wardriving

Sep 2026 Added Bingfu 9dbi antenna teardown photos. Thoughts on Acceltex dome antenna.

Aug 2026 Added WDG, Wardrive Go and Biscuit shop sections (more to flesh out in those).

This wardriving blog (and every blog written by thebaldgeek on this site) is AI free.
tbg is NOT a writer and DOES NOT use AI to fix/enhance/repair/create or any other tools to write his dumpster fire way of sharing raw info.

Topic menu
Why wardrive
Links and resources
tbg vs Kismet GPS
Android Phones
Phone Placement
WigleFin v1.0
Wigle App Settings
Scanning all the Wi-Fi
wifydra
WiGLE app scan speed setting
CPU Throttling
BLE Scanning impacts Wi-Fi?
Programming the Signal Sleuth
Building the Signal Sleuth
Shorten your coax cables
SMA torque wrench
SMA and Reverse SMA
tbg madness mods to the Signal Sleuth (WDUK)
It really matters where you put the LNA
Yagi vs panel (high gain Wifydra build)
Planning and driving a wardrive
Radiation driving
Antenna gain - good thing or bad?
Wardrive Go
Watch Dogs Go War
Biscuit Shop
Bingfu 9dBi dual-band magmount

thebaldgeek finds wardriving very relaxing and a great way to explore the world. Be it just a few blocks around where you live, or as you travel the planet. Seeing the ebb and flow of the density of WIFI access points gives him a bigger world view and a touch of humility that he appreciates.

Of course, there is also a baldgeek aspect to the hunt, the RF side of building a rig to capture as many SSIDs as you drive down any given length of road. tbg is fascinated by the idea that it's unknowable. No matter how much you tweak your setup, did you get them all? Is there some other change you can make to accurately catch any more SSID broadcast beacons?

  

Lastly, tbg is interested in contributing to large public data sets. Adding his travels to the larger community's pool scratches a part of his brain that needs it.

Over-simplifying, wardriving is about picking up as many Wi-Fi SSID's as possible. Second to that, but very importantly, is having them accurately GPS tagged, and striking the balance between range (raw numbers) and accuracy.   

In other words, if you run a high gain directional antenna, sure, you might get a few more SSID's, but they will be poorly tagged with GPS data and thus dilute the value of the data somewhat.

 

It’s crucial to make clear a common misconception. wardriving these days does NOT involve CONNECTING to the SSID. It is just passively listening and logging the SSID. That’s it.
NO CONNECTION IS EVER MADE.

wardriving is not about warchalking or trying to 'hack' any Wi-Fi, or get anything for free.
The only hacking that is going on is the fun of tweaking your rigs hardware to capture as many beacons as fast as possible.

 

thebaldgeek joined Wigle around Dec 2015. Before then, he was actively wardriving for about 5 years with many different setups - Orinoco cards in an HP Jornada, for example. He's been testing various setups and antennas, using the Wi-Fi SSIDs' broadcasts as signal sources, as the RF aspect is a strong interest.   

Aug 2024 he got the bug again and started pushing for the 1 million mark (Aug 2025, hit the one million Wi-Fi discovered by thebaldgeek. Early 2026 the two million Wi-Fi was logged - interesting to note the second million was harvested much quicker than the first million).

 


This blog is a messy brain dump of notes and current setups tbg is (or has) running.    

 

Why wardrive?    

There are a lot of different goals and reasons to wardrive.   

For tbg, while he did some wardriving in Australian, when he moved to Southern California (high population density and thus high geek density means that a lot of SoCal has already been wardriven by different methods) means that the big wifi nuggets have been mined and picked over to a good extent, so his goal is to build a rig/setup that will extract the flecks of wifi gold that others have missed from the same roads. This does NOT mean high-gain antennas, but rather ensuring that each and _every_ wifi SSID is geotagged as accurately as possible.

This means using sensible antenna gain (5db is the recommended maximum), lower ground speed, higher speed Wi-Fi channel scanning and very good GPS signal / many GPS sats fixing each SSID that is heard.   

