Skip to content

Repository files navigation

cellular

Notes, tools, and reverse-engineering findings for working with cellular modems — the cards and modules inside phones, hotspots, routers, and IoT gear.

The centerpiece is a small family of open tools, the diag* toolkit, for capturing and decoding the raw diagnostic logs a modem emits. Put a modem into diagnostic mode and it streams a firehose of its own internal signaling — every cell it sees and how strong each signal is, every GNSS fix, every LTE/5G measurement — as opaque binary log records. These tools capture that stream and turn it into named, typed, readable fields.

The rest of this repo is a growing collection of per-device notes, guides, and cross-vendor references built up along the way.


The diag* toolkit

Getting usable data out of a modem's diagnostic interface is a short pipeline. Two tools do the main job:

  connected modem              capture                decode
  (USB or network)  ──▶  diaggulp  ──▶  raw log file  ──▶  diaggrok  ──▶  named fields
                                                                          → your analysis
  • diaggulp — capture. The program you actually run. Point it at a connected modem (over USB or the network) and it records the raw diagnostic log stream to a file. Most people start here.
  • diaggrok — decode. The star of the show. It takes those raw log bytes and hands back named, typed fields — turning cryptic log codes and opaque payloads into readable data: signal strength, serving and neighbor cells, GNSS fixes, LTE/5G measurements. It won't guess: a record whose byte layout it hasn't actually reverse-engineered and verified is left undecoded, never filled in with plausible-looking but wrong values.

Two more pieces make those work — and stand on their own:

  • diagmunge — transport + formats. The shared core the other tools lean on: moving diagnostic frames over serial/USB/TCP/UDP and converting between capture formats. Useful by itself if you're building your own pipeline.
  • diagbarf — optional on-device egress. A small helper for the minority of setups where you can't reach the modem's diagnostic port from your host. Most people never need it; it feeds the same pipeline.

Each tool does one thing well and is useful on its own — capture without decode, decode without capture, transport without either. Take just the part you need, or build on any single piece. They're small and permissively licensed on purpose: easy to share, easy to build on.


Guides & how-tos

Task-oriented walkthroughs, drawn from the per-device notes below:


Kernel patches & host tools

Cross-vendor building blocks, not tied to one device:

  • ADB-over-MHI — root shell on a PCIe/MHI modem — patches for Quectel's out-of-tree pcie_mhi driver that expose /dev/mhi_ADB (channels 36/37), plus a kernel 6.8–7.0 build port. Validated on Quectel RM520N-GL-AP and Foxconn T99W640 / Dell DW5934e.
  • mhi-adb tools — mhi_adb_probe.py (verify adbd is answering on the channel) and mhi_adb_bridge.py (relay /dev/mhi_ADB to adb connect 127.0.0.1:6555).

Modules & devices

Per-module notes: identity, AT commands, firmware captures, and quirks.

Casa Systems

Compal

Foxconn

Orbic

Quectel

Telit


References

  • Cellular Modem Scan Commands Reference — Cross-vendor comparison of AT commands that return cell tower observations. Covers Fibocom, Quectel, Sierra Wireless, SIMCom, and Telit modems with data field matrices, WiGLE submission compatibility, and scan strategy recommendations.

Elsewhere

Information

Tools

Blogs

Privacy

Unsorted


Quests


Prior art & thanks

QCSuper, SCAT, and osmo-qcdiag blazed this trail — they reverse-engineered and documented the DIAG protocol in the open over many years, and they're the reason tools like these can exist. This toolkit makes a different set of tradeoffs (small composable pieces, a permissive license), not a judgment on theirs — and it's built to compose with that ecosystem: the capture tools emit the same HDLC/DLF stream those tools already read.


License

The diag* tools are released under the Apache License 2.0 — a permissive license that makes them easy to share, embed, and build on. See each tool's repository for its own LICENSE and NOTICE.

The notes, guides, and references in this repository are the author's own work, shared for the community.

About

A place for my notes and ramblings about all things cellular

Resources

Stars

14 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages