This repository contains a reverse-engineering exercise based on the fictional Oriole M3 cellular modem.
Start with INTERN_BRIEF.md. The supplied ELF is a stripped Linux harness around the same portable C state machines used by the STM32 firmware, so it can be inspected statically and executed safely on an x86-64 Linux workstation.
Run a known-good session with:
chmod +x modem_fw.elf
./modem_fw.elf --input captures/port0_at_session.bin --chunk 7The captures are raw input byte streams. The executable prints each transmitted response as hexadecimal and printable ASCII, followed by a summary. Try different chunk sizes: correct protocol behavior must not depend on how input is divided at the simulated interrupt boundary.
Recommended tools include Ghidra, Binary Ninja, IDA, radare2, Cutter, and standard command-line utilities such as file, readelf, objdump, strings, and xxd.
No source code or protocol specification is included. Recover behavior from the executable and traffic evidence, and document the basis for each reconstructed field rather than trying to guess original identifier names.