CESH 230 Unusual RF: Signal Injection & OTA Attacks
Exploiting · 5 days · Assessed
This is the RF exploitation course. It starts after students can capture a signal, analyse it, and recover enough protocol structure to make deliberate changes. The focus has moved from “what does this signal mean?” into “what can we make the system do?”
Students make the careful transition from receive to transmit, the point where RF testing becomes legally, technically and operationally more sensitive. They then build through packet injection, replay, weak encryption and encoding attacks, RF fuzzing, Layer 2 and above protocol attacks, and resilience testing under interference and deliberate degradation. The course deals with: timing, signal quality, propagation, receiver behaviour and protocol tolerance as part of the attack surface.
Practical work runs on SPYR, our real-to-life synthetic RF range. Each student gets an isolated environment that behaves like live radio. That gives the team a lawful way to practise offensive RF techniques without spectrum licensing, interference risk, or uncontrolled impact on real systems.
By the end, students can move from recovered protocol knowledge to controlled attack execution: injecting, replaying, fuzzing and degrading wireless systems in a way that is technically credible and legally safe.
Want to know what to expect in the classroom? Find out more about our training approach and how we turn technical concepts into practical, hands-on skills.
This list shows the various main topics we cover during the course:
Your new entrants get supervised, lawful experience of injecting, replaying and attacking radio on the SPYR range, instead of the theory-only exposure they usually arrive with. For your organisation, that means a junior who understands the real risk and legal weight of RF attacks before they ever touch a live system.
An experienced tester gets a safe, repeatable place to practise injection, replay and fuzzing against answer-keyed targets, so they can sharpen offensive RF skills without spectrum licensing or interference risk. For your team, that adds a genuinely offensive RF capability you can point at wireless products during assessment, backed by people who have done it in anger.
This course is for RF security professionals, penetration testers and reverse engineers ready to move from analysing wireless protocols into controlled exploitation. Students should already be comfortable capturing and analysing RF signals and have enough understanding of protocol structure to make deliberate changes to transmissions.
Not sure where you fit? Find out more about our training audience and prerequisites.
You will need a laptop with at least 8GB RAM, preferably 16GB, an up-to-date and stable operating system, and an Ethernet port or reliable Ethernet dongle. Your laptop must be fully under your control so that you can install tools and dependencies and run arbitrary code.
It is useful to have the ability to run virtual machines. Any VMs provided during the course will be suitable for importing into VirtualBox; if you use a different hypervisor, you should be comfortable importing VMs from OVF file formats.
All specialist RF hardware, SDR equipment and other tools required for the practical exercises will be provided during the course. You do not need to bring any additional radio or analysis equipment.
We put together a goodie bag which directly relates to the activities in the course. The free goodie bag is yours to keep at the end of the course, just make sure you have enough luggage space to take it home. The exact details of what is in it will vary depending on availability but we always make it a useful and interesting collection. We provide any other tools needed to complete all the tasks set, aside from a laptop.
You don’t need to bring anything extra other than your enthusiasm!
The classroom is well appointed, has good WiFi and hot and cold drinks, it’s spacious, comfortable, has plenty of power sockets, lots of natural light, and is wheelchair friendly. The course is delivered in English and digital versions of slides and handouts will be provided where appropriate.
Lunch and morning and afternoon snacks are provided so please make sure you let us know about any dietary needs at least a week before we get started. With the exception of the social night, all other meals are for you to organise. We suggest getting a hotel that provides breakfast, and there are many good restaurants in Manchester for your evening meals. We will try and facilitate additional social arrangements, but, this is down to the individuals present.
There are a number of good and affordable hotels in the Manchester area. We are based in an area called Media City and we are in the same complex as the northern headquarters of the BBC. This means that there are lots of facilities locally and you could choose to not venture into the city centre.
If you do choose to look further around there are good tram links that can take you into the city as well as to key travel hubs such as Piccadilly, the national railway station, and Manchester International Airport.
Please check the weather before you travel and bring suitable clothes for the season. If in doubt, assume you will need a waterproof coat and an umbrella. The locals will tell you that Manchester is one of the rainiest places in the world, its not actually true but it does drizzle more than you might expect, even in summer.
Take recovered protocol knowledge and put it into practice in a controlled, lawful RF environment. Over five days, you’ll develop hands-on experience with signal injection, replay, fuzzing and protocol manipulation, learning how to test wireless systems for weaknesses without the risks of transmitting against live targets.