 
  Telecom Security Testing & Defense - Vinod Shrimali - DCTAC2025
Name of Training: Telecom Security Testing & Defense
Trainer(s): Vinod Shrimali
Dates: November 3-4, 2025
Time: 8:00 am to 5:00 pm 
Venue: Exhibition World Bahrain
Cost: $3,200
Course Description:
This intensive 2-day training program equips participants with the knowledge and hands-on skills needed to secure telecom networks against evolving cyber threats. Covering 2G, 3G, 4G, and 5G architectures, the course explores vulnerabilities across the RAN, Core, Transport, and Interconnect layers, with a strong focus on real-world attack vectors such as rogue base stations, IMSI catchers, SS7/Diameter exploits, GTP tunneling attacks, and jamming/spoofing attempts.
Participants will learn to analyze, detect, and mitigate telecom-specific threats using global standards and frameworks including 3GPP security specifications, GSMA FS series, GSMA NESAS, ITU-T X.805, as well as adversarial emulation models from MITRE ATT&CK and MITRE FIGHT. The course bridges theory with practice through hands-on labs, where trainees conduct packet analysis, simulate signaling attacks, deploy rogue BTS setups, and perform incident response drills in a controlled environment.
By the end of the program, participants will be able to:
- Identify and test vulnerabilities in legacy and modern telecom networks.
 
- Map real-world telecom attacks to MITRE ATT&CK and MITRE FIGHT frameworks.
 
- Build actionable defense strategies for securing 2G–5G networks against cyber adversaries.
 
- Security by design approach for telecom network
 
- Apply encryption, authentication, and intrusion detection best practices.
 
- Minimum security baseline security standards for telecom workloads
 
- Threat modeling and security monitoring of telecom network
 
Course Outline:
🚀 2-Day Telecom Security Testing & Defense
(with MITRE ATT&CK + MITRE FIGHT Frameworks)
Day 1 – Telecom Security Foundations & Threat Landscape
Session 1 – Telecom Security Foundations
- 
Theory (1.5h)
 - 2G → 5G architectures, RAN vs. Core vs. Transport.
- Evolution of telecom network threat and security landscape
- Telecom vulnerabilities by generation.
- Why telco networks are prime cyber targets.
 
- 2G → 5G architectures, RAN vs. Core vs. Transport.
- 
Framework Integration
 - MITRE ATT&CK → Reconnaissance (IMSI collection), Initial Access (signaling abuse).
- MITRE FIGHT → Access Network Exploitation (Rogue gNB, radio link manipulation).
 
- MITRE ATT&CK → Reconnaissance (IMSI collection), Initial Access (signaling abuse).
- 
Lab (1h)
 - Map sample telecom network → identify surfaces.
- Classify attack points using both ATT&CK + FIGHT.
 
- Map sample telecom network → identify surfaces.
Session 2 – Threat Landscape in Telecom
- 
Theory (1.5h)
 - Rogue BTS / IMSI catchers.
- SS7, Diameter & GTP attacks.
- Jamming & spoofing in real-world telecom incidents.
 
- Rogue BTS / IMSI catchers.
- 
Framework Integration
 - MITRE ATT&CK → Credential Access (SIM vectors), Impact (DoS).
- MITRE FIGHT → Core Network Exploitation (GTP injection, Diameter fraud).
 
- MITRE ATT&CK → Credential Access (SIM vectors), Impact (DoS).
- 
Lab (1h)
 - Analyze SS7 traces with Wireshark.
- Detect rogue BTS anomaly → map to MITRE FIGHT (Access Network) + ATT&CK.
 
- Analyze SS7 traces with Wireshark.
Session 3 – Identity, Encryption & Standards
- 
Theory (1.5h)
 - SIM/USIM security, authentication vectors.
- Weak cipher fallback (A5/1, EPS-AKA).
- End-to-end encryption: SRTP, IPsec, MACSec.
- GSMA FS, 3GPP security, ITU-T X.805.
 
- SIM/USIM security, authentication vectors.
- 
Framework Integration
 - MITRE ATT&CK → Defense Evasion (downgrade attacks).
- MITRE FIGHT → Subscriber Exploitation (SUPI/IMSI exposure, AKA weaknesses).
 
- MITRE ATT&CK → Defense Evasion (downgrade attacks).
- 
Lab (1h)
 - Verify cipher suites in LTE/5G traffic.
- Map findings → GSMA FS + FIGHT “Subscriber Exploitation” category.
 
- Verify cipher suites in LTE/5G traffic.
✅ End of Day 1 Outcomes
- 
Understand telco architectures, vulnerabilities, Evolution of telecom network threat and security landscape.
 
- Ability to map threats to both ATT&CK & FIGHT frameworks.
- Recognize subscriber/core/RAN exploitation patterns.
Day 2 – Security Testing, Hardening & Defense Strategy
Session 4 – Securing Legacy & Modern Networks
- 
Theory (1.5h)
 - 2G/3G downgrade & cipher cracking.
- LTE: GTP tunneling, EPS-AKA flaws.
- 5G: SBA threats, slicing, SUPI exposure.
 
- 2G/3G downgrade & cipher cracking.
- 
Framework Integration
 - MITRE ATT&CK → Lateral Movement (GTP pivoting).
- MITRE FIGHT → Core Network Exploitation (NF misconfig, SBA exposure).
 
- MITRE ATT&CK → Lateral Movement (GTP pivoting).
- 
Lab (1h)
 - Simulate downgrade attack.
- Analyze GTP tunnel leakage → map to MITRE FIGHT.
 
