Included tools

Every tool in every RF Swift toolbox, the architectures it runs on, and how to add the ones that are not installed by default.

Reference · 44 min read · Updated September 27, 2026

This page lists the tools inside each RF Swift toolbox (container image). It is a reference: you don’t need to read it from top to bottom. If you are still choosing a toolbox, start with Choose a toolbox.

How to use this page

  • Find a tool. Long tables have a filter box above them: type part of a name to narrow the table down. To search the whole documentation at once, press Ctrl K.

  • Read the status columns.

    • Yes: the tool is installed by default: it is in the image when you pull or build it.
    • No: install it manually: the image ships an installation function for it, which you run after creating your lab.
    • Limited: the tool may have architecture-specific issues.
  • Add a tool marked No. Create your lab, then run the function named in the Installation function column:

    bash
    rfswift container install -c my_lab -i <installation_function_name>

    Leave out -i to pick the function from a searchable list. Add more software compares this with the other ways to add tools, and container install has every option.

RF Swift is in active development: the tool collection is regularly expanded and optimized for all supported architectures.

Image hierarchy

Each RF Swift image builds upon a foundation of tools, with specialized images adding domain-specific capabilities: corebuild is the base, sdrsa_devices adds the SDR drivers, sdr_light builds on it, sdr_full on sdr_light, and so on. The full diagram is in Choose a toolbox. A tool listed for a base image is also in every image built on it.

Tools by image

Core SDR device support

The sdrsa_devices image serves as the foundation for many RF Swift images, providing essential drivers and utilities for software-defined radio hardware.

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
UHD tools and libs USRP Hardware Driver - Universal driver for Ettus Research USRP devices uhd_adc_self_cal | uhd_fft | uhd_rx_cfile | uhd_cal_rx_iq_balance | uhd_find_devices | uhd_rx_nogui | uhd_cal_tx_dc_offset | uhd_image_loader | uhd_siggen | uhd_cal_tx_iq_balance | uhd_images_downloader | uhd_siggen_gui | uhd_config_info | uhd_modes.py | uhd_usrp_probe Yes Yes Yes uhd_devices_install Yes
RTL-SDR tools and libs RTL-SDR driver and tools for RTL2832U-based DVB-T receivers rtl_biast | rtl_fm | rtl_sdr | rtl_test | rtl_adsb | rtl_eeprom | rtl_power | rtl_tcp Yes Yes Yes rtlsdr_devices_install Yes
RTL-SDR v4 tools Enhanced RTL-SDR Blog v4 driver with improved performance rtl_biast | rtl_fm | rtl_sdr | rtl_test | rtl_adsb | rtl_eeprom | rtl_power | rtl_tcp Yes Yes Yes rtlsdrv4_devices_install No, (optional alternative)
libiio and libad9361 Industrial I/O and AD9361 library for PlutoSDR and similar devices iio_adi_xflow_check | iio_attr | iio_genxml | iio_info | iio_readdev | iio_reg | iio_stresstest | iio_writedev Yes Yes Yes ad_devices_install Yes
Nuand bladeRF tools bladeRF SDR tools and libraries built from source bladeRF-cli | bladeRF-fsk Yes Yes Yes nuand_devices_fromsource_install Yes
HackRF tools and lib HackRF One SDR platform tools and libraries hackrf_clock | hackrf_debug | hackrf_operacake | hackrf_sweep | hackrf_cpldjtag | hackrf_info | hackrf_spiflash | hackrf_transfer Yes Yes Yes hackrf_devices_install Yes
Airspy tools and lib Airspy R2/Mini and HF+ SDR receivers airspy_gpio | airspy_rx | airspyhf_info | airspy_gpiodir | airspy_si5351c | airspyhf_lib_version | airspy_info | airspy_spiflash | airspyhf_rx | airspy_lib_version | airspyhf_calibrate | airspy_r820t | airspyhf_gpio Yes Yes Yes airspy_devices_install Yes
LimeSDR tools and lib LimeSDR and LimeSDR Mini SDR platform LimeQuickTest | LimeSuiteGUI | LimeUtil Yes Yes Yes limesdr_devices_install Yes
Funcube tools and lib Funcube Dongle and Dongle Pro SDR receivers qthid-fcd-controller Yes Yes Yes funcube_devices_install Yes
XTRX tools and lib XTRX mini-PCIe SDR platform xtrx_fft Yes Yes Yes xtrx_devices_install Yes
OsmoFL2K tools and lib FL2000-based VGA adapter as SDR transmitter fl2k_file | fl2k_tcp | fl2k_fm | fl2k_test Yes Yes Yes osmofl2k_devices_install Yes
SignalHound Spike Spectrum analyzer software for SignalHound BB and SM series Spike Yes No No signalhound_spike_sa_device Yes
SignalHound VSG60 Signal generator software for VSG60 vector signal generator vsg60 Yes No No signalhound_vsg60_sa_device Yes
Harogic Devices SAStudio4 spectrum analyzer software for Harogic HTRA devices sastudio Yes Yes No harogic_sa_device Yes
RFNM RFNM SDR platform library and drivers librfnm Yes Yes Yes rfnm_devices_install Yes
LibreSDR B2x0 Open-source FPGA images for USRP B2x0 series libresdr_swapfpga Yes Yes Yes libresdr_b2x0_devices_install Yes
pocketVNA Vector Network Analyzer software for pocketVNA device pocketVNA Yes No No pocketvna_sa_device No, (install manually)
LiteX M2SDR LiteX-based M2SDR platform with SoapySDR drivers SoapySDR drivers Yes Yes Yes litexm2sdr_devices_install Yes
HydraSDR/RFOne tools HydraSDR RFOne SDR platform tools and libraries hydrasdr_gpio | hydrasdr_calibrate | hydrasdr_gpiodir | hydrasdr_lib_version | hydrasdr_reset | hydrasdr_set_rf_port | hydrasdr_spiflash | hydrasdr_info | hydrasdr_r82x | hydrasdr_rx | hydrasdr_si5351c Yes Yes Yes hydrasdr_rfone_install Yes
kalibrate-hydrasdr GSM frequency calibration tool for HydraSDR kal Yes Yes Yes kalibrate_hydrasdr_device Yes
USDR Library waveLab USDR software-defined radio library libusdr Yes Yes Yes usdr_lib_install Yes
ANTSDR UHD MicroPhase ANTSDR variant of UHD for ANTSDR devices Same as UHD tools Yes Yes Yes antsdr_uhd_devices_install No, (optional alternative to UHD)
SoapySDR modules Additional SoapySDR device modules (osmosdr rtlsdr bladerf hackrf uhd mirisdr rfspace) Various SoapySDR modules Yes Yes Yes install_soapy_modules Yes
SoapyPlutoSDR SoapySDR module for PlutoSDR devices SoapySDR PlutoSDR support Yes Yes Yes install_soapyPlutoSDR_modules Yes

Device-Specific Notes:

  • UHD vs ANTSDR: Choose either standard UHD or ANTSDR variant during build (mutually exclusive)
  • RTL-SDR versions: Standard rtl-sdr or rtlsdrv4 blog version (mutually exclusive)
  • Manual installation tools: SoapySDR modules, SoapyPlutoSDR, and pocketVNA require manual installation after container creation

Common device troubleshooting

RTL-SDR kernel module conflicts

If your RTL-SDR device is unavailable when using tools like nfc-spy, the DVB-T kernel module may have claimed it. Blacklist the module with:

bash
echo "blacklist dvb_usb_rtl28xxu" | sudo tee /etc/modprobe.d/blacklist-dvb_usb_rtl28xxu.conf

You’ll need to restart your host system after adding this blacklist entry.

PlutoSDR connection issues

If the PlutoSDR doesn’t appear with iio_info -s and you see errors like:

output
with backends: local xml ip usb
Unable to create Local IIO context : No such file or directory (2)
ERROR: Unable to create Avahi DNS-SD client :Daemon not running
Scanning for IIO contexts failed: Text file busy (26)

This can be resolved in two ways:

  1. On Linux hosts: Ensure avahi-daemon is running on your host system
  2. Inside the container: Run the Avahi daemon with:
    bash
    avahi-daemon --no-drop-root --no-rlimits

SDR light

The sdr_light image includes essential software-defined radio tools for signal capture, analysis, and basic decoding.