SoCal town of Temecula before and after being wardriven by thebaldgeek

Your goals might be different. Like all hobbies, there are some that are only interested in climbing, or ranking in the top 'nth of the WiGLE leader board. For them, its all about new points. Nothing more.
Regardless, take a pause to think about why you are wardriving, what your goals are, and how to reach them the most efficient and interesting way.
And yes, to some extent, it will depend on where you live, if it is in a location that has been heavily wardriven already, or if its in a location that has hardly been touched.
Lastly, if you've not started wardriving yet, just know that its a marathon, not a sprint. The more you can make it a simple part of your every-day life, the more long term fun it will be.

In June 2025, moving to North Idaho opened up a whole new area to wardrive. thebaldgeek found it a great way to get to know the new hometown location with the goal of diving every road possible. Pointing back to the opening paragraph, tbg found it a very helpful de-stressing / escape from the move. Driving while listening to his beloved pure trance is very therapeutic, and being able to add wardrving to the ‘reason’ was a key part of escaping past chains and exploring new worlds.

Jump to top

------------------------------------------------------

Wardriving sites and resource links

Reddit wardrivers sub is pretty solid: https://www.reddit.com/r/wardrivers/ (Do note that like most places there are 1-2 arrogant and demeaning folks there). 
Wigle forums are very quiet, but worth browsing: https://wigle.net/phpbb/index.php
Some Discord options are out there, drop a comment to this blog if you find some of value. tbg has heard good things about RF Hackers Sanctuary https://discord.com/invite/JjPQhKy 
(tbg has found that Discord is generally an unmoderated toxic mess. It should have stopped at being a gaming chat platform).
This page is required reading: https://www.kismetwireless.net/posts/2022-07-71-wardriving/
Hard core Kismet build: https://www.busysignal.io/wardriveferris3/ Franky, all of BusySignal's blog is worth a read: https://www.busysignal.io/
Window coax passthrough 3D print from MrBillhttps://www.thingiverse.com/thing:5678750
More wardriving 3D print ideas: https://www.thingiverse.com/search?q=%22wardriving%22&page=1
Why add Bluetooth to wardriving: https://deflock.me
A few old broken links, but good history and worth a review: https://www.wardriving.com/
Solid Wigle overview and some wardriving basics: https://www.youtube.com/watch?v=1ibg0tgVugY
Community photo dump of builds: https://github.com/rfhs/rfhs-wiki/wiki/Community-Builds
WiGLEfin STL files here: https://thebaldgeek.github.io/wardrive.html
Bullet point wardriving cold hard facts: https://ringmast4r.substack.com/p/the-wonderful-world-of-wardriving
Watch Dogs Go. A different take on wardriving. You get points for new SSIDs, but also there is value in catching the same ones over and over: https://wdgwars.pl
From the WDG folks, this is a fantastic must read on-ramp to all things wardrving: WDGWARS ON-RAMP
biscuit pro, ultra, crumbs and DIY nodes: https://biscuitshop.us/

 
 
--------------------------------------------------------------

 

Short tbg rant about Kismet

A lot of hard core wardrivers run kismet on a laptop or SBC and many (many) wifi adaptors.
This makes perfect sense and tbg tried really really hard to build such a rig.
One very horrible memorable week... Well, 5 FULL 8 hour days were spent trying to get Kismet to see a GPS, all to null result.
Nightly builds, distro images, build from source, 'apt-get install' were all tried to simply get Kismet to see any of the 4 tested GPS units.
GPSd worked fine in all cases, other Linux apps worked just fine in all cases.

Hundreds of purple links proved that tbg was not the only one to have the issue....
Regardless, Kismet is now dead to thebaldgeek. Not going back there again any time soon. (Its been a year since that week, his mind has not yet been changed even a tiny bit).

Update. Aug 2026. tbg has heard that a LOT of work has been done to the Kismet code base to improve GPSD functionality.

