Agent skill

Offensive Lorawan Sub Ghz

by SnailSploit in SnailSploit/Claude-Red

LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz…

MITAuto-check passedDevOps & Cloud

Install Offensive Lorawan Sub Ghz

skills CLI
$ npx skills add SnailSploit/Claude-Red --skill offensive-lorawan-sub-ghz -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SnailSploit/Claude-Red offensive-lorawan-sub-ghz --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills/wireless/offensive-lorawan-sub-ghz .claude/skills/offensive-lorawan-sub-ghz && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
offensive-lorawan-sub-ghz
GitHub stars
7.3k
Token cost
~1.7k tokens
SKILL.md length
492 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz…

  • Works in 4 steps: Identify the band + modulation (LoRa CSS… → Capture transmissions with appropriate… → For LoRaWAN: capture join + uplinks;… → …
  • LoRaWAN deployments (smart cities
  • SKILL.md covers Quick Workflow, Hardware, LoRaWAN and Sub-GHz Proprietary Protocols, plus 4 more sections
  • Calls git and python; reaches github.com

What it does

Offensive Lorawan Sub Ghz is an agent skill from SnailSploit/Claude-Red. LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz protocol replay (KeeLoq garage doors, fixed-code remotes, TPMS spoofing, smart plug telemetry), HackRF / RTL-SDR / Flipper Zero workflows, signal analysis with Inspectrum / Universal Radio Hacker, and reconstruction of proprietary packet formats. Use for LoRaWAN deployments (smart cities, asset tracking, industrial…

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Deployment. The repository describes itself as: claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level… The licence is MIT.

When your agent uses it

  • LoRaWAN deployments (smart cities
  • Industrial telemetry)
  • Any wireless device using the unlicensed 433/868/915 MHz bands (garage openers

Example prompts

  • “/offensive-lorawan-sub-ghz”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Identify the band + modulation (LoRa CSS vs. simple OOK/FSK)
  2. Capture transmissions with appropriate hardware (HackRF / RTL-SDR / Flipper Zero)
  3. For LoRaWAN: capture join + uplinks; analyze key derivation
  4. For proprietary sub-GHz: demodulate, identify packet format, replay or craft

What it can do on your machine

Read from SKILL.md and the folder at commit 739512a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Offensive Lorawan Sub Ghz loads about 1.7k tokens when it runs. Until then it costs about 169 tokens; SKILL.md has 492 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~169
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SnailSploit/Claude-Red at commit 739512a, republished under its MIT licence (© SnailSploit). 492 words, ~1,722 tokens.

Download SKILL.mdSave it as .claude/skills/offensive-lorawan-sub-ghz/SKILL.md (or your agent's skills folder).
name
offensive-lorawan-sub-ghz
description
LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz protocol replay (KeeLoq garage doors, fixed-code remotes, TPMS spoofing, smart plug telemetry), HackRF / RTL-SDR / Flipper Zero workflows, signal analysis with Inspectrum / Universal Radio Hacker, and reconstruction of proprietary packet formats. Use for LoRaWAN deployments (smart cities, asset tracking, industrial telemetry), or any wireless device using the unlicensed 433/868/915 MHz bands (garage openers, doorbells, IoT sensors, RC equipment).

LoRaWAN & Sub-GHz Attacks

LoRaWAN provides long-range low-bitrate communication for IoT — common in smart cities, asset tracking, and industrial telemetry. Outside LoRaWAN, the 433 / 868 / 915 MHz ISM bands host garage doors, doorbells, smart plugs, weather stations, and TPMS — most with weak or no crypto.

Quick Workflow

  1. Identify the band + modulation (LoRa CSS vs. simple OOK/FSK)
  2. Capture transmissions with appropriate hardware (HackRF / RTL-SDR / Flipper Zero)
  3. For LoRaWAN: capture join + uplinks; analyze key derivation
  4. For proprietary sub-GHz: demodulate, identify packet format, replay or craft

Hardware

ToolRangeUse
RTL-SDRRX only, 24 MHz–1.7 GHzCheap reconnaissance
HackRF OneRX/TX, 1 MHz–6 GHzFull transceiver
Flipper ZeroRX/TX, sub-GHzQuick replays, fixed-code attacks
LimeSDR / BladeRFRX/TX, wider bandHigher fidelity for LoRaWAN
YARD Stick OneTX-focused sub-GHzTargeted replays
LoRa-specific gateway (RAK / Heltec)LoRaWAN dual-directionStandards-compliant LoRaWAN testing

LoRaWAN

LoRaWAN is a MAC layer over LoRa physical (chirp spread spectrum). Devices either:

  • OTAA (Over-the-Air Activation) — derive session keys at join
  • ABP (Activation By Personalization) — pre-flashed keys
OTAA Join Capture
bash
# Capture LoRa packets with HackRF + Inspectrum
hackrf_transfer -r capture.iq -f 868000000 -s 1000000 -n 60000000
# Or LoRa-specific: rak_common_for_gateway

