MITRE ATT&CK answers "what technique, exactly" for enterprise IT — phishing, credential dumping, lateral movement over SMB. It has nothing to say about a SendRoutingInfoForSM query against an HLR, a rogue Network Function registering itself with an NRF, or a malformed PRACH preamble flood against a gNB scheduler. Those aren't software vulnerabilities in the CVE sense; they're abuses of trust assumptions baked into 3GPP protocol design going back to SS7 in the 1970s. MITRE FiGHT (5G Hierarchy of Threats) exists to give that class of technique a name, a tactic, and a place in a matrix a SOC analyst can actually operationalize.
This is the index to read before any single deep-dive on the site. Where our telecom penetration testing methodology walks through how an assessment applies FiGHT phase-by-phase, and our threat actor tracking framework explains why FiGHT needs its own tactic column alongside the 14 standard ATT&CK tactics, this piece is the technique catalog itself — organized by the attack surface each technique actually lives on, not by an abstract tactic label. A defender reading "Collection" in isolation learns nothing; a defender reading "here are the techniques an attacker uses against your Diameter S6a interface" can go build a detection rule.
TelcoSec's internal technique catalog spans well over 60 entries across 20-plus protocol and infrastructure domains — everything from GSM A5/1 cipher cracking to Non-Terrestrial Network uplink jamming. This guide doesn't reproduce all of them; it selects roughly twenty representative techniques, grouped into the seven attack surfaces that matter most for threat modeling a modern operator: the signaling plane, the radio/air interface, O-RAN's disaggregated fronthaul, the 5G Core's Service-Based Architecture, IMS/VoIP, physical and fiber infrastructure, and satellite/NTN links. Each technique below carries its catalog ID, tactic classification, and a description of real impact — not a marketing gloss.
This index maps roughly twenty representative MITRE FiGHT-aligned attack techniques across seven telecom attack surfaces — signaling, RAN/air interface, O-RAN, 5G Core SBA, IMS/VoIP, physical/fiber infrastructure, and satellite/NTN. Each technique includes its tactic classification and real-world impact, drawn from TelcoSec's full technique catalog of 60+ entries spanning 2G through 5G-Advanced and non-terrestrial networks.
I. Why 5G Needed Its Own Attack Taxonomy
Enterprise ATT&CK's tactic list — Reconnaissance, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact, plus Resource Development — describes why an attacker takes an action, independent of target. That abstraction works because enterprise IT, regardless of industry, shares a common substrate: Windows domains, web applications, cloud IAM. Telecom does not share that substrate with anything else. A SendRoutingInfo MAP query, a Diameter Insert-Subscriber-Data-Request, a GTP-U tunnel with a guessed TEID, an RRC SecurityModeCommand negotiating EEA0 — none of these have an enterprise-IT equivalent. There's no CVE, no malware sample, no phishing email. The "vulnerability" is that the protocol was designed in an era (or under a threat model) where the interconnect itself was assumed trusted.
MITRE FiGHT fills that gap the same way ATT&CK filled the gap for enterprise IT: by cataloging real, observed techniques against a taxonomy of tactics, and mapping each to mitigations and detections a defender can implement. TelcoSec's technique catalog builds on that same tactic vocabulary — Reconnaissance, Collection, Credential Access, Execution, Persistence, Lateral Movement, Fraud, and Impact recur constantly below — while organizing techniques the way an operator's security team actually thinks about their network: by which interface, protocol, or physical layer is exposed.
Two structural facts matter before diving into the technique tables:
- Multiple generations run concurrently, and so do multiple threat models. A single operator running 2G/3G for legacy roaming, 4G for mass-market data, and 5G SA for new services simultaneously exposes GSM-era cipher weaknesses, LTE Diameter abuse, and 5G SBA API abuse — all at once, all against overlapping subscriber populations. Downgrade attacks exist specifically to let an attacker choose the weakest available generation.
- Technique complexity does not correlate with impact. Several of the highest-impact techniques below — subscriber location tracking via SS7
ProvideSubscriberInfo, USSD balance-transfer fraud, NB-IoT resource exhaustion — are rated "Low" complexity, meaning any SS7-interconnected party or a single compromised roaming partner can execute them. The techniques rated "Critical" impact and "High" complexity (baseband RCE, NRF poisoning, macrobend fiber tapping) tend to be nation-state or organized-crime tooling, not opportunistic abuse.
