RF Scope is a 10-part tutorial series on rfscope — GopherTrunk’s protocol-agnostic RF network analyzer, “Wireshark for the RF physical layer.” Point it at any band, a recorded capture or a live SDR, with no prior knowledge of the technology, modulation, framing, or encryption, and it produces a structured Scene: what’s on the air and how it behaves. We start from your first scene summary and build to segmentation tuning, live cockpit analysis, and scripting the whole thing into a reverse-engineering pipeline.
A note up front: despite the name, RF Scope is not a waterfall or spectrum-scope UI — it is an analyzer that turns raw IQ into tables, trees, and graphs. If you want live constellations and eye diagrams, that’s Signal Lab.
Every post reads three ways: a TL;DR + cheat-sheet for skimmers, bold headers, tables, and diagrams for the medium read, and full prose for the deep read. Ada (new operator) and Reese (RF veteran) walk it with you.
This is one leg of the Lab Bench trilogy: Signal Lab, RF Scope (this one), and Crypto Lab. A mystery signal — Mercury — runs through all three.<ol class="post-list series-list"><li class="post-card"> <h2 class="post-card__title">RF Scope, Part 1: Wireshark for the RF Physical Layer</h2> <p class="post-card__meta"> Tutorials </p><p class="post-card__desc">rfscope is GopherTrunk’s protocol-agnostic RF network analyzer — point it at any band, recorded IQ or a live SDR, with no prior knowledge of the technology, modulation, framing, or encryption, and get a structured Scene of what is on the air and how it behaves.</p></li><li class="post-card"> <h2 class="post-card__title">RF Scope, Part 2: From IQ to Bursts — The Segmentation Pre-Pass</h2> <p class="post-card__meta"> Tutorials </p><p class="post-card__desc">rfscope’s segmentation pre-pass turns a wideband IQ span into bursts — discovering carriers with a wideband FFT, estimating a robust noise floor, downconverting each carrier to a narrow baseband, and slicing onset→offset bursts with per-burst spectral metrics and a blind modulation class.</p></li><li class="post-card"> <h2 class="post-card__title">RF Scope, Part 3: Protocol Hierarchy — What’s on the Air</h2> <p class="post-card__meta"> Tutorials </p><p class="post-card__desc">rfscope’s hierarchy analyzer is the RF analog of Wireshark’s Protocol Hierarchy — it groups bursts by modulation class, then occupied-bandwidth bucket, then names the protocol of the longest digital burst with siglab, attaching burst counts, airtime, spectrum share, and symbol volume to every node.</p></li><li class="post-card"> <h2 class="post-card__title">RF Scope, Part 4: The I/O Graph — Per-Channel Activity Over Time</h2> <p class="post-card__meta"> Tutorials </p><p class="post-card__desc">rfscope’s timeline analyzer is the RF analog of Wireshark’s I/O Graphs — it groups bursts by frequency into channels and fills each with a 100-bin occupancy and power series plus duty cycle, occupancy percentage, burst rate, dominant class, and the sparkline the cockpit renders.</p></li><li class="post-card"> <h2 class="post-card__title">RF Scope, Part 5: Timing & Periodicity — Recovering the TDMA Frame</h2> <p class="post-card__meta"> Tutorials </p><p class="post-card__desc">rfscope’s timing analyzer builds burst-length and inter-arrival histograms per channel and recovers a TDMA or frame period by autocorrelating each channel’s occupancy series, keeping only peaks above a minimum confidence — the time-domain counterpart to cryptolab’s byte-period detection.</p></li><li class="post-card"> <h2 class="post-card__title">RF Scope, Part 6: Topology — Emitters, Frequency Hoppers & Conversations</h2> <p class="post-card__meta"> Tutorials </p><p class="post-card__desc">rfscope’s topology analyzer is the RF analog of Wireshark’s Conversations and Endpoints — it clusters bursts into emitters by RF fingerprint, collapses a frequency hopper’s scattered bursts into one logical source, links emitters into conversations, and defers to hunt’s authoritative map when a trunking control channel decodes.</p></li><li class="post-card"> <h2 class="post-card__title">RF Scope, Part 7: Entropy & Encryption Triage — The Crypto Lab Bridge</h2> <p class="post-card__meta"> Tutorials </p><p class="post-card__desc">rfscope’s entropy analyzer triages unidentified digital emitters — blind-demodulating a representative payload, running the cryptolab randomness battery and classify-auto measurements, and returning a verdict from plaintext to strong-encrypted with a recommended cryptolab command, plus a -frames-out file that hands the bytes to Crypto Lab.</p></li><li class="post-card"> <h2 class="post-card__title">RF Scope, Part 8: Expert Info — Anomalies & What They Mean</h2> <p class="post-card__meta"> Tutorials </p><p class="post-card__desc">rfscope’s expert analyzer is the RF analog of Wireshark’s Expert Information — rule-based anomaly flags at note, warn, and alert severity for frequency hoppers, intermittent emitters, abnormally wide or narrow carriers, noise-like spectra, and the encrypted or obfuscated findings the entropy triage produced.</p></li></ol><p class="blog-feed-link"> See all tutorials or subscribe via RSS. </p>