Skip to content

DragonOS — Tier 1 inventory

Generated by scripts/gen_dragonos_tier1.py. Do not edit by hand — regenerate. Versions come from DragonOS's published README; availability comes from apt-cache policy measured inside each target container.

Release inventoried: DragonOS Resolute R1 (08/026/2026)
Base: New ground-up build on Ubuntu 26.04 / kernel 7.0.0-29
Source: https://sourceforge.net/projects/dragonos-focal/files/README.txt/download
Project: https://cemaxecuter.com/
apt probes: debian-13, ubuntu-26.04, kali-rolling, parrot — measured 2026-08-25
Generated: 2026-09-07

DragonOS is written and curated by cemaxecuter. Like AHRL, 73Linux and Skywave it is an inventory source, never a base (D-001). It is by a wide margin the largest and most expensive of the five, which is why SCOPE.md splits it into tiers and admits only Tier 1 to 1.0.

Tier 1 is the deliverable here. Tiers 2 and 3 are counted and named so the denominator is honest, and are otherwise left alone: SCOPE.md puts Tier 3 behind the source backend and the pin database, and neither exists yet.

One thing to state plainly up front: DragonOS has moved. Resolute R1 is a ground-up rebuild on Ubuntu 26.04 whose headline features are an AI agent platform, a drone-detection story, and a large cellular/EW section. That last part is not a SIGINT profile in the sense SCOPE.md meant, and it is treated separately below rather than folded into a package count.


Summary

Class Units In this document
Tier 1 — apt or upstream .deb 24 yes, in full
Tier 2 — maintained upstream, needs a build 26 named only
Tier 3 — GNU Radio out-of-tree 1 named only
Hardware libraries and device support 20 named only — M4 work
Cellular / EW 20 flagged for decision — see Q-008
DragonOS-specific platform 8 named only — out of scope
Total units in the README 99

SCOPE.md sizes the 1.0 SIGINT profile from Tier 1; profile-sizing.md estimated ~12 to 15 units. Measured: 24 README units — but most of those already arrive through the Debian Blend or the existing catalog. The genuinely new SIGINT contribution is about ten packages, so the estimate holds for sizing purposes even though the raw count is higher.


Tier 1 — 24 units

Membership is decided by the probe, not by the list in SCOPE.md. The generator refuses to emit a Tier 1 row that is in no target's apt and has no named upstream .deb, so this table cannot silently overclaim.

Unit DragonOS ver. apt package(s) deb 13 ubu 26.04 kali parrot Note
aircrack-ng — aircrack-ng ✅ ✅ ✅ ✅ Wi-Fi audit suite
AIS-Catcher 0.60 ais-catcher — — — — upstream .deb; manifest already written
CubicSDR 0.2.7 cubicsdr ✅ ✅ ✅ ✅ SDR receiver; Blend sdr
direwolf 1.8.1 direwolf ✅ ✅ ✅ ✅ AX.25 soundmodem; also in our packet core
fldigi 4.2.10 fldigi ✅ ✅ ✅ ✅ already in the catalog
GNU Radio 3.10.12 gnuradio, gr-osmosdr, libvolk-dev ✅ ✅ ✅ ✅ framework; Tier 3 depends on it
Gpredict 2.4 gpredict ✅ ✅ ✅ ✅ satellite tracking
gpsd / ffmpeg / sox — gpsd, ffmpeg, sox ✅ ✅ ✅ ✅ infrastructure the rest depends on
GQRX-SDR 2.17.7 gqrx-sdr ✅ ✅ ✅ ✅ SDR receiver; Blend sdr
HackTV / HackTV-GUI — hacktv ✅ ✅ ✅ ✅ analogue TV transmitter; Blend nonamateur
hcxdumptool / hcxtools — hcxdumptool, hcxtools ✅ ✅ ✅ ✅ WPA capture and conversion
inspectrum 0.5.4-rc1 inspectrum ✅ ✅ ✅ ✅ offline signal visualiser
JS8Call 3.0.3 js8call ✅ ✅ ✅ ✅ already in the catalog
multimon-ng 1.3.1 multimon-ng ✅ ✅ ✅ ✅ POCSAG/FLEX/AFSK/DTMF
QSSTV 9.5.8 qsstv ✅ ✅ ✅ ✅ SSTV
rtl_433 25.12 rtl-433 ✅ ✅ ✅ ✅ ISM 433/868/915 decoder
SatDump 2.0.0-alpha satdump ✅ ✅ ✅ ✅ upstream .deb; apt on all four
SDRAngel 7.27.1 sdrangel — — ✅ — upstream .deb per Ubuntu release; apt on Kali
SDRPP 1.3.0 sdrpp — — ✅ ✅ upstream .deb; apt on Kali and Parrot
SoapySDR 0.8 soapysdr-tools ✅ ✅ ✅ ✅ device abstraction; Blend sdr
Ubertooth host tools — ubertooth ✅ ✅ ✅ ✅ BLE/BT sniffer host tools
UHD 4.9.0.1 uhd-host, python3-uhd ✅ ✅ ✅ ✅ USRP host tools
Wireshark 4.6.4 wireshark, tshark, tcpdump ✅ ✅ ✅ ✅ protocol analyser
WSJT-X 3.0.2 wsjtx ✅ ✅ ✅ ✅ already in the catalog