II. Signaling Plane Techniques (SS7 / Diameter / GTP)
The signaling plane — SS7 for 2G/3G interconnect, Diameter for 4G/LTE, and GTP for tunneled user-plane transport — remains the highest-yield, lowest-cost attack surface in telecom precisely because none of it was designed with an adversarial interconnect partner in mind. Every technique in this section requires nothing more than access to a GRX/IPX roaming interconnect, a compromised MVNO peering relationship, or a rogue STP — no CVE, no malware.
| Technique ID | Name | Description / Impact |
|---|---|---|
T1589.002 | Global Title Reconnaissance | Scans reachable Global Titles/Point Codes via M3UA/SCTP SendRoutingInfo/ATI to map MSC/VLR addresses and IMSI ranges — the reconnaissance precursor to nearly every other SS7 technique. Low complexity, Medium impact. |
T0019 | SMS Interception & Redirection | Sends a MAP UpdateLocation to the target's HLR with a rogue MSC/VLR Global Title, silently rerouting mobile-terminated SMS (including OTPs) through the attacker's node. Low complexity, High impact. |
T0021 | Subscriber Data Exfiltration (IDR) | Abuses Diameter Insert-Subscriber-Data-Request/Update-Location-Request on S6a to pull full HSS subscriber profiles — MSISDN, QoS, VoLTE/IMS settings — from a peer Diameter session. Low complexity, High impact. |
T0016 | SGSN/GGSN Tunnel Interception | Captures and de-encapsulates GTP-U traffic on the unencrypted Gn interface; 32-bit TEID space and predictable allocation make tunnel guessing feasible without any credential. Medium complexity, High impact. |
T0073 | Diameter Routing Loop | Manipulates Destination-Host/Route-Record AVPs to induce circular routing between DRAs, exhausting signaling-node CPU until legitimate traffic is denied service. Medium complexity, High impact. |
Signaling-plane risk has one defining property: it is functionally invisible to enterprise-grade EDR and SOC tooling. A SendRoutingInfoForSM query returning live subscriber location data doesn't touch an endpoint, doesn't execute code, and generates no Windows event log. The only place to catch it is at the signaling firewall — GSMA FS.11 (SS7) and FS.19 (Diameter) Category filtering, SMS Home Routing to mask real MSC/VLR addresses, and IPsec/TLS on Diameter peer sessions. LightBasin's five-year, thirteen-carrier campaign — profiled in our threat actor tracking framework — operated entirely within this category and never triggered a single enterprise detection.
III. RAN & Air Interface Techniques
The air interface is the only telecom attack surface that requires zero access to operator infrastructure at all — a $300 SDR and open-source tooling (srsRAN, OpenAirInterface) is sufficient to receive, and in permissive lab conditions transmit, broadcast signaling. This category spans everything from 2G's total absence of network authentication through 5G's baseband firmware attack surface.
| Technique ID | Name | Description / Impact |
|---|---|---|
T0015 | Fake BTS (IMSI Catcher) | GSM has no mutual authentication — a rogue BTS broadcasting a stronger signal captures IMSI/IMEI via a pre-auth Identity Request and can force A5/0 (null cipher) or record for offline A5/1 cracking. Medium complexity, High impact. |
T0014 | A5/1 Cipher Cracking | Precomputed rainbow tables (the Kraken project, ~2TB) recover the 64-bit GSM session key (Kc) from ~2 seconds of captured traffic in under a minute on commodity hardware. High complexity, Critical impact. |
T0032 | Handover Security Downgrade | Manipulates X2 Handover Request messages to force a target cell that only advertises EEA0/EIA0, stripping ciphering the moment the UE completes handover. Medium complexity, High impact. |
T0031 | Baseband Exploitation | Fuzzes malformed RRC/NAS/LPP PDUs against baseband firmware (Qualcomm, MediaTek, Samsung Shannon) to trigger memory corruption; DMA access to application memory on many platforms turns this into full device compromise. High complexity, Critical impact. |
The unifying weakness across this surface is asymmetric trust: legacy generations authenticate the subscriber to the network but never verify the network to the subscriber, and even 5G's SUCI concealment and mutual AKA don't fully close inter-RAT downgrade paths back to 2G/3G. Mitigation is layered — disabling EEA0/A5/0 except true emergency fallback, UE-side rogue-BTS detection, and baseband firmware patch cadence — but the fundamental fix (retiring 2G/3G entirely) is a decade-plus migration most operators haven't completed.
