Sn0ren Tests the HackRF Pro Portapack H4M Pro

Over on YouTube, RF enthusiast sn0ren has posted a video reviewing the new 'HackRF Pro Portapack H4M Pro'. The HackRF Pro is the latest official version of the popular HackRF software-defined radio. It started shipping to customers back in January 2026, and it includes improvements such as improved noise figure measurements, a USB-C port, increased frequency limits, a TCXO, and an improved, flatter frequency response.

The Portapack H4M is currently the most recommended portapack product for the HackRF. A Portapack is a separate PCB board that piggybacks on a HackRF board and turns the HackRF into a portable device that can receive and transmit various signals in the field.

In the video, sn0ren starts by showing a performance comparison between the HackRF and HackRF Pro, noting increased signal strength with the HackRF Pro. The Portapack H4M Pro appears to mostly be a change in order to fit the new HackRF Pro PCB layout, but there are some minor improvements that sn0ren finds in the video, such as better buttons, a slightly larger case, a removable battery lid, metal screws, and a lanyard hole. 

The Biggest HackRF Upgrade in Over a Decade

Building a Homemade Weather Radar with a HackRF or PlutoSDR and Salvaged Automatic RV Dish

After nearly being hit by a tornado that NEXRAD didn't see coming, Koakno decided to build his own DIY self-contained mobile weather radar built from a $5 salvaged RV satellite dome, a HackRF or PlutoSDR, and open-source software. 

Koakno notes that NEXRAD (the US weather radar system) data is typically 4-6 minutes old, and from a radar station that is often 100+ miles away, resulting in warnings coming in too late or not being detected at all. Only professional local mobile Doppler radar trucks have the capability of detecting local tornadoes rapidly enough to take action. Koakno set out to recreate this capability on a budget.

His antenna consists of a salvaged Winegard Carryout Anser GM-5000 automatic satellite dome built for RV motor homes. The dish carries an LNB that radiates an 850 MHz signal at 10.4 GHz, which is a perfect wavelength for weather radar. The SDR hardware can either be a HackRF or PlutoSDR. As the HackRF is only half-duplex, it uses pulsed timing, whereas the full-duplex PlutoSDR uses a continuous FMCW chirp. Open-source Python software processes the results, producing a live radar display showing color-scaled reflectivity.

Importantly, Koakno addresses the licensing concerns around this project. He notes there are clauses in the amateur radio FCC legislation that support the use of automatically controlled beacons for the observation of propagation, and experimental activities in the 3cm 10.0 - 10.5 GHz amateur radio band, but he is not an attorney, so this activity may still exist in a grey area.

The screenshot below was generated via the simulation the software provides for testing the UI.

A Demo of the Weather Radar Display
A Demo of the Weather Radar Display

Overhead Sky: A Mac App That Names Local Aircraft in your Menu Bar

Thank you to Chris Miller for submitting news about the release of his (paid) Mac app called Overhead Sky. This app sits in the MacOS menu bar, and names aircraft as they pass overhead, by making use of the adsb.lol ADS-B data aggregator.

The app costs $24.99 one off, or $3.99 monthly, however Chris writes that people who feed adsb.lol with an RTL-SDR or other SDR get the app discounted at $9.99. Chris writes that detecting people feeding to adsb.lol was a challenge, and shares his methods below:

I started on a commercial flight-data API and found it bills per aircraft returned rather than per call, which means one person leaving the app running over a busy sky costs more in a month than the app costs in a year. So I went to the community feeds and read the licences properly, and most said no. airplanes.live is non-commercial. ADS-B Exchange's affordable tier is a non-commercial community tier, and the site is Jetnet-owned now. adsb.lol is ODbL, which permits commercial use with attribution. So that is what it runs on, credited in the app, on the privacy page, and in the App Store description.

Two things follow from being a paid product living on a volunteer commons, both written down before it went on sale. Ten percent of profit goes back to the ADS-B open-data community, totalled once a year and published so the promise stays checkable. And anyone who feeds pays $9.99 instead of the full sticker.

