ScanEyes is a PHP web front end for visualizing, listening to, and archiving trunked radio traffic.
It allows user registration, permissions, and playlist creation.
sdrscan viewed from a mobile device
Talkgroup browse mode
Number of calls in a 24 hour period chart
Admin control panel, log section
App config of AdminCP
Fake scanner interface
Problem, Objective and Solution
A new radio system is being deployed in my city. New talkgroups pop up every day, need a way of logging them for review later so I can identify the unknown ones and submit the info (X City Police Dept) into the RadioReference Database
A means to record police dispatch calls in my city, so I can recall them when my local news paper publishes their “police blotter” section.
Program a script that records the calls so I can listen them to later, a pretty web interface is optional
Two essential pieces of software were written by me. LogRecorder (Available here) and the main ScanEyes application
The ScanEyes application is run in Apache with PHP without the need for a SQL server.
LogRecorder is a PHP script that runs in php-cli.exe (no web server) It polls sdrsharptrunking.log for file changes every 150ms and spawns an audio recorder if an active talkgroup is picked up by Unitrunker.
LogRecorder tells sox.exe to write an mp3 file containing call audio to a specific folder ‘YYYY/MM/DD/UNIXTIMESTAMP_TGID_TGNAME_RID_RNAME.mp3’
EverythingSearch by Void Tools indexes these files and when a user queries ScanEyes, the query is sent to es.exe with the search term. The resulting data is manipulated into various tables and charts.
Here is a diagram of the entire setup, including extra features I’ve built into the server for, for example, streaming live audio with low latency. This entire setup runs at about 7% total CPU utilization for a Core i5 4670K during idle. Main culprits for CPU usage are SDRSharp, 5%; and Unitrunker, 2%.
There are two pieces of hardware in this setup, two SDR dongles. One talks to Unitrunker, another talks to SDRSharp.
Beginners explanation of trunked radio
Unitrunker listens to the control channel and gives a birds eye view of the entire radio system. It shows all the talkgroups on the radio system (Talkgroups are like virtual channels, unlike traditional analog radio, talkgroups are not bound to a particular frequency, rather grouped into a pool with other channels, sharing or competing for a group of frequencies. When an officer keys up their trunked radio, the voice signal can be on any voice channel defined by the control channel. The control channel tells all the other radios what talkgroup to listen to)
Unitrunker has plugins that allow remote tuning of the active control channel. By default, every talkgroup has the same priority, so it’s first come first serve. Unitrunker has 2 features, priority, and lockout. Lockout mutes the talkgroup so it is never listened to, and priority gives a talkgroup more priority over others. Useful for example, when you want to hear SWAT traffic over FD traffic.
remote.dll is a plugin that writes the current listening talkgroup to a file. SDRSharp is a piece of software that acts as a virtual radio, you can tune it to what ever frequency you want, and it will communicate with the second SDR to receive radio signals.
SDRSharp has a plugin that listens to remote.dll. This way, unitrunker can tell SDRSharp what channel to listen to, to get voice out. SDRSharp will then output this sound to a virtual audio cable. Virtual audio cables act as pipelines for audio from one program to another. In this case, we are taking the audio from SDRSharp, and putting it into our digital voice program.
P25 is a radio communications protocol that usually carries voice traffic. If you were to listen to P25 straight from the speaker, you would not hear voice, but digital noises like this. These noises can be decoded into regular voice by a program called DSD. All DSD needs is an input and output audio device and you’ll get clean listenable audio.
Listenable talkgroups along with all data is set through unitrunker, locking out a talkgroup causes LogRecorder to not record the call in the first place.
User and talkgroup prototype feature in unitrunker allows a user to prioritize newly added talkgroups, or lock them out, if only known talkgroups want to be logged.
Responsive design works on tablets, phones as well as desktop browsers
Users can create playlists to share via email, reddit, G+, or Facebook.