IV. O-RAN Techniques
Open RAN's disaggregation of the baseband into O-RU (radio unit), O-DU (distributed unit), and O-CU (centralized unit) connected over standard IP transport reintroduces a class of risk that integrated, vendor-proprietary RAN architectures had mostly engineered away: plaintext signal exposure on the transport network itself.
| Technique ID | Name | Description / Impact |
|---|---|---|
T0002 | O-RAN Open Fronthaul Interception | The 7-2x lower-layer-split fronthaul (eCPRI/IEEE 1914.3) carries raw IQ samples between O-RU and O-DU over plain Ethernet. Without MACsec, anyone with access to the fronthaul switching fabric captures the entire cell sector's traffic before any PDCP encryption applies. High complexity, High impact. |
The risk theme here is architectural, not implementation-specific: disaggregation is a deliberate tradeoff of vendor lock-in for a larger, IP-routable attack surface. MACsec (802.1AE) on every fronthaul segment and strict VLAN isolation between fronthaul, management, and data planes are non-negotiable for any O-RAN deployment — not because the standard is insecure, but because the standard assumes the operator will enforce transport-layer security the RAN protocol itself doesn't provide.
V. 5G Core / Service-Based Architecture Techniques
The 5G Standalone core's Service-Based Architecture exposes every Network Function as an HTTP/2 REST API secured by OAuth2 tokens the NRF issues. This is the single biggest architectural departure from every prior generation — it imports the entire cloud-native web-API threat landscape (BOLA, token scope abuse, service-registry poisoning) directly into the telecom core for the first time. See our full SBA vulnerability breakdown for the offensive walkthrough.
| Technique ID | Name | Description / Impact |
|---|---|---|
T0025 | Service-Based Architecture API Abuse | Exploits insufficient OAuth2 scope validation on NF endpoints, letting a compromised or malicious NF call APIs outside its authorized scope (e.g., a scoped SMF token reaching UDM subscriber data). Medium complexity, High impact. |
T0054 | Network Repository Function Poisoning | Registers a rogue NF instance in the NRF via NFRegister; subsequent NFDiscover calls from legitimate NFs can be misdirected to the rogue instance for interception or credential theft at scale. High complexity, Critical impact. |
T0053 | UPF Session Hijacking | Manipulates PFCP Session Establishment/Modification on the N4 interface to overwrite the F-TEID and divert user-plane traffic to an attacker-controlled UPF. High complexity, Critical impact. |
T0043 | Network Slice Evasion | Manipulates Allowed NSSAI during registration or exploits AMF slice-selection logic to attach a UE to a higher-privilege slice than authorized — eMBB to URLLC, for instance. High complexity, High impact. |
T0052 | AMF/SMF Signaling Storm | Floods NAS Registration/Service Request/PDU Session Establishment traffic to exhaust stateful AMF/SMF processing capacity — a DDoS shape unique to 5GC's per-message cryptographic verification cost. Low complexity, Critical impact. |
Every technique in this table traces back to one root cause: the SBA's security model depends entirely on correct, consistently-enforced OAuth2 scope and mTLS validation at every single NF boundary, with no fallback. There is no equivalent of a signaling firewall sitting outside the trust boundary — the trust boundary is the API gateway logic, and a single misconfigured NF endpoint undermines the entire mesh's isolation guarantees.
