Turn a signalling pcap into per-subscriber call flows: 5G, 4G and IMS, every failure explained
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Deterministic 5G / 4G / IMS signalling analyzer and call-flow correlator.
The correlation and root-cause layer on top of tshark: one subscriber across
every interface, every failure explained from a verified cause table, and
nothing generated.
For core-network SRE and R&D, RAN/core interoperability test, and third-line troubleshooting at vendors and operators. It assumes you already read signalling for a living.

Two outputs from one analysis. Mermaid you can paste into a ticket:
That is real output from tests/fixtures/ki-mismatch, not an illustration: a UE
provisioned with the wrong key, captured on a local Open5GS testbed. It is
not the MAC failure you would expect β a UE whose K does not match computes
an AUTS the network cannot resynchronise from, so you get #21 and then a bare
#111. The cause table says so because we ran it, not because it sounded right.
And the same capture in the browser: a packet list driven by real tshark
display filters, per-frame decode tree and bytes, the ladder with the initiator
and the cause on every failing event, and a per-PDU-session matrix where every
cell cites the frame it came from.

| Generation | Protocols | Cause explanations |
|---|---|---|
| 5G core | NGAP, NAS-5GS, HTTP/2 SBI, PFCP, GTP-U | 206 |
| 4G / EPC | S1AP, NAS-EPS, GTPv2-C (S11, S5/S8, N26), SGsAP (SGs) | 236 |
| IMS | SIP (calls, KPIs), Diameter, H.248/MEGACO | 333 |
Every cause code is resolved through a hand-verified table to the specification
it comes from, what it means in plain language, and the root causes that
actually produce it in the field β 775 of them, every name taken verbatim
from tshark and re-checked against it by a test. Nothing is generated: a cause
the table does not carry is reported as not catalogued, and a clause number is
printed only where a person transcribed it. Every network function is named
rather than shown as an IP, with the evidence for that name on hover.
| Today | With TelcoLadder |
|---|---|
| Copying UE IDs by hand between windows to follow one subscriber | One subscriber's whole lifetime in one flow: SUPI, 5G-S-TMSI, NGAP and S1AP UE IDs, TEIDs, Call-ID β with keys that are recycled treated as recycled |
| N2 and SBI in separate captures that never line up | N2, SBI and N4 stitched on one timeline; N4 joins through the GTP-U tunnel endpoint the UPF allocated and NGAP relayed |
| An N26 handover spread across NGAP, N26, S11 and S1AP | One segment across all four, joined through the S1-U SGW F-TEID the MME copies from Create Session Response into HandoverRequest |
| A bare cause number and a trip to the spec | 775 causes with the specification named, plain language and field root causes; clauses where a person checked them |
| RAN and core blaming each other for a dropped context | Every UE context release marked requested by the RAN or ordered by the core β a wire fact, not an opinion |
| A procedure that stalls for no visible reason | The gap named when it matches a NAS timer's default (T3560, T3460 β¦), and failures counted by TAC, cell, DNN and core element |
| VoLTE Gm signalling hidden inside IPsec ESP | NULL-encrypted ESP is detected and decoded, so the SIP and SDP inside join the subscriber's ladder. ESP that is really encrypted stays unreadable and is counted, not guessed |
| A B2BUA (an AS, or an SBC that keeps the charging ID) changes the Call-ID, so one call shows up as unrelated dialogs | Legs that share a charging ID (ICID) and overlap in time are one call, end to end β H.248, HSS, charging and ENUM attached only where evidence ties them to that call |
| Customer captures that must never leave the building | A command on your machine: no network listener beyond 127.0.0.1, no telemetry, no cloud, no model |
Windows without Python? Skip
pipand jump to 4. Windows, no install β the only prerequisite is Wireshark.
4. Windows, no install. A standalone executable in a portable zip, built by CI from the tagged source. Nothing is installed and no registry key is written; it needs Wireshark 4.0 or newer on the machine, nothing else.
TelcoLadder-Windows-x64.zip (about 10 MB) from
the Releases page.check-environment.cmd. It finds tshark.exe in
Wireshark's default install location under Program Files β or wherever
TELCOLADDER_TSHARK points β and checks the dissectors.serve listens on http://127.0.0.1:3005: open it in your browser, drop a
capture (up to 1 GB), or paste a path for anything larger.5. Hand a capture to someone else. telcoladder anonymize in.pcap out.pcap
rewrites subscriber identities, addresses, hostnames, PLMN and cell identifiers
into keyed pseudonyms of the same length β TBCD, ASCII, JSON and HPACK-Huffman
alike β recomputes every checksum, then re-reads its own output and refuses to
keep it if any original value is still visible. The output walks the same
pipeline to the same procedures, roles and failures; only the names differ.
Same key, same pseudonyms across captures; the key is printed once and never
written down. Compressed HTTP/2 bodies cannot be rewritten in place and are
refused unless --blank-opaque-bodies.
Requires Python 3.11+ and tshark (Wireshark 4.0 or newer) for the pip
route. Neither the macOS nor the Windows installer puts tshark on your PATH;
TelcoLadder looks in the standard install directories and finds it anyway, or
takes TELCOLADDER_TSHARK. The venv-by-venv Windows walkthrough is in the
user guide.
Cross-interface correlation. A subscriber is a union of identity keys, each with the right scope: NGAP and S1AP UE IDs are unique only within one association, TEIDs and TMSIs are reallocated and treated as episodes, and the GTP-U tunnel endpoint is one definition shared by NGAP, PFCP, GTP-U and now S1AP. The failure mode of a wrong key is two people in one flow with a ladder that still renders, so the key shapes are tested against captures built to provoke exactly that.
775 verified causes. Names from tshark -G values, re-checked by tests on
every CI platform; two Diameter number spaces kept apart; NGAP and S1AP cause
groups looked up in the group the message selected. Ordered-sequence rules
written by people β #21 followed by #111 is a key mismatch, not a sequence
problem β are matched and reported with the frames.
Fault attribution. UEContextReleaseRequest is only ever sent by the RAN
and the release Command only by the core; the ladder, the procedure list and
the xDR say which one started it. The reason still comes from the cause table;
there is no second verdict string.
Timer match and blast radius. An unanswered network request followed by a
release or reject a timer's default later is reported as consistent with that
timer β never as a proven timeout, because the capture shows timing and not the
AMF's state. With several subscribers, failures are counted by TAC, cell, DNN
and core-side element; an unknown location is a null row, not a dropped one.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/telcoladder)<a href="https://allmcps.com/mcp/telcoladder"><img src="https://allmcps.com/api/badge/telcoladder?style=directory" alt="Telcoladder on AllMCPs" /></a>