The verification is the part I think fits your readership best. adsb.lol has no login, so the app calls GET /0/me, which reports the caller's own receiver based on the source IP of the request. If your Mac shares a public IP with your receiver, your beast or mlat client shows up and you are verified with no input at all. That call has to run from the user's machine rather than my server, because through a proxy it would judge my IP and match nobody.

The same reasoning sets the data path. Positions go from the Mac straight to adsb.lol, coarsened to about a one kilometre square first, because adsb.lol rate limits per IP and routing every user through one Cloudflare egress would have earned the block it deserved. Only route lookups pass through my server, carrying a callsign already on the user's screen and no location, unlogged.

So that leaves two honest gaps, since they belong in any piece about this. The app reads the aggregated network rather than a local dump1090 or tar1090 feed, so it is API-backed rather than receiver-backed today. And I do not run a receiver myself yet (though I hope to eventually).

Overhead Sky
Overhead Sky

FrameRF: An SDR-Based Technical Surveillance Counter-Measure Analysis Platform

Thank you to Stefano Cangiano, an Italian TSCM (Technical Surveillance Counter-Measures) specialist, for writing in and sharing with us about the release of his FrameRF product. Stefano writes:

After more than ten years of operational field experience, I developed FrameRF, a professional SDR-based TSCM analysis platform designed to help operators rapidly identify, classify and prioritize RF signals in complex environments.

Rather than replacing existing SDR software, FrameRF focuses on operational analysis by correlating multiple wireless technologies (Wi-Fi, Bluetooth, BLE, GSM, LTE and others) into a single workflow that supports real-world investigations.

FrameRF has been developed from real operational TSCM field experience, with the goal of reducing RF analysis time and helping operators make faster and more informed decisions during technical inspections.

To summarize, FrameRF appears to be a portable deployable kit, consisting of a laptop, SDR hardware, antennas, and custom software in a rugged briefcase. The product is intended to be used by TSCM specialists for applications like sweeping for RF bugs, corporate security audits, and finding anomalous signals.

It can do things like detect LTE voice activity, automatically classify signals, alert the user based on patterns, detect a DECT phone call, recognize Apple AirTags, estimate if different random Bluetooth MAC addresses belong to the same physical device, analyze the WiFi environment, reconstruct device relationships, and detect hidden WiFi networks and potential spoofing.

If you are interested, Stefano has provided a PDF brochure explaining the product further.

FrameRF Live Monitor
FrameRF Live Monitor
FrameRF – Professional RF Behavioral Analysis Platform | TSCM Video Demonstration

9GRadio: An Android RTL-SDR App for Spectrum Monitoring and Decoding Analog/HAM/Aviation/Marine Radio Traffic

Thank you to Richard (9G5AR) for writing in and sharing with us the release of his open source Android app called 9GRadio. Richard writes that 9GRadio is an app designed for spectrum monitoring/analysis and the decoding of analog/ham/aviation and marine radio traffic.

In terms of demodulation it supports AM, FM, NFM, WFM, WFM Stereo, USB, LSB, CW, CWR, DSB and RAW IQ modes.

For digital decoding, it supports APRS, digital voice modes such as DMR, D-STAR, YSF, dPMR, NXDN, and aircraft, marine, and datalink modes such as ADS-B, AIS, ACARS, RDS, and multilateration.

Richard also notes that 9GRadio includes a full multilateration stack for locating transmitters, which works with 2+ networked 9GRadio receivers. Interestingly, the multilateration stack is noted to be protocol-agnostic, meaning it should work not only with ADS-B, but also with any mode that provides a digital identity for a transmission, such as AIS, ACARS, RDS, and digital voice modes.

The app is not available on the Google Play Store, but the APK is available for sideloading on the project's GitHub Releases page, along with the open source code.