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
GNU Radio Open-source SDR toolkit and signal processing framework gnuradio-companion | gnuradio-config-info | gr_modtool | gr_plot_* | grcc Yes Yes Yes gnuradio_soft_install Yes
gr-osmosdr Common source/sink blocks for SDR hardware Part of GNU Radio Yes Yes Yes common_sources_and_sinks Yes
SoapySDR modules Device abstraction layer for SDR hardware SoapySDRUtil | SoapySDRServer Yes Yes Yes install_soapy_modules Yes
SoapyPlutoSDR PlutoSDR support for SoapySDR SoapySDR PlutoSDR module Yes Yes Yes install_soapyPlutoSDR_modules Yes
KC908 Spectrum Analyzer DEEPACE KC908 spectrum analyzer software KC908 Yes No No kc908_sa_device Yes
SoapyRFNM RFNM device support for SoapySDR SoapySDR RFNM module Yes Yes No soapyrfnm_grmod_install Yes
SoapyHydraSDR HydraSDR RFOne support for SoapySDR SoapySDR HydraSDR module Yes Yes Yes hydrasdr_rfone_soapy_install Yes
SoapyHarogic Harogic device support for SoapySDR SoapySDR Harogic module Yes Yes No soapyharogic_grmod_install Yes
gr-bladerf bladeRF GNU Radio blocks GNU Radio bladeRF blocks Yes Yes Yes grbladerf_grmod_install Yes
gr-signal-hound Signal Hound device GNU Radio support GNU Radio Signal Hound blocks Yes Yes No grsignalhound_Receiver_grmod_install Yes
gr-htra Harogic HTRA GNU Radio blocks GNU Radio HTRA blocks Yes No No grhtra_grmod_install Yes
GQRX Software-defined radio receiver powered by GNU Radio gqrx Yes Yes Yes gqrx_soft_install Yes
multimon-ng Digital decoder for multiple radio transmission modes multimon-ng Yes Yes Yes multimon_ng_soft_install Yes
Universal Radio Hacker (URH) Wireless protocol investigation and reverse engineering urh Yes Yes Yes urh_soft_install Yes
Inspectrum Offline radio signal analyzer inspectrum Yes Yes Yes inspectrum_soft_install Yes
rtl_433 Generic data receiver for ISM band devices rtl_433 Yes Yes Yes rtl_433_soft_install Yes
retrogram-rtlsdr Retro text-mode spectrogram for rtl-sdr retrogram-rtlsdr Yes Yes Yes retrogram_soapysdr_soft_install Yes
LuaRadio Lightweight real-time SDR framework in Lua luaradio Yes Yes Yes luaradio_sdr_soft_install Yes
dump1090 Mode S ADS-B decoder for aircraft tracking dump1090 Yes Yes Yes dump1090_soft_install Yes
readsb Improved Mode S/ADS-B decoder readsb Yes Yes Yes readsb_soft_install Yes
dumpvdl2 VDL Mode 2 decoder for aircraft ACARS dumpvdl2 Yes Yes Yes dumpvdl2_soft_install Yes
dumphfdl HFDL decoder for HF aircraft communications dumphfdl Yes Yes Yes dumphfdl_soft_install Yes
SDR++ Cross-platform SDR software with modern interface sdrpp Yes Yes Yes sdrpp_soft_fromsource_install Yes
SDR++ Extra Modules Additional demodulators and sources for SDR++ SDR++ plugins Yes Yes Yes sdrpp_extramodules_install Yes
Jupyter Notebook Interactive computing environment for SDR experiments jupyter | jupyter-notebook Yes Yes Yes jupyter_soft_install Yes
Leo Bodnar GPSDO v1 Calibration tool for Leo Bodnar GPS reference v1 leobodnar-gpsdo-v1 Yes Yes Yes leobodnarv1_cal_device Yes
Leo Bodnar GPSDO v2 Calibration tool for Leo Bodnar GPS reference v2 leobodnar-gpsdo-v2 Yes Yes Yes leobodnarv2_cal_device Yes
KCSDI Calibration utilities for KC series devices kcsdi Yes Yes Yes KCSDI_cal_device Yes
NanoVNASaver VNA software for NanoVNA devices NanoVNASaver Yes Yes Yes NanoVNASaver_cal_device Yes
NanoVNA-QT Qt-based software for NanoVNA nanovna-qt Yes Yes Yes NanoVNA_QT_cal_device Yes
GNSSLogger GNSS logging and calibration tool gnsslogger Yes Yes Yes gnsslogger_cal_device Yes
LibreVNA Open-source Vector Network Analyzer software LibreVNA Yes Yes Yes librevna_cal_device_buildx Yes
xnec2c NEC2 antenna modeling software xnec2c Yes Yes Yes xnec2c_cal_device No, (broken - fix source)
GNSS-SDR Global Navigation Satellite Systems software receiver gnss-sdr Yes Yes Yes gnss_sdr_soft_install Yes
Artemis SDR-based RF spectrum monitoring artemis Yes Yes Yes artemis_soft_install Yes
GQRX Scanner Frequency scanner plugin for GQRX gqrx-scanner Yes Yes Yes gqrxscanner_sdr_soft_install Yes
Lotus BUDC Tuner Lotus BUDC tuning device support lotus-budc Yes Yes Yes lotus_budc_tune_device Yes
intercept Signal Intelligence Platform /rftools/sdr/intercept Yes Yes Yes intercept_soft_install No
gr-hydrasdr GNU Radio OOT source block for HydraSDR (PentHertz fork) GNU Radio hydrasdr source block Yes Yes Yes grhydrasdr_grmod_install Yes
hydrasdr_433 rtl_433-style decoder for HydraSDR receivers hydrasdr_433 Yes Yes Yes hydrasdr433_soft_install Yes
FISSURE RF and reverse-engineering framework (AInfoSec) in an isolated venv reusing the image SDR stack fissure Yes Yes Limited fissure_soft_install Yes

Tool Locations: Most SDR tools are installed in standard system paths (/usr/bin, /usr/local/bin), with specialized tools in:

  • /rftools/sdr/ - SDR-specific applications
  • /rftools/sdr/oot/ - GNU Radio out-of-tree modules
  • /rftools/analysers/ - Spectrum analyzer software
  • /rftools/generators/ - Signal generator software

New in v3.0.0

FISSURE, the AInfoSec RF framework, is installed in a dedicated virtual environment created with --system-site-packages so it reuses the GNU Radio, SoapySDR and driver stack already present in the image instead of pip-installing its own pinned copies over your system Python. Launch it with fissure. HydraSDR support also lands here, with the gr-hydrasdr GNU Radio source block and the hydrasdr_433 decoder.

SDR full

The sdr_full image builds on sdr_light to provide a complete SDR development and analysis environment, including GNU Radio and specialized plugins.

GNU Radio out-of-tree modules

These modules extend GNU Radio’s capabilities for specific protocols and signal types:

Tool(s)Descriptionamd64aarch64riscv64Installation functionInstalled by default
gr-osmosdr Common source/sink blocks for various SDR hardware Yes Yes Yes common_sources_and_sinks Yes
gr-gsm GSM/GPRS/EDGE baseband processor for GNU Radio Yes Yes Yes grgsm_grmod_install Yes
gr-lora LoRa PHY implementation for GNU Radio Yes Yes Yes grlora_grmod_install Yes
gr-lora_sdr Alternative LoRa SDR implementation with better decoding Yes Yes Yes grlorasdr_grmod_install Yes
gr-iridium Iridium satellite communication decoder Yes Yes Yes griridium_grmod_install Yes
gr-inspector Signal analysis and classification toolkit Yes Yes Yes grinspector_grmod_install Yes
gr-uaslink Unmanned Aerial System datalink decoder Yes Yes Yes gruaslink_grmod_install Yes
gr-X10 X10 home automation protocol decoder Yes Yes Yes grX10_grmod_install Yes
gr-gfdm Generalized Frequency Division Multiplexing implementation Yes Yes Yes grgfdm_grmod_install Yes
gr-aaronia_rtsa Aaronia real-time spectrum analyzer support Yes Yes Yes graaronia_rtsa_grmod_install Yes
gr-ccsds CCSDS (space communications) protocol support No No No grccsds_move_rtsa_grmod_install No, (broken - strtod_l issue)
gr-ais Automatic Identification System (AIS) decoder Yes Yes Yes grais_grmod_install Yes
gr-aistx AIS transmitter blocks Yes Yes Yes graistx_grmod_install Yes
gr-air-modes Mode S/ADS-B aircraft transponder decoder Yes Yes Yes grairmodes_grmod_install Yes
gr-dvbs2 DVB-S2 digital video broadcasting decoder Yes Yes Yes grdvbs2_grmod_install Yes
gr-tempest TEMPEST electromagnetic emanations receiver Yes Yes Yes grtempest_grmod_install Yes
deep-tempest Deep learning-based TEMPEST for screen reconstruction No No No deeptempest_grmod_install No, (see sdr_deeptemptest_beta image)
gr-dab Digital Audio Broadcasting (DAB/DAB+) decoder Yes Yes Yes grdab_grmod_install Yes
gr-dect2 DECT (cordless phone) protocol decoder Yes Yes Yes grdect2_grmod_install Yes
gr-foo Miscellaneous GNU Radio blocks and utilities Yes Yes Yes grfoo_grmod_install Yes
gr-ieee802-11 WiFi (802.11a/g/p) transceiver implementation Yes Yes Yes grieee802-11_grmod_install Yes
gr-ieee802-11ah WiFi HaLow (802.11ah) sub-1GHz implementation Yes Yes Yes grieee802-11ah_grmod_install Yes
gr-ieee80211 (gr-wifi) Alternative WiFi implementation Yes Yes Yes grieee80211-grwifi_grmod_install Yes
gr-ieee802-15-4 ZigBee and 802.15.4 PHY/MAC implementation Yes Yes Yes grieee802154_grmod_install Yes
gr-rds Radio Data System (RDS) encoder/decoder Yes Yes Yes grrds_grmod_install Yes
gr-droneid DJI DroneID and RemoteID decoder Yes Yes Yes grdroineid_grmod_install Yes
gr-satellites Satellite telemetry decoder (100+ satellites) Yes Yes Yes grsatellites_grmod_install Yes
gr-adsb ADS-B aircraft transponder decoder Yes Yes Yes gradsb_grmod_install Yes
gr-keyfob Car key fob signal analyzer Yes Yes Yes grkeyfob_grmod_install Yes
gr-radar Radar signal processing toolkit Yes Yes Yes grradar_grmod_install Yes
gr-nordic Nordic Semiconductor protocol decoder (nRF24L01+) Yes Yes Yes grnordic_grmod_install Yes
gr-paint Spectrum painting and waterfall annotation Yes Yes Yes grpaint_grmod_install Yes
gr-pdu_utils Protocol Data Unit utilities from Sandia Yes Yes Yes grpdu_utils_grmod_install Yes
gr-sandia_utils Sandia National Labs signal processing blocks Yes Yes Yes grsandia_utils_grmod_install Yes
gr-timing_utils Timing and synchronization utilities from Sandia Yes Yes Yes grtiming_utils_grmod_install Yes
gr-fhss_utils Frequency Hopping Spread Spectrum utilities Yes Yes Yes grfhss_utils_grmod_install Yes
gr-zwave_poore Z-Wave home automation protocol decoder Yes Yes Yes grzwavepoore_grmod_install Yes
gr-mixalot POCSAG pager protocol encoder Yes Yes Yes grmixalot_grmod_install Yes
gr-reveng CRC and checksum reverse engineering Yes Yes Yes grreveng_grmod_install Yes
gr-DCF77_Receiver DCF77 time signal receiver Yes Yes Yes gr_DCF77_Receiver_grmod_install Yes
gr-j2497 MIL-STD-1553 and MIL-STD-1397 decoder Yes Yes Yes grj2497_grmod_install Yes
gr-m17 M17 digital voice protocol implementation Yes Yes Yes grm17_grmod_install Yes
gr-grnet Network socket blocks for GNU Radio Yes Yes No grgrnet_grmod_install Yes
gr-aoa Angle of Arrival estimation Yes Yes Yes graoa_grmod_install Yes
gr-correctiq IQ correction algorithms for SDR devices Yes Yes Yes grcorrectiq_grmod_install Yes
gr-dsd Digital Speech Decoder (P25 DMR NXDN) Yes Yes Yes grdsd_grmod_install Yes
gr-nrsc5 HD Radio (NRSC-5) decoder Yes Yes Yes grnrsc5_grmod_install Yes
gr-ntsc-rc NTSC video signal processing Yes Yes Yes grntscrc_grmod_install Yes
gr-nfc NFC (Near Field Communication) PHY Yes Yes Yes grnfc_grmod_install Yes
gr-fosphor GPU-accelerated spectrum analyzer (requires GPU) Yes Limited Limited grfosphor_grmod_install (GPU images only)
gr-mer Modulation Error Ratio measurement Yes Yes Yes grmer_grmod_install Yes
gr-flarm FLARM aircraft collision avoidance decoder Yes Yes Yes grflarm_grmod_install Yes
gr-guiextra Additional GUI widgets and displays Yes Yes Yes grguiextra_grmod_install Yes
gr-rftap RF tap blocks for protocol analysis Yes Yes Yes grrftap_grmod_install Yes
gr-radio_astro Radio astronomy signal processing Yes Yes Yes grradioastro_grmod_install Yes
gr-cessb Controlled Envelope Single Sideband modulation Yes Yes Yes grcessb_grmod_install

