Skill: Licensed HF/VHF/UHF Radio Attack
SkillDev toolsLicensed HF/VHF/UHF radio attack — ADS-B 1090 MHz, AIS, ACARS, VDL Mode 2, POCSAG/FLEX pagers, APRS, NDB, ATC/maritime VHF, DSC, weather fax, MLAT
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Skill: Licensed HF/VHF/UHF Radio Attack skill
What this skill tells your AI
The instructions your AI receives, as published by brucesongs/kali-claw in skills/hf-vhf-radio-attack/SKILL.md and read by ahel’s review.
Supplementary Files:
payloads.md-- Complete payload collection organized by licensed radio service (ADS-B, AIS, ACARS, VDL Mode 2, HFDL, POCSAG/FLEX/APOC pagers, APRS, NDB, weather fax, DSC, ATC/maritime VHF voice, MLAT/TIS-B/UAT, Inmarsat/Iridium L-band) -- 18 sections covering RX hardware setup, decoding chains, TX-side spoofing with HackRF/BladeRF, replay attacks, OPSEC for engagements, and red-team aviation/maritime scenarios.test-cases.md-- Structured test case templates (12 cases TC-LF-001..TC-LF-012): hardware verification, ADS-B aircraft tracking, AIS maritime decode, ACARS airline comms, VDL Mode 2 digital link, HFDL oceanic intercept, POCSAG pager decode, FLEX pager decode, APRS position reporting, NDB beacon tracking, weather fax reception, DSC maritime distress decode.guides/hf-vhf-radio-attack-playbook.md-- Comprehensive playbook: SDR hardware tier table (RX-only, TX/RX, full-duplex), decoding matrix (which tool for which band), real-world research (Povolny ADS-B spoofing 2012, Trend Micro maritime AIS, DEF CON ACARS/POCSAG talks), antenna design basics for HF/VHF/UHF, ITU region licensing and FCC Part 15 vs Part 97 red-team rules of engagement, lab setup with HackRF + GQRX + multimon-ng + dump1090-mutability.
Summary
HF/VHF/UHF licensed radio attack covers the spectrum above Sub-GHz ISM (handled in sdr-rf-attack) and below cellular operator bands (handled in 5g-telecom-attack). This skill targets licensed radio services in the 9 kHz - 1500 MHz range that have safety-of-life or commercial licensing implications: aircraft ADS-B broadcasts at 1090 MHz, maritime AIS at 161.975/162.025 MHz, airline ACARS data link at 131.550 MHz, VDL Mode 2 at 136.975 MHz, HFDL oceanic comms across multiple HF bands, POCSAG/FLEX/APOC pager networks, amateur radio APRS position reporting, aviation NDB beacons (190-535 kHz, 1750 kHz AM), weather fax, maritime DSC distress on Channel 70, ATC voice (118-137 MHz AM), maritime VHF voice (Channel 16 / 156.8 MHz), and ADS-B MLAT / TIS-B / UAT on 978 MHz. Inmarsat and Iridium L-band (1.5/1.6 GHz) are included briefly for context as the upper edge of this spectrum and the lower edge of satellite work.
The defining property of these services is that they are public broadcast or licensed point-to-point services that are trivially receivable with a $30 RTL-SDR dongle and a basic antenna, but transmitting on them requires explicit licensing (FCC Part 87 aviation, Part 80 maritime, Part 97 amateur) and unauthorized transmission is a federal crime in most jurisdictions. The red-team value is asymmetric: receivers can map aircraft, vessels, pagers, and tactical voice traffic without transmitting a single photon, while transmitters (spoofers, jammers) require Faraday-cage containment and explicit legal authorization. This skill emphasizes the receive-side intelligence, OPSEC, and protocol-security research that dominates licensed-band assessment work, with transmit-side attacks documented as research context only.
Tools: HackRF One, BladeRF 2.0 micro, RTL-SDR (rtl-sdr.com V3), PlutoSDR (ADALM-PLUTO), AirSpy R2/Mini/HF+ Discovery, GNU Radio, GQRX/SDR#/SDRangel/CubicSDR, dump1090-mutability/readsb, dump978 (UAT), AIS-catcher/rtl-ais/ShipXplorer, multimon-ng (POCSAG/FLEX), ACARSDeco/dumpvdl2/dumphfdl, URH (Universal Radio Hacker).
