THE WHOLE PROCESS OF SETTING UP 2G CAPTURES
INFRASTRUCTURE SETUP
- bring some device alive e.g. rtl or hackrf and check GSM downlinks with GQRX and a large bandwidth
- center against a strong GSM downlink with smallest bandwidth and manually define an approximate PPM
- look for LTE channels and write down their approximate center frequency
- define the exact frequency correction and precise PPM with LTE scanner
- scan for 2G BTSen around and write down MNCs / ARFCNs
you are now ready to start digging into some broadcast channel, look for possible hopping channels and inspect immediate assignments.
THE CASE OF A VOICE CALL ON ANOTHER CHANNEL (NO HOPPING)
repeat the commands every time with resp. --args=rtl=0
and --args=rtl=1
to capture a voice call without hopping
HOPPING
deal with hopping using MultiRTL
deal with hopping using channelize