Known Issues:

  • gr-ccsds: Currently broken due to strtod_l dependency issues
  • deep-tempest: Available in separate sdr_deeptempest_beta image due to specific dependencies
  • gr-fosphor: Only included in GPU-enabled builds (requires OpenCL/CUDA)
  • gr-signal-hound: Requires manual installation (architecture-specific)

Additional SDR software

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
CyberEther Real-time SDR signal analyzer with GPU acceleration cyberether Yes Yes Yes cyberther_soft_install Yes
SigDigger Advanced signal analyzer for reverse engineering SigDigger Yes Yes Yes sigdigger_soft_install Yes
QSSTV Slow-scan television (SSTV) transceiver qsstv Yes Yes Yes qsstv_soft_install Yes
nfc-laboratory NFC protocol analyzer and emulator nfc-laboratory Yes Yes Yes nfclaboratory_soft_install Yes
ice9-bluetooth Bluetooth Classic sniffer ice9-bluetooth Yes No No ice9_bluetooth_soft_install Yes
Meshtastic SDR Meshtastic mesh network SDR tools meshtastic-sdr Yes Yes Yes meshtastic_sdr_soft_install Yes
GPS-SDR-SIM GPS signal simulator gps-sdr-sim Yes Yes Yes gps_sdr_sim_soft_install Yes
Gpredict Real-time satellite tracking and orbit prediction gpredict Yes Yes Yes gpredict_sdr_soft_install Yes
V2Verifier V2X message verification tool v2verifier Yes Yes Yes v2verifier_sdr_soft_install Yes
wavingZ Z-Wave protocol analyzer wavingz Yes Yes Yes wavingz_sdr_soft_install Yes
PySpecSDR Python spectrum analyzer pyspecsdr Yes Yes Yes pyspecsdr_sdr_soft_install Yes
AIS Catcher Automatic Identification System decoder aiscatcher Yes Yes Yes AIScatcher_soft_install Yes
TetraKit TETRA digital radio toolkit tetrakit Yes Yes Yes tetrakit_soft_install Yes
TetraKit Player TETRA voice player tetrakit-player Yes Yes Yes tetrakitplayer_soft_install Yes
TETRA Suite Complete TETRA decoder (osmo-tetra telive) osmo-tetra | telive Yes Yes Yes tetra_suite_install Yes
OP25 APCO Project 25 decoder op25 Yes Yes Yes op25_soft_install Yes
Trunk Recorder Multi-channel trunked radio recorder trunk-recorder Yes Yes Yes trunkrecorder_soft_install Yes
SatDump Universal satellite data processing software satdump | satdump-ui Yes Yes Yes satdump_sdr_soft_install Yes
SDRangel Multi-platform SDR software with extensive plugins sdrangel Yes Yes Yes sdrangel_soft_fromsource_install Yes
ML and DL Libraries Machine learning libraries for signal processing (numpy pandas scikit-learn tensorflow) Python ML/DL modules Yes Yes Yes ml_and_dl_soft_install Yes
GPU Drivers - NVIDIA NVIDIA GPU compute drivers for acceleration nvidia-smi | nvidia-settings Yes Yes Yes install_GPU_nvidia Yes
GPU Drivers - Intel Intel GPU compute drivers intel-gpu-tools Yes Yes Yes install_GPU_Intel Yes
GPU Drivers - Radeon (up to 5000) AMD Radeon GPU drivers for older cards rocm-smi Yes Yes Yes install_GPU_Radeon_until5000 Yes
GPU Drivers - Radeon (latest) AMD Radeon GPU drivers for latest cards rocm-smi Yes Yes Yes install_GPU_latest_Radeon Yes
gr-fosphor GPU-accelerated FFT and display for GNU Radio GNU Radio fosphor blocks Yes Limited Limited grfosphor_grmod_install Yes
ACARSdec ACARS aircraft communication decoder acarsdec Yes Yes Yes acarsdec_soft_install No, (need to fix the install)
QRadioLink VoIP and digital radio over IP qradiolink Yes Yes Yes qradiolink_soft_install No, (install manually)
HydraSDR 433 HydraSDR 433MHz ISM band toolkit hydrasdr433 Yes Yes Yes hydrasdr433_soft_install Yes
RFQuack IoT-focused RF analysis framework rfquack Yes Yes Yes rfquak_soft_install No, (install manually)

Major Software Suites:

  • SDR++: Modern cross-platform SDR software with plugin support
  • SDRAngel: Advanced SDR software with extensive plugin ecosystem
  • GQRX: Popular SDR receiver powered by GNU Radio
  • SigDigger: Signal analysis and reverse engineering tool
  • URH: Universal Radio Hacker for wireless protocol analysis (with HydraSDR fork enhancements)

GNU Radio 4.0

The sdr_gnuradio4 image builds GNU Radio 4.0 (RC2) from source alongside the GNU Radio 3.10 already present in sdr_light. GR4 is a separate C++23 codebase with its own headers, namespace and prefix, so nothing about your existing 3.10 flowgraphs changes:

bash
rfswift container create -i penthertz/rfswift_resolute:sdr_gnuradio4 -n gr4
Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
GNU Radio 4.0 (RC2) Next-generation GNU Radio runtime (C++23) built from source in /opt/gnuradio4 alongside the apt GNU Radio 3.10 GR4 binaries under /opt/gnuradio4/install/bin and /opt/gnuradio4/build/bin (added to PATH by /etc/profile.d/gnuradio4.sh) Yes Yes No, (not yet) gnuradio4_soft_install Yes
GNU Radio 4 Python env Dedicated Python 3.12 virtual environment for GR4's embedded PythonBlock interpreter /opt/gnuradio4/venv/bin/python Yes Yes No, (not yet) gnuradio4_soft_install Yes
GNU Radio 3.10 The stock GNU Radio inherited from sdr_light - untouched by the GR4 build gnuradio-companion | gr_modtool | gnuradio-config-info Yes Yes Yes gnuradio_soft_install Yes

How GR4 is isolated:

  • Built into /opt/gnuradio4, exposed through /etc/profile.d/gnuradio4.sh (which prepends /opt/gnuradio4/install/bin and /opt/gnuradio4/build/bin to PATH)
  • Ships its own Python 3.12 virtual environment at /opt/gnuradio4/venv for the embedded PythonBlock interpreter, so it never touches the system Python (3.14 on Resolute) or GNU Radio 3.10’s bindings
  • The apt GNU Radio 3.10 remains the default gnuradio-companion in the image

GNU Radio 4 is a release candidate. It is experimental, its install tooling is still maturing upstream, and the build is heavy and template-intensive. Expect API churn. This image is for evaluating GR4, not for production flowgraphs. Not yet available on RISC-V64.

RFID

The rfid image focuses on radio-frequency identification analysis and exploitation:

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
proxmark3 RRG/Iceman Proxmark3 firmware and client proxmark3 | pm3 Yes Yes Yes proxmark3_soft_install Yes
libnfc Near Field Communication library and tools nfc-list | nfc-scan-device | nfc-poll | nfc-dep-initiator | nfc-dep-target Yes Yes Yes libnfc_soft_install Yes
nfc-tools Utilities for libnfc nfc-barcode | nfc-read-forum-tag3 | nfc-emulate-forum-tag4 | nfc-mfclassic | nfc-relay-picc | nfc-jewel | nfc-mfultralight Yes Yes Yes libnfc_soft_install Yes
mfoc MIFARE Classic Offline Cracker mfoc Yes Yes Yes mfoc_soft_install Yes
mfcuk MIFARE Classic Universal toolKit mfcuk Yes Yes Yes mfcuk_soft_install Yes
mfdread MIFARE dump reader and parser /rftools/rfid/mfdread/mfdread.py Yes Yes Yes mfread_soft_install Yes
RFIDler Open-source RFID emulator and reader /root/thirdparty/RFIDler/ Yes No No rfidler_soft_install Yes
miLazyCracker Automated MIFARE Classic cracking with DarkSide attack /rftools/rfid/miLazyCracker/ Yes Yes Yes miLazyCracker_soft_install Yes
libfreefare MIFARE tag manipulation library and tools mifare-classic-format | mifare-desfire-info Yes Yes Yes libfreeware_soft_install Yes
nfcpy Python NFC library for contactless communication Python nfcpy module Yes Yes Yes nfcpy_soft_install Yes
ChameleonUltra ChameleonUltra NFC emulator CLI /rftools/nfc/ChameleonUltra/ Yes Yes Yes chameleon_ultra_soft_install Yes