The playlist URL contains a gzipped encoded call ID (no DB required)
When playlists are called, every file is played back in chronological order
I’ve decided not to open source my work until an experienced PHP developer can review my code from a security standpoint. I’ve taken all possible measures to deter hackers, focusing mainly on input sanitization. That said. If you find anything on sdrscan.com, I’ll pay you via paypal to report these vulnerabilities to me.
Until then, I will allow other users(persons) to run this software provided that they don’t share it, or use my code elsewhere without my permission. Also, I doubt this will ever happen, but if a company would like this software, you can contact me directly.
As it stands right now, this software uses licensing servers with key validation.
This was my first large scale PHP project. I’ve learned a lot along the way, which has caused some code discrepancies. For example not having a database out of pure laziness to learn MySQL. As I learn new things, I will begin to incorporate or update those features.
This article is meant to go with my video, but the video I have is older than the steps I show here. Follow this tutorial, but use my video if you want to know how specific programs work. (don’t follow the video, just watch it)
Note: Lots of things are changing rapidly in the areas of SDR, especially the $9 RTL-SDR’s So What I say today, could change tomorrow. That said, I will provide as much detail as I can, and will list the versions of software I use.
Intel 2nd generation Core i5 or better (AMD processors have been untested)
You need to at least somewhat know how to work SDR# and UniTrunker. I suggest you play with some analog stuff and get familiar with the UI before getting into advanced things, or else you’ll tear your hair out.
Rick (Developer of UniTrunker) has implemented RTL-SDR INTO his program, so we don’t have to use this setup in theory, The latest preview build of Unitrunker has RTLSDR tuning support built in (no need for SDR#) but audio decoding isn’t too great, I still suggest using the tutorial below.
Virtual Audio Cable uses lots of CPU resources, even if it doesn’t seem like it. It seems VAC works well on some machines, and bad on others. My latest videos show decoding being done on a desktop with a core i5 4670K. I know this setup works with my hardware, and you can replicate my build for ~$300(used). Decoding varies a lot from PC to PC, and is generally not recommended on PC’s older than 2008.
Lets go through how this setup works. Below is a picture to familiarize yourself with what’s happening.
You have 2 USB Dongles with a (special)driver loaded that allows you to communicate directly with the chip inside the dongle. The chip controls the frequency at which you listen to. If you tune it to 100MHz for example, you’ll see the end of the FM broadcast band (87-108MHz)
SDRSharp and UniTrunker can utilize this driver to feed audio into their programs. When you listen to trunked audio, you have to have at least 2 receivers. One receiver is dedicated to listening to the control channel, the other listens to the voice channel. In this setup UniTrunker will listen to the control channel from SDR#1. Control Channels send data like, who’s talking, who joined the network, what the frequencies of the channels are, and how many channels there are. Control channels usually transmit 24/7, so they are easy to pick out in a waterfall display. Unitrunker reads this information into a nice window like this.
This window will only pop up when UniTrunker has detected a compatible radio system
Now lets talk about DSD. All DSD does is listen to Virtual Audio Cable for audio it can decode. Think of Virtual Audio Cable as the pipes that send audio from one program to another.
SDRSharp gets its orders from a plugin “Zefie’s Mod”
Zefie’s Mod is a 2 part plugin, it requires the installation of VC++ REDIST. Part one emulates a radio interface in UniTrunker. This is shown here
Part 1 is also known as remote.dll
Part 2 is a plugin for SDRSharp, It takes orders from remote.dll via a file called sdrsharptrunking.log. Sdrsharptrunking.log contains the current channel you should be listening to.
This is what the plugin looks like
Unitrunker tells the debug receiver to listen to a channel, the debug receiver writes the file called sdrsharptrunking.log, Zefie’s Mod SDRSharp plugin listens for that file, and tells SDRSharp to change its frequency based on the file.
This is currently the only way to listen to the voice channel. In analog trunked systems, you can directly listen to the output audio without the use of DSD. But if your system uses P25 CAI you will need to decode the audio, otherwise you’ll just hear weird noises any time someone talks.
