Protocols from 1975.
National critical infrastructure.
SS7 without authentication, Diameter without native encryption, exposed 5G SA APIs — telecom networks run everything else. An SS7 flaw at a partner operator allows interception of your subscribers’ communications without ever touching your network.
A PROTOCOLARY AND SYSTEMIC ATTACK SURFACE
OUR SERVICES
QREDTEAM
ADVERSARY SIMULATION
- Red Team simulating a complicit operator — SS7/Diameter exploitation on a live network
- 5G SA SBI API testing — authentication, slice traversal, inter-operator roaming
- BGP hijacking and DNS poisoning simulation on operator infrastructure
- Pentest of LI (Lawful Interception) systems — a critical, under-audited vector
- Red Team of the core-network infrastructure (EPC, IMS, HLR/HSS).
QLAB
DEEP SECURITY RESEARCH
- Audit of SS7/Diameter/GTP protocols — identification of real exposures
- 0-day research on network equipment (Nokia, Ericsson, Cisco, Juniper)
- Firmware analysis of critical network equipment without source access
- Audit of 5G SBI APIs and inter-operator roaming interfaces
- Equipment supply-chain audit — backdoor detection in network firmware.
QSHIELD
SOFTWARE PROTECTION
- Protection of network-management system code against reverse engineering
- Anti-cloning for telecom-solution vendors exporting to risky markets
- IP protection of proprietary routing and network-optimization algorithms
- Protection of LI systems against analysis by adversary states
- Obfuscation of network-monitoring probe code.
QUARKSLAB DIFFERENTIATOR
Operators are audited on NIS2 compliance — not on their real SS7 exposure. Quarkslab masters SS7, Diameter and 5G SA stacks at a level only a few research teams worldwide possess. We combine offensive research on network protocols, reverse engineering of equipment firmware without sources, and QShield to protect proprietary solutions — a chain unique in Europe.
WHAT WOULD WE SAY TO EACH OTHER, FACE TO FACE
Do you know whether your SS7 network can be exploited from a foreign partner operator — today?
Most telecom CISOs have decent visibility into their IT perimeter. Very few have real visibility into their SS7 exposure — the core protocols that allow interception of your subscribers’ communications without ever touching your network.