RFID Device Requirements: When using RFID tools, you need to ensure that your RFID reader device (typically appearing as /dev/ttyACM0) is properly bound to the container:

bash
# When creating a new container
rfswift container create -i rfid -n rfid_tools -s /dev/ttyACM0:/dev/ttyACM0

# Or with an existing container
rfswift config bindings add -c rfid_tools -d -t /dev/ttyACM0   # serial port, attached on demand

Bluetooth

The bluetooth image contains specialized tools for Bluetooth protocol analysis and security testing:

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
hcitools Bluetooth HCI layer tools for device configuration and management hciattach | hciconfig | hcidump | hcitool Yes Yes Yes blueztools_soft_install Yes
bluez tools BlueZ Bluetooth protocol stack utilities bluetoothctl | bluetoothd | btmon Yes Yes Yes blueztools_soft_install Yes
mirage Modular framework for BLE security auditing with Python 3.10 venv mirage Yes Yes Yes mirage_soft_install Yes
Sniffle TI CC13x2/CC26x2 BLE sniffer with OpenDroneID support /rftools/bluetooth/Sniffle/ Yes Yes Yes sniffle_soft_install Yes
bluing Python-based Bluetooth Low Energy scanner and analyzer /rftools/bluetooth/bluing/bluing/bin/ Yes Yes Yes bluing_soft_install Yes
bdaddr Tool to change Bluetooth device address /rftools/bluetooth/bdaddr/bdaddr Yes Yes Yes bdaddr_soft_install Yes
WHAD Wireless Hacking Devices protocol framework whadup | wplay | wsniff | wfilter | wextract | wdump | wshark | wanalyze | winject | wserver | wble-central | wble-periph | wble-proxy | wble-spawn | wble-connect | wuni-scan | wuni-mouse | wuni-keyboard Yes Yes Yes whad_soft_install Yes
esp32_bluetooth_classic_sniffer ESP32-based Bluetooth Classic sniffer with Python CLI BTSnifferBREDR Yes Yes Yes esp32_bluetooth_classic_sniffer_soft_install Yes
BlueKit Bluetooth security assessment toolkit bluekit Yes Yes Yes bluekit_soft_install No, (install manually)
WhisperPair (CVE-2025-36911) Bluetooth pairing exploit PoC /rftools/bluetooth/exploits/CVE-2025-36911-exploit/ Yes Yes Yes CVE_2025_36911_whisperpair_install Yes
RACE Toolkit Bluetooth RACE exploit (CVE-2025-20700/01/02) /rftools/bluetooth/exploits/race-toolkit/ Yes Yes Yes race_toolkit_exploit_install Yes
PyBluez Python Bluetooth library and bindings Python pybluez module Yes Yes Yes pybluez_soft_install Yes
BlueDucky Bluetooth HID emulation and exploitation tool /rftools/bluetooth/exploits/BlueDucky/ Yes Yes Yes blueducky_soft_install Yes
Breaktooth Bluetooth Classic exploitation framework /rftools/bluetooth/exploits/breaktooth-unofficial/ Yes Yes Yes breaktooth_soft_install Yes
BLERP BLE Re-Pairing attacks PoC (NDSS 26') /rftools/bluetooth/exploits/blerp/ Yes Yes Yes blerp_soft_install Yes
Caeruleus Single-binary BLE assessment workflow (scan GATT enumerate read/write/notify fuzz assess) with JSON/JSONL output caeruleus Yes Yes Yes caeruleus_soft_install Yes
BlueSploit Bluetooth exploitation framework bluesploit Yes Yes Yes bluesploit_soft_install Yes

Required Capability: Bluetooth tools require the NET_ADMIN capability to function properly. Always include this capability when running the container:

bash
rfswift container create -i bluetooth -n bt_tools -a NET_ADMIN

Without this capability, many Bluetooth tools will fail with permission errors when attempting to configure network interfaces.

Python Virtual Environments: Some Bluetooth tools run in isolated Python environments:

  • Mirage: Uses Python 3.10 venv at /opt/mirage-env/, accessed via wrapper script at /usr/sbin/mirage
  • Bluing: Uses Python 3.10 venv at /rftools/bluetooth/bluing/, run with bluing_run script

New in v3.0.0: Caeruleus, a single Go binary covering the whole BLE assessment workflow on BlueZ (scan, GATT enumeration, read/write/notify, fuzzing and structured assessment with JSON/JSONL output), and BlueSploit, a Bluetooth exploitation framework. Both sit next to the existing WhisperPair exploit for CVE-2025-36911.

Tool Locations:

  • /rftools/bluetooth/ - Main Bluetooth tools directory
  • /rftools/bluetooth/firmwares/ - Firmware for various BLE sniffers (Btlejack, Injectable NRF52840, Sniffle)

Wi-Fi

The wifi image provides tools for Wi-Fi network analysis, packet capture, and security assessment:

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
iproute2 Modern network configuration utilities ip | ss | bridge | rtmon Yes Yes Yes common_nettools Yes
hostapd IEEE 802.11 AP and authentication server hostapd Yes Yes Yes common_nettools Yes
dnsmasq Lightweight DNS/DHCP server for rogue AP dnsmasq Yes Yes Yes common_nettools Yes
macchanger MAC address spoofing utility macchanger Yes Yes Yes common_nettools Yes
tshark Command-line network protocol analyzer tshark Yes Yes Yes common_nettools Yes
aircrack-ng Complete WiFi security auditing suite airbase-ng | aircrack-ng | airdecap-ng | airdecloak-ng | aireplay-ng | airmon-ng | airodump-ng | airodump-ng-oui-update | airolib-ng | airmon-zc | airtun-ng | besside-ng | easside-ng | tkiptun-ng | wesside-ng Yes Yes Yes aircrack_soft_install Yes
hcxdumptool Modern WiFi capture tool for hashcat hcxdumptool Yes Yes Yes hcxdumptool_soft_install Yes
hcxtools Convert captures to hashcat format hcxpcapngtool | hcxhashtool | hcxpsktool | hcxpmktool Yes Yes Yes hcxtools_soft_install Yes
reaver WPS brute-force attack tool reaver | wash Yes Yes Yes reaver_soft_install Yes
bully Alternative WPS brute-force tool bully Yes Yes Yes bully_soft_install Yes
pixiewps WPS Pixie Dust attack implementation pixiewps Yes Yes Yes pixiewps_soft_install Yes
eaphammer Targeted evil twin and credential harvesting /rftools/wifi/eaphammer/ Yes Yes Yes eaphammer_soft_install Yes
airgeddon Multi-tool WiFi security auditing framework /rftools/wifi/airgeddon/airgeddon.sh Yes Yes Yes airgeddon_soft_install Yes
wifite2 Automated WiFi attack tool wifite Yes Yes Yes wifite2_soft_install Yes
sparrow-wifi WiFi and Bluetooth analyzer with SDR support /rftools/wifi/sparrow-wifi/ Yes Yes Yes sparrowwifi_sdr_soft_install Yes
krackattacks-scripts KRACK attack proof-of-concept /rftools/wifi/krackattacks-scripts/ Yes Yes Yes krackattacks_script_soft_install Yes
BeEF Browser Exploitation Framework for phishing beef | /opt/network/beef/beef Yes Yes Yes beef_soft_install Yes
asleap LEAP/PPTP password cracker asleap Yes Yes Yes asleap_soft_install Yes
roguehostapd Modified hostapd for advanced attacks hostapd-mana Yes Yes Yes roguehostapd_soft_install Yes
wifiphisher Automated phishing attack framework wifiphisher Yes Yes Yes wifiphisher_soft_install Yes
hostapd-mana Evil twin AP with credential harvesting hostapd-mana Yes Yes Yes hostapdmana_soft_install Yes
dragonslayer WPA3 dragonfly vulnerability testing /rftools/wifi/wpa3/dragonslayer/ Yes Yes Yes wpa3_dragonslayer_soft_install Yes
dragonforce WPA3 downgrade and DoS attacks /rftools/wifi/wpa3/dragonforce/ Yes Yes Yes wpa3_dragonforce_soft_install Yes
dragondrain-and-time WPA3 resource exhaustion attacks /rftools/wifi/wpa3/dragondrain-and-time/ Yes Yes Yes wpa3_dragondrain_and_time_soft_install Yes
wacker WPA3 SAE timing attacks /rftools/wifi/wpa3/wacker/ Yes Yes Yes wpa3_wacker_soft_install Yes
Pyrit GPU-accelerated WPA/WPA2 cracker pyrit Yes Limited Limited Pyrit_soft_install No, (commented out - Python3 issues)
mdk3 Wireless denial-of-service testing mdk3 Yes Yes Yes mdk3_soft_install No, (install manually)
wifipumpkin3 Rogue AP framework wifipumpkin3 Yes Yes Yes wifipumpkin3_soft_install No, (install manually)
fernwifi-cracker GUI-based WiFi security testing Fern-Wifi-Cracker Yes Yes Yes fernwificracker_soft_install No, (install manually)
Kismet Wireless and Bluetooth packet capture sniffing and IDS kismet | kismet_cap_linux_wifi | kismetdb_dump_devices Yes Yes Yes kismet_soft_install Yes
bettercap Network and wireless attack framework (Wi-Fi BLE and Ethernet) bettercap Yes Yes Yes bettercap_soft_install Yes

Required Capability: Wi-Fi tools require the NET_ADMIN capability to manipulate wireless interfaces. Always include this capability when running the container:

bash
rfswift container create -i wifi -n wifi_tools -a NET_ADMIN

If you see errors about insufficient permissions when using Wi-Fi tools, this capability is likely missing.

