DEF CON 33 - Recording PCAPs from Stingrays With a $20 Hotspot - Cooper Quintin, oopsbagel

DEF CON 33 - Recording PCAPs from Stingrays With a $20 Hotspot - Cooper Quintin, oopsbagel

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 39:52

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Ray Hunter: Detecting Cell Site Simulators

BLUF: EFF researchers developed Ray Hunter, a cost-effective tool that runs on $20 mobile hotspots to detect cell site simulators (Stingrays) used for surveillance by exploiting vulnerabilities in 4G/5G networks.

Key Takeaways:

• Cell site simulators impersonate cell towers, tricking phones into revealing IMEI/IMSI identifiers and potentially downgrading connections to 2G for interception 1:36
• Law enforcement agencies widely use these devices, with San Bernardino using them 231 times in 2017 5:27
• Despite 4G requiring network authentication, vulnerabilities exist in pre-authentication messages that allow exploitation 9:19
• Ray Hunter uses four detection heuristics: 2G downgrade attacks, null cipher use, incomplete SIB chains, and IMSI requests without authentication 19:24
• Field testing has detected suspicious activity in Chicago, Penn Station, and Caribbean cruise ports, indicating active surveillance 26:36

The project needs community support for device porting, international testing, and refining detection heuristics to minimize false positives globally 31:32.

Published Date: August 13, 2023

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hi everybody. Thanks for coming out. How y'all doing so far today? >> All right. Uh my name is Cooper Quinton aka Cyber Tiger. I'm a senior staff technologist where I've been at Electronic Frontier Foundation for the last 10 years working on things like Privacy Badger, State Sponsored Malware, Street Level Surveillance, Threat Lab Project, and of course, mobile security. And how many of you in here have heard of the Electronic Frontier Foundation? Amazing. Uh if you haven't heard of us, go check out our booth and the vendor all afterwards. We're a nonprofit. We've been around for 35 years. And we exist based on donations from people like from people like you. And this is my colleague uh on this project, Oops. >> Hi, I'm Oops. You may remember me from such talks as Huey Louie and the malici…