As such, this is why non-kismet builds are the focus of tbg in this blog.
In reflection, tbg is happy to leave the Kismet rig builds in the rearview as they are well documented and discussed. The light weight builds and methods are attractive to starting out and can yield surprising results.
Thus, most of this blog is a LOT more approachable for all levels of skill and interest.

tl;dr Read this blog with the notion of it being middle ground in wardriving rigs. Simple ESP32 builds are talked about but it has a more Android centric focus being the core.

Jump to top

-------------------------------------------------------------

Android Phones running Wigle.   

By FAR and AWAY, the quickest way to get started in wardriving is simply use an Android phone.

Never throw out old Android phones. (But there are age limits.)   

Old phones that are, say, more than 6-8+ years old often struggle to have the right SSL certificates, and so they can’t connect to the wigle.net servers. On some, you can side-load the old version of the Wigle APK and get the app running, but generally it's a bit more hassle than it's worth.    

Safe to say that simply installing the Wigle app from the Google Play store and letting it run on your phone any time you are out and about is the easiest way to get going with wardriving.    

Do note that Google decided to throttle the wifi channel scanning speed to save a bit of battery power; it's up to you if you want to enable developer mode and disable that throttle or not. tbg turns it off on every Android he has and has not really noticed that much of a battery life hit, but just know that it's an option, and be aware of the downsides. Of course, if it hurts your battery life, turn the throttle back on, experimentation is the name of the wardriving game.
(Google can guide you on how to do this, in short, tap the build display in the settings 7 times and then go into developer and toggle the wifi throttle slider).     

And sorry iPhone folks. Apple does not like its users playing on the other side of its walled garden. Ask some friends, family, or co-workers if you can have / buy their old Android phones they have sitting in the top drawer going unused.

Phones that tbg has tested or currently uses as of Aug 2024:    

Note 9 - not great
Pixel 5 - Okish
Pixel 8 Pro - pretty good. Daily driver phone and in-car wigle map display
Samsung G23 - solid. tbg sons daily driver. Tested in-car only.
Samsung G20 - Beast. No, really, this phone is the best wardriving Android that tbg has found hands down.
Nexus 7 - External antenna mod. Great setup, on the large size, but the external antenna mod makes it worth running. (Died Aug 2024 - display issues).   

Aug 2025 tbg added:
Pixel 9 Pro XL - pretty good. Replaces the Pixel 8 as the in car daily driver
Note 20 Ultra - horrible. Returned back it to Amazon, it was so bad.
Wifydra - Interesting, mixed results (keep reading)
Signal Sleuth aka Wardriver UK - Interesting, mixed results (keep reading)

 


Aug 2024 tbg runs three phones on 98% of his wardrives, the P8P in the car showing the wigle map - it’s also scanning of course, P5 and G20 are the main scanners.   
 


The P8P on the left: 2170
Samsung S20 on the right: 3570
Same drive. The S20 really is a wardriving beast.   

tl;dr of thebaldgeek tested rigs. Best to worse.

  1. Samsung S20 FE - The gold standard (so far)
  2. Samsung S10
  3. Pixel 9
  4. Samsung G23
  5. Nexus 7 with external antenna mod
  6. Pixel 8
  7. Signal Sleuth / wardriver UK / Wifydra / ESP32 & BW16
  8. Pixel 5
  9. Samsung Note 20 Ultra
Untested, but thebaldgeek has heard amazing things about the OnePlus15, Samsung Galaxy S26Ultra and S24 (in that order)

 
--------------------------------------------------------------------------- 

Phone placement.    

Clearly, just having a phone in the car on a vent or suction cup mount is the safest and cleanest way to set things up. If you have one Android phone as your daily wardriver, then just running the Wigle app while going about your life is fantastic and good fun.   

Once you start running three or more phones, it gets a lot more fun and complicated keeping them charged and uploading after each run.    