WPA3 Attack Tools: RF Swift includes a complete suite of WPA3 vulnerability testing tools:

  • dragonslayer - Dragonfly handshake vulnerabilities
  • dragonforce - Downgrade and DoS attacks
  • dragondrain-and-time - Resource exhaustion
  • wacker - SAE timing attacks

All WPA3 tools are located in /rftools/wifi/wpa3/

Telecommunications

The telecommunications images are divided into several categories based on mobile network generations:

Telecom utilities

Foundation tools for cellular network analysis:

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
pycrate Python library for mobile network protocols (2G/3G/4G/5G) Python pycrate module Yes Yes Yes pycrate_soft_install Yes
CryptoMobile Mobile network cryptographic functions (Milenage TUAK Kasumi) Python CryptoMobile module Yes Yes Yes cryptomobile_soft_install Yes
PySIM SIM card management and programming pySim-shell.py | pySim-read.py | pySim-prog.py Yes Yes Yes pysim_soft_install Yes
pySCTP Python bindings for SCTP protocol Python pysctp module Yes Yes Yes pysctp_soft_install Yes
sysmo-usim-tool SIM card programming for Sysmocom cards sysmo-usim-tool Yes Yes Yes sysmoUSIM_soft_install Yes
SCAT Signaling collection and analysis toolkit scat | signalcat Yes Yes Yes SCAT_soft_install Yes
SigPloit Signaling exploitation framework sigploit Yes Yes Yes SigPloit_soft_install Yes
PyHSS Python Home Subscriber Server pyhss Yes Yes Yes pyhss_soft_install Yes
Bromelia Python Diameter protocol stack Python bromelia module Yes Yes Yes bromelia_soft_install Yes
jSS7 Java SS7 protocol stack jSS7 tools Yes No No jss7_soft_install Yes
Py5sig 5G NAS security tool py5sig Yes Yes Yes py5sig_soft_install No, (install manually)
Modmobmap Mobile network mapping tool modmobmap Yes Yes Yes Modmobmap_soft_install No, (install manually)

Python Libraries:

  • pycrate: Complete Python cellular protocol stack
  • CryptoMobile: Mobile network cryptography (Milenage, TUAK, Kasumi, etc.)
  • pysctp: Python SCTP bindings for signaling protocols
  • bromelia: Diameter protocol stack for LTE/5G core

2G/3G

Tools for GSM, UMTS, and related technologies:

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
YateBTS Complete 2G/GSM base station with Yate softswitch yate | yatebts | mbts Yes Yes Yes yatebts_blade2_soft_install Yes
OpenBTS Open source GSM base station OpenBTS | transceiver Yes No No openbts_uhd_soft_install Yes
OpenBTS UMTS Open source 3G UMTS base station OpenBTS-UMTS Yes No No openbts_umts_soft_install Yes
OsmoCom BTS Suite Complete 2G network infrastructure suite osmo-bts | osmo-bsc | osmo-msc | osmo-hlr | osmo-mgw | osmo-sgsn | osmo-ggsn Yes Yes Yes osmobts_suite_soft_install Yes

Architecture Limitations:

  • YateBTS: Requires Qt5 dependencies, may have limited multi-arch support
  • OpenBTS/OpenBTS-UMTS: x86_64 only due to build dependencies
  • OsmoCom suite: Builds on all architectures but requires significant system resources

OpenBTS and OpenBTS-UMTS on Resolute

Both are legacy C++ code bases that GCC 15 (the compiler shipping with Ubuntu 26.04) rejects outright. RF Swift installs them from PentHertz forks on dedicated resolute branches, PentHertz/OpenBTS and PentHertz/OpenBTS-UMTS, rather than from the dead upstreams.

Porting is still in progress: some translation units (notably the OpenBTS-UHD Transceiver code, which trips a std::complex ambiguity under GCC 15) may still fail to build. RF Swift records these as build failures instead of aborting the image, so check /var/lib/db/rfswift_build_report.tsv inside a telecom_2Gto3G container to see exactly what landed in your build. YateBTS and the OsmoCom suite are unaffected and remain the recommended 2G/3G path.

Tool Locations:

  • /telecom/2G/ - 2G base stations and tools
  • /telecom/3G/ - 3G/UMTS tools
  • /telecom/SIM/ - SIM card programming tools
  • Configuration files in /root/config/osmobts/

4G/5G

Tools for LTE and 5G-NSA:

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
srsRAN 4G Complete LTE stack (eNB EPC UE) srsenb | srsepc | srsue Yes Yes Yes srsran4G_5GNSA_soft_install Yes
Open5GS Open source 5G Core and EPC open5gs-amfd | open5gs-smfd | open5gs-upfd | open5gs-mmed | open5gs-sgwud | open5gs-hssd | open5gs-pcrfd Yes Yes Yes Open5GS_soft_install Yes
Open5GS Web UI Subscriber management web interface Node.js web UI on port 3000 Yes Yes Yes Open5GS_soft_install Yes

srsRAN 4G: Complete LTE stack including:

  • srsENB: LTE eNodeB (base station)
  • srsEPC: Evolved Packet Core
  • srsUE: UE simulator

5G standalone

Tools for 5G standalone (SA) and core networks:

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
OCUDU 5G SA CU/DU stack - replaces srsRAN Project as the default gNB in RF Swift v3.0.0 gnb Yes Yes Yes ocudu_soft_install (also aliased as srsran5GSA_soft_install) Yes
srsRAN Project (bladeRF) 5G SA gNB fork with bladeRF support gnb Yes Yes Yes srsran5GSA_bladerf_soft_install No, (alternative used by the telecom_5G_bladerf image)
Open5GS Open source 5G Core network open5gs-amfd | open5gs-smfd | open5gs-upfd | open5gs-ausfd | open5gs-udmd | open5gs-pcfd | open5gs-nrfd | open5gs-scpd | open5gs-bsfd | open5gs-udrd Yes Yes Yes Open5GS_soft_install Yes
Open5GS (nohttp2) Open5GS without HTTP/2 support Same as Open5GS Yes Yes Yes Open5GS_nohttp2_soft_install No, (alternative)
Open5GS (0caps) Open5GS with null cipher support Same as Open5GS Yes Yes Yes Open5GS_0caps_soft_install No, (alternative)
Open5GS Web UI Subscriber management web interface Node.js web UI on port 3000 Yes Yes Yes Open5GS_soft_install Yes
UERANSIM 5G UE and RAN simulator nr-ue | nr-gnb | nr-cli | nr-binder Yes Yes Yes UERANSIM_soft_install Yes
UERANSIM (null cipher) UERANSIM with null cipher support Same as UERANSIM Yes Yes Yes UERANSIM_nullciph_soft_install No, (alternative)
5Greplay 5G traffic replay and testing 5greplay Yes Yes Yes 5greplay_soft_install Yes

5G SA now runs on OCUDU

As of v3.0.0, the CU/DU stack installed in the 5G images is OCUDU instead of srsRAN Project. The srsran5GSA_soft_install function is kept as an alias so existing recipes and scripts keep working, but it now installs OCUDU. It builds into /telecom/5G/ocudu and still provides the gnb binary, so your existing configuration files and workflows carry over.

srsRAN 4G is unaffected and remains the 4G/5G-NSA stack. See the 4G/5G section above.

MongoDB Requirement: Open5GS requires MongoDB for subscriber database. The container includes:

  • MongoDB 6.0 from official repository
  • Web UI for subscriber management (Node.js based)
  • Database directory at /data/db/

To start all Open5GS components: Open5Gs_deployall

Automotive

The automotive image contains tools for vehicle network analysis and communication:

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
can-utils Linux SocketCAN userspace utilities candump | cansend | canplayer | cangen | cansniffer | cansequence Yes Yes Yes canutils_soft_install Yes
CANtact CANtact hardware support utilities cantact Yes Yes Yes cantact_soft_install Yes
Caring Caribou CAN bus security and penetration testing caringcaribou Yes Yes Yes caringcaribou_soft_install Yes
SavvyCAN Cross-platform CAN bus reverse engineering SavvyCAN Yes Yes Yes savvycan_soft_install Yes
Gallia Extendable automotive penetration testing framework gallia Yes Yes Yes gallia_soft_install Yes
V2GInjector Vehicle-to-Grid (V2G) protocol testing v2ginjector Yes Yes Yes v2ginjector_soft_install Yes

Tool Locations:

  • /automotive/ - Main automotive tools directory
  • CAN/LIN/FlexRay tools
  • Vehicle protocol analyzers

Reverse engineering & SAST

The reversing image provides tools for firmware analysis, hardware reverse engineering and static application security testing:

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
Kaitai Struct Declarative binary format parser kaitai-struct-compiler | ksc Yes Yes Yes kataistruct_soft_install Yes
Unicorn Engine Lightweight multi-architecture CPU emulator Python unicorn module Yes No No unicorn_soft_install Yes
Keystone Engine Lightweight multi-architecture assembler Python keystone module Yes No No keystone_soft_install Yes
Radare2 Reverse engineering framework r2 | rabin2 | radare2 | rafind2 | ragg2 | rahash2 | rarun2 | rasm2 | rax2 Yes Yes Yes radare2_soft_install Yes
Ghidra NSA reverse engineering suite ghidra | ghidraRun Yes Yes Yes ghidra_soft_install Yes
Sasquatch Modified unsquashfs for non-standard SquashFS images sasquatch Yes Yes Yes sasquatch_soft_install Yes
Unblob Accurate recursive extraction of firmware unblob Yes Yes Yes unblob_soft_install Yes
Binwalk Firmware analysis and extraction binwalk Yes Yes Yes binwalk_soft_install Yes
Binwalk v3 Rust-based binwalk rewrite binwalk Yes Yes Yes binwalkv3_soft_install Yes
QNX6 Extractor QNX6 filesystem extractor qnx6extractor Yes Yes Yes qnx6extractor_soft_install Yes
LLVM Compiler infrastructure for static analysis clang | clang++ | llvm-* | opt Yes Yes No LLVM_install Yes
AFL American Fuzzy Lop fuzzer afl-fuzz | afl-gcc | afl-g++ | afl-clang | afl-clang++ Yes Yes No AFL_install Yes
Honggfuzz Security-oriented fuzzer honggfuzz Yes Yes No honggfuzz_install Yes
Semgrep Static analysis for finding bugs semgrep Yes Yes Yes semgrep_install Yes
Cppcheck Static analysis for C/C++ code cppcheck Yes Yes Yes cppcheck_install Yes
Clang Static Analyzer C/C++/Objective-C static analyzer scan-build | scan-view Yes Yes Yes clang_static_analyzer_install Yes
Joern Code analysis platform for C/C++ joern | joern-parse | joern-export | joern-flow | joern-lookup Yes Yes Yes joernsast_install Yes
AppleDB Rust Apple device database in Rust appledb Yes Yes Yes appledb_rs_soft_install No, (commented out)
Cutter Qt-based reverse engineering platform cutter Yes Yes Yes cutter_soft_install Yes
ImHex Hex editor for reverse engineers imhex Yes Yes Yes imhex_soft_install Yes
Qiling Advanced binary emulation framework Python qiling module Yes No No qiling_soft_install No, (debconf issues)
EMBA Embedded firmware analyzer emba Yes Yes Yes emba_soft_install No, (takes long time)
Bytecaster Bytecode analyzer bytecaster Yes Yes Yes bytecaster_soft_install No, (install manually)
angr Binary analysis framework with symbolic execution Python angr module Yes Yes Yes angr_soft_install Yes
angrop ROP gadget finder for angr Python angrop module Yes Yes Yes angrop_soft_install Yes
Trivy Vulnerability misconfiguration secret and SBOM scanner for images filesystems and repos trivy Yes Yes (no upstream binary) trivy_install Yes
Sighthound Tree-sitter based static vulnerability scanner with source-to-sink taint flow (Python JS/TS Java PHP C# Go Ruby; text/JSON/CSV/SARIF output) sighthound Yes Yes Yes sighthound_install Yes

