Thanks to SDRplay, I was sent both their new RSPdx and older RSPduo SDRs at the end of January.
The main reason was to get them integrated into Procitec’s go2MONITOR and go2DECODE software, to increase the number of SDRs that the company’s products are compatible with.
This I’ve been successful in doing with the RSPdx – I’m still to unbox the RSPduo at this time of writing.
First of all though, I’ve been extremely pleased with the RSPdx in its own right. The SDRuno software works really well, is pretty easy to use – and it looks good too.
The fact that you can have up to 10 MHz of bandwidth is brilliant, and it isn’t too bad on the CPU usage either – running at around 25% with 10 MHz bandwidth on my ancient PC. Used with SDRConsole you can cover a good number of frequencies at once, and can record them if necessary. Of course, you can do this with SDRuno too, but at the moment only IQ – you can’t record individual frequencies.
Saying that, I’ve seen the SDRuno Roadmap for future releases and not only will recording of individual frequencies be possible, a more advanced scheduler is to be included. This is something I feel SDRConsole – amazing though it is – is lacking when it comes to single frequency recording. There is also the issue with SDRConsole that you are limited to recording only 6 hours worth of wav file per frequency.
Anyway, I digress. Back to the RSPdx and go2MONITOR.
To get the SDRs to work correctly with any of the go2 products means creating a configuration file and adding a ExtIO DLL file to the software. This is reasonably easy to do once you get use to it and it enables a GUI to become active so that you can control the SDR through go2MONITOR.
One interesting aspect with the RSPdx GUI is that regardless of what you enter as some of the parameters in the configuration file, the ExtIO file overrides these. Effectively, I just left some of the data as found in a basic configuration template and let the GUI do all the work for me.
So, below are some of the results with today’s first test.
First of all I went into the VHF/UHF side of things and targeted the local TETRA networks. These were found easily and after messing around with the GUI, I was able to get go2MONITOR set up to nicely find all the emissions within the 1.6 MHz bandwidth I’d chosen to use
From there, all I had to do was to select one of the found emissions and let the software do its thing.
Next I moved on to HF where there’s a plethora of data to choose from to test out the SDR. There was quite a large storm going through at the time and my Wellbrook loop and coax feed were getting a bit of a bashing with some considerable interference being produced with the really strong gusts, as can be seen below – the interference between the two HFDL bursts is one such gust.
I’ve frequently mentioned the Results Viewer that’s part of go2MONITOR and with things such as HFDL and TETRA, that process data quickly from lots of signals, this part of the software comes into its own.
The image below is two minutes of HFDL monitoring. All the red blocks is received data that scrolled through the Channel window too quickly to read live. In the viewer you can select any of the signals and you’ll be shown the message as sent. In this case, it is one sent by an Open Skies Treaty observation flight OSY11F.
By looking at the Lat/Long and comparing it to the flight history from FlightAware and its location at 1313z it ties in nicely. This flight was carried out by the German Air Force A319 1503 specially kitted out to make these flights.
go2MONITOR has a basic map function within the Result Viewer function so if there’s any Lat/Long position within any message it will plot it – as shown below for OSY11F at 1313z.
Within the General tab of Result Viewer you can get all the parameters of the signal.
One final test that I carried out was how well everything coped with a bigger bandwidth. In HF I can use up to 3 MHz of bandwidth with the licence I have – going up to 10 MHz once into VHF/UHF. In HF then, I selected 3 MHz in the GUI and then ran an emissions search.
My PC is nearing the end of its life but it coped easily with the amount of data found despite only having 4 GB of RAM with a 3.6 GHz AMD processor – a new PC is in the pipeline that is going to give me much better processing power.
Despite having 3 MHz available, not everything was identified. Most of this was at the fringes of the bandwidth, but some of the weaker signals also failed. That doesn’t mean you can’t then process them further, you can, it’s just the Emissions scan hasn’t quite been able to ID them. Saying that, the software managed to ID things within 2.2 MHz of the 3 MHz bandwidth.
I picked one of the weaker signals to see how both the RSPdx and software coped and they did very well, pretty much decoding all of the CIS-50-50 messages that were coming through on 8678 kHz.
So, overall, pretty pleased with how the RSPdx works with go2MONITOR.
Once I get a better PC I’ll be able to test at bigger bandwidths but even with 3 MHz here I was able to achieve the same, if not better, results than I have with the considerably more expensive WinRadio G31 Excalibur I have been using previously (running with the G33 hack software).
Not that I’m likely to really use go2MONITOR at big bandwidths – 1.6 MHz is probably fine for me – but for Pro’s there’s no doubt that having these “cheaper” SDRs would make absolutely no difference over using an expensive one such as those in the WinRadio range. In all honesty, I don’t think I’ll be holding on to the WinRadio for much longer – I’m more likely to get another RSPdx to cover this area of my monitoring.
On its own, as an SDR, the RSPdx is worth the money I’d say. I like it just as much as I do the AirSpy HF+ Discovery – the only real difference I can see between these two SDRs is the max bandwidth available.
