5-day deep dive · Live targets
Software Defined Radios 101
Five-day deep dive · Intercept. Demodulate. Decode. Attack.
Wireless is the one attack surface most security teams never touch, because the tooling looks like maths and the maths looks like a wall. This training takes it apart across five days, nothing assumed and nothing pre-recorded — from your first look at the spectrum to compromising a live device over the air.
Format
Five days
Full module set in class
Level
Beginner
Hands-on throughout
Price
$4,000
per student
Dates & venue
To be announced
Also available privately
Abstract
SDR 101 closes the gap between theoretical radio physics and practical RF exploitation, walking students through the complete RF kill chain: intercept, demodulate, decode, attack.
You work on real software defined radio hardware and real digital signal processing frameworks from the first afternoon. You'll learn to navigate the electromagnetic spectrum, capture raw baseband to disk, pull bits out of a waveform by hand, build your own receivers in GNU Radio, and then transmit — replay, jamming, and forged packets of your own construction. Either edition ends the same way: a custom-built wireless device on the bench and nothing but your own tooling to break it.
Who it's for
RF beginners across the cyber security and engineering fields. No prior RF experience is required — the course starts at wave propagation and builds from there.
Red team & pentest
Expand your physical-layer toolkit, compromise IoT systems, and breach airgaps.
Blue team & SOC
Security analysts and IT professionals who need to understand how attackers exploit RF vulnerabilities and compromise wireless systems.
Engineers & developers
Work at the intersection of hardware and software, build custom DSP tools, or secure your own RF-enabled products.
EW & SIGINT
Move beyond proprietary vendor solutions and start working in flexible, open-source SDR frameworks.
Directors & PMs
Technical leads who need a practical understanding of RF and SDRs to write requirements and guide procurement.
Industry veterans
Add RF exploitation to an established skill set.
What you'll
be able to do
Intercept
Drive SDR hardware directly — gain staging, offset tuning, and the spectral artefacts the hardware itself creates. Scan wideband spectrum with sweeping and FFT stitching to find emitters, then record clean raw baseband without clipping or aliasing.
Demodulate
Build real-time DSP pipelines in GNU Radio that filter, mix, resample and demodulate, taking a signal from raw IQ down to baseband and out to audio, a file, or a network socket.
Decode
Read the anatomy of a transmission — preamble, sync word, payload — and extract bits by hand. Work through the line coding and modulation schemes that make real protocols awkward: Manchester, differential, PSK and M-ary FSK.
Attack
Transmit safely and deliberately: replay attacks, targeted spot jamming, and protocol injection using modulated baseband files you generate yourself from raw binary.
Book
Five days, one radio, and a device on the bench at the end of it. $4,000 per student.
Ask about datesOutline
Course outline
One kill chain, taught in kill-chain order. Nothing assumed and nothing pre-recorded — each day ends somewhere the previous day could not reach.
The week
Five days, the full module set taught live in class.
Day 1
Intro RF theory
The foundational physics: the electromagnetic spectrum, wave propagation, complex numbers and baseband IQ data. How radio waves travel, how SDR hardware turns analog voltages into digital samples, and what actually separates amplitude, frequency and phase modulation.
- 1.1 Electromagnetic spectrum. Radio waves, frequency bands, and wavelength mathematics.
- 1.2 Antennas. How RF radiates — gain, polarisation, and reading radiation patterns.
- 1.3 Radio architecture. Superheterodyne receivers, frequency translation, and the ADC.
- 1.4 Complex numbers and IQ data. Quadrature sampling, and how I/Q coordinates carry phase and amplitude.
- 1.5 Modulating RF waves. Encoding digital data onto analog waveforms: AM/ASK, FM/FSK, PM/PSK.
- 1.6 RF network topologies. Point-to-point links, repeaters, star hubs and mesh networks.
- 1.7 RF propagation. Ground waves, sky waves, line-of-sight, and link budget calculations.
Day 2
SDRs and signal analysis
Theory gives way to the radio. Students interface with the SDR, navigate the spectrum, capture raw IQ files, and extract and decode binary payloads out of live transmissions.
- 2.1 Basic SDR interfacing. The hardware hierarchy and practical receiver operation.
