carrier-explode
Explode and decode carrier data
GitHub
About
Carriers
Countries
Features
Builds
Compare
Wiki
iOS
▾
iOS
Pixel
iPadOS
watchOS
Close
Carriers
Dish_US
iOS 26.0 – 26.0.1 image · build 65.0.1
▾
iOS 27.2 beta 1–2 image · build 72.7.1
beta
iOS 27.0 – 27.0.1 image · build 72.0
current release
iOS 26.5 – 26.6.2 image · build 70.0
iOS 26.4 – 26.4.2 image · build 69.0
iOS 26.3.1 image · build 68.0
iOS 26.3 image · build 68.0
iOS 26.2 – 26.2.1 image · build 67.0
iOS 26.1 image · build 66.0
iOS 26.0 – 26.0.1 image · build 65.0.1
OTA iOS 18.5+ · build 64.1
OTA iOS 18.4+ · build 63.1
OTA iOS 18.2+ · build 61.1
OTA iOS 17.2+ · build 57.1
OTA iOS 17.0+ · build 55.1
Overview
Settings
Modem
Files (36)
Changes
overrides_D49.der.pri
iPhone SE (3rd generation)
Header
Written for
Qualcomm modem
PRI Revision
5.0.161
Settings (72)
efs:/data/3gpp/throttling
(1)
·
srv_req_throt_config.txt
unverified
=
"FAILURE_TIMER_5:20; "
Data services setting: Data services (PDN, throttling, AT commands)
efs:/data/3gpp/throttling/srv_req_throt_config.txt
efs:/nv/item_files/data/3gpp
(3)
·
3GPP MTU
likely
=
1430
Default PDN MTU in bytes
efs:/nv/item_files/data/3gpp/ds_3gpp_mtu
·
RPM params
likely
=
hex, 10 bytes
Radio Policy Manager retry limits (10 bytes)
efs:/nv/item_files/data/3gpp/rpm_params
·
RPM SIM list
likely
=
hex, 60 bytes
SIMs Radio Policy Manager applies to
efs:/nv/item_files/data/3gpp/rpm_suppported_sim
efs:/nv/item_files/ims
(2)
·
IMS enable
=
2
Enables the IMS task (VoLTE, VoWiFi, SMS over IMS)
efs:/nv/item_files/ims/IMS_enable
·
IMS media service config
unverified
=
hex, 512 bytes
IMS media (codec/RTP) service config; no public schema
efs:/nv/item_files/ims/media_service_config
efs:/nv/item_files/modem
(1)
·
LTE connection control
unverified
=
1
efs:/nv/item_files/modem/lte_connection_control
efs:/nv/item_files/modem/data/3gpp
(1)
·
Call before PS attach
likely
=
0
= Off
Allow data-call origination before PS attach
efs:/nv/item_files/modem/data/3gpp/call_orig_allowed_before_ps_attach
efs:/nv/item_files/modem/data/3gpp/ps
(2)
·
Service request throttle behaviour
likely
=
1
Service-request throttling behaviour
efs:/nv/item_files/modem/data/3gpp/ps/ser_req_throttle_behavior
·
3gpp_rel_version
likely
=
5
3GPP release: Signalled 3GPP release
efs:/nv/item_files/modem/data/3gpp/ps/3gpp_rel_version
efs:/nv/item_files/modem/data/3gpp/ps/apn_reject
(1)
·
APN reject name
likely
=
"reject_apn:ims; "
APN whose rejection triggers carrier throttling
efs:/nv/item_files/modem/data/3gpp/ps/apn_reject/apn_reject_name.txt
efs:/nv/item_files/modem/lte/L2/mac
(1)
·
lte_mac_enable_aas
unverified
=
0
LTE setting: LTE RRC / L1 / L2
efs:/nv/item_files/modem/lte/L2/mac/lte_mac_enable_aas
efs:/nv/item_files/modem/lte/ML1
(1)
·
cdrx_opt_info
unverified
=
257
LTE setting: LTE RRC / L1 / L2
efs:/nv/item_files/modem/lte/ML1/cdrx_opt_info
efs:/nv/item_files/modem/lte/rrc/bbq
(1)
·
Fake eNodeB mitigation
likely
=
1
= On
LTE false-base-station (fake eNodeB) mitigation
efs:/nv/item_files/modem/lte/rrc/bbq/bbq_mitigation
efs:/nv/item_files/modem/lte/rrc/cap
(4)
·
whitelist_ca_combos
likely
=
hex, 32 bytes
CA combo list: LTE CA / EN-DC band-combination allow/deny list
efs:/nv/item_files/modem/lte/rrc/cap/whitelist_ca_combos
·
blacklist_ca_combos
likely
=
hex, 65 bytes