In early November, whilst working on an article for Janes, I noticed a Link-11 SLEW signal on 4510 kHz (CF) that was slowly growing in reception strength. I’d been monitoring frequencies used by the Northern Fleet of the Russian navy around this one and had already spotted that Link-11 CLEW was being used on a nearby frequency, though this remained at a constant signal strength at my location. The fact that the Link-11 SLEW was getting stronger made me stop what I was doing and start concentrating on this instead.
Link-11 SLEW (Single-Tone Link-11 waveform) ,or STANAG 5511, is a NATO Standard for tactical data exchange used between multiple platforms, be it on Land, Sea or Air. Its main function is the exchange of radar information, and in HF this is particularly useful for platforms that are beyond line of sight of each other and therefore cannot use the UHF version of Link-11.
With propagation being the way it is, in theory radar data could be exchanged between platforms that are hundreds to thousands of miles apart, therefore providing a wider picture of operations to other mobile platforms and fixed land bases. This data can also be forwarded on using ground stations that receive the data and then re-transmit on another frequency and/or frequency band. However, the approximate range of an individual broadcast on HF is reported to be 300nm.
As well as radar information, electronic warfare (EW) and command data can also be transmitted, but despite the capability to transmit radar data, it is not used for ATC purposes. In the UK, Link-11 is used by both the RAF (in E-3 AWAC’s and Tactical Air Control Centres) and the Royal Navy. Primarily it is used for sharing of Maritime data. Maritime Patrol Aircraft (MPA’s) such as USN P-8’s and Canadian CP-140’s use Link-11 both as receivers and transmitters of data, so when the RAF start using their P-8’s operationally in 2020 expect this to be added to the UK list. Whilst it is a secure data system, certain parameters can be extracted for network analysis and it can be subjected to Electronic Countermeasures (ECM).
Link-11 data is correlated against any tracks already present on a receivers radar picture. If a track is there it is ignored, whilst any that are missing are added but with a different symbol to show it is not being tracked by their own equipment. As this shared data is normally beyond the range of a ships own radar systems, this can provide an early warning of possible offensive aircraft, missiles or ships that would not normally be available.
I started up go2MONITOR and linked it to my WinRadio G31 Excalibur. Using a centre frequency of 4510 kHz I ran an emission search and selected the Link-11 SLEW modulation that it found at this frequency.
It immediately started decoding as much as it could, and I noticed that three Address ID’s were in the network.
As the signal was strong, and it is normally maritime radar data that is being transmitted, I decided to have a quick look on AIS to see if there was anything showing nearby. Using AISLive I spotted that Norwegian navy Fridtjof Nansen class FFGHM Thor Heyerdahl was 18.5 nm SW of my location, just to the west of the island Ailsa Craig. Whilst it was using an incorrect name for AIS identification, its ITU callsign of LABH gave me the correct ID. This appeared to be the likely candidate for the strong Link-11 signal.
It wasn’t the best day and it was pretty murky out to sea with visibility being around 5nm – I certainly couldn’t see the Isle of Arran 11.5 nm away. I kept an eye on the AIS track for Thor Heyerdahl but it didn’t appear to be moving.
Whilst my own gear doesn’t allow me to carry out any Direction Finding (DF) I elected to utilise SDR.hu and KiwiSDR’s to see if I could get a good TDoA fix on a potential transmitter site – TDoA = Time Difference Of Arrival, also known as multilateration or MLAT. Whilst not 100% accurate, TDoA is surprisingly good and will sometimes get you to within a few kilometres of a transmission site with a strong signal.
One of my thoughts was that the signal was emanating from the UK Defence High Frequency Communications Service (DHFCS) site at either St. Eval in Cornwall or Inskip in Lancashire. With this in mind I picked relevant KiwiSDR’s that surrounded these two sites and my area and ran a TDoA.
As expected, the result showed the probable transmitter site as just over 58 kilometres from St. Eval, though the overall shape and “hot area” of the TDoA map also covered Inskip, running along the West coast of England, Wales and Scotland. It peaked exactly in line to where the Norwegian navy ship and I were located! With the fact that there were signals being received from three different sources it is highly likely this has averaged out to this plot.
Just after 10am the weather cleared allowing me to see a US Navy Arleigh Burke class DDGHM between myself and Arran. This added an extra ship to the equation, and also tied in with the TDoA hot spot. Things were getting even more interesting!
Thor Heyerdahl still hadn’t moved according to AISLive but the Arleigh Burke was clearly heading in to the Royal Navy base at Faslane. With my Bearcat UBC-800T scanning the maritime frequencies it wasn’t long before “Warship 101” called up for Clyde pilot information along with an estimate for Ashton Buoy of 1300z. Warship 101 tied up with Arleigh Burke USS Gridley.
As USS Gridley progressed towards Faslane, the signal started to get weaker. Ashton Buoy is where most ships inbound for Faslane meet the pilot and tugs, taking up to another 30 minutes to get from there to alongside at the base – a journey of about 8.5nm.
At 1328z the Link-11 SLEW signal ended which coincided with the time that USS Gridley approached alongside at Faslane. It would be at about this time that most of the radar systems used on the ship would have been powered down so data was no longer available for transmission, therefore the Link-11 network was not required any further and it was disconnected.
So, was this Link-11 SLEW connected to USS Gridley? And was the ship also the NCS of the network? I think the answer is yes to both, and I’ll explain a couple of things that leads me to this conclusion. But first…………….
