc. +- All command names: crackle, btlejack, rtl_433, rfcat, etc. +- All control IDs: RFSAM-*, BSAM-* +- All file paths and code +- CVSS, CVE, OWASP, CWE, FCC ID, etc. diff --git a/src/data/coverage-map.js b/src/data/coverage-map.js index 33b3ec5..d3766d0 100644 --- a/src/data/coverage-map.js +++ b/src/data/coverage-map.js @@ -68,6 +68,7 @@ export const coverageMap = [ { protocol: 'ADSB', controls: [ { id: 'RFSAM-ADSB-PHY-01', title: 'Message capture and decode', layer: 'PHY', status: 'existing', objective: 'Assess capture and decoding of ADS-B messages.' }, { id: 'RFSAM-ADSB-LL-01', title: 'Message authenticity assessment', layer: 'LL', status: 'existing', objective: 'Assess what authenticity guarantees, if any, the link provides.' }, + { id: 'RFSAM-ADSB-AT-01', title: 'Forge and inject (contained lab)', layer: 'AT', status: 'existing', objective: 'Assess resilience to forged/injected ADS-B frames (authorised, contained-lab testing only).' }, ]}, { protocol: 'NR5G', controls: [ { id: 'RFSAM-NR5G-SP-01', title: 'Cell identification and capture', layer: 'SP', status: 'existing', objective: 'Assess identification and capture of the target 5G NR cell.' },