# Decode with PHY + MAC stack
git clone https://github.com/Lora-net/LoRaMac-node
# Or use ChirpStack as a sniffing gateway

The Join-Request and Join-Accept are encrypted with the device's AppKey. With AppKey (extracted from device firmware — see offensive-iot):

  • Decrypt Join-Accept → recover NwkSKey, AppSKey
  • Subsequent traffic decryption + injection
ABP — Pre-Flashed Keys

ABP devices have NwkSKey + AppSKey flashed at manufacture. Common flaws:

  • Same key across thousands of devices (vendor laziness)
  • No frame counter rollover protection → replay any historical uplink
  • DevAddr predictability (sequential allocation)
bash
# If you have NwkSKey + AppSKey + DevAddr, decode/inject with lorawan-test-tools
git clone https://github.com/IoTsec/loraserver-attack-tools
python lora_inject.py --nwkskey <NWKS> --appskey <APPS> --devaddr <ADDR>
Frame Counter Replay

Older LoRaWAN 1.0.x doesn't enforce strict frame counter monotonicity in all stacks. Replay an uplink with a different timestamp → server processes as fresh.

If you control AppSKey + NwkSKey, you can inject downlinks (configuration changes, remote commands) to devices.

Sub-GHz Proprietary Protocols

Quick Capture + Replay (Flipper Zero / HackRF)
bash
# RTL-SDR live monitor
rtl_433 -f 433.92M -A     # auto-decode many devices
gqrx                       # interactive spectrum analyzer

# Flipper Zero Sub-GHz menu: Read → identify modulation → capture → save
# Then replay from the saved file

# HackRF capture
hackrf_transfer -r garage.iq -f 433920000 -s 8000000 -n 80000000
# Inspectrum to visualize, identify OOK / FSK, decode bits
Show full SKILL.md (209 more words)Show less
KeeLoq (Old Garage Doors, Some Cars)

KeeLoq uses a 32-bit block cipher with a manufacturer key. The manufacturer key was extracted publicly years ago for major brands. With it:

  • Decrypt rolling code → predict next valid code
  • Combined with capture-replay, take over the remote
bash
# rolling-code-tools (research)
git clone https://github.com/AndrewMohawk/RollingPwn

Modern KeeLoq deployments (last 5 years) have rotated manufacturer keys, but legacy hardware (older garage doors, some industrial equipment) is in scope.

Fixed-Code Remotes

Many cheap garage openers, doorbells, and smart plugs use fixed codes — the same packet every time you press the button. Capture once, replay forever.

bash
# Flipper Zero: Read → Save → Send (from saved file)
# Or with RFCat:
python -c "import rflib; ..."
# OR with HackRF:
hackrf_transfer -t replay.iq -f 433920000 -s 8000000
TPMS Spoofing

Tire-pressure monitoring sensors broadcast at 315/433 MHz with no authentication. Spoof low-pressure alerts:

bash
# Capture legitimate TPMS
rtl_433 -f 315M -F json | grep TPMS

# Synthesize crafted alerts (custom modulator with HackRF)
# Useful for testing TPMS-aware vehicle systems or as denial-of-trust attack
Reconstruction of Unknown Protocols
bash
# Universal Radio Hacker (URH) — visual reverse engineering
urh
# Load .iq capture, identify modulation visually,
# auto-detect symbols, decode bits, identify packet structure

URH walks you from raw RF to a parsed protocol description, even with no docs.

Engagement Cheatsheet

bash
# 1. Identify band + modulation
rtl_433 -f <freq> -A           # auto-detect known protocols
gqrx                           # spectrum view to find activity

# 2. For LoRaWAN
#    - Set up gateway (or HackRF + LoRa decoding)
#    - Capture joins + uplinks
#    - Extract keys from device firmware (see offensive-iot)

# 3. For proprietary sub-GHz
#    - Capture with HackRF / RTL-SDR
#    - Visualize / decode with Inspectrum or URH
#    - Replay or craft

# 4. Document modulation, frequency, packet format, replay viability

Detection

  • LoRaWAN networks have server-side anomaly detection (frame counter, signal strength, geographic) — varies widely by operator
  • Sub-GHz consumer products typically have no monitoring
  • TPMS / industrial equipment has minimal telemetry on RF anomalies

Reporting

  • Identify exact frequency, modulation, baud, and packet format per device
  • Distinguish capture-replay vs. crafted-frame attacks
  • Note crypto state (cleartext / weak-fixed-key / standards-compliant)
  • For LoRaWAN: identify AppKey / NwkSKey / AppSKey storage in firmware

Key References

© SnailSploit, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in Skills/wireless/offensive-lorawan-sub-ghz of SnailSploit/Claude-Red.