Link-11 SLEW Technical details
Using Upper Side Band (USB) in HF, a single waveform is generated in a PSK-8 modulated, 1800 Hz tone. The symbol rate is 2400 Bd and the user data rate is 1800 bps. Link-11 SLEW is an improved version of the older Link-11 CLEW modulation and due to enhanced error detection and correction is a more robust method of sending data. This makes it more likely that transmissions are received correctly the first time. Moreover, an adaptive system is used to counter any multipath signals the receiving unit may experience due to HF propagation.
The waveform transmission consists of an acquisition preamble followed by two or more fields, each of which is followed by a reinsertion probe. The field after the preamble is a header field containing information that is used by the CDS (Combat Data System) and an encryptor. If a network Participating Unit (PU) has any data, for instance track data, this follows the reinsertion probe. Finally, an end-of-message (EOM) is sent followed by a reinsertion probe.
The header is made up of 33 data bits and 12 error detection bits (CRC – Cyclic Redundancy Check). The 45 bit sequence is encoded with a 1/2 rate error correction code therefore giving a 90 bit field. The header contains information on the transmission type used, Picket/Participating Unit (PU) address, KG-40 Message Indicator, the NCS/Picket designation and a spare field.
Broken down, each piece of information is made up as follows:
The transmission type indicates the format of the transmission – 0 for a NCS (Network Control) Interrogation Message (NCS IM); 1 for a NCS Interrogation with Message (NCS IWM) or a Picket reply.
The address contains either the address of the next Picket or that of the Picket that initiated the call.
The KG-40 Message Indicator (MI) contains a number sequence generated by a KG-40AR cryptographic device. Synchronization is achieved when the receiver acquires the correct MI. For a NCS IM this will be made up of zeros as no message or data is actually sent.
The NCS/Picketdesignation identifies whether the current transmission originates from the NCS or PU: 0 = NCS; 1 = PU
Following on from the header, the SLEW data field consists of 48 information data bits along with 12 error detection and correction bits, themselves encoded with 2/3 rate error correction. This creates a 90 bit data field.
The EOM indicates the end of the transmission and is also a 90 bit field. There are no error detection or correction bits. Depending on the unit that is transmitting, a different sequence is sent – NCS = 0’s; PU = 1’s
There is a specific order of transmissions which takes place for data to be exchanged.
Ordinarily the NCS sends data that creates the network, synchronizing things such as platform clocks etc. Each PU is called by the NCS and any data that a PU has is then sent, or the NCS sends data, or both. This is a very simple explanation of how data is exchanged but if you monitor a SLEW network you’ll see the exchanges take place rapidly. Except for the message itself which is encrypted, go2MONITOR will decode all the relevant information for you for analysis. This means that you don’t need to look at each raw data burst as sent to calculate whether it was a PU reply or NCS IWM, the decoder will do this for you.
At this point I need to say that Link-11 decoding is only available in the Mil version of go2MONITOR so doesn’t come as standard. Should you be interested in Link-11 decoding yourself then you would need to go for the full go2MONITOR package to enable this.
As previously mentioned, the data itself is encrypted but it is possible to try to calculate who is who within the network, and the analysis of the header information in particular will give you a good clue if you already know of potential PU’s that could be on the frequency.
In this case we already have four possible PU’s:
St. Eval transmitter site
Inskip transmitter site
It later transpired that Thor Heyerdahl had gone into Belfast Harbour for repairs so this practically cancelled out this ship as the NCS though it could still be a PU. Moreover, Thor Heyerdahl and USS Gridley were part of the same NATO squadron at that time which meant it was highly likely they were on the same network. This left us with three choices for the NCS, but still four for the network.
Here, I’d cancel out Inskip completely as both the NCS and a PU as the TDoA appeared to give a stronger indication to St. Eval – that left us with three in the network.
The pure fact that the strength of the major signal increased as USS Gridley got closer to my location, then slowly faded as she went further away added to my theory of her being the NCS. This was practically confirmed when the signal stopped on arrival to Faslane. Throughout the monitoring period he other signals on the frequency remained at the same strength.
Based on this, this meant that the strong signal was USS Gridley using ID Address 2_o.
Let’s take a look at one the previous screenshots, but this time with annotations explaining a number of points.
Firstly, we need to look for the NCS. The easiest way to do this is to look at the NCS/Picket Designation and find transmissions that are a zero, combined with a Message Type that indicates it is a NCS IWM. Here, there is just one transmission and that emanates from Address ID 2_o – the long one that includes a data message.
We next need to find NCS/Picket Designation transmissions that still have a zero – therefore coming from the NCS – but that have a Message Type that show it to be a NCS IM. These are calls from the NCS to any PU’s that are on the network looking to see if they have any “traffic” or messages.
Because of this there should be numerous messages of this type, and if you notice none have an ID address of 2_o. However, all of these messages are actually coming from 2_o as the ID address shown in a NCS IM is that of the PU being called rather than who it is from.
Any reply messages from PU’s will show as a NCS IWM/PU Reply transmission, but importantly the NCS/PU designation will be a one – showing it isn’t the NCS. Here there is one data reply from 71_o. You’ll notice that in the “reflection” there isn’t any transmission, unlike the ones from 2_o.