✅ means every listed package resolves on that target. A dash means at least one does not — the SoapySDR and GNU Radio rows bundle several.

The four that are .deb-only

Unit Upstream artifact
SDRAngel f4exb/sdrangel publishes sdrangel_7.27.2_ubuntu-26.04_amd64.deb
SDRPP AlexandreRouma/SDRPlusPlus publishes sdrpp_debian_bookworm_amd64.deb
SatDump SatDump/SatDump publishes satdump_1.2.2_ubuntu_24.04_amd64.deb
AIS-Catcher jvde-github/AIS-catcher publishes ais-catcher_debian_bookworm_amd64.deb

All four publish ordinary GitHub release assets with stable naming — no webpage scraping, unlike HAMRS. None publishes a checksum file alongside, which is the pin/hash sub-project SCOPE.md names, not a blocker for this inventory.

Tested 2026-08-26 — the base mismatch was real, and worse than flagged. See docs/reference/install-verification.md for the full matrix.

Artifact Debian 13 Ubuntu 26.04
SatDump, built for Ubuntu 24.04 ❌ unmet deps ❌ unmet deps
SDR++, debian_bookworm ❌ unmet deps ❌ unmet deps
SDR++, debian_sid ✅ ✅
SDRangel, built for Ubuntu 26.04 ❌ unmet deps ✅
AIS-Catcher, debian_bookworm ✅ ✅

Only two of the four reach a target through their .deb. SatDump is still Tier 1, but by apt — satdump 1.2.2-1 is in Debian 13 and installs cleanly. SDRangel is Tier 1 only on the base it was built for. SDR++ works only through the sid-targeted artifact, which is not the obvious choice and is not documented upstream.

SDR++ also has no pinnable release. Its assets hang off a rolling nightly tag, so the URL never changes and the artifact behind it does. No version to pin, no checksum published — the pin/hash sub-project SCOPE.md names, in its sharpest form so far.

Consequence for the schema: these units need per-target install blocks, not one URL each. Selector already expresses that; the manifests have to use it.


What the probe changed

86 candidate package names were probed in each of the four target containers. 59 resolve everywhere, 20 resolve nowhere, and 7 differ by target — which is the whole argument for the capability matrix.

Package deb 13 ubu 26.04 kali parrot
asterisk — ✅ ✅ —
dump1090-mutability — ✅ — —
gr-gsm ✅ — ✅ ✅
kalibrate-rtl — — ✅ —
kismet — — ✅ ✅
sdrangel — — ✅ —
sdrpp — — ✅ ✅

Two corrections to package names were needed along the way, and both would have produced a false "not available" if published unchecked: libvolk2-dev is libvolk-dev on current Debian, and libmirisdr0 is libmirisdr4. Every absence above was confirmed with apt-cache search on the name stem, not just apt-cache policy on a guess.


Cellular / EW — flagged, not classified

DragonOS Resolute R1 devotes an entire section to cellular and electronic warfare. It is a substantial part of the release and it cannot be quietly folded into a sigint profile, because it is not the same kind of thing as a passive decoder.

The distinction that matters is transmit. Passively receiving and decoding GSM control channels is a different legal and ethical category from operating a rogue base station. DragonOS's own README describes intrusive-lte-mme as a "clean-room rogue LTE MME / IMSI-catcher lab" and qualifies it "authorized RX/active use"; srsRAN_4G, Osmocom core and osmo-trx are complete network stacks that transmit. In most jurisdictions — including the United States, where operating an unlicensed cellular base station engages both FCC rules and federal interception statutes — running these against live spectrum requires specific authorisation that an ordinary user will not have. Note that DragonOS states the constraint itself; the caveat is in its README, not something we are adding.