For a time around November 2024 tbg ran tasker to turn WiGLE scanning on & off as he left and arrived on his home Wifi. Tasker is not a free app, so there is some expense and its also somewhat complicated to setup. tbg did not find a clear how-to and really should write up how to do this. This one here is about the best: https://www.designer2k2.at/en/mods/technik/214-automate-wigle-wardriving-with-tasker But in the end he found it too unreliable to be trustworthy.  From 2025 onwards, he's not using it. YMMV.

tbg heard about one guy who runs five phones on every wardrive. 1 daily driver up front with him on the driver's side, one at the front of the car on the passenger side, one on the rear driver's side window, one on the rear passenger side window, and 1 in the middle of the back window. Pretty solid if somewhat crazy setup. Not something tbg wanted to replicate...    


IF YOU READ NOTHING ELSE IN THIS BLOG... READ THIS SECTION!


One thing tbg learned the hard way with L-Band ACARS is that often window tint can block GHz signals. In the case of cars, this includes the ceramic and 3M window tint (very popular in SoCal), or any brand tint that blocks UV radiation (heat).  Tip. A lot of windscreens have a clear UV block tint.

Test tip: Put your hand near your windscreen or window near your Android location, think about how warm from radiated heat it feels. Wind down the window and feel the direct sun heat. If the direct sun is warmer, your car has UV (RF) blocking tint.

Given this first-hand experience from the placement of 1.7GHz satcom helix antennas, of course, he figured he should test it with his wardriving phone setup.   

3D printed 1.6Ghz helix. Don't point it out the window.

tbg figured the best place for a GHz RF antenna is outside the car, outside the RF shield, getting an extra few feet of height does not hurt either..

 thebaldgeek firmly believes this one change has given him a massive jump in the Wigle leaderboard rankings. Beyond just wardriving consistently, beyond driving new ground, just getting the phone outside of the Faraday cage that blocks about 50% of the signal!!!

Keep in mind the bulk of those numbers came from the Pixel 8 in the car and the Pixel 5 on the roof.
thg did not get the S20 till way late in those numbers. With the S20 on the roof, the numbers really kicked into high gear.
His point is, you can make any wardrive a lot more impactful by getting your backup device outside the cage.

Let's take a look at some numbers to back up that belief.

 The birth of the 'reference drive'.

The commute to work is a good baseline. Take the same route at the same time each day.
Make five runs and see what the average is with the phone on the typical dashboard / in-car vent mount.
Move the same phone outside and make the same baseline run 5 times and see what the difference is.

P5 in-car five run average Wi-Fi SSIDs: 2456
P5 roof five run average Wi-Fi SSIDs: 4971

Stunning. Almost double the Wi-Fi SSIDs by having the phone on the roof of the car!!!

Same drive, same time, five working-day average. About double the number of SSIDs were heard by the exact same phone just by mounting it on the roof of the car!!!

(As an aside, tbg thinks the 2018 Chevrolet Bolt is the best wardiving car — it’s quiet, cheap, has a good enough turning circle, and most of all, a one-pedal driving mode with steering wheel mounted re-gen paddle that can't be beat for wardriving. He can drive for hours in a typical suburb and not have to lift his foot for the brake even once!).

 


Magnets in the base of the blue box floor are holding it to the roof. Not the best, but for a 40mph max speed, 32mph average, 5 drive run, it proved the point.
Please don’t reproduce this setup! You will break/lose your phone!

thebaldgeek then got his CAD / 3D printing guy on the job, and this is what he has now…

Jump to top

-----------------------------------------------------------

WiGLEfin

 

The wiglefin

The lid pin pulls out, the lid slides up and off, and some foam edges the phone.
The WigleFin was sized to fit pretty much everything from the smallest to mega Samsung Note size.
It probably won't hold a folded flip phone or any of the new fold phones.
The foam case is up to you to make it custom for your phone.

Try not to fully wrap the phone, give it some air space to breath.

If its 100F outside, the phone can NEVER be cooler than 100F, even with vents etc. So don't fully wrap the phone, it will get much hotter than ambient.
 
 
Early prototype - too big and heavy

No effort was made to watertight the fin. It's a fair weather wardrive accessory.
(tbg has wrapped the fin seam with tape and risked it - don't be tbg).