Moreover, though not shown here as the messages were off screen and not captured in the screen grab, you can see that one of the PU’s sent another reply message. As I was able to look at the complete message history I was able to see that this was also from 71_o – and 2_o either replied to this or sent further data.
There are two fainter transmissions which were not captured by go2MONITOR. These were from a PU, and must have been 30_o as there are no transmissions at all in the sequence that are from this ID address.
We now have a quandry. Who was 30_o and who was 71_o?
Data is definitely being sent by 71_o so to me this is more likely to be a ship rather than a transmitter site – but – a strong TDoA signal pointing at St. Eval makes it look like 71_o is this location instead.
Now though, we need to think outside the box a bit and realise that I’m looking at two different sources of radio reception. The TDoA receivers I selected were nowhere near my location as I’d selected KiwiSDR’s that surrounded St. Eval. This meant the signal that was weak with me could have been strong with these, therefore giving the result above.
If I base the fact that I think USS Gridley is 2_o due to strength, then I must presume the same with 71_o and call this as Thor Heyerdahl as this is the second strongest signal. I can also say that having gone through the four and a half hours of Link-11 SLEW transmissions available that 30_o never sent a single data transmission – or rather, not one that was received by me.
Here then is my conclusion:
USS Gridley = 2_o and the NCS
Thor Heyerdahl = 71_o
St. Eval transmitter site = 30_o
Of course, we’ll never really know, but I hope this shows some of the extra things you can do with go2MONITOR and that it isn’t just a decoder. It really can add further interest to your radio monitoring if you’re an amateur; and if you’re a professional with a full plethora of gear, direction finders, receiver networks etc. then you really can start getting some interesting results in SIGINT gathering with this software – and highly likely be able to pinpoint exactly who was who in this scenario.
Now, how do I get some Direction Finders set up near me….Hmmmmmm??
If you follow me on Twitter you’ll see that in the last month or so I’ve been sending out images of classification and decoder software go2MONITOR working with a number of my SDR’s.
go2MONITOR is part of the go2SIGNALS range of software solutions created by PROCITEC GmbH operating from Pforzheim in Germany, themselves part of the PLATH group. PLATH Group is the leading European-based solution provider for communication intelligence and electronic warfare (EW) with worldwide government customers. The group covers all aspects of signal interception and analysis split between a number of companies such as PROCITEC. EW, COMINT/SIGINT, Jamming and Decoding are just a small part of what the group specialises in.
go2MONITOR is advanced high-performance, automatic HF, VHF and UHF monitoring software capable of recording, SDR control, wideband and narrowband classification and multichannel signal decoding.
It isn’t for the faint hearted, but once you get used to using it, it really does make gathering information on networks extremely easy. And it decodes many modes other software can’t.
In a series of blogs I’m going to show you the capabilities of this amazing software, though I must stress now, it is aimed at Professional SIGINT gathering and it comes with a Professional price tag.
Saying that, it doesn’t mean it isn’t available to the non-professional. It is open to all and to cover this it comes in various versions starting with the Standard package progressing to a full Military package – which gives you the full range of HF, VHF and UHF classification and modem recognition decoders available, including PMR and SAT (Inmarsat AERO). The Standard version isn’t to be sniffed at, it still gives you an amazing range of decoders, though you could easily argue that many of these are available in other free – or near to free – decoding software like MultiPSK or Sorcerer. A full list of decoders available can be found here. Note, this list is broken down into the various packages and not all are available with the Standard option. Confirm what belongs to what if you’re thinking of purchasing.
So what’s the difference in what go2MONITOR can do with other software available? That’s the idea of these blogs, to answer just that question. It will take quite a few blogs – mainly because there isn’t just one answer.
Here then, is a brief overview of what can be done, what SDR’s it works with – in fact, not just SDR’s but all receivers that can produce a recording – and any other things I can think of.
As, I’ve said then, it can decode pretty much any data signal out there. Obviously, some signals are encrypted so it wouldn’t fully decode unless you had the key, but you can get the encrypted messages. It can also classify voice signals, not just data. So, if you wanted to hunt out various voice networks, go2MONITOR can assist you in doing this.
Here is where it excels. Classification – and doing it very quickly.
Imagine being on your SDR (SDR1) and you can see a whole load of data signals on the waterfall/spectrum and you quickly want to know what they all are. With go2MONITOR operating another SDR (SDR2) you can dial in the centre frequency of the bandwidth shown on SDR1 into the go2MONITOR/SDR2 combo, click one button – Find Emissions – and within seconds the whole bandwidth has been analysed and every signal classified.
I’ll go back a step though here. You don’t need two SDR’s. One will do. SDR1 – as long as it is a compatible SDR – can be controlled through a GUI by go2MONITOR. The software includes a waterfall/spectrum display. Like all SDR software, these displays are fully adaptable to how you like to see the signals.
Either way, you now have a list of every emission that go2MONITOR has received within that bandwidth. This list includes Modulation type, Frequency, Bandwidth, Symbol (Baud) rate and SNR. It also shows which SDR you have used for interception (useful if you’re using go2MONITOR with more than SDR at the same time, but also with other advanced features such as network control), and it also shows if the frequency is already stored within the frequency database – yes, you can create this too; or import ready made databases in a CSV format.
