RF & Signals Intel: Mission Domain Intelligence Guide
Aircraft over a whole region started reporting navigation integrity failures within the same hour. No one announced anything. The spectrum was the only witness, and it had been talking for weeks.
Aircraft over a whole region started reporting navigation integrity failures within the same hour. No one announced anything. The spectrum was the only witness, and it had been talking for weeks.
What RF & Signals Intel covers as a mission domain
Radiofrequency and signals intelligence, in the open and defensive sense practised here, is the study of the electromagnetic environment to detect interference, denial and anomalous emissions and to understand their effect on dependent systems. Practitioners use open receiver networks, aggregated aircraft and vessel navigation integrity data, published spectrum registries and community observation to characterise jamming and spoofing of navigation and communications, identify unlicensed or unexpected emitters, and map the operational consequences for aviation, maritime, emergency services and critical infrastructure timing.
Sub-areas include GNSS interference monitoring, satellite communications interference detection, terrestrial spectrum anomaly analysis, and emitter geolocation using distributed receivers and time difference of arrival techniques. Actor types include state electronic warfare units conducting protective or coercive jamming, criminal users of illegal privacy jammers that disrupt fleet tracking, unlicensed commercial operators, and simple equipment failure, which is a far more common explanation for interference than any deliberate cause.
Why it matters
Almost every modern safety-critical system assumes a working satellite navigation and timing input. Aviation, shipping, mobile networks, power grid synchronisation and financial timestamping all degrade when that assumption fails. Regional GNSS interference is now persistent across several theatres and routinely affects civil traffic that has nothing to do with the conflict driving it. Regulators, air navigation service providers and infrastructure operators need independent measurement because interference reporting through official channels is slow and geographically patchy.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Aircraft navigation integrity parameters degrading across a region simultaneously, the standard aggregate indicator of GNSS jamming rather than receiver fault.
- Vessel or aircraft positions teleporting to a single common coordinate, a hallmark of spoofing that projects a false fixed location.
- AIS or ADS-B tracks describing implausible geometry such as perfect circles, which indicates synthetic position injection rather than real movement.
- Satellite transponder carriers appearing off-plan, with unexpected bandwidth or modulation persisting beyond any test window.
- New emitters appearing in a band allocated to a different service, and persisting across days rather than minutes.
- Broadcast schedule and frequency changes on state shortwave services, which often correlate with wider posture changes.
- Direction-finding bearings from multiple independent receivers converging on a location with no licensed transmitter registered.
- Airspace notices warning of unreliable satellite navigation issued for regions with no published exercise or test activity.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- OpenSky Network — Open research access to historical and live aircraft surveillance data including navigation integrity and accuracy fields.
- ADS-B Exchange — Unfiltered aggregated aircraft position feed, useful for observing anomalous tracks and coverage effects.
- GPSJAM — Daily aggregated maps of GNSS interference derived from aircraft navigation integrity reporting, free and well documented.
- ITU Radio Regulations and BR IFIC — International frequency allocations, notified assignments and the formal harmful interference reporting procedure.
- National spectrum databases such as the FCC ULS — Licensed transmitter locations, frequencies, power and licensee details for identifying unregistered emitters.
- KiwiSDR and WebSDR receiver networks — Publicly shared software defined radio receivers giving geographically distributed listening and recording capability.
- SatNOGS — Open global network of satellite ground stations with an archive of received transmissions and observation metadata.
- NOTAM archives and EASA safety bulletins — Official notices of navigation service unreliability, jamming warnings and airspace advisories by region.
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Define the affected system — Start from the dependent service, whether aviation navigation, maritime positioning or grid timing, rather than from the spectrum in the abstract.
- Establish the quiet baseline — Characterise normal integrity, occupancy and error rates across seasons and traffic levels so an anomaly is measurable.
- Aggregate observations — Combine open receiver, aircraft and vessel data across many independent platforms, since a single receiver cannot distinguish local fault from area effect.
- Classify the phenomenon — Separate jamming, which denies, from spoofing, which deceives, and both from equipment failure, using position plausibility and integrity behaviour.
- Bound the source region — Use geographic extent, altitude dependence and multi-receiver bearings to estimate a source area, expressed as a region with uncertainty.
- Assess operational impact — Quantify effects on traffic, routing, timing and emergency services, which is the output regulators and operators can act on.
