Notes, tools, and reverse-engineering findings for working with cellular modems — the cards and modules inside phones, hotspots, routers, and IoT gear.
The centerpiece is a small family of open tools, the diag* toolkit, for capturing and decoding the raw diagnostic logs a modem emits. Put a modem into diagnostic mode and it streams a firehose of its own internal signaling — every cell it sees and how strong each signal is, every GNSS fix, every LTE/5G measurement — as opaque binary log records. These tools capture that stream and turn it into named, typed, readable fields.
The rest of this repo is a growing collection of per-device notes, guides, and cross-vendor references built up along the way.
Getting usable data out of a modem's diagnostic interface is a short pipeline. Two tools do the main job:
connected modem capture decode
(USB or network) ──▶ diaggulp ──▶ raw log file ──▶ diaggrok ──▶ named fields
→ your analysis
diaggulp— capture. The program you actually run. Point it at a connected modem (over USB or the network) and it records the raw diagnostic log stream to a file. Most people start here.diaggrok— decode. The star of the show. It takes those raw log bytes and hands back named, typed fields — turning cryptic log codes and opaque payloads into readable data: signal strength, serving and neighbor cells, GNSS fixes, LTE/5G measurements. It won't guess: a record whose byte layout it hasn't actually reverse-engineered and verified is left undecoded, never filled in with plausible-looking but wrong values.
Two more pieces make those work — and stand on their own:
diagmunge— transport + formats. The shared core the other tools lean on: moving diagnostic frames over serial/USB/TCP/UDP and converting between capture formats. Useful by itself if you're building your own pipeline.diagbarf— optional on-device egress. A small helper for the minority of setups where you can't reach the modem's diagnostic port from your host. Most people never need it; it feeds the same pipeline.
Each tool does one thing well and is useful on its own — capture without decode, decode without capture, transport without either. Take just the part you need, or build on any single piece. They're small and permissively licensed on purpose: easy to share, easy to build on.
Task-oriented walkthroughs, drawn from the per-device notes below:
- Root / ADB shell on a Foxconn T99W640 — get an unauthenticated root shell on the modem's application processor over ADB-over-MHI.
- Dump the
foxnvpartition (Foxconn T99W640) — pull the modem's NV/config partition for offline analysis. - GNSS on a stripped modem (Orbic RC400L) — a QMI LOC GNSS driver for MDM9207 devices whose stock GNSS stack was removed.
- Block carrier remote management (Casa Systems CFW-3212) — stop a carrier from remotely managing a 5G FWA CPE you own.
Cross-vendor building blocks, not tied to one device:
- ADB-over-MHI — root shell on a PCIe/MHI modem — patches for Quectel's out-of-tree
pcie_mhidriver that expose/dev/mhi_ADB(channels 36/37), plus a kernel 6.8–7.0 build port. Validated on Quectel RM520N-GL-AP and Foxconn T99W640 / Dell DW5934e. mhi-adbtools —mhi_adb_probe.py(verify adbd is answering on the channel) andmhi_adb_bridge.py(relay/dev/mhi_ADBtoadb connect 127.0.0.1:6555).
Per-module notes: identity, AT commands, firmware captures, and quirks.
- Casa Systems CFW-3212 — 5G FWA CPE (Qualcomm SDX62 / Quectel RG520N-NA OpenCPU). Root unlock tool and carrier remote management blocking guide.
- Compal RXM-G1 — 5G Sub-6 module / CPE gateway (Qualcomm SDX55). USB gadget composition guide (configfs, safe
optiondriver binding), AT command reference, C-V2X capability notes.
- Foxconn T99W640 — 5G module. Root ADB shell and
foxnvpartition dump guides.
- Orbic RC400L — LTE Cat 4 MiFi hotspot (Qualcomm MDM9207). QMI LOC GNSS driver for stripped MDM9207 devices.
- Quectel Overview
- Quectel BG95-M3 — LPWA module: NB-IoT / LTE Cat M1 (Qualcomm MDM9205). AT command docs and firmware captures.
- Quectel EC2x / EG2x (EG25-G) — LTE Cat 4 module (Qualcomm MDM9207). AT command docs, firmware captures, scanning commands.
- Quectel RM502Q — 5G Sub-6 module (Qualcomm SDX55). AT command docs.
- Telit Overview
- Telit LM960 — LTE Cat 18 module (Qualcomm SDX20). AT command docs and firmware captures.
- Cellular Modem Scan Commands Reference — Cross-vendor comparison of AT commands that return cell tower observations. Covers Fibocom, Quectel, Sierra Wireless, SIMCom, and Telit modems with data field matrices, WiGLE submission compatibility, and scan strategy recommendations.
Information
Tools
- QCSuper — capture raw 2G/3G/4G/5G radio frames from Qualcomm-based phones and modems.
- SCAT: Signaling Collection and Analysis Tool
- MobileInsight
Blogs
Privacy
- EFForg/rayhunter — worth watching; lots of extra logging that may be useful for PCI scanning/mapping (discussion).
- MarlinDetection/Marlin
Unsorted
Figure out a way to get geolocation data on the Rayhunter (context).Done — see the Orbic RC400L GNSS driver.
QCSuper, SCAT, and osmo-qcdiag blazed this trail — they reverse-engineered and documented the DIAG protocol in the open over many years, and they're the reason tools like these can exist. This toolkit makes a different set of tradeoffs (small composable pieces, a permissive license), not a judgment on theirs — and it's built to compose with that ecosystem: the capture tools emit the same HDLC/DLF stream those tools already read.
The diag* tools are released under the Apache License 2.0 — a permissive license that makes them easy to share, embed, and build on. See each tool's repository for its own LICENSE and NOTICE.
The notes, guides, and references in this repository are the author's own work, shared for the community.