Open the folder on GitHubat commit 739512a

Compare with similar skills

Offensive Lorawan Sub Ghz next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Offensive Lorawan Sub Ghz compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Offensive Lorawan Sub Ghz this skillSnailSploit/Claude-Red7.3k—~1.7kAutomated safety check: PassMIT
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
KubeSphere ServiceMesh Managerkubesphere/kubesphere17k—~2.4kAutomated safety check: PassCustom licence
Vercelremotion-dev/remotion62k—~1.2kAutomated safety check: PassCustom licence
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT

Similar skills

  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Vercel

    remotion-dev/remotion

    Official

    Set up a Codex monitor for Vercel deployments and preview URLs.

    62k GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes

More from SnailSploit/Claude-Red

All 10 skills in this repo
  • Offensive Krack Fragattacks

    SnailSploit/Claude-Red

    KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.

    7.3k GitHub stars~1.1k tokensUpdated 19 days ago
    Auto-check: notes
  • Offensive Fuzzing

    SnailSploit/Claude-Red

    Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies…

    7.3k GitHub stars~3k tokensUpdated 19 days ago
    Auto-check: warnings
  • Offensive Mobile

    SnailSploit/Claude-Red

    Mobile (Android + iOS) application penetration testing methodology.

    7.3k GitHub stars~3.5k tokensUpdated 19 days ago
    Auto-check passed
  • Offensive Wifi

    SnailSploit/Claude-Red

    Wireless / 802.11 attack methodology for red team engagements and wireless security assessments.

    7.3k GitHub stars~2.8k tokensUpdated 19 days ago
    Auto-check: notes
  • Offensive Wps

    SnailSploit/Claude-Red

    WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout…

    7.3k GitHub stars~1.5k tokensUpdated 19 days ago
    Auto-check: notes
  • Offensive Z Wave

    SnailSploit/Claude-Red

    Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection…

    7.3k GitHub stars~1.3k tokensUpdated 19 days ago
    Auto-check passed

Categories

Questions about Offensive Lorawan Sub Ghz

What does Offensive Lorawan Sub Ghz do?

LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz…. Offensive Lorawan Sub Ghz is an agent skill from SnailSploit/Claude-Red. LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz protocol replay (KeeLoq garage doors, fixed-code remotes, TPMS spoofing, smart plug telemetry), HackRF / RTL-SDR / Flipper Zero workflows, signal analysis with Inspectrum / Universal Radio Hacker, and reconstruction of proprietary packet formats.

When should I use Offensive Lorawan Sub Ghz?

Offensive Lorawan Sub Ghz fits situations like: loRaWAN deployments (smart cities; industrial telemetry); any wireless device using the unlicensed 433/868/915 MHz bands (garage openers.

How do I install Offensive Lorawan Sub Ghz in Claude Code?

Run `npx skills add SnailSploit/Claude-Red --skill offensive-lorawan-sub-ghz -a claude-code`. Or copy the skill folder (Skills/wireless/offensive-lorawan-sub-ghz in SnailSploit/Claude-Red) into .claude/skills/offensive-lorawan-sub-ghz in your project. Claude Code loads it when a task matches its description.

How do I install Offensive Lorawan Sub Ghz in Codex?

Run `npx skills add SnailSploit/Claude-Red --skill offensive-lorawan-sub-ghz -a codex`. Or copy the skill folder (Skills/wireless/offensive-lorawan-sub-ghz in SnailSploit/Claude-Red) into .agents/skills/offensive-lorawan-sub-ghz in your project. Codex loads it when a task matches its description.

Can I use Offensive Lorawan Sub Ghz in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SnailSploit/Claude-Red --skill offensive-lorawan-sub-ghz -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/offensive-lorawan-sub-ghz, .gemini/skills/offensive-lorawan-sub-ghz, .github/skills/offensive-lorawan-sub-ghz and .opencode/skills/offensive-lorawan-sub-ghz in your project.

What does Offensive Lorawan Sub Ghz need to run?

Going by SKILL.md and its folder, Offensive Lorawan Sub Ghz needs the command-line tools its instructions call (git and python). Our summary lists: Python 3.

Does Offensive Lorawan Sub Ghz access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Offensive Lorawan Sub Ghz safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Offensive Lorawan Sub Ghz use?

Offensive Lorawan Sub Ghz is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Offensive Lorawan Sub Ghz use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Offensive Lorawan Sub Ghz?

Skills that share tags, products or a category with Offensive Lorawan Sub Ghz: Kubeshark Installer (kubeshark/kubeshark, 12k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), KubeSphere ServiceMesh Manager (kubesphere/kubesphere, 17k stars) and Vercel (remotion-dev/remotion, 62k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Offensive Lorawan Sub Ghz?

SnailSploit (a GitHub user) maintains it in SnailSploit/Claude-Red, which has 7,340 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 19, 2026.

Source: SnailSploit/Claude-Red on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.