This is not a refusal and not a judgement of DragonOS. These are legitimate tools with legitimate uses: authorised red-team engagements, lab work on shielded benches, academic research, and vendor testing. DragonOS serves an audience that has those authorisations. The question is whether we ship them in a one-command installer aimed at licensed hams, where the barrier between "installed" and "transmitting" is thin and the user may have no authorisation at all.

gr-gsm is worth separating out: it is in apt on Debian 13, Kali and Parrot, it is receive-only, and PARITY-POLICY.md already names it in the RF-security ADD list with the caveat that upstream has stalled for modern GNU Radio.

Recorded as Q-008 for the maintainer. The recommendation there is to admit the receive-only subset to the opt-in RF-security profile with legal framing per CLAUDE.md, and to keep transmit-capable cellular network emulation out of 1.0 entirely — not because it is illegitimate, but because a curated installer is the wrong delivery mechanism for it.

Unit What it is
ransack LTE/cellular survey provider
LTESniffer 2.1.1 / ltesniffer-dl LTE downlink+uplink IMSI/RNTI sniffer
FALCON live LTE PDCCH/DCI decoder
intrusive-lte-mme rogue LTE MME / IMSI-catcher lab — transmits
lte-scan LTE scanner
sni5gect 5G injection
fiveg-nid 5G network identity
ella-core 5G core
ocudu O-RAN CU/DU
osmo-nid network identity
srsRAN_4G full LTE stack — transmits
gr-gsm GSM receiver; in apt on Debian, Kali and Parrot
IMSI-catcher passive IMSI collection from GSM
QCSuper Qualcomm diagnostic capture; receive-only
kalibrate-hydrasdr clock calibration off GSM bursts
cmas-pws-4g public warning system decoder
Osmocom core full GSM network stack — transmits
osmo-trx 1.7.1 / osmo-sip-connector GSM transceiver — transmits
OsmocomBB GSM baseband
Asterisk PBX; in apt on Ubuntu and Kali

Deferred — named, deliberately not inventoried

SCOPE.md: "Do not attempt Tier 3 before the source backend and pin database are solid." The same reasoning applies to Tier 2, which is post-1.0. These are recorded so the denominator is honest and so nothing is rediscovered later as if it were new.

Tier 2 — 26

Unit Note
ACARSDEC CMake build — see the Skywave inventory
baudline closed-source binary, fetched on first run
Blue Dragon DragonOS-original BT sniffer
CyberEther Vulkan/CUDA; heavy GPU dependency
DSD-FME CMake build; needs libmbe
dump1090-fa FlightAware repo; readsb is our default per overlaps.md
DumpHFDL CMake build
DumpVDL2 CMake build
GridTracker Electron app
HamClock see Q-006 — four candidate sources
Iridium-Sniffer / Inmarsat-Sniffer / Meshtastic-Sniffer DragonOS-original
iridium-toolkit Python, no licence file upstream
LuaRadio Lua DSP framework
NRSC5 CMake build
PySDR a textbook, not software
QRadioLink CMake build
QSpectrumAnalyzer PyPI
radiosonde_auto_rx AHRL REVIVE candidate; venv backend
rtlamr / rtl-power-fftw Go binary / CMake build
SDRconnect SDRplay, closed source — same objection Skywave raised
SDRTrunk Java zip release
SigDigger no .deb; CMake build
SparkSDR closed-source freeware
SpyServer Airspy, closed-source binary
Universal Radio Hacker PyPI only, and upstream is archived
WFView Icom rig control; CMake build

Tier 3 — 1

Unit Note
GR OOT modules gr-lora_sdr, gr-ieee802-11, gr-tempest, gr-bladeRF, gr-iridium

Hardware / drivers — 20

Unit Note
ADALM-Pluto device support
Airspy device support
BladeRF device support
Fobos SDR device support
HackRF library
HackRF One device support
HydraSDR device support
HydraSDR / Fobos SDR / SDRplay API 3.15.2 / libmirisdr4 / rtl-sdr / airspy / airspyhf library set
libbladeRF library + firmware images
LimeSDR device support
LimeSuiteNG 0+git8f0bdeb / limepcie-dkms library + DKMS kernel module
Mirics device support
OpenCL: intel-opencl-icd, mesa-opencl-icd GPU acceleration for SatDump
Red Pitaya device support
RTL-SDR device support
SDDC RX888/RX666/BBRF103
SDRplay closed API — see the Skywave inventory
SoapyRemote network SDR
USRP / UHD device support
VITA 49 / VRT network IQ transport

