Penetration Testing of 5G Mobile Communications
Training Description
Characteristics
5G networks introduce a different risk profile compared to previous generations: greater reliance on cloud and virtualization, an expanded control layer, network slicing, a massive number of IoT devices, and complex authentication and encryption mechanisms. As a result, traditional security testing approaches are insufficient; a testing model is needed that accounts for 5G architecture, interfaces, dependencies, and realistic abuse scenarios.
This training is a practical workshop focused on authorized penetration testing of 5G mobile communications. Participants will learn methods for identifying attack surfaces, building test plans, selecting tools, and conducting tests in a way that is safe for the environment (controlling impact on service availability and ensuring compliance with requirements). Great emphasis is placed on interpreting results, prioritizing risks, and preparing reports and remediation recommendations.
Note: The training is conducted exclusively for defensive purposes. All exercises are performed in a laboratory environment or on systems to which the organization has unambiguous consent for testing.
Training Objectives
- Understanding key elements of 5G architecture (NR, mmWave, Massive MIMO, beamforming, slicing) and their security implications.
- Identifying the attack surface in a 5G network: interfaces, dependencies, radio layer, core, cloud elements, and integrations.
- Designing a security plan and 5G testing model (scope, scenarios, success criteria, limitations).
- Selecting and safely using testing tools—from reconnaissance to vulnerability validation.
- Conducting penetration tests (in a lab) and assessing the impact on confidentiality, integrity, and availability.
- Fundamentals of incident forensics in the context of 5G and preparing hardening and monitoring recommendations.
- Understanding testing standards and best practices, and how to utilize them in security control audits.
Book the Training
- Format: Remote
- Language: Polish
- Type: Open training, guaranteed
- Date: 9-11.03.2026
- Duration: 3 days (7 hours/day)
- Trainer: Tomasz Siroń
- Level: Intermediate / Advanced (cybersecurity, networks, telecommunications).
- Outcome: Participants will be able to plan and conduct authorized security tests of 5G components, interpret results, and prepare recommendations.
Net price per participant.
Participant Profile
The training is recommended for:
- cybersecurity specialists, pentesters, red team / blue team, SOC/CSIRT
- network and telecommunications engineers (RAN, Core), 5G solution architects
- persons responsible for IoT security and cloud environments supporting mobile services
- technical auditors and GRC teams who need to verify 5G security controls
Prerequisites
- Network engineers
- System administrators
- Infrastructure maintenance specialists
- People working with network devices (e.g., Cisco/Juniper) and laboratory environments
- Testers and DevOps/SREs who need practical Linux skills in the area of networks and infrastructure services
Prerequisites
Participants should have basic knowledge of:
- TCP/IP networks, DNS, routing, and fundamental network security
- Linux (console, network tools), basic scripting (welcome)
- Concepts in cellular telecommunications (LTE/5G high-level) – if lacking, the trainer will provide the necessary minimum.
Methodology and Form of Classes
- Brief theory + demonstrations + laboratory exercises (hands-on).
- Working with scenarios: from building a testing model, through tests, to reports and recommendations.
- Quality checkpoints: verification of scope, risk, and impact on availability (anti-outage).
- Materials: test checklists, test plan template, report template, list of standards and sources.
Sample Laboratory Exercises (to be adapted)
Depending on the form of training and infrastructure availability, laboratories may include:
- Mapping 5G architecture/client environment to a testing model and preparing scope and test security rules.
- Building a test checklist for network slicing, cloud supporting 5G, and IoT integration.
- Executing a controlled test scenario (reconnaissance → validation → evidence → recommendations).
- Log and telemetry analysis for forensics (event correlation, timeline, causal hypotheses).
- Preparing a brief final report and presenting results in the language of business risk.
Training Environment and Organization
- Laboratory environment (recommended): isolated, with monitoring and ability for quick rollback.
- Access to tools and permissions limited to the minimum necessary for exercises (principle of least privilege).
- Possibility of remote implementation using virtual desktops/labs (option DaDesktop).
Materials, Outcomes and Next Steps
- Training materials: handout + checklists + document templates (test plan, report)
- Training completion certificate
- Trainer recommendations: areas for further strengthening (hardening, monitoring, IR processes, automation)
Training Program
1. Introduction
- Challenges in testing 5G networks: architectural complexity, multi-access, low latency, critical services.
- Threat models: attacks on the user, operator, service provider/IoT, and the cloud layer.
- Rules for conducting tests safely and legally: scope, consents, activity logging, test interruption plan.
2. Overview of 5G Functions and Architecture
- New Radio (NR): components, basic interfaces, and typical risk points.
- Millimeter waves: mmWave specifics and consequences for reliability, availability, and security.
- Massive MIMO and beamforming: impact on connectivity and potential vectors of abuse.
- Network slicing (network slicing): isolation, policies, risk of "leaks" and misconfigurations.
