SENTINELLE-GSM
Passive GSM rogue-BTS sensor — RX only, off-path.
Alerts 0
| Time | Cell ID | ARFCN | Score | Reason | Target |
|---|---|---|---|---|---|
| no alerts yet — waiting for stream… | |||||
Trusted phones
| ID | Label | Added | Actions |
|---|---|---|---|
| loading… | |||
IMSI values are HMAC-hashed at registration. Plaintext IMSI is never stored.
Live logs 0
waiting for journal stream…
Tail of journalctl -u secubox-sentinelle-gsm -f. The
stream auto-reconnects on transient network errors.
Scan control
stderr (last 2 KB)
(no output)
Observations 0
| Cell ID | ARFCN | MCC | MNC | LAC | CI | First seen | Last seen | Sightings |
|---|---|---|---|---|---|---|---|---|
| no observations yet — start a scan | ||||||||
RDS / FM 0
| PI | PS | RadioText | PTY | TP / TA | Freq | Count | Last seen |
|---|---|---|---|---|---|---|---|
| no stations yet — start a sweep or single-freq scan | |||||||
FM RDS shares the RTL-SDR with GSM scanning. Starting an RDS scan while a GSM scan or scan-auto job is in flight returns 409 with the holder's name. PI (Programme Identification) is the natural station key; PS is the 8-char display name. RadioText (up to 64 chars) carries song titles or news tickers.
Operator baseline 0
| Cell ID | MCC | MNC | LAC | ARFCN | Cipher | Learn count | Last learned |
|---|---|---|---|---|---|---|---|
| no baseline yet — start a scan + click "Start learn" | |||||||
Cells graduate to baseline after 3 sightings under normal scan. The "Start learn" button accepts every cell observed within the next 5 minutes immediately.
Scoring heuristics
Score sum ≥ 60 (default) emits an alert. Each heuristic can be enabled/disabled and its contribution adjusted. Changes are audit-logged to the live journal stream.
Actions
Test alert writes a synthetic event through the full pipeline (sink → SSE → UI). Desktop notifications require an HTTPS context and a one-time user gesture.