Domain: hf-vhf-radio-attack
MITRE ATT&CK: T1595-Active Scanning (RF), T1592-Gather Victim Host Info (RF fingerprinting), T1557-Adversary-in-the-Middle (RF relay), T1580-Cloud Infrastructure Discovery (RF telemetry exfil), T1499-Endpoint Denial of Service (RF jamming, authorized research only).
Detection Methods
RF Spectrum Monitoring
- Unauthorized transmissions: Transmit on aviation/maritime frequencies without license.
- ADS-B anomalies: Aircraft position reports with impossible geometry; signal strength inconsistent with reported altitude.
- POCSAG pager anomalies: Pager messages with malformed capcodes; broadcast vs point-to-point.
- APRS anomalies: Position beacons from fixed location reporting movement.
SIEM Detection Rules
- Splunk SPL (RF):
index=rf sourcetype=adsb | where altitude < 0 OR speed > 1500 - SDR monitoring: Continuous spectrum recording; alert on new transmissions in reserved bands.
Defense Evasion Techniques
Transmission Stealth
- Low power: Use minimum TX power needed; reduces detection range.
- Brief transmissions: <5 second bursts; below triangulation threshold.
- Frequency hopping: Spread across many channels; per-channel detection threshold not exceeded.
- Directional antennas: Limit RF footprint to target only; reduces collateral detection.
ADS-B Spoofing Stealth
- Match legitimate aircraft: Use real aircraft Mode S address; mimic flight profile.
- Gradual drift: Slowly drift spoofed position (1 m/s²); avoids sudden jump detection.
- Single target: Don't spoof multiple aircraft simultaneously; reduces anomaly detection.
Differentiation
This skill is explicitly bounded to avoid overlap with two adjacent RF skills:
vs. sdr-rf-attack (Sub-GHz ISM and unlicensed radio)
sdr-rf-attack covers unlicensed ISM band devices: 315/433/868/915 MHz keyfobs, garage door openers, wireless doorbells, weather stations, Sub-GHz IoT (Zigbee/LoRa raw radios at 868/915), plus RFID/NFC at 125 kHz and 13.56 MHz, GSM/LTE cellular, and 2.4 GHz BLE/Zigbee. Those are devices you own, test, and replay at will within ISM band rules.
This skill (hf-vhf-radio-attack) covers licensed services above the ISM band -- aviation, maritime, pager, and amateur radio infrastructure where the transmitters are operated under FCC/ITU licenses and the receivers are anyone with an SDR. The frequencies and protocols are entirely different (1090 MHz ADS-B, 162 MHz AIS, 131.550 MHz ACARS, etc.) and the legal posture is different: receiving is mostly unrestricted, transmitting without a license is a crime.
vs. 5g-telecom-attack (cellular operator infrastructure)
5g-telecom-attack covers the operator-side cellular stack: 5G Core (AMF/SMF/UPF), RAN, and signaling protocols (NGAP/PFCP/GTP/Diameter/SS7), IMSI catchers, and O-RAN security. Those are the carrier network components between the UE and the internet.
This skill does not cover cellular operator infrastructure. It covers licensed non-cellular services: aircraft transponders, ship AIS, airline ACARS data links, pagers, amateur radio APRS, aviation beacons, and maritime distress. Even where there is overlap in frequency (e.g., both 5G and AIS are in the 1.5-2 GHz region for satellite AIS), the protocols, threat models, and tooling are distinct.