Static analysis alongside the RE tooling

Beyond the disassemblers and unpackers, the image carries a full SAST/fuzzing set you can point at extracted firmware and source trees: Semgrep, Joern, cppcheck, the Clang static analyzer, AFL and honggfuzz. Two of those are new in v3.0.0: Trivy, which scans images, filesystems and repos for vulnerabilities, misconfigurations, secrets and SBOMs, and Sighthound, a tree-sitter based scanner that follows source-to-sink taint flows through Python, JS/TS, Java, PHP, C#, Go and Ruby and reports in text, JSON, CSV or SARIF.

Architecture-Specific Tools:

  • Ghidra: Java-based, works on all architectures
  • Radare2/Cutter: x86_64 only due to Qt dependencies
  • Unicorn/Keystone: x86_64 only (ARM64 builds broken)
  • Binwalk v3: Requires Rust 1.82+, uses cargo for installation

Tool Locations:

  • /reverse/ - Reverse engineering tools and projects
  • Ghidra at /reverse/ghidra_X.X.X_PUBLIC/
  • ImHex: x86_64 uses .deb, ARM64 uses AppImage extraction

Network

The network image contains general network analysis and security tools:

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
Burp Suite Community Web application security testing burpsuite Yes Yes Yes burpsuite_community_install Yes
Nmap Network discovery and security auditing nmap | ncat | nping | ndiff Yes Yes Yes nmap_soft_install Yes
Wireshark Network protocol analyzer wireshark Yes Yes Yes wireshark_soft_install Yes
Metasploit Penetration testing framework msfconsole | msfvenom | msfdb | msfrpc | msfd Yes Yes No metasploit_soft_install Yes
Tshark Command-line network protocol analyzer tshark Yes Yes Yes tshark_soft_install Yes
Impacket Python classes for network protocols psexec.py | smbexec.py | wmiexec.py | secretsdump.py | GetNPUsers.py Yes Yes Yes impacket_soft_install Yes
AutoRecon Network reconnaissance automation autorecon Yes Yes Yes autorecon_soft_install Yes
Responder LLMNR NBT-NS and MDNS poisoner responder | Responder.py Yes Yes Yes responder_soft_install Yes
TruffleHog Find secrets in git repositories trufflehog Yes Yes Yes trufflehog_script_install Yes
hping3 Network tool for crafting packets hping3 Yes Yes Yes hping3_soft_install Yes
arping ARP-level ping utility arping Yes Yes Yes arping_soft_install Yes
NetExec Network protocol exploitation (formerly CrackMapExec) nxc | netexec Yes Yes Yes netexec_soft_install Yes
SubEnum Subdomain enumeration tool subenum Yes Yes Yes subenum_soft_install Yes
WebCopilot Web application reconnaissance automation webcopilot Yes Yes Yes webcopilot_soft_install Yes
gowitness Web screenshot and recon tool gowitness Yes Yes Yes gowitnes_soft_install Yes
SIPVicious VoIP security testing suite sipvicious | svmap | svwar | svcrack | svreport | svcrash Yes Yes Yes sipvicious_soft_install Yes
Voipire VoIP attack toolkit voipire Yes Yes Yes voipire_soft_install Yes
SIPpts VoIP penetration testing suite sippts Yes Yes Yes sippts_soft_install Yes
MBTget Modbus security assessment tool mbtget Yes Yes Yes mbtget_soft_install Yes
Kismet Wireless network detector and IDS kismet | kismet_server | kismet_client Yes Yes Yes kismet_soft_install Yes
Bettercap Swiss Army knife for network attacks bettercap Yes Yes Yes bettercap_soft_install Yes
Hashcat Advanced password recovery hashcat Yes Yes Yes hashcat_soft_install Yes
John the Ripper Password cracker john | unshadow | unique Yes Yes Yes john_soft_install Yes
Caido Modern web security proxy caido Yes Yes Yes caido_soft_install Yes
DonPAPI Dump DPAPI secrets remotely donpapi Yes Yes Yes donpapi_soft_install No, (install manually)
BeEF Browser Exploitation Framework beef Yes Yes Yes beef_soft_install No, (install manually)
Argus The Ultimate Information Gathering Toolkit argus Yes Yes Yes argus_soft_install_fromsource Yes
curlie The power of curl - the ease of use of httpie curlie Yes Yes Yes curlie_soft_install_fromsource Yes
vortix Terminal UI for WireGuard and OpenVPN with real-time telemetry and leak guarding vortix Yes Yes Yes vortix_soft_install_fromsource Yes
snitch a prettier way to inspect network connections snitch Yes Yes Yes snitch_soft_install Yes
sslyze Fast and powerful SSL/TLS scanning library sslyze Yes Yes Yes sslyze_soft_install Yes
netcat (OpenBSD) The network swiss army knife nc Yes Yes Yes netcatopenbsd_soft_install Yes
telnet (client) text based protocol and application telnet Yes Yes Yes telnet_soft_install Yes
SQLMap Automatic SQL injection and database takeover sqlmap Yes Yes Yes sqlmap_soft_install Yes
SSTImap Server-Side Template Injection exploitation tool sstimap Yes Yes Yes sstimap_soft_install Yes
WireTapper Network traffic interception and analysis wiretapper Yes Yes Yes wiretapper_soft_install_fromsource Yes
DonPwner Domain enumeration and exploitation donpwner Yes Yes Yes donpwner_soft_install No, (install manually)
Above Network protocol fuzzer above Yes Yes Yes above_soft_install No, (install manually)
Titus Penetration testing framework titus Yes Yes Yes titus_soft_install Yes
Brutus Network brute-force tool brutus Yes Yes Yes brutus_soft_install Yes
Nerva Network analysis and reconnaissance nerva Yes Yes Yes nerva_soft_install Yes
Trippy Modern network diagnostic tool (traceroute) trippy Yes Yes Yes trippy_soft_install Yes
MIC Microphone capture utility mic Yes Yes Yes mic_soft_install Yes
CryptoCONdor Cryptography testing toolkit cryptocondor Yes Yes Yes cryptocondor_soft_install Yes
Nmap Automator Automated Nmap scanning wrapper nmapautomator Yes Yes Yes nmapautomator_soft_install Yes
ReconFTW Automated reconnaissance framework reconftw Yes Yes Yes reconftw_soft_install No, (install manually)
Tetsuo H3sec Security testing framework tetsuo Yes Yes Yes tetsuo_h3sec_soft_install No, (commented out)
SecLists Collection of wordlists for fuzzing discovery and password attacks Wordlists in /opt/fuzzing/SecLists Yes Yes Yes seclist_soft_install Yes
whosthere Identify hosts and services on the local network whosthere Yes Yes Yes whosthere_soft_install Yes
Ettercap Man-in-the-middle attack suite (text-only build) ettercap Yes Yes Yes ettercap_soft_install Yes
ISC DHCP server Rogue/lab DHCP server for network attack setups dhcpd Yes Yes Yes isc_dhcp_server_soft_install Yes
lighttpd Lightweight web server for hosting payloads and captive portals lighttpd Yes Yes Yes lighttpd_soft_install Yes
crunch Wordlist generator crunch Yes Yes Yes crunch_soft_install Yes
NetWatch Terminal UI network monitor netwatch Yes Yes Yes netwatch_soft_install_fromsource Yes
Sniffnet Cross-platform network traffic monitor with a graphical UI sniffnet Yes Yes Yes sniffnet_soft_install_fromsource Yes
betterleaks Search engine and collection tooling for leaked credential datasets betterleaks Yes Yes Yes betterleaks_soft_install Yes
SSRFmap Automatic SSRF fuzzer and exploitation tool ssrfmap Yes Yes Yes ssrfmap_soft_install Yes
GraphQLmap Scripting engine to interact with and attack GraphQL endpoints graphqlmap Yes Yes Yes graphqlmap_soft_install Yes
John the Ripper (jumbo) Password cracker with the community jumbo patch set JohnJumbo Yes Yes Yes johnjumbo_soft_install Yes
Hetty HTTP toolkit for security research (open-source Burp alternative) hetty Yes Yes Yes hetty_soft_install Yes
HExHTTP HTTP header analysis and web cache poisoning testing hexhttp Yes Yes Yes hexhttp_soft_install Yes

Major Frameworks:

  • Metasploit: Full penetration testing framework (x86_64/aarch64)
  • NetExec: Network protocol exploitation
  • Kismet: Wireless/Bluetooth packet capture and analysis
  • Caido: Modern web security testing platform
  • Burp Suite Community: Multi-architecture support (JAR fallback for non-x86_64)