- 2.2 Hardware hierarchy and FFTs. The Fast Fourier Transform and the tradeoff between time and frequency resolution.
- 2.3 Capturing and inspecting raw signal files. Recording baseband data without clipping or aliasing.
- 2.4 Signals analysis. Preamble, sync word, payload — and manual bit-level extraction.
- 2.5 Spectrum scanning. Sweeping, FFT stitching, and baseline anomaly detection across wide bandwidth.
- 2.6 Mini-capstone. The day's intercept and analysis work, applied end to end.
Day 3
GNU Radio and DSP flowgraphs
GNU Radio as the primary DSP framework. Students build custom flowgraphs that filter, mix, resample and demodulate in real time — the bridge between raw samples and usable audio or packets.
- 3.1 Introduction to GNU Radio. Core architecture, the thread scheduler, and complex data types.
- 3.2 Basic DSP building blocks. The mathematical blocks needed to build a software receiver from scratch.
- 3.3 Extending GNU Radio. Out-of-tree modules, and integrating external command-line decoders over named FIFOs and network sockets.
Day 4
Custom blocks and transmitting
Writing custom embedded Python blocks, then going active. Students execute physical denial-of-service (jamming), signal replay attacks, and custom protocol generation.
- 4.1 GNU Radio custom blocks. Embedded Python performing DSP inside the data stream.
- 4.2 SDR transmission fundamentals. The mechanics of transmitting, explored through jamming and replay.
- 4.3 Protocol attacks. Beyond replay — generating modulated baseband files mathematically from raw data.
Day 5
Advanced DSP and capstone
Advanced physical layer concepts, then the week's work against a live target: students reverse-engineer and exploit a custom hardware device using everything built during the course.
- 5.1 Advanced DSP concepts. Phase shift keying, M-ary modulation (4FSK), and line coding (Manchester, differential).
- 5.2 Course review. A consolidated recap of the DSP, analysis and transmission mechanics.
- 5.3 Capstone. Free-form practical application against a live target.
Capstone hardware
Students are handed a custom-built wireless printed circuit board and must run the full RF kill chain against it — find it, characterise it, decode it, and compromise the system.
Custom-tailored editions are also available, cut to an organisation's own timeline and training objectives.
Before you
arrive
Prerequisites
Install the student VM before arriving; the instructor sends it out ahead of time. Nothing else is pre-recorded — every module is taught in class. No prior RF experience is required.
What to bring
A laptop able to run the student VM, with a free USB port for the radio. And your favourite caffeine.
Provided on the day: SDR hardware, all training material, and the capstone target. Audience skill level is beginner.
Certificate
Every student who completes the training receives a continuing education certificate in both forms — a printed copy and a digital version you can file for CPE records or add to your LinkedIn profile.
Your trainer
Richard Shmel
RNS Technology Solutions
Richard designed and delivers SDR 101, the beginner-facing RF exploitation course built around real radios, open-source DSP frameworks, and a custom wireless target he builds himself.
The course reflects how he teaches: no proprietary black boxes, no slide-only sections, and every concept put straight onto hardware. Condensed and custom-tailored editions are built on request around an organisation's own timeline and objectives.
- Teaches
- SDR
- DSP
- RF Exploitation
- GNU Radio
- SIGINT
Radio hardware
Take a radio home — optional
SDR hardware is provided for use in class, so nothing is required to take part. If you want your own unit to keep, you can buy the radio the course is built around.
Optional · HackRF One bundle — $600
An optional add-on, purchased with your seat. Includes the HackRF One, antenna, metal case, and an upgraded crystal oscillator. Yours to keep.
Students may bring their own HackRF One.
Register
Dates to be announced
The five-day deep dive is scheduling now, as a public course and as a private one run for a single organisation.
5-day deep dive
$4,000
Per student. Full module set taught in class, nothing pre-recorded.
Private and custom trainings
Custom-tailored editions are available on request, cut to fit your organisation's specific timeline and training objectives. Tell us the days you can spare and what you need your team to walk out able to do.
Includes SDR hardware, all training material and the capstone target. Venue is confirmed at booking; cancellation terms follow the standard Switchback training policy.