Quick frequency map for orientation
| Band | Frequency | Covered in |
|---|---|---|
| LF (NDB aviation beacons) | 190-535 kHz, 1750 kHz | this skill |
| MF (AM broadcast) | 530-1710 kHz | out of scope (broadcast) |
| HF (amateur, marine, aviation, HFDL) | 3-30 MHz | this skill |
| VHF ATC voice | 118-137 MHz AM | this skill |
| VHF maritime voice | 156-174 MHz FM (Ch 16 = 156.8 MHz) | this skill |
| VHF AIS | 161.975 / 162.025 MHz | this skill |
| 2m amateur APRS | 144.39 MHz (US), 144.64 MHz (EU) | this skill |
| VHF ACARS | 131.550 MHz AM | this skill |
| VDL Mode 2 | 136.975 MHz | this skill |
| Sub-GHz ISM (keyfobs, IoT) | 315/433/868/915 MHz | sdr-rf-attack |
| UAT (978 MHz) | 978 MHz | this skill |
| ADS-B | 1090 MHz | this skill |
| Inmarsat / Iridium L-band | 1525-1660 MHz | this skill (briefly, context only) |
| GSM/LTE/5G | 700/850/1800/2100/2600/3500 MHz | 5g-telecom-attack and sdr-rf-attack |
| WiFi/BLE | 2.4 GHz, 5 GHz, 6 GHz | sdr-rf-attack, wifi-pentest, bluetooth-rfid-nfc |
| GNSS (GPS/Galileo/GLONASS) | 1575.42 MHz, etc. | sdr-rf-attack (gps-spoofing-guide) |
Description
Licensed HF/VHF/UHF radio attack encompasses a broad range of receive-side intelligence and (with proper authorization) active RF testing against radio services operated under aviation, maritime, paging, and amateur radio licenses. This skill covers the complete assessment lifecycle from hardware selection and antenna matching through signal capture, protocol decode, anomaly detection, and authorized spoofing/injection research in controlled environments.
Core Attack Surfaces:
- Aircraft Tracking (ADS-B 1090 MHz, UAT 978 MHz): Receive Mode S extended squitters from any aircraft within line of sight; decode ICAO 24-bit address, callsign, position, velocity, altitude, and trajectory intent. Detect spoofed aircraft, MLAT/TIS-B injection, and ghost aircraft. Map real-time air traffic over a 300+ nm radius with a $30 RTL-SDR and a 1090 MHz collinear antenna.
- Maritime Vessel Tracking (AIS 161.975/162.025 MHz): Decode Class A and Class B AIS position reports, static voyage data, and SAR aircraft positions. Detect "dark targets" (vessels with AIS off), spoofed MMSIs, and aid-to-navigation manipulation. AIS is unencrypted by design -- the security question is not "can you read it" but "can you trust what you read."
- Airline Communications (ACARS 131.550 MHz, VDL Mode 2 136.975 MHz, HFDL): Decode aircraft-to-ground data link messages including airline operational comms (AOC), air traffic control (ATC) uplinks, and oceanic position reports. ACARS is partially unencrypted and reveals aircraft intent, ETA, fuel state, and crew messages on many operators. VDL Mode 2 is the VHF digital link successor; HFDL is the HF oceanic counterpart.
- Pager Networks (POCSAG 512/1200/2400 bps, FLEX 1600/3200/6400, APOC): Decode pager messages from public safety, hospital, utility, and enterprise pager fleets. POCSAG and FLEX are unencrypted in nearly all deployments and routinely expose sensitive patient data, dispatch codes, and infrastructure alerts. Pager security research (Andrea Barisani, DEF CON 18) showed nationwide pager fleet coverage from a single rooftop.
- Amateur Radio APRS (144.39 MHz US, 144.64 MHz EU): Decode automatic position reporting system packets from amateur operators, including position, status, messages, weather, and telemetry. Useful for OPSEC assessment of ham radio infrastructure and for understanding AX.25/KISS RF data links.
- Aviation NDB (190-535 kHz, 1750 kHz AM): Track non-directional beacons used for aviation navigation. Continuous wave AM Morse code identification. Useful as a calibration signal and for assessing legacy aviation infrastructure.
- Weather Fax (HF): Decode radiofax images broadcast by meteorological services (NOAA, DWD Germany, JMA Japan) on HF bands for maritime and aviation weather briefings. Demonstrates HF image transmission protocols.
- Maritime DSC (Digital Selective Calling): Decode distress, urgency, safety, and routine calls on VHF Channel 70 (156.525 MHz), MF 2187.5 kHz, and HF 4/6/8/12/16 MHz DSC channels. Reveals maritime distress infrastructure and the unencrypted nature of DSC messaging.
- ATC Voice (118-137 MHz AM): Monitor air traffic control voice communications between pilots and controllers. AM modulation, 25 kHz (or 8.33 kHz in Europe) channel spacing. Critical context for aviation security assessment and red-team OPSEC.
- Maritime VHF Voice (Ch 16 = 156.8 MHz, Ch 13 = 156.65 MHz): Monitor international maritime distress, safety, and bridge-to-bridge communications. NBFM modulation, 25 kHz channel spacing.
