From a faint 434 MHz blob to a decoded TFA pool sensor
A full SDR workflow: visual discovery, shifted-center validation, antenna-disconnect control, pulse fingerprinting, and rtl_433 protocol decoding of a 434 MHz ASK/OOK pool temperature sensor.
Personal technical notebook
Technical research notes on security, SDR, systems, networking and hardware.
Capture, decoding, protocol analysis, and RF experiments.
Explore →Offensive security, tooling, and protocol research.
Explore →FreeBSD and OpenBSD
Explore →Boards, components, firmware, and physical systems.
Explore →Historical honeypot packet observations.
Explore →Older notes outside the core technical categories.
Explore →A full SDR workflow: visual discovery, shifted-center validation, antenna-disconnect control, pulse fingerprinting, and rtl_433 protocol decoding of a 434 MHz ASK/OOK pool temperature sensor.
Research notes on passively identifying APRS traffic near 144.800 MHz with BladeRF, SDR++ IQ WAV captures, Python signal extraction, AFSK1200 decoding, Dire Wolf validation, and log-only realtime protocol analysis.
A passive SDR research note on finding, demodulating, validating, and fingerprinting wireless M-Bus T1 traffic around 868.95 MHz.
Passive SDR notes on TETRA control-channel metadata exposure, encrypted resource-grant visibility and the absence of readable user-content recovery.
Research notes on passively capturing and decoding Meshtastic LoRa traffic with BladeRF, GNU Radio, CRC-gated packet forwarding, protobuf parsing, and privacy-aware analysis.
H.323 Devices discovery scan via TPTK/Q.931/H.225.0.CS
SoftEther reflection DDoS amplification attack via OpenVPN P_CONTROL_HARD_RESET_CLIENT_2