150lb pulling force magnets, four of them, hold the wiglefin to the roof. Tested at 87mph on Los Angeles freeways:- Just moving with the flow officer.


Zero movement with the kitchen drawer non-slip coating on the bottom of the fin.

Be sure to put something between the metal magnets and your metal surface, you don't wanna scratch up your car roof. TIP: check the bottom of the WigleFin each time before you slap it on the roof, it can pick up bits of metal like staples all too easily.

  


tbg is in the process of printing another red and another white ‘wiglefin’, so will have color matching fins for the two cars he drives. (The wife wants them to match in color when she’s in the car <shrug>)   

 

DO NOT use this setup in North Dakota in winter, or Arizona/Texas in summer, you will kill both your phone and battery. This setup is for fair weather/temperature wardrives only. Keep it at 72F / 23C.  

You can find the STL files here: https://thebaldgeek.github.io/wardrive.html
150lb magnets that the WigleFin has been made to fit are from Amazon (20 bucks for 10)

If you use the STL files, or modify them (adding vents for example), please include a link to this blog or thebaldgeeks GitHub page as a way of saying thanks and for letting folks know the source.
Also please let him know in the comments what you ended up doing etc.

Aug 2026 WigleFin v2 is about done and v3 is already  cooking in CAD.

Jump to top

-----------------------------------------------------------------------------

WiGLE App Settings

The main Wigle website setting section is out of date and incomplete, so here is thebaldgeeks lame attempt to fill in the gaps and update the settings description.

 


1. Your username (if you have made an account).
2. Your password becomes the 'Auth User' once you log in.
3. If you don't want to track your points and stats, you can chose to upload anonymously.
4. If beeps and boops are your thing, tick the next few.
5. More beeps and boops.
6. This is a big deal. You really should have this checked or your phone will slowdown more and more as it gathers more and more networks and tries to display them all.
7. Not everyone lives in the USA.
8. If checked, it will use GPS and Google Location Services to help your phone know where it is.
9. WiGLE pops up notifications now and then, if you want to see them, leave this unchecked. tbg checks on his roof phones as he does not want them turning on their screen or showing any of this data.
10. Auto start WiGLE on boot. Depends on how you are using your phone for wardriving.
11. Auto exit WiGLE before the phone dies.
12. Australian or English <grin>
13. Dark theme uses less power.

 


14. tbg finds this clutters the map and makes navigation hard to use/see/read.
15. tbg find this clutters the map and make navigation hard to use/see/read.
16. SSID's found by everyone or just you. If you select just yours, you won't know if you are driving an area that has already been wardriven, but that might be useful at times.
17. Since the start of time, or since you joined WiGLE or since a few years back - old areas need to be re-driven, so chose the purple dot date for your needs.
18. The black worm on the map - your driven path on the current run.
19. You can log your path for use in other mapping programs.
20. Light or dark map. (Note, both are useless when driving. Light = white roads on a white background. Dark = dark purple dots on a dark background - but, hey, light grey roads. The app really really needs a UI/UX color overhaul).
21. Track up or north up. Personal navigation preference.
22. To scan BLE or not to scan BLE, that is the question.
23. How fast to scan all the Wi-Fi channels while you are stopped? (Slower saves battery)
24. Has fast to try and scan all channels while you are moving very slowly?
25. The most important setting in the app after #6. See here for this critical setting.
26. tbg is not sure.
27. How the main page button acts.
28. tbg is not sure. WiGLE said "use the same GPS update interval as the scan interval".
29. tbg is not sure.
30. tbg is not sure.
31. GPS can get some jitter and noise on it, mostly in cities etc, the app clearly has the option to try and smooth them out.
32. Probably only useful in really deep city or areas with thick trees.
33. tbg is mostly deaf. Never used or explored this page option. Feel free to let him know what you found.

Jump to top

 -----------------------------------------------------------------------------

Wardrive Go

Seems like this Android only app has been in alpha development mode for some time.
tbg was not aware of it till it was released and started to show up in a few wardriving feeds / hashtags for him in mid Aug 2026

You can download the released version of the Android only app from the Google Play Store Wardrive Go Play Store Link (If you have wisely de-Googled, there are options, but tbg cant help - yet).