VI. IMS / VoIP Techniques
VoLTE and VoNR both run on IMS's SIP/SDP signaling plane, which inherits SIP's original design assumptions from fixed-line VoIP — a plane that, absent enforced SRTP and rate limiting, offers both a DoS surface and a media-interception surface.
| Technique ID | Name | Description / Impact |
|---|---|---|
T0022 | VoLTE/SIP Invite Flooding | Saturates the P-CSCF's SIP transaction state machine with high-volume INVITE traffic; since every INVITE triggers PCRF policy evaluation and S-CSCF authentication, CPU exhaustion cascades through the entire IMS core. Low complexity, High impact. |
T0023 | RTP Media Interception | If SRTP negotiation is stripped or absent, an attacker observing the media path (compromised P-CSCF or shared network segment) captures and decodes the voice stream directly from unencrypted RTP. Medium complexity, High impact. |
Both techniques share a single point of failure: SDP negotiation happens in the SIP signaling exchange itself, so an attacker who can influence or observe that exchange controls whether the resulting call is protected at all. Mandating SRTP as a hard floor (not a negotiated option) and TLS on every SIP leg closes both rows in this table simultaneously.
VII. Physical & Fiber Infrastructure Techniques
The most-overlooked attack surface in telecom threat modeling is the one with the lowest cost of entry: physical access to copper, fiber, or the cabinets and manholes that carry them. None of these techniques require a single crafted protocol message.
| Technique ID | Name | Description / Impact |
|---|---|---|
T0035 | Physical Wiretapping | Direct tap insertion on twisted copper pairs at the MDF or street cabinet; analog POTS taps are nearly undetectable without active TDR monitoring. Medium complexity, High impact. |
T0038 | Optical Tapping (Macrobending) | Bending single-mode fiber beyond its critical radius (15-30mm for SMF-28) causes evanescent field leakage a nearby detector can capture, at a loss increase (~0.1-0.5 dB) easily lost within normal link-budget tolerance. High complexity, Critical impact. |
T0040 | Fiber Interception (Passive Splitting) | GPON downstream is a broadcast medium — every ONT on a PON tree receives every GEM frame. If AES-128 GEM encryption is disabled for performance (a documented real-world operator practice), a passive splitter captures every subscriber's downstream traffic on that PON. High complexity, High impact. |
The defense posture here is fundamentally different from protocol-layer mitigation: it's physical security (locked conduits, tamper-evident seals) plus continuous optical/electrical baseline monitoring (OTDR sweeps, TDR, line SNR baselines) to catch the millidecibel-scale signal changes a tap introduces — because by the time a tap is discovered through service degradation, it has likely been in place for a long time.
VIII. Satellite / Non-Terrestrial Network Techniques
As 3GPP NTN standards extend LTE/NR direct-to-device service to satellite links (Starlink Direct to Cell, AST SpaceMobile), the satellite attack surface has gone from a niche VSAT concern to a mainstream extension of the cellular core.
| Technique ID | Name | Description / Impact |
|---|---|---|
T0070 | Space-Ground Link Interception | Ku/Ka-band downlinks (VSAT, DVB-S2) frequently carry no link-layer encryption, relying on beam directionality for security; a 90cm+ parabolic dish and a commodity SDR is sufficient to demodulate and capture traffic in bulk. High complexity, Critical impact. |
T0072 | In-Orbit DoS (Uplink Saturation) | A high-power CW or wideband noise signal at a transponder's uplink frequency saturates the Automatic Level Control circuit, degrading the link budget for every legitimate user sharing that transponder. High complexity, Critical impact. |
Satellite risk compounds the physical-layer problem from Section VII with geography: an attacker doesn't need proximity to a specific cabinet, just line-of-sight to the same satellite footprint as the legitimate ground stations — which, for a geostationary bird, can span a continent.
IX. Applying the Taxonomy to Your Own Network
A technique catalog is only useful as a threat-modeling instrument if it's run against an actual network topology, not read as a museum tour. Three questions turn this index into a gap analysis:
- Which of these seven attack surfaces does your network actually expose? A pure-5G-SA greenfield deployment has no GSM/A5/1 exposure at all (Section III mostly doesn't apply) but inherits the full weight of Section V. A legacy 2G/3G/4G operator with 5G NSA overlay is exposed on every section simultaneously — including the downgrade paths that let an attacker choose the weakest generation available.