CA combo list: LTE CA / EN-DC band-combination allow/deny list
efs:/nv/item_files/modem/lte/rrc/cap/blacklist_ca_combos
·
whitelist_ca_combos_with_laa
likely
=
hex, 32 bytes
CA combo list: LTE CA / EN-DC band-combination allow/deny list
efs:/nv/item_files/modem/lte/rrc/cap/whitelist_ca_combos_with_laa
·
LTE bands with UL CA
likely
=
B2 B5 B12 B14 B30 B48 B66
hex, 32 bytes
LTE bands allowed in uplink carrier-aggregation combos
efs:/nv/item_files/modem/lte/rrc/cap/whitelist_ca_combos_with_ulca
efs:/nv/item_files/modem/lte/rrc/efs
(11)
·
lte_conn_ctrl_barring_optimz_params
unverified
=
1
LTE setting: LTE RRC / L1 / L2
efs:/nv/item_files/modem/lte/rrc/efs/lte_conn_ctrl_barring_optimz_params
·
LTE feature enable
likely
=
hex, 32 bytes
LTE RRC capability feature-enable bitmap; bit list unpublished
efs:/nv/item_files/modem/lte/rrc/efs/lte_feature_enable
·
disable_4l_per_band
unverified
=
hex, 32 bytes
LTE setting: LTE RRC / L1 / L2
efs:/nv/item_files/modem/lte/rrc/efs/disable_4l_per_band
·
LTE band priority list
likely
=
hex, 12 bytes
Prioritised band list for LFS/FFS scans (uint16 array)
efs:/nv/item_files/modem/lte/rrc/efs/band_priority_list_v2
·
lte_rrc_sub_feature_enable
unverified
=
"@"
LTE setting: LTE RRC / L1 / L2
efs:/nv/item_files/modem/lte/rrc/efs/lte_rrc_sub_feature_enable
·
lte_connection_ctrl_params
unverified
=
hex, 16 bytes
LTE setting: LTE RRC / L1 / L2
efs:/nv/item_files/modem/lte/rrc/efs/lte_connection_ctrl_params
·
LTE feature disable
likely
=
hex, 32 bytes
LTE RRC capability feature-disable bitmap
efs:/nv/item_files/modem/lte/rrc/efs/lte_feature_disable
·
lte_fgi_r8
likely
=
2101342462
0x7d3ff0fe
LTE Feature Group Indicators: 3GPP TS 36.331 Annex B featureGroupIndicators sent in UE-EUTRA-Capability
efs:/nv/item_files/modem/lte/rrc/efs/lte_fgi_r8
·
lte_fgi_r10
likely
=
14142
LTE Feature Group Indicators: 3GPP TS 36.331 Annex B featureGroupIndicators sent in UE-EUTRA-Capability
efs:/nv/item_files/modem/lte/rrc/efs/lte_fgi_r10
·
lte_fgi_r10_tdd
likely
=
14142
LTE Feature Group Indicators: 3GPP TS 36.331 Annex B featureGroupIndicators sent in UE-EUTRA-Capability
efs:/nv/item_files/modem/lte/rrc/efs/lte_fgi_r10_tdd
·
lte_fgi_r8_tdd
likely
=
2101342462
0x7d3ff0fe
LTE Feature Group Indicators: 3GPP TS 36.331 Annex B featureGroupIndicators sent in UE-EUTRA-Capability
efs:/nv/item_files/modem/lte/rrc/efs/lte_fgi_r8_tdd
efs:/nv/item_files/modem/mav
(7)
·
LTE CA combos per PLMN
likely
=
1
= On
Prune the advertised LTE CA combos per PLMN from /policyman/band_combos_per_plmn.xml
efs:/nv/item_files/modem/mav/lte_ca_xml_generation
·
EN-DC combos per PLMN
likely
=
1
= On
Same per-PLMN capability pruning for EN-DC combos (next to cap_prune, skip_cap_prune)
efs:/nv/item_files/modem/mav/endc_ca_file_generation
·
mav_monitor_enable_nr5g_uwb_based_on_motion_state_no_uli_case
likely
=
0
5G icon rule: Status-bar 5G / 5G UW / 5G UC / 5G+ icon override logic
efs:/nv/item_files/modem/mav/mav_monitor_enable_nr5g_uwb_based_on_motion_state_no_uli_case
·
mav_avoid_pco_for_aging
unverified
=
1
Apple modem option: Apple-only (Maverick) modem option; undocumented
efs:/nv/item_files/modem/mav/mav_avoid_pco_for_aging
·
mav_monitor_mm_mb_replace_nr5g_with_nr5guwb
likely
=
1
5G icon rule: Status-bar 5G / 5G UW / 5G UC / 5G+ icon override logic
