Ask about dates

5-day deep dive · Live targets

Software Defined Radios 101

Five-day deep dive · Intercept. Demodulate. Decode. Attack.

Wireless is the one attack surface most security teams never touch, because the tooling looks like maths and the maths looks like a wall. This training takes it apart across five days, nothing assumed and nothing pre-recorded — from your first look at the spectrum to compromising a live device over the air.

Ask about dates 5-day deep dive No prior RF experience required

Format

Five days
Full module set in class

Level

Beginner
Hands-on throughout

Price

$4,000
per student

Dates & venue

To be announced
Also available privately

Abstract

SDR 101 closes the gap between theoretical radio physics and practical RF exploitation, walking students through the complete RF kill chain: intercept, demodulate, decode, attack.

You work on real software defined radio hardware and real digital signal processing frameworks from the first afternoon. You'll learn to navigate the electromagnetic spectrum, capture raw baseband to disk, pull bits out of a waveform by hand, build your own receivers in GNU Radio, and then transmit — replay, jamming, and forged packets of your own construction. Either edition ends the same way: a custom-built wireless device on the bench and nothing but your own tooling to break it.

Who it's for

RF beginners across the cyber security and engineering fields. No prior RF experience is required — the course starts at wave propagation and builds from there.

Red team & pentest

Expand your physical-layer toolkit, compromise IoT systems, and breach airgaps.

Blue team & SOC

Security analysts and IT professionals who need to understand how attackers exploit RF vulnerabilities and compromise wireless systems.

Engineers & developers

Work at the intersection of hardware and software, build custom DSP tools, or secure your own RF-enabled products.

EW & SIGINT

Move beyond proprietary vendor solutions and start working in flexible, open-source SDR frameworks.

Directors & PMs

Technical leads who need a practical understanding of RF and SDRs to write requirements and guide procurement.

Industry veterans

Add RF exploitation to an established skill set.

What you'll
be able to do

Intercept

Drive SDR hardware directly — gain staging, offset tuning, and the spectral artefacts the hardware itself creates. Scan wideband spectrum with sweeping and FFT stitching to find emitters, then record clean raw baseband without clipping or aliasing.

Demodulate

Build real-time DSP pipelines in GNU Radio that filter, mix, resample and demodulate, taking a signal from raw IQ down to baseband and out to audio, a file, or a network socket.

Decode

Read the anatomy of a transmission — preamble, sync word, payload — and extract bits by hand. Work through the line coding and modulation schemes that make real protocols awkward: Manchester, differential, PSK and M-ary FSK.

Attack

Transmit safely and deliberately: replay attacks, targeted spot jamming, and protocol injection using modulated baseband files you generate yourself from raw binary.

Book

Five days, one radio, and a device on the bench at the end of it. $4,000 per student.

Ask about dates

Outline

Course outline

One kill chain, taught in kill-chain order. Nothing assumed and nothing pre-recorded — each day ends somewhere the previous day could not reach.

The week

Five days, the full module set taught live in class.

Day 1
Intro RF theory

The foundational physics: the electromagnetic spectrum, wave propagation, complex numbers and baseband IQ data. How radio waves travel, how SDR hardware turns analog voltages into digital samples, and what actually separates amplitude, frequency and phase modulation.

  • 1.1 Electromagnetic spectrum. Radio waves, frequency bands, and wavelength mathematics.
  • 1.2 Antennas. How RF radiates — gain, polarisation, and reading radiation patterns.
  • 1.3 Radio architecture. Superheterodyne receivers, frequency translation, and the ADC.
  • 1.4 Complex numbers and IQ data. Quadrature sampling, and how I/Q coordinates carry phase and amplitude.
  • 1.5 Modulating RF waves. Encoding digital data onto analog waveforms: AM/ASK, FM/FSK, PM/PSK.
  • 1.6 RF network topologies. Point-to-point links, repeaters, star hubs and mesh networks.
  • 1.7 RF propagation. Ground waves, sky waves, line-of-sight, and link budget calculations.

Day 2
SDRs and signal analysis

Theory gives way to the radio. Students interface with the SDR, navigate the spectrum, capture raw IQ files, and extract and decode binary payloads out of live transmissions.