Already then, you have built up a picture of what these signals are. One thing to note. If the signal type is not one of those included within the package you have, it will be classed as unknown. Example – a STANAG 4285 will show as unknown in the Standard and PMR/SAT package, but will be classified correctly in the MIL package.
OK, those of us that are looking at SDR’s all the time can pretty much tell what the signals are just by looking at them, so there’s no great advantage here is there? Except, now go2MONITOR has logged these in its database which can be searched through at a later date – handy if you’re looking for potential schedules for example.
However, the next step is where things get interesting. By putting one of these emissions into a “Channel” you can carry out an advanced classification, recognition and decode. You have multiple choices here, but I generally start off with a Classification. Whilst the software has already decided what the emission type is, by doing this it double checks just this one channel and produces a choice of decoders that it is likely to be.
By using STANAG 4285 as an example, it will put this into the list of choices, but it may put other PSK signals there too. By clicking on another button, this puts the channel into Recognition mode and it reduces the hundreds of decoders down to just those in the classification list produced. The software then calculates which is the best decoder and starts to decode the signal.
If you think about STANAG 4285 in other software, you generally have to try all the various potential Baud rates – is it Long Interleaving? is it Short? etc etc. Well go2MONITOR does this automatically. It checks the alphabet and protocol and will decode it if known. More often than not it can’t calculate the alphabet, but every now and again it does and it will produce encrypted data – don’t forget, if it’s encrypted it won’t decrypt it without the correct key.
This further Recognition and Decoding is also stored in the database for later analysis, along with a recorded wav file for playback and deeper signal analysis.
Seriously, it is harder describing it in text than it is doing it so I’ve created a video that’s at the end of this blog.
I mentioned previously that the software works with receivers that aren’t SDR’s. That’s because, as long as you can create a wav file recording – Narrowband as it’s known in go2MONITOR – it can be analysed. There are things missing, the actual frequency for instance (though this can be typed into a text box so that you can then have the right information – this i’ll show in a later blog). Time stamps aren’t naturally there but again you can add these by telling the software to use the time the recording was started.
I’ve used recordings made on my Icom IC-R8500 as an example of this but it is literally the bandwidth of the mode used by the receiver that is shown on the go2MONITOR spectrogram.
You don’t actually need to own a receiver of your own. Use an online SDR such as a KiwiSDR, record the IQ as a wav file and play it back through go2MONITOR for analysis. I’m doing just that for a Jane’s Intelligence Review magazine article.
If you use SDRConsole, then you may have also tried the File Analyser function that I blogged about in August last year. The File Analyser in SDRC is excellent, there’s no doubt about it, but it has one drawback. Once you’ve carried out your recording you have to create a run through of the recording, making an XML file that effectively joins all the wav files up. If you’ve made a wide and long IQ recording this can take quite some time. With most of my overnight recordings – normally 7 hours long, with a 768 kHz bandwidth – this takes around 45 minutes to complete.
With go2MONITOR you can also record the bandwidth IQ data. With this you can do two things. Firstly you can run it through as a normal playback, classifying and decoding as you go. Secondly though, you can open the Results window which gives you a time based view of the whole recording allowing you to immediately see any transmissions. Unlike SDRC Analyser, the signals have already been classified, and more importantly, this is done straight away without any need to create an XML file first. The Results window will be covered in greater detail in a blog of its own.
However, there are no decodings here. With just an IQ recording you need to play it back and run an emission search etc. There are some basic automation tasks available, such as setting up an emissions search every 10 seconds.
But, if you have the Automated Monitoring and Tasking package, you can also have the software automatically record, recognise and decode a single emission type – or all emissions types within the bandwidth, a set frequency, between two frequencies or any other parameters you may wish to set up.
The list of SDR’s that can be used with go2MONITOR is pretty good, though due to the target audience, many of them are high end, “government/military” receivers. But, it does work with Perseus, SDRplay RSP1 & RSP2, RFSpace NetSDR and SDR-14, and of course AirSpy R2 – and now the AirSpy HF+ and AirSpy HF+ Discovery.
Supported receiver list:
Max. Rx bandwidth
Grintek GRX Lan
IZT R3xxx series
Up to 3 channels spectrum
IZT R4000 (SignalSuite)
1 channel only
Limited USB 3.0 compatibility
narda® NRA-3000 RX
narda® NRA-6000 RX
narda® IDA 2
VITA 49 support. Only 1 MHz and no receiver control at LINUX
PLATH SIR 2110
LINUX recommended. External receiver control only
PLATH SIR 2115
External receiver control only
PLATH SIR 5110
16×768 kHz subbands External receiver control only
PLATH SIR 5115
40×768 kHz subbands External receiver control only
No gain control available
R&S EM100 / PR100
External receiver control only
Experimental support. Continuous signal up to 2.4 MHz
SDRplay RSP1 & RSP2
Up to 2 channels + spectrum
Generic VITA 49 receiver support
Max. receiver bandwidth
Can be configured in a wide range for different receiver types
Other generic “Winrad ExtIO” supported receivers
Max. receiver bandwidth
As you can see, there is a huge difference in bandwidth capabilities for each receiver. I use my WinRadio G31DDC quite often with go2MONITOR, but the AirSpy HF+ Discovery (not listed as i’ve only just got it working) isn’t much worse with it’s full 610 kHz bandwidth.
