What it does, what that is worth, and what it cannot tell you.
This is a working document rather than a brochure. Every figure below was measured on a named session, and where something has not been measured it says so instead of estimating. Read it alongside the narrative on the front page, which explains why the system is shaped this way.
- · Levels are relative in dB over a learned local background. Never absolute dBm.
- · An event position is where the signal was received. Never the location of the transmitter.
- · No bearing, no distance, no range, no drone type. Fibre-guided and LTE-linked drones are invisible.
- · Detection is passive throughout. RadAir transmits nothing and jams nothing.
Every screen below is the real application rendered on a synthetic session — a generated route with invented network names, and a generated spectrum recording fed through the real detection engine. Nothing here is a mock-up, and nothing here is a real measurement, so no identifier on this page belongs to anybody. The generators ship with the project.
Measured on the reference route
Two runs over the same route, the second on the build that carried the fixes from the first. The numbers that matter for a swept receiver are the revisit interval and what the sweep budget costs, so those are first.
| Run 1 — 07:45–09:09 | Run 2 — return, 16:39–17:46 | |
|---|---|---|
| Duration | 92 min | 67 min |
| Sweeps completed | 882 | 1740 |
| Sweep groups | 2 | 3 |
| Rotation cycle | 60–65 s | 41.9 s |
| Coverage gaps logged | 221 | 0 |
| Receiver errors | — | 0 |
| RF alarms | 2 at the 430 MHz sweep edge, traced to receiver saturation | 3 on 433 MHz in 67 min, all ordinary priority, none matching a drone signature |
| GPS | 29 fix losses | 3 fix losses · median 9 satellites · HDOP 1.1 |
| Journal growth | ~40 MB per hour with spectrum frames recorded | |
Sweep budget and revisit interval
One receiver rotates between band groups, so a band is only listening while the receiver is parked on it. An alarm needs roughly three consecutive sweeps of the same band, which means the honest figure for time to alarm is the dwell plus the wait for the next visit — not the sweep time.
| Group | Step | Bins | Sweep | Dwell | Effect |
|---|---|---|---|---|---|
| 1070–1380 MHz | 100 kHz | 3552 | 3.9 s | 6 sweeps | Analogue FPV video band; 1090 MHz excluded so SSR replies do not enter |
| 430–870 MHz | 55 kHz | 10 112 | 5.6 s | 6 sweeps | Split into 433 and 868 groups after run 1, cutting the cycle from 60–65 s to 41.9 s |
A narrow FHSS control link is not reliably visible at this sampling — rtl_power averages rather than holding a maximum, so a single hop inside an integration window is diluted. Hop-level detection needs a peak detector on a node, which is a receiver question, not a software one.

rec: because the frames came from a recording.Sensing
Swept spectrum monitoring
Active- What it does
- Continuous sweeps across operator-defined bands, each frame carrying its range, bin width, integration time, receiver identity and configuration, from a local USB receiver or a networked sensor node over the same JSON lines protocol.
- Why it matters
- One frame format for live hardware, a recording and a remote node means the detection engine can be tested against recorded truth rather than against the weather, and a receiver change is a configuration entry, not a rewrite.
- Scope and limits
- Measured on the reference route: 3552 bins at a 100 kHz step sweep in 3.9 s; 10 112 bins at 55 kHz take 5.6 s. Sweeps are not simultaneous — see the sweep budget below. Levels are relative to a learned background, never absolute dBm.
Wi-Fi and BLE observation with source classes
Active- What it does
- Wi-Fi scanning on a configurable interval and continuous BLE advertisement capture, each observation labelled with a proposed class — vehicle, dash camera, home or carrier router, infrastructure, IP camera — from network names and 130 manufacturer prefixes checked against the IEEE registry.
- Why it matters
- A class is something an operator can act on; a MAC address is not. The label answers “what kind of thing is this” without asserting whose it is.
- Scope and limits
- Access points only. A camera, or anything else, attached to a router as an ordinary client emits nothing an AP scan can see and stays invisible until monitor mode exists. Across every recording so far the classifier has produced one camera — a network a person had named kamera — and zero factory camera names.
