Back to Courses

CESH 220 Unusual RF: Signal Analysis & Protocol RE

Reversing · 5 days · Assessed

BG

About the course

This is the RF analysis and reversing course. It starts after the signal has been captured properly and teaches your people how to turn that recording into data they can inspect, explain and act on.

Students run spectrum reconnaissance and signal hunting to identify what is transmitting, then choose a demodulation strategy that fits the signal, analogue or digital. Most of the course deals with the hard middle ground between “I can see it in the waterfall” and “I have a useful bitstream”: symbol timing, slicing, de-whitening and recovery of structured data from imperfect real-world captures. From there, students reverse engineer unknown and proprietary protocols, infer framing and addressing, identify meaning without a datasheet, and classify similar-looking devices through signal fingerprinting.

The course uses the open SDR stack, including GNU Radio. By the end, students can take a credible capture and work systematically towards demodulation, bitstream recovery and protocol understanding.

Want to know what to expect in the classroom? Find out more about our training approach and how we turn technical concepts into practical, hands-on skills.

Skills and topics covered

This list shows the various main topics we cover during the course:

  • Signal identification from captured RF
  • Spectrum reconnaissance for analysis
  • Modulation recognition and hypothesis testing
  • Demodulation strategy selection
  • Analogue versus digital signal analysis
  • Symbol timing recovery
  • Slicing and threshold selection
  • Clock recovery and bitstream reconstruction
  • Whitening, scrambling and encoding analysis
  • Frame boundary identification
  • Addressing and field inference
  • Proprietary protocol reverse engineering
  • Signal fingerprinting and device classification
  • Toolchain and workflows

What will a new trainee gain?

Your new entrants leave with a repeatable method for taking a captured signal all the way to a decoded bitstream, the one skill that separates people who own an SDR from people who can use one. For your organisation, that produces an analyst who can characterise an unknown protocol and write it up clearly enough for others to act on.

What will an experienced team member gain?

An experienced analyst picks up the harder reversing skills (de-whitening, symbol recovery and protocol inference) that turn vague familiarity with SDR into the ability to crack genuinely undocumented signals. For your team, that means fewer targets written off as too obscure, and the in-house capability to reverse a proprietary radio rather than send it out.

Who this course is for

This course is for security professionals, RF analysts and reverse engineers who want to turn captured radio signals into meaningful data and understand undocumented wireless protocols. Familiarity with basic RF concepts and signal capture is recommended, as the course builds on those foundations to focus on demodulation, bitstream recovery and protocol reverse engineering.

Not sure where you fit? Find out more about our training audience and prerequisites.

Required equipment, tools, and software

You will need a laptop with at least 8GB RAM, preferably 16GB, an up-to-date and stable operating system, and an Ethernet port or reliable Ethernet dongle. Your laptop must be fully under your control so that you can install tools and dependencies and run arbitrary code.

It is useful to have the ability to run virtual machines. Any VMs provided during the course will be suitable for importing into VirtualBox; if you use a different hypervisor, you should be comfortable importing VMs from OVF file formats.

All specialist RF hardware, SDR equipment and other tools required for the practical exercises will be provided during the course. You do not need to bring any additional radio or analysis equipment.

We put together a goodie bag which directly relates to the activities in the course.  The free goodie bag is yours to keep at the end of the course, just make sure you have enough luggage space to take it home. The exact details of what is in it will vary depending on availability but we always make it a useful and interesting collection.  We provide any other tools needed to complete all the tasks set, aside from a laptop.

You don’t need to bring anything extra other than your enthusiasm!

Venue and travel information

The classroom

The classroom is well appointed, has good WiFi and hot and cold drinks, it’s spacious, comfortable, has plenty of power sockets, lots of natural light, and is wheelchair friendly. The course is delivered in English and digital versions of slides and handouts will be provided where appropriate.

Food and refreshments

Lunch and morning and afternoon snacks are provided so please make sure you let us know about any dietary needs at least a week before we get started. With the exception of the social night, all other meals are for you to organise. We suggest getting a hotel that provides breakfast, and there are many good restaurants in Manchester for your evening meals. We will try and facilitate additional social arrangements, but, this is down to the individuals present.

Staying in Manchester

There are a number of good and affordable hotels in the Manchester area. We are based in an area called Media City and we are in the same complex as the northern headquarters of the BBC. This means that there are lots of facilities locally and you could choose to not venture into the city centre.

Getting here

If you do choose to look further around there are good tram links that can take you into the city as well as to key travel hubs such as Piccadilly, the national railway station, and Manchester International Airport.

Please check the weather before you travel and bring suitable clothes for the season. If in doubt, assume you will need a waterproof coat and an umbrella. The locals will tell you that Manchester is one of the rainiest places in the world, its not actually true but it does drizzle more than you might expect, even in summer.

Ready to turn signals into something meaningful?

Move beyond spotting signals in a waterfall and learn how to work systematically from a captured transmission to a useful bitstream. Over five days, you’ll develop practical skills in demodulation, signal recovery and protocol reverse engineering, giving you the tools to understand even undocumented wireless systems.

Get in touch

Register interest