- Report through proper channels — Submit harmful interference findings to the national regulator and relevant international body, preserving raw recordings and metadata.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- Radio Frequency Intelligence — The Electromagnetic Spectrum as an Intelligence Source
- Signals Intelligence — Intelligence from Intercepted Communications and Emissions
- Measurement & Signature Intel — Signatures, Measurements, and Physical Phenomena
- Technical Intelligence — Technology Capability, Design, and Exploitation
- Space Intelligence — Orbital Activity, Space Assets, and Counterspace
- Aviation Intelligence — Aircraft, Flights, and the Aviation Domain
- Maritime Intelligence — Vessels, Shipping, and the Maritime Domain
Worked in these data points
- Radio Callsign — A licensed radio identifier for a station, vessel, aircraft, or operator.
- Location / Coordinates — A geographic point, place, or region — the basis of GEOINT analysis.
- GPS Coordinates — Precise latitude/longitude coordinates identifying an exact point on Earth — the atomic unit of GEOINT analysi
- IMEI / Device Identifier — A unique mobile-equipment identifier; the TAC prefix identifies make and model.
- Cell Tower / Cell ID — A mobile network cell identifier (MCC/MNC/LAC/CID) usable for coarse device geolocation.
- Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
Adjacent mission domains
- Space & Satellite Intel
- Military & Defense
- Aviation Security
- Maritime Security
- Critical Infrastructure
- Nation State
Inside the platform: where RF & Signals Intel lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
domain.php?d=rf— RF & Signals Intel dashboardtheater.php?d=rf— Threat theater viewsearch.php— Advanced search, filter and pivotcorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
Relevant playbooks
Of the 14 incident playbooks in playbooks.php, these apply directly to RF & Signals Intel:
- NetFlow / Traffic Anomaly — a step-checked workflow with the pivots, sources and handling rules already wired in.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Define the affected system is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Aggregate observations turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Report through proper channels feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses RF & Signals Intel
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence use of open spectrum analysis is protective and situational: understanding where navigation and communications denial is occurring, what it does to dependent systems, and how resilient friendly and partner capabilities are to it. Products support electromagnetic protection planning, alternative navigation procedures, route and timing decisions for aviation and maritime movement, and assessment of the operating environment where interference is persistent. Analysis addresses effects and dependencies rather than any capability to cause them. Constraints are strict: findings on civil systems go to operators, regulators and safety authorities, and nothing produced here should facilitate interference with navigation, communications or safety-of-life services.
🕵 National intelligence
National intelligence requirements typically cover the geographic extent and persistence of navigation interference, its effect on civil aviation and shipping, the resilience of national timing infrastructure that depends on satellite signals, and the identification of unauthorised emitters affecting protected services. Fusion combines aggregated aircraft and vessel integrity data, regulator filings, operator reports and community observation. The open layer is unusually informative and shareable, which makes it valuable for coordination with civil aviation authorities and spectrum regulators. Judgments should distinguish observed effect from asserted source, since open data supports the first far better than the second.
👮 Law enforcement
Enforcement against unlawful transmission and interference is primarily a regulatory function, with criminal escalation where safety services are affected. Evidence must come from the regulator's own calibrated measurement and direction-finding rather than third-party observation, and warrants are normally required for premises entry and equipment seizure. Common cases include illegal privacy jammers that disrupt fleet tracking and stolen vehicle recovery, unlicensed broadcast transmitters interfering with aeronautical bands, and repeater or amplifier installations causing harmful interference. Charging rests on telecommunications and safety legislation, and expert evidence on measurement methodology is usually decisive.
🔍 Private investigation and corporate security
Corporate security and fleet operators encounter this domain through vehicle tracking loss, timing dependency in trading and industrial systems, and site interference affecting operations. Legitimate work covers documenting the pattern and extent of tracking loss, assessing timing resilience and backup arrangements, and supporting a report to the regulator. Private actors may not operate direction-finding equipment in ways that intercept communications content, may not attempt any transmission, and must not investigate suspected jammer users directly. Findings go to the spectrum regulator and, where a crime is indicated, to police with the documentation they require.
📰 Journalism and OSINT media
Reporting interference requires care because the observable data is indirect. Aggregated aircraft navigation integrity data shows where receivers reported degraded performance, which is strong evidence of an effect and weak evidence of a source. Verification means using more than one dataset, checking space weather and known testing notices, and being precise about the distinction between jamming and spoofing. Sources in airlines, air navigation service providers and shipping face professional consequences for discussing safety incidents. Give authorities and operators a right of reply, and never publish material that would help someone reproduce interference against safety-of-life systems.