UPDATE: This blog aged like milk left out of the fridge.... The dev `RocketGod` as been pushing 20 to 30 updates a day and in a week, that has made a lot of this blog and screenshots age badly.
This section was drafted at the end of Aug 2026, by the first week of Sept, a TON has changed.

tbg is going to leave it up, but do keep in mind things are very fluid in the Wardrive Go app.


Lets first take a look at how tbg tested this app....

Sadly, there is no way to reset the count other than doing an upload. After every upload, the 'new' counter in the app is reset back to zero. The only other way to reset the count is to uninstall and reinstall the app - this quickly becomes tedious after every test drive, so tbg made note of the count at the end of the drive and subtracted it from each reference drive. (He did not see the point of doing an upload to Wigle after every test drive - eg days after turning off BLE and Cell, tbg still has counts stuck on the main page from when he was testing that option). 
Note; this is not a big deal - only folks that want to quantify their wardrive rigs need a way of testing them via the app they are using - it just bears mentioning as the Wigle app has a really sweet live 'Dashboard' page that shows the new and seen really clearly and its easy to delete the Wigle local DB and thus reset the 'new' any time.

Sept '26. There is a whole new section accessed from the main screen 'ANALYTICS' button.
tbg has taken a mid level dive and not really found anything helpful in as far as quantifying you wardriving rig changes (ie, drive by drive, or change by change).
The data show is at a glance, amazing, comprohensive and for sure, unique, but lacks any actual meat for answering antenna gain, LNA and signal strength questions.
That said, the 'delta' information on drive-by-drive is the one value that comes close, but the date range seems broken?

Sept '26. The main screen now has two counters, 'Wigle' and 'WDG'.
Both are sort of named wrong in tbg's mind.

Wigle is what THIS PHONE has seen before. So, we now have an internal 'lifetime' database of all SSIDs this phone has seen and so as you re-drive an area THIS PHONE has seen before, this count will go up less. It has NOTHING to do with what Wigle has on its site.

WDG is raw live SSIDs (APs). No matter if this phone running this app has seen that SSID 1000's of times before, it will always show up in this count every time.


Reminder, a reference drive is the exact same drive, done around the same time of day and you are NOT looking for 'new', but rather just the raw number of 'seen'.

Wardrive Go does not display the SSID count information in the same way the Wigle app does, so that takes a moment to get your head around.



There are also very different settings and options for this app, so it's taken some time and many many miles to even get some baseline data.

tl;dr Phone only (Samsung S20) - Wardrive Go sees around 10% to 15% less SSID's than the Wigle App.

Where this app really kicks into gear is when you pair it with an OTG (On The Go) cable and an external USB network adaptor.



Let's take a sec to talk about OTG cables....
tbg has had mixed results over the years of using OTG cables (He uses them a lot when pairing an SDR to an Android).
There are two variables, the OTG cable, and the phone USB port. 
Granted, since phones have largely moved to USB-C ports, OTG functionality and predictability  has improved greatly, so the issues really only arise with older 'droids with USB micro ports.
tbg has tested Wardrive Go on a Samsung S20, S25 and Pixel 9 Pro. (All are USB-C)

tbg likes this flying cable OTG from Amazon: https://www.amazon.com/dp/B0CQKZRDHF
(Note it comes in silver or black)
For a more compact solution into the base of the phone ie, something you might shove in your pocket or backpack and thus put less bending pressure on your phone USB socket, tbg likes this one: <tbg to update link>
Do note, both are USB-C

Supported USB network adaptors: (Taken from the 'About page in the app).

2.4Ghz
Atheros AR9271
Ath9k_hts
Alfa AWS036NHA
TP-Link TL-WN722N v1

Dual-Band
MediaTek MT7612U
Alfa AWUS036ACM
Panda PAU0D AC1200
Realtek RTL8821AU
Alfa AWUS036ACS

(The app also supports ESP32 scanners via USB to serial adaptors, thebaldgeek has no idea about any of this option and has not tested in any way shape or form  (He's generally not a fan of ESP devices for wardriving due to their slow scan rate and biggly deafness)).