9GRadio GIF of various screens
9GRadio GIF of various screens

Scanner Command: Mapping Incidents from Live Radio Calls and ADS-B to Airband Voice with AI

Recently, we posted about DeepSDR, which is a program that automatically transcribes voice data from public safety radio communications and uses an LLM to categorize and plot incidents on a map as they happen.

In that post, we noted that we expect to see more projects like this soon, and sure enough, another program called "Scanner Command" with a similar angle has been submitted to the blog by author Benjamin Blood. Like DeepSDR the software listens to public safety and then uses voice transcription and an LLM to automatically understand, categorize and map incidents on the map. One additional feature that Scanner Command has is a fun tool that correlates ADS-B data with airband voice. Benjamin explains it best:

Scanner Command turns a radio scanner into a live AI incident map. A Uniden SDS200 covers the trunked digital public safety side (the LA area's P25 Phase II system, with ProScan driving the scanner and handing off every recording), and two $45 RTL-SDR dongles handle the rest, one decoding ADS-B with readsb, one capturing VHF airband transmission by transmission. Everything gets transcribed locally with Whisper, an AI extraction pass works out what happened and where, and about 30 seconds after a call ends it's a color-coded pin on the map with the audio one click away. Location matching is honest on purpose: an exact intersection match gets a solid pin, an area-only match gets a dotted one, and it tells you which.

Here's the design idea underneath it, and what I think separates it from the other transcribe-and-map projects out there: this is built for tactical situational awareness when the grid's down. The system does its learning while it's online, building its own gazetteer of local streets and places, learning unit callsigns and talkgroup names, priming the transcriber's vocabulary from real local traffic, precisely so it's more capable when it's cut off. Map tiles, geocoding, and hazard data are all cached locally with that scenario in mind.

The picture in my head has always been: grid's down, the box is running on backup power serving wifi, and my neighbors connect with their phones and everyone can see what's happening around us, instead of one guy hunched over a scanner relaying it. It's not shelf gear you dust off when something happens; the whole point is that running it every day is what trains it for the day you need it. Transcription is already fully local, the LLM extraction step currently uses a hosted model when online (it runs me about a dollar a day at 24/7), and the next build phase is a GPU box that closes that last gap with a local model.

The feature people are having the most fun with is the airband/ADS-B correlation. The system pulls spoken callsigns out of airband transcripts and matches them to ADS-B tracks by time and geometry, with match windows scaled by altitude and speed, plus hex-to-tail-number derivation. Click a plane on the map and hear what its pilot actually said, with a confidence badge when the match came from a partial readback. Beyond that: an ATAK feed (CoT/KML/GeoJSON), twice-daily AI briefs, a BOLO board, incident threading with a unit activity board, and helicopter orbit detection.

ADS-B aircraft position data automatically linked to airband voice transcripts
ADS-B aircraft position data automatically linked to airband voice transcripts

Benjamin adds that a public demo is available at https://demo.scannercommand.com. But he notes that "the public demo is a replay of two real days of traffic from my setup".

The software has not yet been released, and it does not appear to be free or open-source. There is a signup waitlist available on the scannercommand.com website.

This is an exciting time with AI not only helping to rapidly develop new software, but now being used to summarize and condense the vast amount of information about the state of the surrounding world available in the RF spectrum. 

Scammer Command example mapped incident report
Scammer Command example mapped incident report
I Turned My Police Scanner Into a Live AI Incident Map (24/7)

Testing Airspy’s New WebSpy Web SDR Interface with an RTL-SDR

A couple of weeks ago we posted about "WebSpy", a new web client for Airspy software defined radios. Developer @lambdaprog, (aka Youssef Touil) has kindly provided us with an early beta of the server to test.

WebSpy is built into SpyServer, and SpyServer is an existing program that streams data from Airspy and RTL-SDR devices directly to SDR#. This new beta SpyServer now incorporates WebSpy into it, so once SpyServer is running on the server, all you need to do is run the binary and browse to https://SERVER_IP_ADDR:5555 in a browser, and the WebSpy interface will show.