Remote ID, ADS-B and decoded telemetry
Implemented · not yet seen on air- What it does
- Remote ID over BLE decoded per ASTM F3411-22a and EN 4709-002, ADS-B and Mode S through dump1090 against an offline aircraft database including emitter category B6, plus rtl_433 sensors, RS41 radiosondes and FM with RDS.
- Why it matters
- These are the only sources that ever give a position for something other than the receiver. Everything else in RadAir places an event where it was heard.
- Scope and limits
- The Remote ID decoder has been exercised against the reference encoding, never against a transmitter in the air. A Remote ID position is the aircraft's own claim and is labelled as such everywhere it appears, including on export.
RF detection
Passive detection against a learned background
Active- What it does
- For every band, receiver and sweep grid the engine keeps its own background — a per-bin median and a spread from MAD over the last 30 sweeps, usable after 10. An alarm is a run of smoothed bins clearing the background by a margin and holding across sweeps, widened by hysteresis and merged across small gaps.
- Why it matters
- A fixed threshold is useless in a vehicle, where the noise floor moves street to street. A background that travels with the receiver is what makes a city drive workable at all — and because the rule is arithmetic rather than a trained model, every alarm can state why it fired.
- Scope and limits
- Margin
+8 dBover background,+3 dBwhen the receiver has moved more than 200 m inside the background window, hysteresis3 dB, gaps merged below0.5 MHz, smoothing window300 kHz, spread floor1 dB. A transmitter already running during the first ten sweeps becomes the background; the screen says so rather than hiding it.
Sweep-edge guard, saturation and gain-shift handling
Active- What it does
- Bins within 0.3 MHz of a tuner hop edge cannot form the core of an alarm. A frame containing a bin above −6 dBFS promotes no new alarms. A band-wide median shift of 6 dB or more is logged as a separate event, and running alarms end with that reason rather than pretending the energy fell away.
- Why it matters
- These are the three ways a sweeping receiver lies. Naming each one keeps an artefact from being reported as a contact, which is the difference between a tool an operator trusts and one they learn to ignore.
- Scope and limits
- Derived from the recordings, not assumed: across 438 frames of the 430–870 MHz group there is no constant first-hop artefact — the first 0.5 MHz sits about 2 dB below its neighbourhood. Two alarms at the 430 MHz edge on the first run coincided exactly with an LTE 800 downlink reaching −7.7 and −4.9 dBFS in the same sweep; with the saturation rule they no longer form.
Signature library
Active · none field-verified- What it does
- An editable JSON library. Each signature carries its frequency span, its own hop model, a duration, a confidence, a specificity saying how many other systems share that shape in the band, the provenance of its numbers, and a field-verification flag.
- Why it matters
- Signatures are as much for silencing as for alerting. An amateur repeater that gets reported on every pass trains the operator to dismiss the band. Naming it once ends that.
- Scope and limits
- Shipped entries: analogue video, OFDM 40/20/10 MHz, FHSS families on 433/868/915 MHz and 2.4 GHz, short 868 MHz bursts, and a narrow 70 cm carrier described as a fixed transmitter rather than a drone. Families, never products. The verification flag is false on every entry, and the alarm evidence line says so.


Analysis across sessions
Sessions, replay and comparability
Active- What it does
- Every session is a JSONL journal of typed records — observations, sensor state, spectrum frames, RF events, decisions — replayable on a shared time axis, comparable against another session, and summarised by a data quality report.
- Why it matters
- A single drive is a survey of an environment, not intelligence. Comparison is the only thing that turns thousands of readings into a short list of what changed.
- Scope and limits
- Comparison accounts for shared area, GPS freshness, observation time, configuration and sensor availability. A reference session is not automatically the norm, and an absent reading is never treated as proof that something disappeared. A journal carrying spectrum frames grows about 40 MB per hour.
Observation places and per-place baselines
Active · nothing admitted yet- What it does
- Places drawn as circles or polygons, with entry and exit derived from the console GPS under hysteresis, and a catalogue of transmitters that belong to a given place, built from archived sessions.