If you want to buy something that 'just works' you should be hyper vigilant about using the EXACT USB adapter, a single minor alphanumeric change or omission in the part number may result in the app not detecting it.
For example, on Amazon, TP-Link TL-WN722N v1 is listed, but a v2 is supplied when ordered in Aug 2026.
tbg asked on the discord about driver support for something folks could buy and it did not go well. (Note, it was NOT the developer with the sharp words).

It's been reported that the Alfa AWUS036NH works ok (Note the missing A off the end of what is listed as supported), but the Alfa AWUS036H does NOT work (it's found, but the driver does not load correctly).


tbg wants to be clear, this is NOT the 'fault' of the dev `RocketGod`, drivers are tricky at the best of times - non-root USB drivers on Android must be just bonkers hard.

The Alfa AWUS036ACS is listed as supported under the dual band, but tbg found that only the 2.4Ghz band is used on this adaptor. Your milage may vary.

ALFA Network AWUS036ACM has been found to be by far the best of all tbg tested adaptors and is a current line item from Amazon USA.

Internals of the AWUS036ACM

So just keep your wits high and expectations low and try every USB adaptor in your junk pile and see if you get lucky.

Drop a comment on this blog if you test any other USB network adaptors and lets know either what works and what does not work - please double check the FULL part number in your comment - every single identifier matters greatly it seems.

Ok, you have your OTG cable and your functional USB network adaptor. Now what?

What's in the box?



Just before we jump into the app settings, a word about more... If one adaptor is good, then two is better right? No. Not yet. The Android USB port can really only support 1 network card bandwidth. A few folks have tried a multi-port USB hub and running more than one network adaptor, but the dev confirmed in his tests, there is just too much bus contention. There are phones coming with USB3, the dev has 'more is good' in mind, but we are not there yet. 
For now, just dig up another Android and run as many network adaptors as you have phones and USB cables.

tbg is just going to talk about the settings here, the app is clearly a work in progress and has many other non-wardriving features that tbg is not interested in exploring. (For example, flock and meta camera alerts, apple tag tracking etc.)

Click the gear icon on the top right to dig in.
Appearance. Set the color and fonts as you like.
Scanning.
Wi-Fi priority. (ON) tbg turns this on as he does not care about BLE - keep reading here as there is another 'more powerful' wifi setting that would seem to override this one.

Wi-Fi Only. (ON) tbg's fav switch. Just go hard core wardriving. Forget all about BLE and cell. Flip this switch ON for wardrive mode!

Keep scanning in background.(ON) This works well. If you are using your main phone, you probably want this on but do note that simply swiping the app closed will not close the app if this setting is on (this might draw down your battery faster than you might expect). You will see the background scanning in the status bar up top. You must use the menu item 'power off' to really stop the app.

External: Capture clients.(OFF) This switch will depend on what you are doing with the app - like all the other switches - in tbg's case, it's pure wardrive, so this switch is off since Wigle does not count client's and so he does not want to spend a single CPU cycle looking for them.

External: camp busy channels. (ON) tbg loves this feature and it works as expected, higher scan speed, more SSIDs found. Note that it uses your phone's wifi, so don't leave the Wifi off on the droid and try to keep the phone mounted up in the vehicle, not sitting flat on the floor on the passenger side under a bunch of laptops and other hardware <grin>

GNSS full tracking.(OFF) you will know if you need this. (default off for battery drain reasons)

Notifications: tbg turns all these off, he's not interested in all the bells and whistles while driving.

Behavior & display: Keep screen on is the main one here that tbg flips back and forth. tbg also switches off the animations. 

Keys & privacy. Add your Wigle (and WDG) keys here.

When an external adaptor is used there is a buried screen in the main data section that wardrivers will want to test / play around with.