DSD is a program that decodes a number of digital voice protocols. It’s still experimental and has bugs. As of version 160 it does not support P25 Phase II, but support is currently being worked on here. By default, DSD is not very good at decoding audio, It tries to guess what type of signal it is receiving and sometimes its guesses cause the audio to break up. Command line switches are used to specify what type of signal it should be listening to. This will be discussed further, later on. DSD requires some DLL’s to work, and can only utilize the “default” audio in and output for Windows. The audio you hear out of DSD should be words that we can understand.
Look for a device called “Bulk-In, Interface (Interface 0)” There may be two
Select WinUSB as the target, and click “Install Driver“
If the driver install fails (usually on Windows 8), Select “Edit Name“, Rename the device to “Interface” and try the install again.
Driver installation should be successful, Check the second Bulk-In and make sure the second device has its drivers installed too.
You may close zadig now.
Installing Virtual Audio Cable
You can purchase, or find an alternative to “Virtual Audio Cable”
Go through the setup for VAC and open the “Control Panel” (blue icon with yellow cables)
Under “Cable Parameters” set “SR” to “22050 … 192000” and “NC” to “1 … 1“
We are lowering the fidelity of the cable to save CPU usage.
Click the “set” button
You may close Control Panel now.
Crossed out steps above have been found to be un-necessary.
Configuring Windows Sound
Right click on the speaker icon in the system tray
Click on “Playback Devices“
click on the “Recording” tab
Double click on “Virtual Audio Cable”
In the “Advanced” tab, set the fidelity to “48,000hz , mono“
Set the default recording device to “Virtual Audio Cable”
Click on the “Playback” tab
Double click on “Virtual Audio Cable”
In the “Advanced” tab, set the fidelity to “48,000hz , mono”
Using SDR# for the first time
RTL-SDR Dongles have a warm up period of 5-10 minutes. During this time there may be a frequency shift of 5PPM or more.
Please open SDR# and select RTL-SDR/USB
Press “Play” in the main window
Feel free to play with SDR# to become accustomed to the user interface.
You can change frequency by dragging on the FFT/Waterfall, by clicking on the top or bottom of numbers, or by putting your mouse cursor over the numbers, and typing a frequency in. Look for FM radio stations, or Weather radio stations nearby and see if you can listen to them, set your mode accordingly WFM for FM radio, NFM for everything else.
If you feel like you might mess up the software, feel free to make a copy and run that one instead.
Once you’re back- Calibration can be set by going into “Configure“
Take note of how some settings may be locked, this is because you are currently running
Press “Stop” in the main window
“Device” selects which RTL dongle you will use
“Sample Rate” selects the amount of spectrum you will be able to see. Note that 2.8+ MSPS is not recommended due to audio cutouts, 0.25 is not recommended either due to interference.
Set this value to 0.900001 for optimal performance during trunking. Doing so will show 0.9MHz per fully zoomed out screen. Take note of how this correlates to the MSPS.
“Tuner AGC” can help in situations where you need the best signal possible for long range listening, however it is not recommended for nearby systems due to the possibility of overloading the SDR and causing harmonics in the FFT/Waterfall.
“RF Gain“should be set to a maximum of 32.8dB to avoid overloading.
Under “Frequency Correction” you can set the amount of correction needed. If you don’t set this properly, your decodes will not sound as good as they should, or not come in at all.
The PPM varies by unit. Generally around 55-65 in R820T based dongles
To calibrate your tuner you can find a control channel on radioreference, and tune to it inside SDR#. (you can also calibrate using a known NOAA weather frequency)
Notice how changing the PPM slightly changes the frequency, zoom in to get a better look.
Do this for both SDR’s, switch using the “device” drop down menu
Be sure to remember your number, It will be needed for UniTrunker.
Note: In practice, UniTrunker must always be opened before opening SDRSharp or the RTL device will not show up. If you currently have SDRSharp running, please close both UniTrunker, and SDRSharp, then open UniTrunker only.
Double clicking on the receiver will open the setting panel for the corresponding device.
In the “info” tab set the “RTL Device” to the second device on the list.
Set your “correction” to the PPM you had set from SDR# (e.g. 57.00000)
set “gain” to 300
checkmark “Auto Gain“,
Set your park frequency to the control channel frequency (e.g. 854.16250)
Start the receiver
If your dongle successfully found a control channel, a new window should pop up.