- Why it matters
- A baseline with an address is what stops a permanent mast from being rediscovered on every pass, and turns “how many emitters” into “what is here that was not here before”.
- Scope and limits
- A transmitter enters the catalogue only after returning in at least two sessions on two different days, in the same cells of a 25 m grid. A signal near 432 MHz returned on both runs of the reference route and is still refused, because both runs were the same day. Entry hysteresis has been exercised on synthetic fixes and a recorded journal, never against live GPS.
Evidence and interoperability
Decision record, integrity manifest and incidents
Active- What it does
- Every operator decision that opens something sensitive is written into a hash-chained record — who, when, which source, on what authority, for how long — alongside a session integrity manifest and an optional second-person requirement. An incident is the operator's own account, carrying references to the alarms, events and decisions it was built from.
- Why it matters
- A survey of eleven commercial counter-UAS and RF products found no equivalent: no hash-chained operator log, no two-person gate. For a unit that has to account for how a capability was used, this is the part that decides whether the tool can be fielded at all.
- Scope and limits
- Entries cannot be removed through the interface. The gate currently protects the decision, not a picture — there is no video demodulator yet, so there is no frame to withhold.
Cursor on Target export
Active · not yet against ATAK- What it does
- CoT 2.0 events over UDP, unicast to a TAK server or to the SA multicast group ATAK listens on by default. Console position as
a-f-G-U-C, an RF alarm asb-m-p-s-mat the place of reception, ADS-B aircraft asa-n-A-C-F, a Remote ID track asa-u-A-M-F-Q. Off by default. - Why it matters
- There is no vendor-neutral schema for RF detections in TAK, so what matters is what each event admits about itself once it is on somebody else's map and out of reach of its own caveats.
- Scope and limits
- An RF alarm carries
ceandleof 9999999 — the agreed sentinel for unknown — and the sentence “position = place of reception, not the transmitter” in remarks. One UID per track, so escalation and end update a single marker. Wi-Fi and BLE contacts carry no identifiers unless an operator enables them. Verified against a local UDP listener only.
Per-receiver calibration
In development- What it does
- A calibration table in the frame model, so a receiver can report absolute levels where one exists.
- Why it matters
- Relative levels cannot be compared between receivers or sites, which forecloses power-of-arrival methods and any regulatory use. The table exists now so that attaching a field-class receiver is a purchase, not a rewrite.
- Scope and limits
- dBm will appear only where an operator has entered a figure against a stated reference. An RTL-SDR stays in relative dB regardless, and the interface will keep saying so.

Receiver envelope
Everything above runs today on an RTL-SDR, which is a development fixture rather than field equipment. It is worth being exact about what that forecloses, because those limits are the receiver's and not the software's.
| Parameter | Today (RTL-SDR, R820T2) | What it forecloses |
|---|---|---|
| Tuning range | 24 MHz – 1.766 GHz | 2.4 GHz and 5.8 GHz are out of reach entirely — a tuner ceiling, not a bandwidth question |
| Instantaneous bandwidth | ~2.4 MS/s | Analogue video demodulation needs about 4 MS/s, so video preview waits on a wider receiver, not on a field-class one |
| Converter | 8 bit, no preselection | A strong LTE downlink compresses the front end; handled by rule rather than by hardware |
| Absolute accuracy | None — uncalibrated | No dBm, no power-of-arrival, no regulatory or evidentiary level claim |
| Time reference | Console clock; node clock uncorrected | Multilateration needs 10 ns or better between nodes, so it needs GNSS PPS at the node — NTP and even PTP are one to two orders of magnitude short |
The frame protocol, receiver registry and provider layer already exist, so a field-class receiver on a Linux node changes the hardware and not the detection engine. Which receiver is a purchasing decision still ahead.

What this is not
RadAir is a passive observation and evidence tool. It is not a counter-UAS effector, it is not calibrated measurement equipment, and it does not identify people. An observation is a measurement, not an identification; a human-readable name for anything RadAir has clustered is only ever assigned by an operator. Absence of a reading is not evidence that something is gone. These are design commitments, not disclaimers added at the end.
← Back to the front page