When you think that the G31 has a much better operational bandwidth than 800 kHz when you use it on its own, it’s obvious which is better value if you were buying an SDR solely for using it with go2MONITOR. It is this kind of thing that many Government agencies are looking at when it comes to funding operations aimed at large scale monitoring.
That then is a very basic overview of go2MONITOR. The quick video and images have hopefully shown you a little of what is possible.
Outside of a Professional SIGINT operation, why would an amateur radio monitor need something like go2MONITOR? And would they pay the price?
I think they would. After all, most of us have spent a fair amount on radio monitoring over the years, so why not on software that would make their monitoring not only quicker and easier, but potentially open up new areas of monitoring.
Many of us specialise in certain monitoring areas – Russian military, particular the Navy and Strategic aviation for me for example. With go2MONITOR I have already used it to hunt out potential Russian Northern Fleet frequencies by running an automated 10 second CW emission scan overnight within a bandwidth block. By doing this, and then analysing data found in the results window, I was able to target certain frequencies to see what activity there was on subsequent nights.
Whilst there are other decoders available – some of which are plugins in software such as SDR#; some of which are free – it is the quickness and ease with which it can be done that makes go2MONITOR attractive. The big question is, would you pay for this?
Sunday the 6th of October 2019 sees the start of Exercise Joint Warrior 192.
Taking part primarily to the North West of Britain, mainly off the coast of Scotland, the exercise brings together a number of navies and ground forces for two weeks of training.
Despite media headlines such as “Joint Warrior 19(2) features 17 countries, 75 aircraft, 50 naval vessels and 12,000 troops” this isn’t the JW of old. It is one of the smallest, if not the smallest, in participant numbers since the exercises started and the headlines are completely incorrect – in fact most of the headlines use stock Royal Navy media notices that cover all JW exercises.
In reality, JW 192 has 16 ships, will not really go over 30 aircraft at any one time and feature nowhere near 12,000 troops. Rumours have it that the exercise would have been cancelled had not the French elements insisted on it taking place. Unfortunately, media outlets have misinterpreted some of the RN notices as ships from other countries – such as Japan – participating, when in fact the countries have sent a number of officers to observe or be trained in the handling of exercises.
This JW has coincided with other NATO exercises – Dynamic Mariner/Flotex-19 for example -which are taking place in far sunnier climes, so the draw of the rough seas and bad weather of Western Scotland was not so great on this occasion. And with NATO forces spread out on real world tasks, the number of ships, aircraft and personnel required to cover all of these exercises is low.
The weather has already taken its toll with some of the first few days activities cancelled due to high sea states. Whilst you could argue that surely they should be able to “fight” no matter what the weather, in reality in the real world, operations do get delayed because of this. For exercises though, safety must come first. However, MPA activity is taking place with at least three flights up at the time of writing on Monday 7th October.
One saving grace for the number of ships and personnel that are taking part is the fact that Exercise Griffin Strike is shoehorned into JW192. Griffin Strike is a training exercise for the Combined Joint Expeditionary Force (CJEF) involving the UK and France and which is due to become fully implemented in 2020. Griffin Strike will contain the Amphibious part of JW192.
There are no visiting fighter aircraft from other countries, but there are the usual Maritime Patrol Aircraft (MPA) consisting of 2 x US Navy P-8’s, 2 x Canadian CP-140’s and 2 x French Navy Atlantique ATL2’s. These are operating out of Prestwick again, likely doing the usual 4 hours “on-station” missions. This means that there will likely only ever be two or three airborne at any one time with a 1 hour or so transit each end of the flight. Callsigns so far have been OCTOPUS** and SUNFISH**(FNY), DINKUM** (RCAF), GROMMET** and DRAGON** (USN).
Also out of Prestwick will be mixed Royal Navy and Royal Air Force Hawks, along with Cobham Aviation Dassault Falcon 20’s acting as enemy aircraft. For information on how the Falcon 20’s operate read my previous blog on monitoring Joint Warrior.
There will be other aircraft movements of course, with RAF Typhoons playing their part. Also expected are E3’s of both the RAF and NATO fleets, RAF Sentinel and Rivet Joint aircraft providing ISTAR support and Air to Air refuelling from RAF Voyagers and C130’s. I would also expect F-35’s from 617 Sqn at Marham to be involved in some form, though I can’t confirm this for sure. These will all be operating from their home bases.
The aviation side of the exercise is capped off with plenty of helicopters operating from both land and sea, with Chinooks operating from Lossiemouth and most ships providing one or two various types. I was able to watch one Chinook, ONSLAUGHT01, practising a deck landing on RFA Lyme Bay (using callsign 4QW) to the front of my house in the Firth of Clyde. Lyme Bay later tweeted the event.