- For each surface you expose, do you have monitoring at the right layer? Enterprise SIEM ingestion of Windows/Linux/cloud logs contributes nothing to detecting
T0021Diameter IDR abuse orT0038fiber macrobending — those require signaling-firewall telemetry and OTDR baselines respectively, tooling most enterprise-inherited SOCs don't have at all. - Which mitigations in the tables above are actually deployed, versus assumed? GSMA FS.11/FS.19 Category filtering, MACsec on O-RAN fronthaul, SRTP-as-floor on IMS, AES-128 GEM on GPON — every one of these is a documented, standard-referenced control. The gap between "the standard recommends it" and "our deployment enforces it" is where nearly every technique above actually succeeds in the field.
This same taxonomy underlies both our telecom penetration testing methodology, which walks an offensive engagement through these same attack surfaces phase by phase, and our threat actor tracking framework, which uses it to explain why documented APTs like LightBasin, Salt Typhoon, and Volt Typhoon produce such structurally different kill chains despite all three targeting telecom infrastructure. A finding from an assessment and a technique observed in a live intrusion should be describable in the exact same vocabulary — that's the entire value of using one shared taxonomy instead of ad hoc, per-report prose.
X. Frequently Asked Questions
MITRE FiGHT (5G Hierarchy of Threats) is a technique catalog purpose-built for 5G and telecom infrastructure, structured the same way as MITRE ATT&CK — tactics describing intent, techniques describing specific actions — but populated with telecom-native techniques ATT&CK has no vocabulary for: SS7/Diameter/GTP signaling abuse, rogue base stations, NRF poisoning, PFCP session hijacking. A telecom-targeting actor's technique list frequently mixes both catalogs; some actors (like LightBasin) operate almost entirely within FiGHT-class techniques, while others (Salt Typhoon, Volt Typhoon) never touch one at all.
Tactics (Reconnaissance, Collection, Impact, etc.) describe why an attacker does something, which is useful for comparing actors' overall intent — that's the organizing principle in our threat actor tracking framework. This index exists for a different purpose: threat modeling a specific network. A defender needs to know "what can happen to my Diameter S6a interface," not "what happens during the Collection tactic in general" — so grouping by attack surface (signaling, RAN, O-RAN, core, IMS, physical, satellite) maps directly onto how an operator's infrastructure and security teams are actually organized.
Only if your network still interworks with 2G/3G for roaming, legacy device support, or fallback voice — which most commercial operators still do. A downgrade attack (T0013, forcing a 3G device to fall back to GSM) exists specifically to let an attacker choose the weakest generation a target device will still accept, regardless of what the "primary" network generation is. A pure greenfield 5G SA private network with no legacy interworking is the one case where Section III's GSM-era techniques genuinely don't apply.
Not all telecom traffic traversing fiber and copper is encrypted end-to-end — a meaningful share of GPON deployments run with AES-128 GEM encryption disabled for performance reasons (documented in T0040 above), and legacy analog POTS lines carry no encryption at all. Even where transport is encrypted, physical-layer interception is often the precursor to a downstream attack (traffic analysis, timing correlation, targeting decisions) rather than the end goal itself — and it requires no network credential, no protocol exploit, and often no detectable network-layer signature at all.
The full catalog spans 60-plus techniques across more than twenty protocol and infrastructure domains — this index selects roughly twenty representative entries across seven consolidated attack surfaces for depth over breadth. Domains not detailed here in full tables — SIM/UICC (binary SMS exploitation, Ki extraction), Wi-Fi offload (evil twin, WPA3 downgrade, KRACK), IoT/NB-IoT (resource exhaustion, broker hijacking), roaming-specific abuse (SUCI/SUPI de-concealment, VPMN profile manipulation), app-layer bridges, and MEC — are part of the same catalog and follow the identical tactic/technique/mitigation structure shown above.
Reading the taxonomy is the prerequisite; applying it against your own interconnects, RAN deployment, core, and physical plant is where the actual risk reduction happens. The deep-dive articles referenced throughout this index — SS7, Diameter, RAN/air interface vulnerabilities, 5G SBA vulnerabilities, and IMSI catchers/rogue base stations — each expand a single row of this index into a full offensive and defensive treatment.


