subghz-sdr

Capture, demodulate, replay, and fuzz sub-GHz RF signals with HackRF/RTL-SDR hardware.

Updated Apr 23, 2026
One-click install
npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill subghz-sdr
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: subghz-sdr
Source: https://github.com/YukiIto1999/ctf-sleuth/tree/main/.claude/skills/subghz-sdr
Command: npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill subghz-sdr

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

An SDR-driven framework for sub-GHz RF signal analysis that enables capture, demodulation, replay, and fuzz testing of <1GHz protocols to uncover vulnerabilities and understand RF communications in lab environments.

Core Features & Use Cases

  • Spectrum analysis and signal identification across common sub-GHz bands (e.g., 315, 433.92, 868, 915 MHz)
  • Capture, recording, and replay of RF signals using SDR hardware (HackRF, RTL-SDR, Flipper Zero)
  • Protocol reverse engineering, demodulation, and decoding of observed transmissions
  • Jamming and interference testing within safe, legal, and regulatory guidelines
  • Custom signal generation and transmission for testing and validation
  • Documentation of findings, including frequency, modulation, timing, and protocol notes
  • Use Case: Investigate garage remotes, IoT RF devices, and other sub-GHz systems in CTF or security assessment contexts.

Quick Start

Start a new SDR analysis session with your HackRF or RTL-SDR and begin a basic capture and demodulation workflow on a target sub-GHz signal.

Frequently Asked Questions about subghz-sdr

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I capture and demodulate sub-GHz RF signals with SDR hardware?

To capture and demodulate sub-GHz RF signals, connect SDR hardware like HackRF or RTL-SDR to analyze spectrums across 315, 433.92, 868, and 915 MHz bands. The framework guides signal identification, recording, and protocol demodulation to decode observed transmissions effectively.

What is sub-GHz RF replay testing for IoT devices and garage remotes?

Sub-GHz RF replay testing involves capturing wireless transmissions from IoT devices or garage remotes and re-transmitting the recorded signals. This process helps uncover protocol vulnerabilities and access control weaknesses during security assessments or hardware CTF challenges.

Can I use Flipper Zero and RTL-SDR for sub-GHz protocol reverse engineering?

Yes, you can use SDR tools including Flipper Zero, HackRF, and RTL-SDR for sub-GHz protocol reverse engineering. The framework supports these devices to perform spectrum analysis, capture signals, and demodulate transmissions across common sub-GHz frequency bands.

How do I reverse engineer wireless protocols in the 433.92 MHz band?

Reverse engineering 433.92 MHz wireless protocols requires capturing the RF signal with SDR hardware, then demodulating and decoding the transmission. The framework facilitates this by analyzing timing, modulation, and protocol structure to document findings for IoT and access control systems.

What are the regulatory constraints for sub-GHz RF jamming and interference testing?

Sub-GHz RF jamming and interference testing must operate within safe, legal, and regulatory guidelines. The framework enforces compliant operation during signal analysis and custom transmission generation, ensuring lab environments remain secure while testing for vulnerabilities.

What SDR tools do I need to analyze sub-GHz RF signals and test replay attacks?

Analyzing sub-GHz RF signals and testing replay attacks requires SDR tools such as HackRF, RTL-SDR, or Flipper Zero. These hardware devices capture wireless transmissions, enabling spectrum analysis, demodulation, and custom signal generation for security validation.