Test benches & product security
Signed session manifests and hardware preflight for fixture-based validation — garage/gate controllers, keyless bench harnesses, Wi-Fi labs.
Authorized RF & Wi-Fi security testing
SignalLab is the RF & Wi-Fi security-testing platform for labs, red teams, and researchers doing written-authorized work. Build a signed engagement manifest, run hardware preflight, and drive a monitor-mode & gated-active executor — with an audit trail and honest boundaries. The public app never transmits; it prepares and verifies the authorization.
Validated Aug 2026: dual Alfa radios (MT7612U + MT7921U) in one WSL2 instance, monitor mode + concurrent scans, and bidirectional frame injection on channel 1 — with the long-duration stability limit stated plainly.
Who uses SignalLab
If you run contained, written-authorized RF or Wi-Fi security testing, SignalLab gives you a repeatable, auditable authorization workflow and a real executor.
Signed session manifests and hardware preflight for fixture-based validation — garage/gate controllers, keyless bench harnesses, Wi-Fi labs.
An auditable authorization envelope per engagement: scope, fixtures, frequency and power allowlists, expiration, and a session report for the engagement folder.
Monitor-mode capture and gated active tests on your own spectrum, with the stability and recovery boundaries documented instead of hidden.
Validated
Capabilities are stated from real acceptance runs with evidence — and the boundaries are stated just as plainly. That honesty is the point.
Platform hardware
The recommended active hardware is a genuine HackRF One used with RF containment. Wi-Fi security checks use a separate dedicated lab access point and client because a wideband SDR is not a substitute for a normal 802.11 test interface.
Half-duplex SDR for controlled transmit-or-receive research. SignalLab only performs a WebUSB identity check in this release; it does not claim the interface or send samples.
WebUSB has not been checked.
Local RF executor
The public PWA prepares and verifies the authorization; it never touches a radio. The RF executor is the separate, local bridge that does — a small headless Linux VM on your own workstation that gives SignalLab a real 802.11 monitor-mode radio over native USB passthrough. It captures for detection, and runs active Wi‑Fi tests only inside a signed plan with an isolated-range gate. This is the desktop bridge the hardware section describes, now built.
Downloads
Everything needed to build the RF executor on a Windows workstation: the installer, dashboard, setup guide, and the exact validated Linux kernel package set. Authorized lab use only.
A one-shot PowerShell setup that installs VirtualBox and its Extension Pack, builds the Ubuntu RF-executor VM, wires up USB passthrough and SSH, and ships the browser dashboard. Re-runnable and idempotent.
Contains setup-rf-executor.ps1, the alfa-dashboard bridge and launcher, and the README. Needs Windows with VirtualBox, Node.js, and PuTTY.
Set up the ACM, the AXML, or both together through the tested WSL2 and USB/IP path, with exact kernel, module, attach, interface-mapping, monitor-mode, recovery, and VirtualBox fallback steps. Read it here or take the PDF.
The guide is hosted on this site as a page for reference.
The exact unmodified Ubuntu kernel, modules, headers, and firmware packages used to validate the AWUS036AXML. The archive is approximately 795 MiB and includes per-package SHA-256 checksums.
The AXML passed bounded feature tests on this kernel but remains experimental under VirtualBox: sustained monitor traffic reproduced an xHCI kernel panic. Keep the previous kernel available for rollback.
A custom WSL2 kernel image, complete matching module tree, build configuration, and embedded firmware for both the MT7612U and MT7921U Alfa adapters. The archive is approximately 669 MiB and includes byte-level provenance.
Both the AXML and ACM passed simultaneous USBIP attach and initialization, passive scans, and bounded bidirectional synthetic-frame injection. No disruptive frames or real-network targets were used. The MT7612U later disconnected after about 11 minutes of repeated monitor/capture work and recovered by software reattach, so short-session injection passes while long-duration USBIP stability does not.
Permitted test families
Permanently blocked
Authorization manifest
The PWA stores manifests locally. A future signed bridge will accept only unexpired manifests whose fixture, mode, frequency, power, and containment rules match the connected hardware.
Local output
No manifest generated.
No manifest is uploaded automatically. Hardware transmission remains disabled in this public release.
Manifest library
Every manifest is held in this browser only, capped at the 25 most recent. Status is recomputed from the expiry timestamp, so a session that lapses while this page is open changes state on its own.
Verification
Runs the same checks the signed bridge will: schema, authorizations, expiry, RF envelope bounds, prohibited-action flags, and the SHA-256 integrity hash. A mismatched hash means the content was edited after it was generated.
Input
Result
Local audit trail
Records that an action occurred — created, verified, downloaded, cloned, deleted, preflighted — with a timestamp and engagement id. It deliberately stores no manifest content, and never leaves this browser.
Link budget
Arithmetic only — no hardware is involved. It exists so the envelope is set from a computed figure instead of a guess: what containment has to hold is the power arriving at the fixture, not the number on the transceiver.
Inputs
Result
A sanity rail, not a safety certification. The real limits are the fixture’s damage threshold and the enclosure’s isolation, neither of which this page knows.
Test sessions
The manifest records what was permitted. This records what was done — start and end times keyed to the manifest hash, with an outcome and notes. A session can only be started against an authorization that is currently valid and unrevoked.
Start and End are on each manifest in the library. Fill the outcome and notes fields there before ending a session — they are captured at the moment you end it.
Import
An exported bundle is a file, and a file can be edited between export and import. Every manifest is re-validated and its hash recomputed here — the stored digest is treated as a claim, never as proof. Import merges and dedupes; it never replaces what you already hold.
Use Import bundle in the library toolbar to load a file.
Compare
The review question that actually gets asked when one authorization supersedes another. Timestamps and the hash are excluded, because those always differ and would bury the fields that matter.
Engagement artifact
One printable page combining the authorization, the bench preflight as actually confirmed, and every session recorded against it. This is the thing that goes in the engagement folder — not the raw JSON.
View or generate a manifest, then use Session report above.
Engagements
Pricing is per engagement. Tell us your scope and we’ll follow up. This form opens your own email client — nothing is uploaded from this page.
What happens next
SignalLab is only for isolated fixtures and written client-authorized lab work. We do not take engagements against live access-control targets.
Help
Everything here happens in your browser. No manifest, note or audit entry is ever uploaded, and there is no account to create.
Start here
Field reference
Verification
A failing integrity check alongside another failure is normal: editing a manifest to weaken it changes the content, so the hash stops matching too. That is the mechanism working, not a second fault.
Revocation
Revoking records the manifest’s hash on a local revocation list with a reason and a timestamp. The manifest file itself is deliberately left untouched — writing a revoked flag into it would change its content and break its hash, which would make a withdrawn authorization indistinguishable from a forged one.
That list lives in this browser only. Revoking here does not reach a copy someone already downloaded — a real limit of a local-only tool, and the reason expirations should be short.
Troubleshooting
Data and boundaries
SignalLab prepares and verifies authorizations. It does not transmit, replay captured signals, jam, deauthenticate, unlock, or actuate anything, and it will not gain those abilities. Transmission, if it is ever built, lives behind a signed local bridge with a hardware interlock — never in this page.