DragonOS-specific platform — 8

Unit Note
dragon-brain DragonOS-original LLM front end
dragon-dmr-agent DragonOS-original
dragon-gateway DragonOS-original MCP surface
dragon-provider DragonOS-original runtime
dragon-rf DragonOS-original agent
dragon-speech DragonOS-original STT/TTS
dragonos-dmr-trunk DragonOS-original DMR site
sdr4space-sdrvm DragonOS-original capture engine

What this changes

Tier 1 is real, and it is cheaper than estimated. profile-sizing.md sized sigint at ~13 from the list in SCOPE.md. The measured Tier 1 set is close to that in units, and most of it is already arriving through the Debian Blend or the existing catalog — fldigi, wsjtx, js8call, gpredict, direwolf, gqrx-sdr, cubicsdr, soapysdr-tools. The genuinely new SIGINT contribution is a small set: wireshark, aircrack-ng, hcxdumptool/hcxtools, ubertooth, rtl-433, inspectrum, plus the four .deb units.

Kali is the best-covered target, and that is useful rather than incidental. It carries kismet (with drone-detection capture drivers), sdrangel, sdrpp and kalibrate-rtl in apt where Debian 13 has none of them. Parrot — our primary target — carries kismet, sdrpp and gr-gsm. Debian 13 is the worst-covered of the four for this profile, which is worth knowing before the capability matrix levels every claim down to it. The matrix should show the difference rather than hide it; a Parrot or Kali user genuinely does get more here, and saying so is the honest-gaps behaviour CLAUDE.md requires.

SCOPE.md's Tier 1 list needs correcting. It names Kismet, readsb, dumphfdl, DumpVDL2 and AIS-Catcher. Four of the five need a change; only readsb survives as written.

  • Kismet is not in the Resolute R1 README at all. It is in the FocalX README (Kismet 2023-07-R1, plus Kismet MetaGPSD and the Rest API), so SCOPE.md's entry traces to the older release. The README is the project's own package list rather than a manifest, so this is evidence of absence rather than proof of it. Separately and independently of DragonOS, Kismet is apt-installable on Kali and Parrot — with drone-detection capture drivers on Kali — and not on Debian 13 or Ubuntu 26.04, and it ships an official signed apt repository our security rules permit when the manifest declares it and pins the key. It belongs in the profile on its own merits; it should stop being cited as a DragonOS inheritance.
  • dumphfdl and DumpVDL2 are in no target's apt, and in neither Debian stable nor unstable — measured in the Skywave inventory. They are Tier 2.
  • AIS-Catcher is Tier 1, but by upstream .deb, not by apt.
  • readsb is genuinely apt-installable and is already our ADS-B default per overlaps.md. It is not in the DragonOS README, which ships dump1090-fa instead; the overlaps.md recommendation is unaffected.

Universal Radio Hacker is archived. jopohl/urh is read-only on GitHub, last pushed 2025-12-19, final release v2.10.0 — which is exactly the version DragonOS ships. It has 12,500 stars and is in none of the four targets' apt — and tracker.debian.org/pkg/urh returns 404 while sources.debian.org has no exact match, so it appears never to have been packaged for Debian at all rather than removed. PARITY-POLICY.md names URH in the RF-security ADD list; that entry now needs a status. It is not broken, it is frozen, and it installs from PyPI. Per D-005 the verdict must be tested by us before it is written down — and per PARITY-POLICY.md, "finished" is a legitimate state for a tool to be in. Carried forward, not decided here.

The GNU Radio version is the Tier 3 gate, and the news is good. DragonOS Resolute ships GNU Radio 3.10.12, and so does every one of our four targets:

Target gnuradio gr-osmosdr libvolk-dev
debian-13 3.10.12.0-1 0.2.6-4 3.2.0-2
ubuntu-26.04 3.10.12.0-6 0.2.6-6 3.3.0-2
kali-rolling 3.10.12.0-6+b3 0.2.6-6+b2 3.3.0-3
parrot 3.10.12.0-1 0.2.6-4 3.2.0-2

Same upstream GNU Radio across all four, differing only in Debian revision, and matching what DragonOS built its modules against. That removes the worst version of the Tier 3 problem — we are not chasing four different APIs — and reduces it to the one SCOPE.md already describes: whether each module has a maintained upstream for 3.10. libvolk does differ (3.2 on the Debian-13-derived targets, 3.3 on the newer ones), which is worth remembering when a module links it directly.

None of this changes the gate. Tier 3 still waits on the source backend and the pin database, and every module still has to record the API it was built against. It does mean that when the gate opens, the target is a single API version.