efs:/nv/item_files/modem/mav/mav_monitor_mm_mb_replace_nr5g_with_nr5guwb
·
mav_ignore_high_bw_check
unverified
=
1
Apple modem option: Apple-only (Maverick) modem option; undocumented
efs:/nv/item_files/modem/mav/mav_ignore_high_bw_check
·
sdm_nsa_icon_override
likely
=
0
Smart data mode: Apple SDM: turns NR / SA off or deprioritises SA when it does not pay off
efs:/nv/item_files/modem/mav/sdm_nsa_icon_override
efs:/nv/item_files/modem/mmode
(4)
·
SMS domain preference list
unverified
=
hex, 15 bytes
Per-RAT/PLMN SMS domain list; layout not public
efs:/nv/item_files/modem/mmode/sms_domain_pref_list
·
LTE band preference
likely
=
178120883634175
0xa1fffffeffff
LTE band bitmap (bit n = band n+1)
efs:/nv/item_files/modem/mmode/lte_bandpref
·
LTE disable duration
likely
=
0
How long LTE stays disabled when CS services are unavailable
efs:/nv/item_files/modem/mmode/lte_disable_duration
·
Voice domain preference
=
3
= IMS PS voice preferred
E-UTRAN voice domain (TS 24.301 9.9.3.44)
efs:/nv/item_files/modem/mmode/voice_domain_pref
efs:/nv/item_files/modem/nas
(7)
·
mav_pssi_reg_unblock_hplmn_max_reg_failure
likely
=
1
PSSI registration rule: Apple PLMN search / system-selection (PSSI) registration tuning
efs:/nv/item_files/modem/nas/mav_pssi_reg_unblock_hplmn_max_reg_failure
·
mav_pssi_reg_unblock_hplmn_voice_not_avail_based_on_motion_st
likely
=
1
PSSI registration rule: Apple PLMN search / system-selection (PSSI) registration tuning
efs:/nv/item_files/modem/nas/mav_pssi_reg_unblock_hplmn_voice_not_avail_based_on_motion_st
·
ISR
likely
=
1
= On
Idle-mode Signalling Reduction (TS 23.401)
efs:/nv/item_files/modem/nas/isr
·
Reject LTE null ciphering
likely
=
1
= On
Reject an LTE NAS Security Mode Command that selects null ciphering (EEA0)
efs:/nv/item_files/modem/nas/mav_lte_reject_smc_null_ciphering
·
SRVCC support
=
1
= On
SRVCC capability indication from E-UTRAN to UTRAN (TS 23.216)
efs:/nv/item_files/modem/nas/nas_srvcc_support
·
Reject NR null ciphering
likely
=
1
= On
Reject a 5G NAS Security Mode Command that selects null ciphering (NEA0)
efs:/nv/item_files/modem/nas/mav_nr_reject_smc_null_ciphering
·
CSG support
likely
=
1
Closed Subscriber Group (femtocell) support
efs:/nv/item_files/modem/nas/csg_support_configuration
efs:/nv/item_files/modem/nr5g/rrc
(5)
·
endc_whitelist_ca_combos
likely
=
hex, 32 bytes
CA combo list: LTE CA / EN-DC band-combination allow/deny list
efs:/nv/item_files/modem/nr5g/rrc/endc_whitelist_ca_combos
·
endc_whitelist_ca_combos_with_laa
likely
=
hex, 32 bytes
CA combo list: LTE CA / EN-DC band-combination allow/deny list
efs:/nv/item_files/modem/nr5g/rrc/endc_whitelist_ca_combos_with_laa
·
endc_blacklist_specific_lte_bands
likely
=
hex, 32 bytes
CA combo list: LTE CA / EN-DC band-combination allow/deny list
efs:/nv/item_files/modem/nr5g/rrc/endc_blacklist_specific_lte_bands
·
endc_reduced_cc_lte_fr1_ca_combos
likely
=
517
CA combo list: LTE CA / EN-DC band-combination allow/deny list
efs:/nv/item_files/modem/nr5g/rrc/endc_reduced_cc_lte_fr1_ca_combos
·
nrsa_whitelist_ca_combos
likely
=
hex, 32 bytes
CA combo list: LTE CA / EN-DC band-combination allow/deny list
efs:/nv/item_files/modem/nr5g/rrc/nrsa_whitelist_ca_combos
efs:/nv/item_files/modem/nr5g/RRC
(3)
·
cap_csi_rs_32_port_control
likely
=
hex, 195 bytes