- MLAT / TIS-B / UAT (978 MHz): Decode Mode U transponders, Traffic Information Service-Broadcast (TIS-B), and Automatic Dependent Surveillance-Broadcast (ADS-B) on the UAT frequency used primarily in US airspace. Complements 1090 MHz ADS-B reception.
- Satellite L-band (Inmarsat / Iridium 1525-1660 MHz): Brief coverage for context -- Inmarsat STD-C (fleet messaging), Iridium bursty transmissions, and the limits of consumer SDR in this band. Full satellite exploitation is out of scope; see
sdr-rf-attack/satellite-signal-analysis-guide.mdfor complementary NOAA/AIS/ADS-B satellite work.
Privacy and OPSEC Implications:
- Aircraft and vessel tracking: Any SDR receiver within line of sight can track aircraft and vessels in real time. This is the basis of Flightradar24, FlightAware, MarineTraffic, and VesselFinder. There is no radio-level privacy on ADS-B or AIS; the privacy question is whether the data is being aggregated and resold.
- Pager interception: Hospital pagers routinely transmit patient PHI (name, room, attending physician, diagnosis). Public safety pagers transmit dispatch codes and addresses. This is unencrypted broadcast data and represents one of the largest unaddressed PHI-leak surfaces in healthcare.
- ACARS intercept: Airline operational communications can reveal aircraft mechanical issues, crew names, diversion decisions, and ATC coordination -- commercially sensitive data that is broadcast in the clear on 131.550 MHz.
- DSC false alerts: Maritime DSC distress false alarms are a real operational problem. Receivers can characterize the local DSC traffic to assess how easily a false distress alert could be injected.
Red-Team Engagement Context:
- Maritime facility assessment: A red team assessing a port or vessel operator can use AIS reception to map vessel traffic patterns, identify dark targets, and characterize the local maritime RF environment before any active testing.
- Aviation facility assessment: ADS-B and ACARS reception at an airport-adjacent facility reveals aircraft callsigns, routes, and operational comms without any active RF emissions.
- Hospital pager audit: Passive reception of POCSAG pagers can document PHI exposure as part of a HIPAA security assessment.
- Critical infrastructure RF survey: Wideband HF/VHF/UHF survey of a facility perimeter can identify unauthorized pager, voice, or telemetry traffic that should not be present.
Related Skills:
skills/sdr-rf-attack/SKILL.md-- Sub-GHz ISM band devices (keyfobs, IoT, weather stations) and RFID/NFC radio-layer attacksskills/5g-telecom-attack/SKILL.md-- Cellular operator infrastructure (5G Core, RAN, signaling)skills/bluetooth-rfid-nfc/SKILL.md-- BLE and RFID/NFC protocol-layer attacksskills/wifi-pentest/SKILL.md-- WiFi at 2.4/5/6 GHzskills/hardware-security/SKILL.md-- Hardware attack vectors including glitching, bus sniffingskills/physical-security-testing/SKILL.md-- Physical security assessment context for RF surveillance
Use Cases
- ADS-B Aircraft Tracking and Anomaly Detection: Deploy a passive ADS-B receiver to map all aircraft within 300+ nm of an engagement site. Detect spoofed aircraft (ghost aircraft with mismatched ICAO 24-bit addresses or impossible trajectories), identify state aircraft (military, government, VIP), and document the air traffic baseline for OPSEC assessment of an aviation-adjacent facility.
- Maritime AIS Vessel Tracking and Dark Target Detection: Receive AIS position reports to map vessel traffic at a port or coastal engagement site. Identify vessels with AIS disabled (dark targets), detect MMSI spoofing (vessels broadcasting another vessel's MMSI), and characterize fishing, commercial, and military vessel patterns.
- Airline ACARS Data Link Interception: Passively receive ACARS messages at 131.550 MHz to document the airline operational communications visible from an engagement site. Useful for assessing whether a facility's location near a flight corridor creates information disclosure exposure for client airline operations.
- Hospital/Healthcare Pager PHI Audit: As part of a HIPAA security assessment, receive POCSAG and FLEX pager messages from a hospital or clinic and document the extent of patient health information being broadcast in the clear. Provide remediation recommendations for migration to encrypted paging or secure messaging.