3. 5G Deployment Phases
- Technology verification and validation: what to test earliest to avoid cementing risk in the project.
- Deployment, activation, and scaling: critical controls, operational requirements, and monitoring.
- Warranty, optimization, monetization: change management, SLA, compliance, and regression testing.
4. 5G Encryption
- Resilience and communication security: protection of data in transit and at rest.
- Identity management: devices, users, services; common IAM errors and risks.
- Privacy and security guarantees: data minimization, metadata, compliance with organizational requirements.
5. Case Study: Hacking 5G
- Scenario analysis and mapping the attack chain (reconnaissance → access → escalation → persistence → exfiltration/disruption).
- Lessons learned: how to design controls to limit the effectiveness of similar attacks.
6. Overview of 5G Testing Tools
- Tool classes: reconnaissance, protocol analysis, API testing, configuration testing, cloud/CI/CD assessment.
- Selecting tools for the goal: accuracy vs. speed, risk to availability.
- Building a "toolbox" and work hygiene: logging, versioning, repeatability, automation.
7. Creating a Security Plan
- Scope and test boundaries (in-scope / out-of-scope), roles and responsibilities, escalation channels.
- Risk model and priority: confidentiality, integrity, availability, and impact on critical services.
- Success criteria: metrics, evidence, reporting requirements.
8. Creating a 5G Testing Model
- Mapping architecture to attack vectors: RAN, Core, cloud, IoT, VoWiFi.
- Test scenarios: configuration vulnerabilities, integration errors, identity abuses, availability attacks.
- Lab design: monitoring, impact control, rollback plan.
9. 5G Penetration Testing
- Reconnaissance and enumeration of network elements and accompanying services (APIs, portals, integrations).
- Vulnerability validation and evidence preparation without risking downtime (safe proof).
- Prioritizing remediation: quick wins vs. architectural changes.
- Report: vulnerability description, business impact, recommendations, and action plan.
10. Case Study: Cyberattack and Vulnerabilities in Mobile Networks
- Root cause analysis (RCA): what failed in controls and processes.
- Recommendations: hardening, detection, response, regression testing.
11. Cloud Communication Security
- Cloud-native risks: IAM, network, storage, secrets, CI/CD.
- Security and testing: policies, segmentation, traffic control, monitoring, and alerting.
12. IoT Device Security
- IoT risks in 5G: scale, heterogeneity, updates, telemetry.
- Device and integration verification: identity, certificates, OTA, APIs.
- IoT threat modeling and test scenarios.
13. VoWiFi Security
- VoWiFi architecture and critical points: authentication, call setup, QoS.
- Tests and common problems: configuration errors, privacy risks, companion service vulnerabilities.
14. Ensuring Data Quality for Baseband Hardware
- Importance of telemetry quality for security and anomaly detection.
- Verifying correctness of logs, metrics, and signals from edge devices.
15. 5G Monitoring
- What to monitor: RAN, core, cloud, IoT, VoWiFi, traffic, and security events.
- Building use-cases for detection and mapping to attack scenarios.
16. Case Study: Financial Fraud via Mobile Networks
- Abuse mechanisms: account takeover, phishing, fraud, identity manipulation.
- Controls: authentication, detection, response, and stakeholder communication.
17. 5G Forensics
- Principles of securing evidence and minimizing impact on production.
- Data correlation: logs, metrics, network traces, cloud artifacts.
- Post-incident conclusions and regression testing.
18. 5G Security Control Audit
- Verification of controls: policies, configurations, operational processes, monitoring, IR.
- Audit report: requirements, evidence, priorities, action plan.
19. 5G Security Automation
- Test and control automation: scanning, configuration validation, security gates in CI/CD.
- Secure automation: versioning, change control, privilege limitation.
20. Cost Control of 5G Testing
- Budget planning: laboratory, tools, licenses, team time, downtime risk.
- Strategy: highest value tests vs. cost, minimum viable control set (MVP).
21. Standards and Testing Best Practices
- Overview of standards and best practices (organizational and technical).
- How to translate standards into checklists, criteria, and reports for stakeholders.
22. Summary and Conclusions
- Key risks and quick wins for improving 5G security.
- Plan for further actions: improvement roadmap, supplementary training, periodic testing.
No funds in the budget? Get funding!
A program that allows you to easily and quickly obtain funds for training for individual people.
Why guaranteed training?
- Guarantee of implementation. The training will take place regardless of the number of participants.
- Exchange of knowledge and experience with specialists from other industries.
- Interactive, live-led classes. Not just theory, but also practical exercises and discussions.
- Flexible remote format. Join from anywhere.
Need Help?
Reach out to learn more about our team and the kinds of tailored solutions we can offer your organization.
Get in Touchwroclaw@nobleprog.pl or +48 (22) 103 3718