🌍 NGO, humanitarian and human rights
Humanitarian organisations depend on satellite navigation and communications for movement, coordination and staff safety, and interference directly affects operations in several active conflict areas. Analysis supports movement planning, backup navigation and communications procedures, and advocacy where interference affects humanitarian access or civilian safety services. Documentation of persistent interference affecting civilian aviation and maritime safety can support accountability and regulatory pressure. Do-no-harm applies to publishing operational detail that could put convoys at risk. Duty of care requires training staff in degraded navigation procedures rather than assuming devices will work.
🎓 University and research
Research in this area uses aggregated integrity reporting, receiver networks and published spectrum records, and the main methodological hazard is inferring source location or intent from effect data. Effect maps show where receivers reported problems, weighted by traffic density, which produces obvious sampling bias over busy corridors. State that bias explicitly, validate against independent networks, and exclude space weather and equipment causes systematically. Ethics review is rarely required, but publication decisions should consider whether methods could assist interference. Cite data snapshots by date, publish processing code, and observe the licence terms of receiver network data.
Playbook: working RF & Signals Intel end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Define the dependency you are protecting
Start from the system that suffers when the spectrum degrades: aircraft navigation on a route, vessel positioning in a strait, fleet tracking, industrial timing, or emergency service communications. The dependency defines which frequencies, which receivers and which failure modes matter. Analysis that starts from the spectrum rather than the dependency produces observations nobody can act on. A good output is a dependency statement naming the service, the signal it relies on and the consequence of losing it. Stop when the consequence is described operationally rather than technically.
Phase 2 — Establish the normal electromagnetic picture
Baseline what is expected in the bands and areas of interest: licensed assignments from the regulator, known transmitters, routine testing notified through official channels, and the normal level of reported navigation integrity degradation for the area. Some regions have chronic interference that is well documented and unremarkable. A good output is a baseline description with the licensed and known emitters mapped. Stop when a new report can be compared against a documented normal rather than an assumption.
Phase 3 — Collect effect data at scale
Aggregate reported navigation integrity degradation from aircraft and vessels, receiver network observations, operator and pilot reports, and regulator interference filings. These are effect observations, not source observations, and their coverage follows traffic density. Record collection dates and data versions because these feeds are updated and revised. A good output is a time-stamped effect dataset with coverage limitations documented. Stop when the coverage bias is quantified rather than merely acknowledged.
Phase 4 — Exclude natural and mundane causes
Before treating an anomaly as interference, exclude space weather, particularly geomagnetic storms and solar radio bursts, ionospheric scintillation at low latitudes, known equipment or firmware issues affecting a receiver type, and notified testing. This step removes a large share of apparent events and is the difference between credible and dismissible analysis. A good output is an exclusion record showing which causes were checked and ruled out. Stop when every excluded cause has a documented check rather than an assertion.
Phase 5 — Classify jamming versus spoofing
Separate denial from deception. Jamming shows as loss of signal, degraded integrity and receivers reporting no fix. Spoofing shows as receivers reporting confident but wrong positions, often clustered at an implausible common location, with timing anomalies and sudden position jumps. The operational consequences differ completely, since a spoofed receiver reports success while being wrong. A good output is a classified event with the evidence for the classification stated. Stop when the classification rests on observed signatures rather than on assumption.
Phase 6 — Map extent, persistence and pattern
Establish the geographic footprint, altitude dependence, daily and weekly rhythm, and duration of the interference. Altitude dependence is informative because ground-based emitters affect higher altitudes over greater distances by line of sight. Persistent patterns with regular hours suggest fixed installations and routine operation rather than incidents. A good output is an extent and pattern description with the temporal profile shown. Stop at the observable pattern without asserting a specific emitter location.
Phase 7 — Assess operational impact
Translate the interference into consequences for the dependent systems: approach procedures unavailable, required navigation performance not achievable, vessel positioning degraded in confined waters, timing holdover exceeded in a network, tracking lost across a fleet. Quantify where possible in flights affected, procedures downgraded or hours of holdover remaining. A good output is an impact assessment expressed in operational terms with the affected procedures named. Stop when an operations manager could act on the assessment without further translation.