- Public Safety Pager Fleet Characterization: For emergency services clients, document the dispatch codes, addresses, and operational data visible in their pager fleet. Useful for OPSEC review of dispatch infrastructure and assessment of pager reliance for sensitive operations.
- VDL Mode 2 and HFDL Oceanic Comms Research: Decode the modern VHF digital link (VDL Mode 2 at 136.975 MHz) and HF oceanic data link (HFDL across multiple HF bands) to assess the security posture of next-generation aircraft communications and to characterize oceanic position reporting.
- Amateur Radio APRS OPSEC Review: For amateur radio operators or organizations relying on ham radio for emergency communications, decode APRS traffic to assess OPSEC exposure of position, status, and message data broadcast on 144.39 MHz.
- ATC Voice Monitoring for Aviation Red Team: As part of an authorized airport or aviation facility assessment, monitor ATC voice traffic on 118-137 MHz AM to characterize traffic flow, identify operational patterns, and document information disclosure risks.
- Maritime DSC Distress Infrastructure Characterization: Receive DSC calls on VHF Channel 70 and HF DSC frequencies to document the local maritime distress infrastructure, characterize routine DSC traffic, and assess the feasibility of false alert injection (research context only, never transmit).
- Critical Infrastructure RF Perimeter Survey: Wideband survey of HF/VHF/UHF bands at a critical infrastructure perimeter (substation, water plant, data center) to identify unexpected pager, voice, telemetry, or amateur radio traffic that could indicate unauthorized RF devices or operational leakage.
- Aviation NDB Beacon Calibration and Tracking: Receive NDB beacons (190-535 kHz AM) as a calibration signal for SDR hardware, and to characterize the legacy aviation navigation infrastructure still in use at many smaller airports.
- Weather Fax Reception for Maritime Assessment: Decode weather fax broadcasts from meteorological services to support maritime engagement situational awareness and document the data available to vessels in the engagement area.
Core Tools
| Tool | Purpose | Command Example |
|---|---|---|
| HackRF One | TX/RX SDR for wideband capture and (authorized) transmission from 1 MHz to 6 GHz | hackrf_transfer -r capture.raw -f 1090000000 -s 2000000 -l 32 -g 40 |
| BladeRF 2.0 micro | Full-duplex TX/RX SDR from 47 MHz to 6 GHz, 56 MHz bandwidth, suitable for protocol emulation | bladerf-cli -f firmware_latest.r3 -l fpga_*.rbf -i script.txt |
| RTL-SDR (rtl-sdr.com V3) | Low-cost RX-only dongle, 24-1766 MHz, 2.4 MHz bandwidth, ideal for ADS-B/AIS/pager | rtl_sdr -f 1090000000 -s 2000000 -g 40 -n 2000000 adsb.raw |
| PlutoSDR (ADALM-PLUTO) | TX/RX learning SDR from 325 MHz to 3.8 GHz, extensible to 70 MHz - 6 GHz with mod | iio_attr -u ip:pluto.local -c -o ad9361-phy test_atten 10 |
| AirSpy R2 / Mini / HF+ Discovery | High-dynamic-range RX SDRs; AirSpy HF+ Discovery optimized for HF (9 kHz - 31 MHz, 110 dB dynamic range) | airspy_rx -f 1090 -r adsb.air -g mixervga -b 10000000 |
| GNU Radio | Block-based signal processing framework for custom decoders and protocol implementations | gnuradio-companion -> Osmocom Source -> Demod -> Sink |
| GQRX / SDR# / SDRangel / CubicSDR | GUI SDR receivers for real-time spectrum monitoring, signal identification, and audio demodulation | gqrx -> Set device -> Tune frequency -> Adjust FFT -> Record |
| dump1090-mutability / readsb | ADS-B decoder for Mode S extended squitters at 1090 MHz, web GUI with live map | dump1090 --net --net-ro-port 30003 --gain 40 --ppm 0 |
| dump978 | UAT decoder for 978 MHz ADS-B (US airspace), complementary to dump1090 | dump978 -f 978000000 -s 2000000 -g 40 -t gaincontrol |
| AIS-catcher / rtl-ais / ShipXplorer | AIS decoders for 161.975/162.025 MHz maritime vessel tracking | AIS-catcher -u 12345 -v -T or rtl_ais -T -p |