NR UE capability: NR RRC UE-capability toggle
efs:/nv/item_files/modem/nr5g/RRC/cap_csi_rs_32_port_control
·
cap_control_mrdc_f_plus_t_band_combos
likely
=
0
NR band-combo class control: Enables an NR-CA / NR-DC / MR-DC band-combination class in the UE capability
efs:/nv/item_files/modem/nr5g/RRC/cap_control_mrdc_f_plus_t_band_combos
·
cap_disable_ul_256qam
likely
=
1
NR UE capability: NR RRC UE-capability toggle
efs:/nv/item_files/modem/nr5g/RRC/cap_disable_ul_256qam
efs:/nv/item_files/modem/qmi/cat
(1)
·
Block SMS-PP envelope
likely
=
0
= Off
Block SIM Toolkit SMS-PP (data download) envelopes, per subscription
efs:/nv/item_files/modem/qmi/cat/qmi_cat_block_sms_pp_env_per_sub
efs:/nv/item_files/modem/sms
(1)
·
Refresh vote OK
likely
=
0
= Off
Vote TRUE for SIM REFRESH
efs:/nv/item_files/modem/sms/mmgsdi_refresh_vote_ok
efs:/nv/item_files/modem/uim/mmgsdi
(4)
·
override_opl_pnn_lookup_for_non_rplmn
unverified
=
2
SIM setting: UIM / SIM manager / SIM Toolkit
efs:/nv/item_files/modem/uim/mmgsdi/override_opl_pnn_lookup_for_non_rplmn
·
SIM refresh retry
likely
=
hex, 16 bytes
SIM REFRESH retry parameters (4 x uint32)
efs:/nv/item_files/modem/uim/mmgsdi/refresh_retry
·
slot_features_status_list__mav_override
unverified
=
266
Apple override: Apple override of the Qualcomm item of the same name
efs:/nv/item_files/modem/uim/mmgsdi/slot_features_status_list__mav_override
·
ens_slot_enabled
unverified
=
1
SIM setting: UIM / SIM manager / SIM Toolkit
efs:/nv/item_files/modem/uim/mmgsdi/ens_slot_enabled
efs:/nv/item_files/modem/uim/uimdrv
(1)
·
nv_pdown_uim_consecutive_techproblems
unverified
=
769
SIM setting: UIM / SIM manager / SIM Toolkit
efs:/nv/item_files/modem/uim/uimdrv/nv_pdown_uim_consecutive_techproblems
efs:/nv/item_files/wcdma/rrc
(1)
·
WCDMA to LTE PS handover
likely
=
0
= Off
WCDMA->LTE PS handover support
efs:/nv/item_files/wcdma/rrc/wcdma_rrc_wtol_ps_ho_support
efs:/policyman
(1)
·
Carrier policy
likely
=
show XML, 998 bytes
PolicyMan rules keyed on MCC/PLMN: RAT capability, RF bands, UE mode
efs:/policyman/carrier_policy.xml
nv
(5)
·
PRI revision
=
10551301
= 5.0.161
0xa10005
Packed PRI Revision header
nv:62005
·
ENS Enabled
likely
=
1
= On
Enhanced Network Selection
nv:3461
·
UMTS AMR Codec Preference Config
likely
=
5
nv:6850
▾
Call Manager Feature Group
2 of 25 flags set
nv:62012
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
12
: Set only on AT&T's network (AT&T, its brands and Dish), always with flag 3 of the unnamed group
20
: Set for every iPhone from iPhone 14, and on older iPhones only by carriers that have shut down 3G; likely the newer form of flag 14
▾
Feature Group (unnamed, tag 9f83e453)
unverified
1 of 25 flags set
nv:62035
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
3
: Set only on AT&T's network, always with Call Manager flag 12. The modem checks it in its geo-MCC attach logic, alongside a home-network check (medium confidence)
pri
(3)
·
Legacy NV item list
=
show list, 35 entries
Legacy NV items the modem may take from this file; with a value here: 62012, 6850, 3461, 62005, 62035.
pri:nv-list
·
NV path schema index
=
show list, 260 entries
260 NV paths the PRI format knows (raw); not overrides.
pri:schema
·
pri:9fa710
=
178
Unidentified field, 1 time, 2 bytes: small binary blob that precedes the NV item list.