Skip to content

Releases: yasindce1998/StaticZero

StaticZero v0.3.0

Choose a tag to compare

@github-actions github-actions released this 01 Jul 09:21

Full Changelog: v0.2.0...v0.3.0

StaticZero v0.2.0

Choose a tag to compare

@github-actions github-actions released this 30 Jun 09:25

What's New

Satellite Communications — Offense (F121–F134)

  • DVB-S2 downlink interception (broadcast TS capture, BISS key extraction)
  • Transponder hijack injection (spoofed PLHeader, carrier-ID manipulation)
  • NTN timing advance exploitation (3GPP NR-NTN TA pre-compensation)
  • NTN-5G core gateway injection (NGAP via feeder link)
  • Iridium L-band frame capture (1616–1626.5 MHz burst decode)
  • LEO constellation signaling injection (Globalstar CDMA, Thuraya GMR-1)
  • VSAT terminal firmware extraction (Hughes/iDirect/Newtec ACM tables)
  • SCPC carrier manipulation (DVB-RCS2 return channel, MF-TDMA slots)
  • Starlink Dishy auth probe (gRPC session tokens, firmware channel)
  • ISL laser link fingerprinting (inter-satellite timing metadata)
  • ADS-B/ACARS frame injection (Mode-S ES 1090 MHz, VHF data link)
  • COSPAS-SARSAT beacon spoofing (406 MHz PLB/ELT hex ID)
  • GPS L1 C/A code spoofing (1575.42 MHz PRN replicas)
  • Multi-constellation L5/E5 spoofing (GPS L5 + Galileo E5a/b + BeiDou B2a)

Satellite Defense (Modules 33–39)

  • DVB-S2/S2X anomaly detection (unauthorized carriers, MODCOD transitions)
  • NTN access anomaly detection (TA/ephemeris mismatch, gateway auth failures)
  • LEO constellation signaling monitor (L-band burst pattern vs TDM schedule)
  • VSAT/SCPC integrity monitor (firmware updates, ACM table changes)
  • Starlink authentication monitor (gRPC token reuse, TLE timing mismatch)
  • Aviation/maritime signal integrity (ADS-B physics violations, false SARSAT beacons)
  • GNSS spoofing detection (C/N0 anomalies, cross-constellation timing divergence)

Correlation Engine

  • New Satellite protocol layer in cross-layer correlation
  • 4 new threat categories: Satellite Link Hijack, GNSS Spoofing, Beacon Falsification, Terminal Compromise
  • Satellite-specific correlation patterns:
    • DVB-S2 + VSAT integrity → transponder takeover
    • GNSS spoofing + ADS-B injection → aviation multi-vector attack
    • Starlink auth + LEO signaling → terminal impersonation chain
    • NTN timing + NAS replay → satellite-terrestrial positioning attack

Infrastructure

  • 6 new eBPF maps for satellite state tracking (link state, GNSS signals, NTN timing, Starlink sessions, ADS-B aircraft, kill switch)
  • --enable-satellite / --sat-iface CLI flags for offense loader
  • --satellite_defense CLI flag for defense engine

Full Changelog: v0.1.1...v0.2.0

StaticZero v0.1.1

Choose a tag to compare

@yasindce1998 yasindce1998 released this 30 Jun 08:56

What's New

5G Advanced Exploitation (F109–F120)

  • PBCH/SIB broadcast spoofing
  • RRC measurement report manipulation
  • Handover hijacking (NGAP/X2AP)
  • HTTP/2 SBI exploitation between Network Functions
  • NRF/AUSF/UDM API abuse
  • OAuth2 token theft between NFs
  • Jamming detection evasion (anti-detection waveforms)
  • MIMO beamforming fingerprinting (CSI-RS/SSB)
  • Sidelink PC5/V2X exploitation
  • 5G-AKA protocol downgrade
  • SUCI replay attack
  • ARPF key extraction via UDM probing

5G Core Defense (Modules 29–32)

  • SBI anomaly detection
  • Handover integrity monitoring
  • RAN sharing isolation verification
  • Signaling storm detection

Protocol Dissectors

  • PFCP (N4 interface, 3GPP TS 29.244)
  • NGAP (N2 interface, 3GPP TS 38.413)
  • XnAP (Xn interface, 3GPP TS 38.423)

Documentation

  • New docs/usecase.md with comprehensive use cases, how-to guides, and full capability reference
  • README updated with complete F89–F120 and Modules 16–32 tables

Full Changelog: v0.1.0...v0.1.1

StaticZero v0.1.0

Choose a tag to compare

@github-actions github-actions released this 30 Jun 06:18