Troubleshooting the control channel (no video)
If you do not see a system pop up, follow these instructions
Go into the scope tab and look at the signal coming in.
If it is random and not uniform, you have not found a control channel
P25 Control channel example scope image
Static, no signal scope image (seen at 21:35)
A way you can detect if you found a control channel is in the info tab
This indicates a P25 signal, with a health of 99/100 was found, and is being decoded.
If you still see no systems, go into radioreference and try typing alternate control channels into the park frequency text box. See pic
If you still can not find a control channel, try a different system, try a better antenna, or go close UniTrunker, Open SDR#, and manually browse for a control channel visually.
This is what a control channel looks like, move your cursor over that frequency and try that the next time you open UniTrunker
Now that you have detected a system in UniTrunker you can begin filling out, or downloading radioreference data.
This is the download button, if you are a premium radioreference subscriber, you can enter your username and password, and UniTrunker will fetch the latest system info, system name, talkgroup names, etc.
Your frequency list should populate with channels like this.
If it does not, stop the R820T receiver, close the system window. and Start the receiver again.
UniTrunker can decode the control channel, we must now add a second receiver that will allow us to follow voice channels.
In the main UniTrunker Window, Add a Debug receiver (the video shows a bit differently, follow this step instead)
Check the box which corresponds with the type of audio you want to listen to (P25/VSELP/ProVoice)
Now for some math. Take the average of your lowest and highest frequency channel. This is done to ensure that the time it takes for the SDR to switch channels is even. SDRs do take a few ms to change their frequency, and you want to have the lowest latency possible. This will vary by radio system, and needs to be changed when you want to listen to a new radio system.
For example: My highest frequency is 856.16250, and lowest is 854.1375. The average is 855.15. So I would put 855.15 into the box.
In the main window under options enable listen
Press play on the debug receiver.
A new file should be created in ./SDR/UniTrunker called sdrsharptrunking.log
This is the file SDRSharp will read and follow, so we can get voice out of the program.
If you do not see sdrsharptrunking.log, you have not properly installed Visual C++ redist.
Following the Voice channel in SDR#(no video)
Now open SDRSharp in the SDR folder named VOICE
Press Start and duplicate my settings
Now we can configure the plugin
On the bottom of the left settings panel in SDRSharp there is a plugin called “Trunker (Plugin)“
Click set and find the UniTrunker install directory.
Also set Single log file output to that same directory.
Click on show options and in the log style box, type %t %s
Set the Parked Str as NOCALL
Check both “enable” boxes
Your VFO should match the parked frequency (if there is no call)
Now, when a call appears, UniTrunker will direct the plugin to write sdrsharptrunking.log, which will get read by SDRSharp, and the audio coming out of SDRSharp can be listened to (on analog systems), or for digital, there will be just one more step.
This is the final mandatory step in decoding P25 voice.
Download this batch file, and put it into the same folder with dsd.exe and cygwin1.dll
It will start DSD without having to open command prompt
Make sure your default audio output is still your sound card, and your input is the virtual audio cable
In most cases, this should work without problem
If you want to see what options are available in dsd.exe (to get better decodes) open a command prompt, navigate to the dsd folder, and type in ‘dsd.exe –help‘
Personally I use ‘dsd.exe -l -f1 -mc -u 9‘. But it varies by system.
That’s it! You should be hearing audio coming from DSD.
Don’t forget you can set call priority and lockout in UniTrunker
Here are a couple extras
Programs for Streaming
I advise you to make only unlisted streams. I know I can’t stop you from making public streams, but If you like what you hear, and don’t want to lose it. Stay far away from streaming services that allow criminals to tune in. This is the number one reason why cities are going encrypted.
Programs for recording
Audacity – has a voice activated recording mode to save silence
Log Recorder – based on SOX, written in batch. Puts each conversation into a folder based upon the date, year, in chronological order. Outputs mp3’s named by their TG and RID. Highly configurable