CESH 220 Unusual RF: Signal Analysis & Protocol RE
Reversing · 5 days · Assessed
This is the RF analysis and reversing course. It starts after the signal has been captured properly and teaches your people how to turn that recording into data they can inspect, explain and act on.
Students run spectrum reconnaissance and signal hunting to identify what is transmitting, then choose a demodulation strategy that fits the signal, analogue or digital. Most of the course deals with the hard middle ground between “I can see it in the waterfall” and “I have a useful bitstream”: symbol timing, slicing, de-whitening and recovery of structured data from imperfect real-world captures. From there, students reverse engineer unknown and proprietary protocols, infer framing and addressing, identify meaning without a datasheet, and classify similar-looking devices through signal fingerprinting.
The course uses the open SDR stack, including GNU Radio. By the end, students can take a credible capture and work systematically towards demodulation, bitstream recovery and protocol understanding.
Want to know what to expect in the classroom? Find out more about our training approach and how we turn technical concepts into practical, hands-on skills.
This list shows the various main topics we cover during the course:
Your new entrants leave with a repeatable method for taking a captured signal all the way to a decoded bitstream, the one skill that separates people who own an SDR from people who can use one. For your organisation, that produces an analyst who can characterise an unknown protocol and write it up clearly enough for others to act on.
An experienced analyst picks up the harder reversing skills (de-whitening, symbol recovery and protocol inference) that turn vague familiarity with SDR into the ability to crack genuinely undocumented signals. For your team, that means fewer targets written off as too obscure, and the in-house capability to reverse a proprietary radio rather than send it out.
This course is for security professionals, RF analysts and reverse engineers who want to turn captured radio signals into meaningful data and understand undocumented wireless protocols. Familiarity with basic RF concepts and signal capture is recommended, as the course builds on those foundations to focus on demodulation, bitstream recovery and protocol reverse engineering.
Not sure where you fit? Find out more about our training audience and prerequisites.
You will need a laptop with at least 8GB RAM, preferably 16GB, an up-to-date and stable operating system, and an Ethernet port or reliable Ethernet dongle. Your laptop must be fully under your control so that you can install tools and dependencies and run arbitrary code.
It is useful to have the ability to run virtual machines. Any VMs provided during the course will be suitable for importing into VirtualBox; if you use a different hypervisor, you should be comfortable importing VMs from OVF file formats.
All specialist RF hardware, SDR equipment and other tools required for the practical exercises will be provided during the course. You do not need to bring any additional radio or analysis equipment.
We put together a goodie bag which directly relates to the activities in the course. The free goodie bag is yours to keep at the end of the course, just make sure you have enough luggage space to take it home. The exact details of what is in it will vary depending on availability but we always make it a useful and interesting collection. We provide any other tools needed to complete all the tasks set, aside from a laptop.
You don’t need to bring anything extra other than your enthusiasm!
The classroom is well appointed, has good WiFi and hot and cold drinks, it’s spacious, comfortable, has plenty of power sockets, lots of natural light, and is wheelchair friendly. The course is delivered in English and digital versions of slides and handouts will be provided where appropriate.
Lunch and morning and afternoon snacks are provided so please make sure you let us know about any dietary needs at least a week before we get started. With the exception of the social night, all other meals are for you to organise. We suggest getting a hotel that provides breakfast, and there are many good restaurants in Manchester for your evening meals. We will try and facilitate additional social arrangements, but, this is down to the individuals present.
There are a number of good and affordable hotels in the Manchester area. We are based in an area called Media City and we are in the same complex as the northern headquarters of the BBC. This means that there are lots of facilities locally and you could choose to not venture into the city centre.
If you do choose to look further around there are good tram links that can take you into the city as well as to key travel hubs such as Piccadilly, the national railway station, and Manchester International Airport.
Please check the weather before you travel and bring suitable clothes for the season. If in doubt, assume you will need a waterproof coat and an umbrella. The locals will tell you that Manchester is one of the rainiest places in the world, its not actually true but it does drizzle more than you might expect, even in summer.
Move beyond spotting signals in a waterfall and learn how to work systematically from a captured transmission to a useful bitstream. Over five days, you’ll develop practical skills in demodulation, signal recovery and protocol reverse engineering, giving you the tools to understand even undocumented wireless systems.