The most disappointing aspect of the exercise is the maritime part. The ships are sparse in numbers in comparison to previous exercises, with a light participation by the Royal Navy. The RN is providing Amphibious Assault Ship HMS Albion, possibly using her Landing Craft Utility (LCU) Mk.10 class vessels operated by the Royal Marines. Albion is the current RN flagship. Also taking part is Duke (Type 23) class FFGHM HMS Sutherland and a small number of Minesweepers and Minehunters.
**Edit: RFA Lyme Bay is now also confirmed as part of the exercise. RFA Argus and RFA Tidesurge are also now confirmed.
France has also sent a Amphibious Assault Ship in the form of FS Tonnerre, a Mistral class LHDM. Tonnerre can embark 450 fully kitted troops and 60 armoured vehicles or 13 main battle tanks, along with Landing craft and up to 16 helicopters. No helicopters were observed on deck as she arrived at the Greenock area on Friday 4th October 2019 – it is not known whether they, if any, were on the hanger deck. The same goes for APC’s/MBT’s on the lower decks.
Modified Georges Leygues class FFGHM FS La-Motte-Picquet arrived into Glasgow on the afternoon of 2nd October along with Éridan (Tripartite) class minehunter FS Cephee going into Faslane earlier in the morning.
The German Navy has sent a single ship – the Berlin (Type 702) class replenishment ship FGS Berlin – whilst the US Navy, who normally send a number of frigates and cruisers, have only sent Military Sealift Command Lewis and Clark class dry cargo/ammunition ship USNS William McLean.
Finally, Danish Navy Iver Huitfeldt class FFGHM HDMS Iver Huitfeldt is also participating, but due to other tasks is heading straight to the exercise area rather than going to Faslane for the pre-exercise briefings.
For submarine participants, Norwegian Type 210 (Ula) class SSK Utsira is one of the MPA targets. She arrived earlier in the week and departed on Sunday 6th October as the exercise began.
Also, an Astute class SSN of the Royal Navy departed Faslane on friday 4th. Though not confirmed, again it is highly likely to be taking part in some form or other.
As well as areas in and around Scotland, it is highly likely there will be the usual missions around the Spadeadam Electronic Warfare Tactics range and possibly areas out over the North Sea. GPS jamming also normally takes place as part of the exercise, normally out in danger areas situated to the NW, over the sea.
There should be Maritime Gunnery firing off the west coast of Scotland. Timings and areas are normally reported via the Royal Navy’s Gunfacts service either by a recorded telephone message and on NAVTEX at 0620 and 1820 UTC. Coastguards also broadcast the details at 0710, 0810, 1910 and 2010 UTC. If you happen to be in the area where gunnery is taking place then the duty broadcast ship sends out details at 0800 and 1400 local, or 1 hour before firing, by making a call on Maritime channel 16 and then the appropriate broadcast frequency for the area.
The navy also provides SUBFACTS warnings on submarine operations on the same telephone hotline and NAVTEX.
NOTAMs will also be available that provide warnings on most of the activities taking place. A good place to look for these is on the NATS AIS NOTAM page.
The amount of frequencies used for the exercise is huge, and near impossible to list. However, there is a list of VHF/UHF and HF frequencies on my Monitoring Joint Warrior Exercises blog from 2014. Despite being 5 years old, the HF freqs tend to be the same especially those used by the MPA’s when communicating with Northwood (Callsign MKL).
Noticeable so far has been the fact that the P8’s and CP140’s have both been out on their frequencies by 1.5 to 2.0 kHz when calling MKL on 6697 kHz (primary freq) and 4620 kHz.
The VHF/UHF frequencies won’t have changed that much either, but as most of the exercise is at sea, and generally out of range of most of us, it is hard to gather them all. Certainly the standard Swanwick Mil, A2A and TAD’s will be used, so if you have these you’re bound to get something.
Nearly two weeks ago I attended the Defence & Security Equipment International 2019 (DSEI19) at the Excel exhibition centre, London.
The intention of this blog is to provide a brief look at what I saw on the day I attended.
Generally, I was more impressed with the smaller companies that I met rather than the larger ones. The larger ones, once they’d read my name badge and saw that I was “Media”, gave me the feeling that they couldn’t wait to get rid of me as I wasn’t there to make a multi-million pound purchase from them. The smaller, or less well known, were far more attentive and provided me with a good amount of information on their products, target audience and hopes for the future.
Whilst this may turn you off from reading the remainder of the blog, I think I’ll start with the things I was a little disappointed with.
One of the companies I was extremely interested in visiting was Barrett Communications. As I’m currently writing an article for Janes on a system very much like one of their products I emailed the UK office in advance to tell them that I was coming and what I was interested in. They did reply and were keen to see I was attending, even sending me a heads up on one their new products that was yet to be revealed. I was, then, very quick to go and see them once the show started.
However, once on the stand, things were very different. As I said above, the media name badge meant I wasn’t a buyer. And despite trying to show keenness on their equipment, which I’d swatted up on before attending, I got the feeling the sales chap just wanted me to leave. On a couple of occasions I was brushed aside so that he could chat or shake hands with a mate rather than carry on showing me some of their products – which are actually very good. Nice gear, not always so good at media relations.
Unfortunately, the same can almost be said with rugged case manufacturer, Peli Products UK. This time I hadn’t emailed in advance, but I sought them out as I am actually in the market for a number of new rugged cases – a new camera case, a 13″ laptop case and a GoPro case.