Active directory

The ad image builds on network and packs the tooling needed for Windows domain engagements, the part of an assessment that starts once you are past the radio layer:

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
AD apt toolchain Base AD client tooling (SMB LDAP Kerberos) smbclient | ldapsearch | kinit | klist | samdump2 | onesixtyone | nbtscan | dig | nslookup Yes Yes Yes ad_apt_tools_install Yes
Impacket Python classes for Windows network protocols psexec.py | smbexec.py | wmiexec.py | secretsdump.py | GetNPUsers.py | GetUserSPNs.py | ntlmrelayx.py Yes Yes Yes impacket_soft_install Yes
Responder LLMNR NBT-NS and MDNS poisoner Responder.py in /opt/network/Responder Yes Yes Yes responder_soft_install Yes
NetExec Network protocol exploitation and AD enumeration (CrackMapExec successor) netexec | nxc Yes Yes Yes netexec_soft_install Yes
DonPAPI Remote DPAPI secret dumping DonPAPI Yes Yes Yes donpapi_soft_install Yes
DonPwner AD exploitation automation on top of DonPAPI Python scripts in /opt/network/DonPwner Yes Yes Yes donpwner_soft_install Yes
ldapdomaindump LDAP-based domain information dumper ldapdomaindump Yes Yes Yes ldapdomaindump_soft_install Yes
BloodHound.py Python ingestor for BloodHound AD graphs bloodhound-python Yes Yes Yes bloodhound_py_soft_install Yes
Certipy AD Certificate Services (ADCS) enumeration and abuse certipy Yes Yes Yes certipy_soft_install Yes
bloodyAD AD privilege escalation framework bloodyAD Yes Yes Yes bloodyad_soft_install Yes
certsync Dump NTDS hashes through ADCS certificates certsync Yes Yes Yes certsync_soft_install Yes
mitm6 IPv6 DNS takeover for NTLM relaying mitm6 Yes Yes Yes mitm6_soft_install Yes
lsassy Remote LSASS credential extraction lsassy Yes Yes Yes lsassy_soft_install Yes
sprayhound AD password spraying with BloodHound integration sprayhound Yes Yes Yes sprayhound_soft_install Yes
kerbrute Kerberos user enumeration and password spraying kerbrute Yes Yes Yes kerbrute_soft_install Yes
SharpLAPS Retrieve LAPS passwords from LDAP (staged as source for the target) SharpLAPS.exe (if a prebuilt binary ships upstream) Yes Yes Yes sharplaps_soft_install (staged in /opt/ad)
pyGoldenGMSA Golden gMSA attack against Group Managed Service Accounts pygoldengmsa Yes Yes Yes install_pyGoldenGMSA Yes
skewrun Wrap a process with a DC-synchronised clock to survive KRB_AP_ERR_SKEW skewrun Yes Yes (built with cargo) skewrun_soft_install Yes

Tool Locations:

  • /opt/ad/ - Staged AD tooling (SharpLAPS and other target-side payloads)
  • /opt/network/ - Shared network tooling inherited from the network image (Responder, DonPAPI, DonPwner, pyGoldenGMSA)
  • pipx-installed tools are symlinked into /usr/sbin/

Kerberos clock skew: domain controllers reject tickets when your clock drifts more than a few minutes, and inside a container you usually cannot (and should not) change the system clock. skewrun resolves the DC’s time over AD protocols and fakes it via LD_PRELOAD/libfaketime for the wrapped process only, so Impacket, NetExec and friends survive KRB_AP_ERR_SKEW without root and without touching the host clock. Run skewrun --help for the exact invocation.

SharpLAPS is a C#/.NET tool meant to run against Windows targets. RF Swift stages the repository under /opt/ad/SharpLAPS rather than compiling it on Linux. Build it on or against your Windows target.

Mobile / Android

The android image covers Android application and device assessment, from pulling an APK off a handset to running it through a full static analysis pipeline:

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
Android platform tools Device communication flashing and screen mirroring adb | fastboot | scrcpy Yes Yes Yes mobile_apt_tools_install Yes
Apktool APK decompiler and rebuilder apktool Yes Yes Yes mobile_apt_tools_install Yes
apksigner / zipalign APK signing and alignment apksigner | zipalign Yes Yes Yes mobile_apt_tools_install Yes
smali / baksmali Dalvik bytecode assembler and disassembler smali | baksmali | dexdump Yes Yes Yes mobile_apt_tools_install Yes
dex2jar Convert Android DEX to Java JAR for decompilation d2j-dex2jar | d2j-jar2dex | d2j-apk-sign (in /mobile/dex-tools-v2.4) Yes Yes Yes dex2jar_soft_install Yes
Frida Dynamic instrumentation toolkit frida | frida-ps | frida-trace | frida-discover Yes Yes Limited frida_soft_install Yes
objection Runtime mobile exploration built on Frida objection Yes Yes Limited objection_soft_install Yes
androguard Android APK static analysis framework androguard Yes Yes Yes androguard_soft_install Yes
drozer Android security assessment framework (ReversecLabs) drozer Yes Yes Yes drozer_soft_install Yes
MobSF Mobile Security Framework - automated static and dynamic analysis mobsf (web UI on port 8000) Yes Yes Limited mobsf_soft_install Yes

USB device access: adb and fastboot need the handset bound into the container. Pass the device (or the whole USB bus) at creation time:

bash
rfswift container create -i android -n mobile_lab -s /dev/bus/usb:/dev/bus/usb

On macOS, attach the device to the Lima VM first with rfswift usb attach (see usb).

Tool Locations and Notes:

  • /mobile/ - dex2jar (/mobile/dex-tools-v2.4) and the MobSF checkout
  • MobSF only supports Python 3.12-3.13, so RF Swift provisions a dedicated interpreter with uv at /mobile/.mobsf-python and drives MobSF through it. Start it with mobsf and browse to http://localhost:8000 (the default host network makes the port reachable as is; with another network mode, publish it with -w 8000:8000/tcp)
  • PDF report export in MobSF relies on wkhtmltopdf, which Ubuntu removed. The upstream static build is installed best-effort on amd64/arm64; MobSF runs fine without it

OSINT

The osint image collects open-source intelligence and reconnaissance tooling on top of corebuild:

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
OSINT apt toolchain Metadata DNS and WHOIS utilities exiftool | exiftran | dnsenum | tor | whois | dig | nslookup Yes Yes Yes osint_apt_tools_install Yes
theHarvester E-mail subdomain and name harvesting from public sources theHarvester Yes Yes Yes osint_pipx_tools_install Yes
Sherlock Hunt usernames across social networks sherlock Yes Yes Yes osint_pipx_tools_install Yes
maigret Profile collection from thousands of sites by username maigret Yes Yes Yes osint_pipx_tools_install Yes
holehe Check which sites an e-mail address is registered on holehe Yes Yes Yes osint_pipx_tools_install Yes
Sublist3r Subdomain enumeration via search engines sublist3r Yes Yes Yes osint_pipx_tools_install Yes
h8mail E-mail breach and password hunting h8mail Yes Yes Yes osint_pipx_tools_install Yes
GHunt Google account investigation ghunt Yes Yes Yes osint_pipx_tools_install Yes
instaloader Instagram profile and media collection instaloader Yes Yes Yes osint_pipx_tools_install Yes
toutatis Extract information from Instagram accounts toutatis Yes Yes Yes osint_pipx_tools_install Yes
censys Censys search CLI for host and certificate data censys Yes Yes Yes osint_pipx_tools_install Yes
subfinder Passive subdomain discovery (ProjectDiscovery) subfinder Yes Yes Yes osint_go_tools_install Yes
assetfinder Find domains and subdomains related to a target assetfinder Yes Yes Yes osint_go_tools_install Yes
waybackurls Fetch known URLs from the Wayback Machine waybackurls Yes Yes Yes osint_go_tools_install Yes
SpiderFoot Automated OSINT collection and correlation platform spiderfoot (web UI) Yes Yes Yes spiderfoot_soft_install Yes
recon-ng Modular web reconnaissance framework recon-ng Yes Yes Yes reconng_soft_install Yes
FinalRecon All-in-one web reconnaissance tool finalrecon Yes Yes Yes finalrecon_soft_install Yes

Tool Locations:

  • /opt/osint/ - SpiderFoot, recon-ng and FinalRecon, each in its own Python virtual environment with a wrapper script in /usr/local/bin
  • pipx-installed tools are symlinked into /usr/sbin/
  • Go tools (subfinder, assetfinder, waybackurls) land in /usr/local/bin

API keys: many OSINT tools (Censys, GHunt, SpiderFoot modules, subfinder sources) need credentials to return useful results. Configure them inside the container and commit the result with rfswift container commit, or bind a configuration directory from the host so your keys survive container recreation.

