RF_SENTINEL

rf_sentinel / guides / imsi-catcher-detector

Stingray / IMSI catcher signs

A cell-site simulator pretends to be a tower so phones attach to it, often forcing them down to 2G where encryption is weak or absent. Without root a phone can't read the signalling, but the cell data Android does expose still shows some of the tell-tale signs.

What Android exposes without root

TelephonyManager.getAllCellInfo() returns the serving and neighbour cells: radio technology (GSM / WCDMA / LTE / NR), MCC-MNC, cell ID, area code (LAC / TAC), and signal. It does not expose ciphering, identity requests or other layer-3 messages; that needs the modem's diagnostic interface (root, or dedicated hardware like Rayhunter).

Signs RF Sentinel checks every 15 s

SignScore
Serving cell on a test / reserved MCC (001, 002, 999)85
Sudden switch from 4G/5G to 2G while strong LTE (≥ −105 dBm) is still visible70
Sudden 4G/5G → 2G without strong LTE; or downgraded to 2G with strong LTE visible50
Network country code differs from the SIM's while not roaming55
Reserved identity: area code 0, 0xFFFE or 0xFFFF, or cell ID 045
Known cell number reappearing in a different area (cloned identity)50
Location / tracking area changed while GPS shows you still for 2+ minutes40
Switched to a cell with no neighbours where several were visible35
Several signs at oncemax + 15, cap 90

Cutting false alarms

Actual protection

  1. Settings → Network → SIM → turn off Allow 2G (Android 12+, if your carrier allows it).
  2. Android 15+: Cellular security → Network notifications warns when a network requests your SIM identity in clear or disables encryption. RF Sentinel's Settings links straight there.
  3. For signalling-level detection, run EFF's Rayhunter on a supported hotspot.

Questions

Is a rooted phone better for IMSI catcher detection?

Yes, with a Qualcomm or similar modem that exposes diagnostic logs, a rooted phone (or Rayhunter) can see identity requests and cipher mode. RF Sentinel stays root-free and limits itself to what public APIs show.

Does 5G protect against IMSI catchers?

5G standalone encrypts the permanent identity (SUCI), but most networks still run non-standalone 5G anchored on LTE, and downgrade attacks to 2G/3G remain the main vector. Disabling 2G closes the easiest one.

Join the DiscordHelp, ideas, new signatures, field captures and ESP32 builds. CIS-C0/RFSentinel on GitHubSource code, releases, issues. A star helps others find it.