Releases: yasindce1998/StaticZero
Releases · yasindce1998/StaticZero
Release list
StaticZero v0.3.0
Full Changelog: v0.2.0...v0.3.0
StaticZero v0.2.0
What's New
Satellite Communications — Offense (F121–F134)
- DVB-S2 downlink interception (broadcast TS capture, BISS key extraction)
- Transponder hijack injection (spoofed PLHeader, carrier-ID manipulation)
- NTN timing advance exploitation (3GPP NR-NTN TA pre-compensation)
- NTN-5G core gateway injection (NGAP via feeder link)
- Iridium L-band frame capture (1616–1626.5 MHz burst decode)
- LEO constellation signaling injection (Globalstar CDMA, Thuraya GMR-1)
- VSAT terminal firmware extraction (Hughes/iDirect/Newtec ACM tables)
- SCPC carrier manipulation (DVB-RCS2 return channel, MF-TDMA slots)
- Starlink Dishy auth probe (gRPC session tokens, firmware channel)
- ISL laser link fingerprinting (inter-satellite timing metadata)
- ADS-B/ACARS frame injection (Mode-S ES 1090 MHz, VHF data link)
- COSPAS-SARSAT beacon spoofing (406 MHz PLB/ELT hex ID)
- GPS L1 C/A code spoofing (1575.42 MHz PRN replicas)
- Multi-constellation L5/E5 spoofing (GPS L5 + Galileo E5a/b + BeiDou B2a)
Satellite Defense (Modules 33–39)
- DVB-S2/S2X anomaly detection (unauthorized carriers, MODCOD transitions)
- NTN access anomaly detection (TA/ephemeris mismatch, gateway auth failures)
- LEO constellation signaling monitor (L-band burst pattern vs TDM schedule)
- VSAT/SCPC integrity monitor (firmware updates, ACM table changes)
- Starlink authentication monitor (gRPC token reuse, TLE timing mismatch)
- Aviation/maritime signal integrity (ADS-B physics violations, false SARSAT beacons)
- GNSS spoofing detection (C/N0 anomalies, cross-constellation timing divergence)
Correlation Engine
- New
Satelliteprotocol layer in cross-layer correlation - 4 new threat categories: Satellite Link Hijack, GNSS Spoofing, Beacon Falsification, Terminal Compromise
- Satellite-specific correlation patterns:
- DVB-S2 + VSAT integrity → transponder takeover
- GNSS spoofing + ADS-B injection → aviation multi-vector attack
- Starlink auth + LEO signaling → terminal impersonation chain
- NTN timing + NAS replay → satellite-terrestrial positioning attack
Infrastructure
- 6 new eBPF maps for satellite state tracking (link state, GNSS signals, NTN timing, Starlink sessions, ADS-B aircraft, kill switch)
--enable-satellite/--sat-ifaceCLI flags for offense loader--satellite_defenseCLI flag for defense engine
Full Changelog: v0.1.1...v0.2.0
StaticZero v0.1.1
What's New
5G Advanced Exploitation (F109–F120)
- PBCH/SIB broadcast spoofing
- RRC measurement report manipulation
- Handover hijacking (NGAP/X2AP)
- HTTP/2 SBI exploitation between Network Functions
- NRF/AUSF/UDM API abuse
- OAuth2 token theft between NFs
- Jamming detection evasion (anti-detection waveforms)
- MIMO beamforming fingerprinting (CSI-RS/SSB)
- Sidelink PC5/V2X exploitation
- 5G-AKA protocol downgrade
- SUCI replay attack
- ARPF key extraction via UDM probing
5G Core Defense (Modules 29–32)
- SBI anomaly detection
- Handover integrity monitoring
- RAN sharing isolation verification
- Signaling storm detection
Protocol Dissectors
- PFCP (N4 interface, 3GPP TS 29.244)
- NGAP (N2 interface, 3GPP TS 38.413)
- XnAP (Xn interface, 3GPP TS 38.423)
Documentation
- New
docs/usecase.mdwith comprehensive use cases, how-to guides, and full capability reference - README updated with complete F89–F120 and Modules 16–32 tables
Full Changelog: v0.1.0...v0.1.1
StaticZero v0.1.0
Full Changelog: https://github.com/yasindce1998/StaticZero/commits/v0.1.0