Phase 8 — Verify resilience and backup arrangements
Check what the dependent systems fall back to: inertial navigation, terrestrial navigation aids, alternative timing sources and their holdover duration, and whether crews and operators are trained and current in degraded procedures. Resilience is usually a training and procedure problem rather than an equipment problem. A good output is a resilience assessment naming the specific gap, whether equipment, procedure or currency. Stop when the gap is specific enough to be fixed by a named action.
Phase 9 — Route findings to authorities
Send characterised findings to the parties with the authority and equipment to act: the spectrum regulator, the civil aviation authority or air navigation service provider, maritime authorities, and the affected operators. Regulators hold the calibrated measurement and direction-finding capability that turns an effect map into an enforcement action. Record the notification and any response. A good output is a documented referral with the data package the authority actually needs. Stop before publishing anything that identifies an emitter location or method.
Phase 10 — Maintain the record and review
Keep a versioned archive of effect data, exclusions and assessments, because interference patterns evolve and historical comparison is the main way persistence and escalation are demonstrated. Review classifications when better data arrives, and correct published assessments openly. A good output is a maintained time series that shows whether a region's interference is worsening, stable or resolving. Stop when the archive supports re-derivation of past findings by another analyst.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| OpenSky Network | Registration | Research-oriented archive of aircraft broadcast data from a global volunteer receiver network with historical query access. | Provides reported navigation integrity indicators and position data used to map interference extent over time. |
| ADS-B Exchange | Open | Unfiltered aggregation of aircraft broadcast data from volunteer receivers with live and historical access options. | Second independent source for aircraft-reported navigation integrity, used to cross-check extent findings. |
| GPSJAM | Open | Daily maps of aircraft-reported navigation integrity degradation aggregated into hexagonal cells with historical archive. | Fast, well-documented view of where navigation interference is being reported and how persistent it is. |
| ITU Radio Regulations and BR IFIC publications | Open | International frequency allocation framework, assignment notifications and procedures for reporting harmful interference. | Establishes which service holds protected status in a band and the formal route for interference complaints. |
| National spectrum licensing databases such as the FCC systems | Open | Licensed transmitter records including location, frequency, power and licensee for many national jurisdictions. | Identifies authorised emitters in an area so unexpected activity can be distinguished from licensed operation. |
| SatNOGS network | Open | Open network of volunteer ground stations recording satellite radio observations with published data and scheduling. | Independent observation of satellite downlinks, useful for confirming transmission status during suspected interference. |
| WebSDR and KiwiSDR receiver networks | Open | Publicly accessible software defined radio receivers allowing remote listening across HF and some higher bands. | Remote observation of band occupancy and unusual emissions from multiple geographic vantage points. |
| NOAA Space Weather Prediction Center | Open | Geomagnetic storm, solar radio burst and radiation environment alerts, forecasts and historical event records. | The exclusion source for natural causes of navigation and HF communications degradation. |
| EASA safety information bulletins and publications | Open | European aviation safety guidance including bulletins on navigation interference and operational mitigations. | Authoritative statements on aviation safety consequences of interference and the operator mitigations regulators expect to see applied. |
| Notices to air missions and aeronautical information publications | Open | Official notices covering navigation aid outages, testing, and warnings of interference affecting specific areas. | Identifies notified testing and official acknowledgement of interference affecting published procedures, which excludes benign causes. |
| NGA Maritime Safety Information and navigational warnings | Open | Official maritime warnings including reports of interference affecting positioning and communications in specific areas. | Maritime counterpart to aeronautical notices, confirming reported positioning and communications effects experienced by shipping. |
| US Coast Guard Navigation Center | Open | Satellite navigation status, outage notices and a channel for reporting anomalies affecting navigation users. | Authoritative constellation status information and the official reporting channel for observed anomalies. |
| National regulator interference reporting guidance | Open | Published procedures for reporting harmful interference, evidence requirements and enforcement powers by jurisdiction. | Defines what a regulator needs to act, which determines how findings should be packaged before referral. |
| Academic and industry resilient timing literature | Open | Published research on timing resilience, holdover performance and alternative navigation for critical infrastructure. | Benchmarks timing dependency assessments and informs realistic holdover expectations for infrastructure that assumes satellite time. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against RF & Signals Intel. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Python with pandas and geospatial libraries — Aggregates aircraft and vessel integrity reports into extent maps and time series. Traffic-density bias must be corrected in analysis, not by the library.
- QGIS — Maps interference extent, altitude bands and affected routes and procedures. Hexagonal binning helps, but coverage bias remains an interpretation problem.
