THE WHOLE PROCESS OF SETTING UP 2G CAPTURES
- bring some device alive e.g. rtl or hackrf and check GSM downlinks with GQRX and a large bandwidth
- center against a strong GSM downlink with smallest bandwidth and manually define an approximate PPM
works only with RTL
- scan for 2G BTSen around and write down MNCs / ARFCNs
if you got hackrf here’s a workaround
- look for LTE channels and write down their approximate center frequency
- define the exact frequency correction and precise PPM with LTE scanner
you are now ready to start digging into some broadcast channel, look for possible hopping channels and inspect immediate assignments.
repeat the commands every time with resp. --args=rtl=0 and --args=rtl=1 to capture a voice call without hopping
deal with hopping using MultiRTL
deal with hopping using channelize