Resources

USENIX Security ‘26 artifact

All of our result files, anonymized PCAPs, and the scripts and tools used to conduct our scans are archived on Zenodo:

https://zenodo.org/records/20274003

A top-level README details the artifact and folder structure. Contents include:

Folder Contents
tls_length_field_manipulations/scanner The length field scanner, with setup instructions
tls_length_field_manipulations/results Per-vantage-point results: anonymized PCAPs, aggregated JSON, txt, and csv
quic_fingerprints Recorded probes from the QUIC version scan
ip_fragmentation_reassembly PCAPs from the IP reassembly scans
ip_fragmentation_reassembly/ipfragtest Geneva, used to generate fragmented packets
dns_injection_behavior PCAPs for the DNS injector results
dns_injection_behavior/compress-crafter Tool used to create the DNS messages
tcp_rst_injection_behavior PCAPs from the TCP RST injection fingerprinting scan
tcp_rst_injection_behavior/getkey Tool used to derive the seed key

We also provide the shell scripts used on our vantage points. Test vectors were created by extending the open-source tool Censor-Scanner as well as using Geneva.

Reporting on the leak

Several news organizations and journalists were granted early access and worked together for the past year to analyze the files, focusing on non-code documents. Their reporting covers the export of Geedge Networks’ censorship systems to Pakistan, Myanmar, Ethiopia, and Kazakhstan, focusing on human-rights impacts, procurement networks, and the spread of Great Firewall–style controls.