- OpenSky historical query interface — Retrieves archived aircraft broadcast data for defined areas and periods. Query volume limits and receiver coverage gaps constrain retrospective work.
- Remote SDR receiver access — Observes band occupancy from multiple locations without deploying equipment. Receiver siting and antenna quality vary enormously between stations.
- Software defined radio for receive-only monitoring — Local observation of band activity with appropriate antennas. Legally constrained in what may be received and decoded, and never used to transmit.
- Space weather alerting feeds — Automates the natural-cause exclusion step against event timing. Requires the analyst to actually check before publishing, which is the usual failure.
- Time series databases with versioned snapshots — Preserves effect data as collected so historical comparison remains valid. Essential because upstream feeds are revised without notice.
- Structured referral templates for regulators — Packages findings in the format an authority can act on. Dull but decisive, because badly formatted reports are simply not actioned.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Effect data is not source data. Aggregated integrity reporting shows where receivers had problems, weighted by how much traffic passes overhead, so a quiet area may simply be an area nobody flies over.
- Exclude space weather before every attribution. Geomagnetic storms and solar radio bursts produce regional navigation and HF degradation that looks exactly like deliberate interference to an analyst in a hurry.
- Jamming and spoofing are operationally different problems. A jammed receiver knows it has failed; a spoofed receiver reports a confident wrong answer, which is far more dangerous and requires different mitigations.
- Altitude dependence is one of the few genuinely informative open signatures, because line of sight from a ground emitter means higher aircraft are affected further away. Use it to characterise geometry without claiming a location.
- Equipment failure is the most common explanation for a single anomalous report. Require a pattern across multiple independent receivers or platforms before treating any single observation as interference.
- Persistent interference with regular daily hours indicates routine operation of a fixed installation rather than an incident, and that distinction changes both the advocacy route and the operational response.
- Route everything to regulators and safety authorities. They hold the calibrated measurement and legal authority to geolocate and act, and public attribution of an emitter serves no protective purpose while creating real risk.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on RF & Signals Intel is producing anything, and they are worth baselining before you change process or tooling.
- Time from an interference pattern emerging in effect data to a characterised report reaching the relevant regulator or safety authority.
- Proportion of assessed events with a documented exclusion record covering space weather, equipment and notified testing.
- Share of events correctly classified as jamming or spoofing, verified against subsequent regulator or operator findings.
- Number of operational mitigations adopted by dependent operators as a result of published impact assessments.
- Coverage bias quantification: the proportion of published extent maps that state traffic density limitations explicitly.
- Proportion of timing-dependent systems assessed with a measured holdover figure rather than a manufacturer specification.
- Rate at which historical assessments can be re-derived from archived data snapshots by an analyst who did not write them.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Equipment failure, antenna problems and receiver firmware bugs explain far more anomalies than deliberate interference ever will.
- Aggregated aircraft data is biased by traffic density, so quiet regions look clean simply because nothing was flying to observe them.
- Propagation effects including ducting and sporadic E create apparent emitters hundreds of kilometres from their true location.
- Geolocation from volunteer receivers carries large uncertainty, and publishing a point estimate implies precision the method cannot support.
- Jamming and spoofing require different responses, and reporting one as the other sends operators to the wrong mitigation.
- Interception of communications content is illegal in most jurisdictions, and the line between monitoring and interception is easy to cross accidentally.
Legal and ethical considerations
Receiving is regulated very differently from decoding and disclosing. In most jurisdictions, including under wiretap and communications privacy statutes, it is unlawful to intercept, record or disclose the content of communications not intended for you, even where the signal is receivable. Confine work to metadata, integrity indicators, occupancy and open beacon data. Operating transmitters requires licensing and deliberate interference is a criminal offence everywhere. Route harmful interference findings to regulators rather than publishing source locations.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for RF & Signals Intel, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 7 intelligence disciplines, 6 data points, 6 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
What can aircraft-derived data actually tell me about jamming?
It tells you where receivers reported degraded navigation integrity, when, and at what altitudes, which is strong evidence that an effect occurred and useful for mapping extent and persistence. It does not tell you where the emitter is, who operates it or why. Coverage follows air traffic, so busy corridors appear well characterised and empty regions appear clear regardless of what is happening there. Use at least two independent aggregations, state the coverage limitation on every map, and treat altitude dependence as geometric information rather than as a location claim.
How do I distinguish jamming from spoofing?
