THE WHOLE PROCESS OF SETTING UP 2G CAPTURES
- bring some device alive e.g. rtl or hackrf and check GSM downlinks with GQRX and a large bandwidth
- center against a strong GSM downlink with smallest bandwidth and manually define an approximate PPM
- look for LTE channels and write down their approximate center frequency
- define the exact frequency correction and precise PPM with LTE scanner
- scan for 2G BTSen around and write down MNCs / ARFCNs
you are now ready to start digging into some broadcast channel, look for possible hopping channels and inspect immediate assignments.
THE CASE OF A VOICE CALL ON ANOTHER CHANNEL (NO HOPPING)
repeat the commands every time with resp.
--args=rtl=1 to capture a voice call without hopping
deal with hopping using MultiRTL
deal with hopping using channelize