sdr-rf-attack

Analyze RF signals and SDR-based attack surfaces for wireless security assessments.

60|14|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/brucesongs/kali-claw --skill sdr-rf-attack
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: sdr-rf-attack
Source: https://github.com/brucesongs/kali-claw/tree/main/skills/sdr-rf-attack
Command: npx skills add https://github.com/brucesongs/kali-claw --skill sdr-rf-attack

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill equips security engineers, researchers, and red teams with structured methods to discover, analyze, and exploit RF signals and wireless protocols using SDR tools, enabling realistic assessments of radio-based attack surfaces.

Core Features & Use Cases

  • SDR reconnaissance and RF signal capture across a broad range of frequencies (including 125 kHz LF, sub-GHz, and 2.4 GHz bands)
  • Structured payloads, test cases, and GNURadio flowgraphs to support reproducible RF security assessments
  • Comprehensive guides and references for GPS spoofing, GSM/LTE analysis, RFID/NFC, IoT protocols, BLE, ZigBee, and sub-GHz devices
  • Hands-on examples for keyfob replay, RFID/NFC analysis, GNURadio development, RF fingerprinting, and defense-oriented testing

Quick Start

Begin by loading the SDR RF Attack payloads and executing the GNURadio flowgraphs to perform a live RF signal capture in a controlled lab environment.

Frequently Asked Questions about sdr-rf-attack

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I analyze RF signals and test wireless protocols for security vulnerabilities?

To analyze RF signals, you can use this Skill to execute GNURadio flowgraphs and structured payloads for capturing and assessing wireless protocols across sub-GHz to 2.4 GHz bands. It provides test cases for authorized RF reconnaissance and replay testing.

Do I need HackRF or RTL-SDR hardware to perform SDR RF attacks?

Yes, performing SDR RF attacks requires physical SDR hardware such as HackRF or RTL-SDR. You also need GNURadio and URH software installed to execute the provided flowgraphs and reproduce the wireless security assessments.

Can I use GNURadio flowgraphs for GPS spoofing and RFID replay testing?

Yes, GNURadio flowgraphs are provided specifically for GPS spoofing, RFID/NFC analysis, and keyfob replay testing. These structured resources enable reproducible investigations into various wireless attack surfaces.

What wireless protocols and frequency bands are covered by SDR RF attack assessments?

SDR RF attack assessments cover a broad range of frequencies including 125 kHz LF, sub-GHz, and 2.4 GHz bands. Supported protocols include GPS, GSM/LTE, RFID/NFC, BLE, ZigBee, and various IoT devices.

What is the best way to start SDR reconnaissance in a controlled lab environment?

The best way to start SDR reconnaissance is by loading the provided RF attack payloads and executing GNURadio flowgraphs to perform live signal captures. This allows security researchers to assess radio-based attack surfaces safely.

Are there limitations to using SDR tools for IoT protocol and BLE security testing?

SDR tools are limited by hardware capabilities and legal constraints, requiring authorized testing environments. While effective for BLE and IoT protocol analysis, defense hardening and accurate RF fingerprinting depend heavily on proper antenna tuning and signal isolation.