| multimon-ng | Multi-protocol decoder for POCSAG, FLEX, APOC, ZVEI, EAS, and other low-rate RF protocols | multimon-ng -t rtl -a POCSAG512 -a POCSAG1200 -a POCSAG2400 -a FLEX |
| ACARSDeco / dumpvdl2 / dumphfdl | Aircraft data link decoders: ACARS (131.550 MHz), VDL Mode 2 (136.975 MHz), HFDL (HF bands) | acarsdeco -r 0:131550000 -g 40 or dumpvdl2 --gain 40 --corrupted-messages --output decoded:text:file:stdout |
| URH (Universal Radio Hacker) | Interactive protocol reverse engineering for unknown RF signals with auto-modulation detection | urh -> Load capture -> Auto-detect modulation -> Assign labels -> Replay |
Methodology
Phase 1: Reconnaissance -- Licensed Band Survey
- Conduct wideband spectrum scan across the HF/VHF/UHF range relevant to the engagement scope using
rtl_powerorhackrf_sweep - Identify active licensed services (aviation, maritime, paging, amateur) by their characteristic frequencies and modulations
- Document the baseline RF environment at the engagement site including expected and unexpected signals
- Identify the specific licensed services in scope for the assessment (e.g., AIS at a port, ADS-B at an airport)
Phase 2: Receive-Side Intelligence (Passive)
- Configure SDR hardware for the target licensed service with appropriate antenna (1090 MHz collinear for ADS-B, VHF marine for AIS, etc.)
- Launch the appropriate decoder (dump1090 for ADS-B, AIS-catcher for AIS, multimon-ng for POCSAG, dumpvdl2 for VDL Mode 2)
- Collect traffic for the assessment period (typically hours to days for traffic pattern analysis)
- Decode and aggregate data into structured form (vessel list, aircraft list, pager message log, etc.)
- Identify anomalies: spoofed aircraft, dark targets, PHI leakage in pagers, unexpected vessel callsigns
Phase 3: Protocol Security Analysis
- Capture raw I/Q samples of the target protocol for offline analysis
- Examine the protocol for authentication, integrity, and encryption mechanisms (most licensed services have none)
- Document the data exposure: what sensitive information is broadcast in the clear
- Cross-reference decoded data with public databases (FAA aircraft registry for ICAO addresses, ITU for MMSI allocations)
Phase 4: Active Testing (Authorized Research Only)
- CRITICAL: Active RF testing on licensed bands requires explicit written authorization and typically must be conducted in a Faraday cage or shielded enclosure
- Verify all transmissions are contained (no leakage to live spectrum)
- Test replay attacks against captured signals in the shielded environment
- Test spoofing/injection (e.g., ghost ADS-B aircraft) only with the target receiver also in the shielded enclosure
- Document findings for protocol security research without impacting live services
Phase 5: Reporting and OPSEC Recommendations
- Document all licensed services observed at the engagement site
- Quantify sensitive data exposure (e.g., "X patient names observable per hour from hospital pager fleet")
- Provide remediation recommendations: encrypted paging alternatives, AIS/ADS-B trust verification, etc.
- Include spectrum analysis evidence, decoded traffic samples (redacted of PHI), and timeline of activities
- Highlight any unauthorized or unexpected RF signals that may indicate rogue devices or operational security gaps
Practical Steps
Step 1: Hardware Setup and Verification
# Verify HackRF One is detected and report capabilities
hackrf_info
# Check RTL-SDR v3 dongle and report tuner type
rtl_test -t
# Calibrate HackRF PPM offset against a known reference signal (e.g., WWV at 10 MHz)
hackrf_transfer -r /dev/null -f 10000000 -s 8000000 -l 32 -g 20 -n 8000000
# Verify AirSpy HF+ Discovery is detected (ideal for HF bands)
airspy_rx --help 2>&1 | head -5
# List all SDR devices connected via USB
lsusb | grep -i "realtek\|hackrf\|nuand\|airspy\|analog"
Step 2: ADS-B Aircraft Tracking
Shortened here. Read the whole file on GitHub.
Signals
- GitHub stars
- 71
- Forks
- 18
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
hf-vhf-radio-attack- Source
- github.com/brucesongs/kali-claw