- Simulate downgrade attack.
Session 5 – Telecom Defense Strategy
- 
Theory (1.5h)
 - Security by design approach for telecom network – Onboarding to sunset
- Perimeter Security and network segmentation strategy
- User access management and RBAC for telecom workloads
- 
Designing Minimum security baseline security standards for telecom workloads and hardening while onboarding network & workloads
 
- IDS/IPS for SS7, Diameter, SIP.
- DPI anomaly detection in live telecom traffic.
- Threat modeling and designing security monitoring of telecom network & workloads
- Integration of security logs of network and supporting components with SOC/SIEM for security monitoring.
- Advanced threat detection strategy for telecom network and integration of cutting edge technologies with telco network
- Implementing Zero trust model for telecom network
 
- Security by design approach for telecom network – Onboarding to sunset
- 
Framework Integration
 - MITRE ATT&CK → Command & Control (rogue BTS), Persistence (profile injection).
- MITRE FIGHT → Management Plane Exploitation (abuse of OAM, misconfig access).
 
- MITRE ATT&CK → Command & Control (rogue BTS), Persistence (profile injection).
- 
Lab (1.5h)
 - Deploy SS7/Diameter firewall rules.
- Detect signaling DoS in SIEM.
- Classify attack paths with ATT&CK + FIGHT side by side.
 
- Deploy SS7/Diameter firewall rules.
Session 6 – Offensive Security & Future Telecom Defense
- 
Theory (1h)
 - Telecom penetration testing methodology.
- Rogue BTS exploitation demo.
- Future: PQC for 6G, AI/ML anomaly detection, zero-trust telco networks.
 
- Telecom penetration testing methodology.
- 
Framework Integration
 - MITRE ATT&CK → Execution (malicious signalling), Exfiltration (CDR theft).
- MITRE FIGHT → Interconnect Exploitation (roaming fraud, inter-PLMN abuse).
 
- MITRE ATT&CK → Execution (malicious signalling), Exfiltration (CDR theft).
- 
Lab (1.5h)
 - Deploy rogue BTS, simulate penetration test.
- Incident response drill → classify every attack step in MITRE FIGHT & ATT&CK matrices.
 
- Deploy rogue BTS, simulate penetration test.
✅ End of Day 2 Outcomes
- Perform practical telecom penetration tests.
- Map red team attacks to both ATT&CK and FIGHT frameworks.
- Learn security hardening, security monitoring and defensive controls for RAN, Core, and Interconnect domains.
- Gain future-ready skills (PQC, AI/ML detection, zero-trust telco defense).
📊 Key Delivery Highlights
- Audience: Telco SOC engineers, security testers, core/RAN engineers.
- Duration: 2 days (~16 hours).
- Balance: ~50% labs, 50% deep dives.
- Tools: Wireshark, srsRAN/OAI, SDR,IMSI Catcher,Rouge BTS 
- 
Framework Value:
 - MITRE ATT&CK → broad enterprise threat taxonomy.
- MITRE FIGHT → telecom-native adversary emulation (Access, Core, Subscriber, Management, Interconnect).
 
- MITRE ATT&CK → broad enterprise threat taxonomy.
Difficulty Level:
Intermediate/Advanced
Audience: Security researchers, penetration testers, defense communication engineers, network engineers, SOC analysts, early-career telecom security professionals, security researchers, penetration testers, defense communication engineers.
Suggested Prerequisites:
📋 Prerequisites (Summary)
- Networking basics: TCP/IP, routing, firewalls, VPN/TLS/IPsec.
 
- Telecom basics: 2G–5G architecture, core & RAN elements, signalling (SS7, Diameter, SIP, GTP).
 
- Security basics: Common attack vectors, cryptography, IDS/IPS/SIEM.
 
- Hands-on skills: Linux, Wireshark, telecom simulators (srsRAN/OAI), VMs/Docker.
 
- Experience: 2–3 years in networking/security/telecom (Intermediate–Advanced level).
 
- Lab setup: Laptop (8GB RAM, 4 cores), Wireshark, Kali VM, optional SDR (HackRF/USRP).
 
What Students Should Bring:
- Course Materials: Slides, lab workbook, MITRE ATT&CK + FIGHT matrices, case studies.
 
- Lab Setup: Prebuilt VM/Docker with Wireshark, srsRAN/OAI, SS7/Diameter tools, sample PCAPs.
 
- References: 3GPP, GSMA FS, ITU-T X.805, ATT&CK Navigator + FIGHT matrix handouts.
 
- Training Aids: Audit checklists, reporting & incident response templates.
 Optional Hardware: SDR (USRP/HackRF) + mini LTE/5G testbed for live demos.
 
Trainer(s) Bio:
Vinod Shrimali is a Telecom Security Expert with over 10 years of hands-on experience in securing next-generation telecommunications infrastructure, data, and networks. His mission is to ensure the security, resilience, and intelligence of communication technologies in an era of rapidly evolving threats.
With a career spanning across core network security, signaling protection, and telecom cyber defense, Vinod specializes in designing and implementing end-to-end security strategies that integrate both offensive and defensive techniques. his work emphasizes not only protection but also proactive threat hunting and detection within telecom ecosystems, enabling early identification of malicious activity across VoLTE, 5G, Satellite, and IMS environments
Registration Terms and Conditions:
Trainings are refundable before October 2, 2025, minus a non-refundable processing fee of $250.
Trainings are non-refundable after October 2, 2025.
Training tickets may be transferred. Please email us at training@defcon.org for specifics.
If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).
Failure to attend the training without prior written notification, will be considered a no-show. No refund will be given.
By purchasing this ticket you agree to abide by the DEF CON Training Code of Conduct and the registration terms and conditions listed above.
Several breaks will be included throughout the day. Please note that food is not included.
All courses come with a certificate of completion, contingent upon attendance at all course sessions.