Hardware security

The hardware image focuses on general hardware security testing and analysis:

Tool(s)DescriptionAvailable commandsamd64aarch64riscv64Installation functionInstalled by default
AVRDUDE AVR microcontroller programmer avrdude Yes Yes Yes avrdude_install Yes
DSView Logic analyzer software for DSLogic DSView Yes Yes Yes dsview_install Yes
PulseView Sigrok logic analyzer frontend pulseview Yes Yes Yes pulseview_install Yes
Arduino IDE Integrated development environment for Arduino arduino | arduino-cli Yes Yes Yes arduino_ide_install Yes
Logic 2 (Saleae) Logic analyzer software for Saleae devices logic2 | Logic Yes No No logic2_saleae_install Yes
Flashrom Flash chip programmer flashrom Yes Yes Yes flashrom_install Yes
dsl2sigrok Convert DSLogic VCD to Sigrok format dsl2sigrok Yes Yes Yes dsl2sigrok_install Yes
SeerGDB Lightweight GUI frontend to GDB seergdb Yes Yes Yes seergdb_install Yes
OpenOCD On-Chip Debugger for embedded devices openocd Yes Yes Yes openocd_install Yes
dfu-util Device Firmware Upgrade utilities dfu-util | dfu-prefix | dfu-suffix Yes Yes Yes dfu_util_install Yes
openFPGALoader Universal FPGA programming utility openFPGALoader Yes Yes Yes openFPGALoader_install Yes
MTKClient MediaTek bootloader client mtkclient | mtk Yes Yes Yes mtkclient_install Yes
esptool ESP8266/ESP32 ROM bootloader utility esptool.py | espefuse.py | espsecure.py Yes Yes Yes esptool_install Yes
ngscopeclient Next-generation oscilloscope software ngscopeclient Yes Yes Yes ngscopeclient_install Yes
GPU Drivers - NVIDIA NVIDIA GPU compute drivers nvidia-smi | nvidia-settings Yes Yes Yes install_GPU_nvidia Yes
GPU Drivers - Intel Intel GPU compute drivers intel-gpu-tools Yes Yes Yes install_GPU_Intel Yes
GPU Drivers - Radeon (up to 5000) AMD Radeon GPU drivers for older cards rocm-smi Yes Yes Yes install_GPU_Radeon_until5000 Yes
GPU Drivers - Radeon (latest) AMD Radeon GPU drivers for latest cards rocm-smi Yes Yes Yes install_GPU_latest_Radeon Yes
HydraNFC Trace Plugin Sigrok plugin for HydraNFC traces Sigrok HydraNFC decoder Yes Yes Yes hydranfc_trace_plugin_install Yes
SPI-TPM Trace Plugin Sigrok plugin for SPI-TPM trace analysis Sigrok SPI-TPM decoder Yes Yes Yes spitpm_trace_plugin_install Yes
SPITkey SPI programming and key extraction tool spitkey Yes Yes Yes spitkey_install Yes
PyHydraBus Python interface for HydraBus hardware pyhydrabus Yes Yes Yes pyhydrabus_install Yes
findus Python module driving the PicoGlitcher fault-injection board Python findus module Yes Yes Yes pythonfindus_install Yes
rd6006 Python module for RD6006 programmable power supplies Python rd6006 module Yes Yes Yes pythonrd6006_install Yes
SLogic PulseView Sipeed SLogic build of PulseView/sigrok isolated in /opt/slogic /opt/slogic/bin/pulseview Yes Yes Yes slogic_pulseview_install_fromsources Yes

Logic Analyzer Software:

  • Logic 2 (Saleae): x86_64 only, uses --no-sandbox flag automatically
  • PulseView/Sigrok: Built from source with ARM64 libsigrokdecode patch
  • DSView: Built from source for DSLogic devices

Tool Locations:

  • /hardware/ - Logic analyzers, programmers, and debugging tools
  • Arduino IDE wrapper at /usr/sbin/arduino
  • OpenOCD with extensive debug probe support

Native Nix environments

The same categories exist as native environments for the Nix engine, defined in RF-Swift-nix. rfswift env catalog lists them on your machine, rfswift env tools <name> shows what one carries, and rfswift env run <environment> <tool> runs a single tool without creating anything. This table comes from the catalog (RF-Swift-nix 4.0.0):

Environment Category Packages What it covers
ad Network 20 Active Directory attack tooling: impacket, NetExec, kerbrute, Samba/LDAP/Kerberos clients.
android Mobile 21 Android / mobile: adb/fastboot, apktool, frida, androguard, scrcpy, jadx and reversing tools.
automotive Automotive 13 Automotive / CAN bus: can-utils, SavvyCAN, gallia and CAN analysis tooling.
bluetooth Bluetooth 29 Bluetooth Classic + BLE: BlueZ stack, Ubertooth, and Python BLE tooling, on the SDR device layer.
cyberether SDR 11 CyberEther: heterogeneous SDR signal visualisation (Vulkan), with the SoapySDR device stack.
hardware Hardware 29 Hardware hacking: avrdude, sigrok/PulseView, OpenOCD, flashrom, openFPGALoader, esptool, dfu-util.
network Network 126 General network & web pentest: nmap, Wireshark, Metasploit, bettercap, Kismet, hashcat/john, sqlmap and more.
osint OSINT 24 OSINT: theHarvester, sherlock, recon-ng, subfinder, exiftool and reconnaissance tools.
reversing Reversing 46 Reverse engineering & firmware analysis: Ghidra, rizin/Cutter, radare2, binwalk, AFL++, semgrep, ImHex.
rfid RFID 23 RFID / NFC toolkit: Proxmark3 (Iceman), libnfc, MIFARE crackers and NFC utilities.
sdr_full SDR 78 Full SDR arsenal: sdr_light plus SDRangel, SatDump, SigDigger, GQRX and many GNU Radio OOT modules available in nixpkgs.
sdr_light SDR 59 Light SDR set: GNU Radio, everyday SDR apps and the full device/driver layer (sdrsa_devices).
telecom Telecom 50 Mobile telecom 2G-5G: Osmocom stack, srsRAN, Open5GS, UERANSIM, YATE and SDR.
telecom_5g_bladerf Telecom 26 5G SA on a bladeRF: srsRAN Project bladeRF fork with its SoapyBladeRF variant, Open5GS core, and the telecom utility set (telecom_5G_bladerf image).
wifi WiFi 45 Wi-Fi audit suite: aircrack-ng, hcxtools, WPS/WPA3 attacks and rogue-AP frameworks, on top of the network toolkit.

Packages are nixpkgs attribute names (python3Packages.impacket, gnuradioPackages.gr-osmosdr), which is also what rfswift env install and rfswift env search --nixpkgs accept, so a tool the catalog does not carry is one env install away. The catalog records the packages that do not build on an architecture, and the environment ships without them there. See Installing software for how this compares with the images.

Tips for using the tools

Where tools are installed

RF Swift organizes tools in specialized directories for easier discovery:

  • /rftools/ - Radio frequency analysis tools
  • /rftools/sdr/ - SDR software and utilities
  • /rftools/bluetooth/ - Bluetooth tools and firmwares
  • /rftools/wifi/ - WiFi security tools
  • /rftools/rfid/ - RFID readers and utilities
  • /rftools/calibration/ - VNA and calibration tools
  • /rftools/analysers/ - Spectrum analyzer software
  • /rftools/generators/ - Signal generator software
  • /hardware/ - Hardware security and testing tools
  • /automotive/ - Vehicle communication and analysis tools
  • /reverse/ - Reverse engineering and firmware analysis tools
  • /telecom/ - Telecommunications tools
  • /telecom/2G/ - GSM/2G base stations
  • /telecom/3G/ - UMTS/3G tools
  • /telecom/4G/ - LTE/4G tools
  • /telecom/5G/ - 5G SA/NSA tools
  • /telecom/SIM/ - SIM card tools
  • /security/ - Security testing tools (Caido, etc.)
  • /opt/network/ - Network security tools
  • /opt/ad/ - Active Directory tooling (ad image)
  • /opt/osint/ - OSINT frameworks in their own venvs (osint image)
  • /mobile/ - Android and mobile tooling (android image)
  • /opt/gnuradio4/ - GNU Radio 4.0 tree and its Python venv (sdr_gnuradio4 image)
  • /opt/fuzzing/ - Wordlists and fuzzing resources (SecLists)
  • /nettools/ - Network monitoring tools built from source
  • /opt/crack/ - Password cracking tools
  • /sast/ - Static analysis security testing

These directories complement the standard system paths (/usr/bin, /usr/local/bin) and contain specialized tools, scripts, and resources.

Finding available tools

To discover which tools are available in your current container:

bash
# List all executable commands in standard paths
find /usr/bin /usr/local/bin -type f -executable | sort

# List RF tools in the dedicated directory
ls -la /rftools

# List tools in other specialized directories
ls -la /hardware
ls -la /automotive
ls -la /reverse
ls -la /telecom

# Search for a specific tool across all locations
find /usr/bin /usr/local/bin /rftools /hardware /automotive /reverse /telecom -name "*sdr*" -type f -executable

Installing tools manually

Some tools are not installed by default but can be added after container creation. To install these tools:

bash
rfswift container install -c container_name -i <installation_function_name>

The Installing software page compares this with apt inside the container, committing the result, recipes, and the Nix engine’s env install and env run.

Common manually-installed tools:

  • mdk3_soft_install - WiFi DoS testing
  • wifipumpkin3_soft_install - Rogue AP framework
  • install_soapy_modules - Additional SoapySDR device support
  • pocketvna_sa_device - PocketVNA software (x86_64 only)
  • srsran5GSA_bladerf_soft_install - 5G SA gNB fork with bladeRF support

To find out what is available in a given image, check the Installation function column of the tables above. Every entry marked No can be installed this way.

Check what actually built. RF Swift images record install failures instead of aborting the whole build, so a tool listed as installed by default may still be missing if its build broke on your architecture. Every image carries its build report at /var/lib/db/rfswift_build_report.tsv. Inspect it from inside a running container:

bash
cat /var/lib/db/rfswift_build_report.tsv

An empty or missing file means nothing failed. Failures are recorded as CATEGORY / STAGE / ITEM / DETAIL, so you can see exactly which tool broke and why, then reinstall it manually with rfswift container install once the upstream issue is fixed.

Tool documentation

Most tools include built-in help available through the -h or --help flags:

bash
tool_name --help

For more detailed documentation, many tools include man pages:

bash
man tool_name

Creating tool aliases

For frequently used tools with complex options, consider creating aliases in your container:

bash
echo 'alias rtlpower-optimized="rtl_power -f 88M:108M:25k -g 50 -i 10 -e 1h power.csv"' >> ~/.zshrc
source ~/.zshrc

Architecture-specific notes

x86_64 / AMD64

  • Broadest tool support
  • All GPU-accelerated tools available
  • SignalHound and specialized SA software supported

ARM64 / aarch64

  • Most tools fully supported
  • Some GUI applications require AppImage extraction
  • Limited SA software support (no SignalHound Spike/VSG60)
  • Python tools may need building from source

RISC-V64

  • Growing support, most core SDR tools work
  • Some tools installed from source due to package availability
  • Limited pre-built binary support
  • Python packages may require longer build times

Next steps