  • 2.1 Basic SDR interfacing. The hardware hierarchy and practical receiver operation.
  • 2.2 Hardware hierarchy and FFTs. The Fast Fourier Transform and the tradeoff between time and frequency resolution.
  • 2.3 Capturing and inspecting raw signal files. Recording baseband data without clipping or aliasing.
  • 2.4 Signals analysis. Preamble, sync word, payload — and manual bit-level extraction.
  • 2.5 Spectrum scanning. Sweeping, FFT stitching, and baseline anomaly detection across wide bandwidth.
  • 2.6 Mini-capstone. The day's intercept and analysis work, applied end to end.

Day 3
GNU Radio and DSP flowgraphs

GNU Radio as the primary DSP framework. Students build custom flowgraphs that filter, mix, resample and demodulate in real time — the bridge between raw samples and usable audio or packets.

  • 3.1 Introduction to GNU Radio. Core architecture, the thread scheduler, and complex data types.
  • 3.2 Basic DSP building blocks. The mathematical blocks needed to build a software receiver from scratch.
  • 3.3 Extending GNU Radio. Out-of-tree modules, and integrating external command-line decoders over named FIFOs and network sockets.

Day 4
Custom blocks and transmitting

Writing custom embedded Python blocks, then going active. Students execute physical denial-of-service (jamming), signal replay attacks, and custom protocol generation.

  • 4.1 GNU Radio custom blocks. Embedded Python performing DSP inside the data stream.
  • 4.2 SDR transmission fundamentals. The mechanics of transmitting, explored through jamming and replay.
  • 4.3 Protocol attacks. Beyond replay — generating modulated baseband files mathematically from raw data.

Day 5
Advanced DSP and capstone

Advanced physical layer concepts, then the week's work against a live target: students reverse-engineer and exploit a custom hardware device using everything built during the course.

  • 5.1 Advanced DSP concepts. Phase shift keying, M-ary modulation (4FSK), and line coding (Manchester, differential).
  • 5.2 Course review. A consolidated recap of the DSP, analysis and transmission mechanics.
  • 5.3 Capstone. Free-form practical application against a live target.

Capstone hardware

Students are handed a custom-built wireless printed circuit board and must run the full RF kill chain against it — find it, characterise it, decode it, and compromise the system.

The custom wireless target board used in the capstone, between a captured baseband waveform and the constellation plot of a modulated signal
Capstone target · captured baseband and constellation

Custom-tailored editions are also available, cut to an organisation's own timeline and training objectives.

Before you
arrive

Prerequisites

Install the student VM before arriving; the instructor sends it out ahead of time. Nothing else is pre-recorded — every module is taught in class. No prior RF experience is required.

What to bring

A laptop able to run the student VM, with a free USB port for the radio. And your favourite caffeine.

Provided on the day: SDR hardware, all training material, and the capstone target. Audience skill level is beginner.

Certificate

Certificate

Every student who completes the training receives a continuing education certificate in both forms — a printed copy and a digital version you can file for CPE records or add to your LinkedIn profile.

Your trainer

Richard Shmel

Richard Shmel

RNS Technology Solutions

Richard designed and delivers SDR 101, the beginner-facing RF exploitation course built around real radios, open-source DSP frameworks, and a custom wireless target he builds himself.

The course reflects how he teaches: no proprietary black boxes, no slide-only sections, and every concept put straight onto hardware. Condensed and custom-tailored editions are built on request around an organisation's own timeline and objectives.

  • Teaches
    • SDR
    • DSP
    • RF Exploitation
    • GNU Radio
    • SIGINT

Radio hardware

Take a radio home — optional

SDR hardware is provided for use in class, so nothing is required to take part. If you want your own unit to keep, you can buy the radio the course is built around.

HackRF One software defined radio by Great Scott Gadgets, in a black metal case with antenna connector
HackRF One · Great Scott Gadgets

Optional · HackRF One bundle — $600

An optional add-on, purchased with your seat. Includes the HackRF One, antenna, metal case, and an upgraded crystal oscillator. Yours to keep.

Students may bring their own HackRF One.

Register

Dates to be announced

The five-day deep dive is scheduling now, as a public course and as a private one run for a single organisation.

5-day deep dive

$4,000

Per student. Full module set taught in class, nothing pre-recorded.

Private and custom trainings

Custom-tailored editions are available on request, cut to fit your organisation's specific timeline and training objectives. Tell us the days you can spare and what you need your team to walk out able to do.

Includes SDR hardware, all training material and the capstone target. Venue is confirmed at booking; cancellation terms follow the standard Switchback training policy.