Whilst this time the guy I spoke to was nice and briefly showed me their new TrekPak dividers – which are pretty cool – I got the impression he didn’t really want to be at the show and he kind of fobbed me off with a brochure rather than trying to sell me the products that I had told him I was interesting in buying. The irony here being that when you go to the TrekPak part of their website, the opening image is that of a rugged case full of camera equipment with “Press” stickers all over them.
In all honesty I could go on about quite a few other companies much like these but I don’t want to have too much of a whinge about the show, so let’s move on to the good stuff.
I obviously paid a visit to the Janes stand first, had a quick coffee and chat – and it was nice to know that they’d heard of me 🙂
Next to the Janes stand was Keysight Technologies, well known manufacturers of Signal Generators, Oscilloscopes and Spectrum Analysers – and many, many other outstanding workbench solutions. I spoke to Radar, EW and Satellite solutions manager Erik Diez, who showed me one of their solutions used to analyse an unknown radar signal with the idea of creating a potential jammer, countermeasure or signal designation. It truly was an interesting chat and the demo of the equipment was very interesting – if only any of it was within my price range 🙂 Saying that, their entry stage Spectrum Analysers etc are comparable in price to the Rigol equipment I have at home.
I enjoyed my time with Erik, with both of us agreeing that when I retire I may be able to buy something from him 🙂
Wondering around, there were plenty of vehicles, weapons systems, EW systems, ELINT/COMINT/SIGINT companies to take a look at. There was a huge Turkish contingent who took over a large area of the north side of the Excel with pretty much all of the above on view.
I had a chuckle to myself as I walked through an area of companies selling UAV’s, straight into another area selling various weapons and systems designed to take drones out.
As well as technical solutions there were clothing/footwear companies – I had a good chat at footwear company Rocky Boots who have some nice military boots.
BAe were there in force with various future ship models, simulators and other technologies. I even bumped into old friend Jamie Hunter on their stand – we calculated that it was over 20 years since we last bumped into each other and travelled to various bases on photo trips.
I would have taken more photos of the vehicles but the stands were generally pretty close and so it made it difficult for photos. Some though I did manage:
I got to play with plenty of weapons. I was very happy on the Sig Sauer stand and spent some time in the pistol area. In comparison to some of the other companies, their handguns felt good and seemed to have a smoother slide – obvs no ammo was available. I was particularly happy with the SP2022 and if given the chance to try it out properly, I’d jump at it.
On a non-live ammo front, an interesting company here in the UK is Ultimate Training Munitions – UTM. They did have a “live firing” area at the show. Instead of being live ammunition however, UTM have created training ammunition that provides a realistic environment without the potential of death. With modifications to real weapons, this ammunition can be used in exercises giving troops/law enforcement agencies the chance to fire near real ammunition at one another and know when they’ve been hit by a projectile that has a plastic cover and a coloured marker.
I’ve got to say it was very good in the small range. I feel like the next time I’m down at Mildenhall I may request a visit.
My final port of call at DSEI was the Rohde & Schwarz stand. This was for two reasons. Firstly, I wanted to spend a bit of time there as I knew their products would be very interesting and secondly – they had a bar with free Augustiner-Bräu Helles beer 🙂
The beer was great, one of my favourites on my regular visits to Bavaria. And I had a great chat with Jo who hosted me in the bar and out at the equipment on display.
R&S really do have an amazing input into many of the worlds military radio requirements. For instance, they recently provided the Royal Navy with the first land-based NAVICS radio system for the Type 26 City class FFGHM – with all ships of the class being fitted out with the integrated comms system. This will provide internal and external comms (both voice and data) via an IP network, all of which will be secure. The External VHF/UHF and HF comms will use M3SR Series 4400 and M3SR Series 4100 radios.
As well as VHF/UHF and HF comms, they will also be providing SATCOM and GMDSS systems, along with a joint venture with STS Defence for the Communication masts.
In total, the NAVICS system has been provided to over 40 navies. For the RN this includes the Queen Elizabeth class Aircraft carriers, the River class batch II patrol ships and the above mentioned Type 26’s.
Also of interest was the WPU2000 ELINT Processor, launched at the show.
The WPU2000 is a wideband processing unit – hence WPU – and has a 2 GHz instantaneous real time bandwidth. It is set out to replace the WPU500 which operates with a 500 MHz bandwidth. It collects, then processes and analyses radar signals such as those produced by low probability of intercept (LPI) radars and emissions from Active Electronically Scanned Array (AESA) radars. I was told that due to its sensitivity it can detect emmissions that may be invisible to ELINT and EW systems currently in use.
As standard, R&S ELINT and radar direction-finding systems comes complete with identification software, analysis software for ELINT signals, and a database system for radar/ELINT/EW data management.
From what I can gather, the system has had considerable interest. It is still under final tests I believe and will be available in 2020.
So, that’s my DSEI 2019 run down. Not that comprehensive really. I could literally spend months writing about the various pieces of equipment, weapons, radios and software that I spotted and was drawn to. I will follow this blog up very soon with a few individual articles on some of those that really caught my eye.