By what the receiver reports rather than by what it fails to report. Jamming raises the noise floor and denies the signal, so receivers report loss of fix, degraded integrity and reduced satellite counts. Spoofing supplies a counterfeit signal, so receivers report a confident position that is wrong, frequently clustered with other affected receivers at an implausible common location, sometimes with time offsets and sudden position jumps. Spoofing is more dangerous precisely because the system reports success. Classify from observed signatures, state your evidence, and note that both can occur in the same area.
Can I locate the source of interference?
Not from open effect data, and you should not try. Geolocating an emitter requires calibrated direction-finding equipment operated from multiple sites, and in most jurisdictions doing it in a way that intercepts communications content is unlawful for private parties. The professional route is to characterise the effect thoroughly, exclude natural and equipment causes, package the evidence in the format the spectrum regulator requires and refer it. Regulators and national authorities have both the equipment and the legal authority. Public attribution of an emitter delivers no protective benefit and creates real risk.
How common is equipment failure as an explanation?
Common enough that it should be the default hypothesis for any single anomalous report. Receiver firmware issues, antenna faults, installation problems and known defects affecting a particular equipment type all produce reports indistinguishable from interference at the individual level. The discriminator is correlation: multiple independent platforms with different equipment reporting degradation in the same area and time window. Before escalating, check whether affected reports share a receiver type or operator, which points to equipment rather than environment, and record that check in the exclusion register.
What should organisations do about timing dependency?
Measure rather than assume. Many industrial, financial and communications systems depend on satellite-derived timing and hold over on internal oscillators when the signal is lost, but the actual holdover duration before functional failure is frequently far shorter than the specification suggests and is rarely tested. The practical steps are to inventory timing-dependent systems, measure real holdover under controlled conditions, provision alternative sources where the consequence justifies it, and add monitoring that alerts on loss of discipline rather than on total failure. Assessments should quote measured holdover, not manufacturer figures.
Is monitoring the spectrum legal?
Receiving is generally lawful within limits that vary by jurisdiction, and those limits usually restrict receiving or decoding certain communications, disclosing their content, and using anything received for gain. Transmitting without authorisation is an offence essentially everywhere, and interfering with safety-of-life services attracts serious criminal penalties. Practically, keep the work receive-only, avoid decoding communications content, use published aggregated data wherever it suffices, and take local legal advice before deploying equipment. When in doubt, work from the aggregated effect datasets and regulator publications, which carry no such risk.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- ITU Radio Regulations, which allocate spectrum, define protected services and set the procedure for reporting harmful interference between administrations.
- ICAO standards and recommended practices for navigation systems, which define required performance and the safety consequences of degradation.
- IMO performance standards for shipborne navigation equipment, which set the maritime equivalent requirements for positioning integrity.
- National telecommunications legislation criminalising unauthorised transmission and harmful interference, which supplies the enforcement basis.
- EASA and national aviation authority safety bulletins on navigation interference, which define expected operator mitigations.
- NIST and equivalent national standards on time and frequency dissemination, which frame timing resilience assessment for infrastructure.
- Wireless privacy and interception law in the relevant jurisdiction, which constrains what may lawfully be received, decoded and disclosed.
- Coordinated vulnerability disclosure practice under ISO 29147 and ISO 30111, applied when receiver or system weaknesses are identified.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- OpenSky Network research data — OpenSky Network association. Open archive of aircraft broadcast data from a global receiver network
- GPSJAM navigation interference maps — GPSJAM. Daily aggregated maps of aircraft-reported navigation integrity degradation
- Radio Regulations and interference procedures — International Telecommunication Union. International spectrum framework and harmful interference reporting process
- Safety information bulletins on navigation interference — European Union Aviation Safety Agency. Aviation safety guidance and operator mitigation recommendations
- Space weather alerts and event archives — NOAA Space Weather Prediction Center. Geomagnetic and solar activity data used to exclude natural causes
- Navigation Center satellite navigation status — US Coast Guard. Constellation status, outage notices and anomaly reporting channel
- SatNOGS open satellite ground station network — Libre Space Foundation. Volunteer network recording satellite radio observations openly
- Spectrum licensing databases — US Federal Communications Commission. Public records of licensed transmitters, frequencies and locations
- Time and frequency standards and guidance — US National Institute of Standards and Technology. Reference material on timing dissemination and resilience
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: aggregated interference detection, jamming versus spoofing classification and operational impact assessment for navigation-dependent systems. Explore the platform, or browse the rest of the library by following any tag above.