As SpyServer supports RTL-SDR dongles, WebSpy also works as intended with RTL-SDRs. So in our test, we used a remote RTL-SDR connected to a networked Pi 5 and started up WebSpy. As the default includes self-signed certificates, you will get an unsecured warning from your browser, but this is safe to ignore. If you were to share your WebSpy publicly, you would want to generate your own certificates. Youssef recommended using acme.sh for that.

Clicking the power icon in the web interface starts the SDR connection, and then you can tune to frequencies using the top tuning interface like you would with SDR#. Audio is extremely clear, as if you were running the SDR directly. As Youssef explained in our earlier post, WebSpy uses some proprietary IQ compressors that preserve spurious-free dynamic range, and it does all the IQ decoding directly in the browser to avoid audio codec compression artifacts.

With an Airspy and RTL-SDR receiving a narrowband 12.5 kHz voice channel, we got about 25 kb/s network usage. Reducing the channel size to 2.4 kHz LSB reduces the usage to around 13 kB/s. A wideband FM signal at 200 kHz uses about 240 kB/s. Of course, expanding the channel size to the max 2.4 MHz of the RTL-SDR results in a much higher network bandwidth of 1.2 MB/s, but there are not many situations that would require that.

We tested in Chrome, Edge, and Firefox, and all browsers worked fine. In terms of CPU usage, it barely touched 10% on any core with a single user. Youssef mentioned that a single Pi 5 should be able to serve up to 40 simultaneous sessions for WFM users, and hundreds for SSB/AM users (and we suspect NFM too).

WebSpy CPU Usage
WebSpy CPU Usage

The implementation of WebSpy is still pretty bare in this beta. Most of the features present in SDR# are not there, but Youssef mentioned that these are being worked on, and plugin support may even be added in the future. You also can't tune individual frequency digits with the mouse wheel like you can in SDR#, and there are no squelch or bias-tee controls.  But as this is still in development, we expect more features and tweaks in the future. 

WebSpy Running an RTL-SDR
WebSpy Running an RTL-SDR
WebSpy Running an Airspy
WebSpy Running an Airspy

Building a $50 BOM Software Defined Radio with a HT9201 20 MHz ADC and an FX2LP USB Controller Clone

Over on Hackaday, we've seen that Anders Nielsen gave a talk at Hackaday Europe 2026 about his effort to build a software-defined radio with 20 MHz of bandwidth on a bill of materials of under US$50. We've posted about his work before, first with the PhaseLoom quadrature sampling front end, and later with PhaseLatch, which combined a 20 MSPS ADC with a 50-year-old MOS 6502 CPU. In this latest work, the 6502 is still part of the stack, but for the wideband work the samples bypass it entirely.

The RF side is a discrete Tayloe detector built around a TLV3253 analog switch, sampling the signal four times per local oscillator cycle to give downconversion and quadrature in one step. A Si5351 provides two clocks offset by 90 degrees from the same PLL, an ADA4891 op amp buffers into a HT9201 dual 20 MHz 10-bit ADC, and an FX2LP clone streams the parallel data over USB 2.0, avoiding the cost and tool chain of an FPGA. USB bandwidth forces a choice between 20 MHz at 8 bits or 10 MHz at 10 bits, and he notes that PCB design was critical in getting a flat frequency response.

Anders ran a live demo streaming 19.375 MHz into GQRX and showing the whole FM band at once, with tuning handled by firmware running on the FX2LP's own 8051 core. Still to come are bias and offset calibration to suppress the mirror images, better filtering and layout, and a front-end mixer to get past the roughly 100 MHz ceiling of the Si5351. He is also looking for help with the SoapySDR driver, so take a look at his GitHub if you have the skills.

Hackaday Europe 2026: Anders Nielsen - High Performance SDR on the Cheap

Below, we're also embedding the video from his YouTube channel, which covers the same project.

Cheapest 20MHz SDR You Can Build