You can force the adaptor to clamp on one channel or hop as needed (directed by the phone if that mode is enabled). Also in that section is the ability to slightly adjust the dwell time for each scan.
Very welcome, very powerful.



tbg is still quantifying what 'Dwell per channel' gives the best numbers. You might think the quickest, and you may be right, but tbg has seen some interesting variation between 125ms and 150ms.


thebaldgeek wishes that there was the option to click on/off the bands on this area (just like you can with auto/and channel). It seems like a dream setup to have two phones and two USB adaptors, one dedicated to scanning 2.4 and one dedicated to scanning 5Ghz vs two adaptors and two phones scanning both bands.
UPDATE. Sept 2026. The function to select channels has been added! tbg is currently testing two adaptors with the same antennas and mounting position (as per the photos above) and will report back if having one on 2.4 and the other on 5 really is the bee's knees or not.


The main screen of the app in wardriving mode is largely informational and will no doubt be customized by each user.
Click around, there is a TON to discover in this app.

Sept 2026. `RocketGod` added RTL-SDR support for those that want to play ADSB on Watch Dogs Go Wars. (WDG).


Using a USB hub, you can now run just these two dongles off the same phone (Still no on running more than one Wi-Fi adaptor - ADSB is MUCH lower bandwidth than Wi-Fi scanning).

The ADSB aircraft you capture on your wardrive (skydrive?) will be uploaded to WDG and if any of them are 'new' (Never seen before), you will get points for them and climb the ADSB leaderboard.


Repeating what tbg already said at the top of this blog - via this blog, he aims to speak to those that want a little more performance on the Wigle leaderboard than an ESP32 based wardriving rig can deliver, but not have to go as all in on an x86/ARM build with hard core Kismet.

Sept 2026. Wardrive Go now includes an antenna testing feature!!!!!!!!!!!!!!!!!!!!
This is huge. This is a killer feature.
This feature has saved tbg untold hours of driving and redriving the reference route to test dozens of antennas.
Drop into the feature under the upgrade menu.
Set up a little test fixture and start measuring your antennas at 2.4 and 5Ghz. Make notes or mark the antennas and you will soon find the good ones.

Crude but effective test range. 
Using an upside-down direct TV satellite dish as the ground plane, tbg was able to walk all the antennas you see in the photo through the setup and get very stable and reproducible results.

All the antennas on the right, in front of the kangaroo showed the selected SSID as having a signal strength of around -56db.
The small number on the left, they showed the same SSID in the same fixture as having -32db.
Those numbers for 2.4Ghz, similar night and day numbers on 5Ghz.


 This feature is the real time saver. Just be sure to count to at least 7 seconds in your head between antenna changes so that the data stabilizes before you click the capture button. 


The Android platform is the perfect sweet spot for so many people - Wardrive Go delivers Kismet type power, but with the ease of use from a phone that most of us carry every day.

MIMO
tbg has tested the dual band Alfa with the single antenna and the dual band Alfa USB adapter with twin antennas and the twin beats the single by a very wide margin.
RF is a black art at the best of times and he can not prove it, BUT thebaldgeek really strongly suspects that the dual antenna Alfa has some really solid beamforming / MIMO tech which gives it the observed edge in Wigle numbers.
MIMO - Multi-input Multi-output processing uses two or more antennas to shape (beamform) the RF pattern. This happens on both transmit (not used in wardriving) and receive.
Think of it being able to switch quickly from a single vertical stick donut type pattern to a simple two element yagi directional type pattern - all while you are driving down the road.
Put another way... it can flick to using just the left antenna, or just the right antenna (for the same SSID as you drive past it) or combining both antennas to form a simple yagi - in some cases, the left is the reflector to the right, or the right to the left.
So the USB adaptor can flick the beam to the left or right of the car at say 30mph to pick up the best signal strength instant by instant, SSID by SSID.
On top of this, the adaptor also uses 'Maximum-ratio combining' (MRC) which phase aligns the received signal from each antenna and then summed to end up with a much better signal-to-noise (SNR) final output that has less fading and noise.
 
The real key is that this all happens IN the USB adaptor - the Wardrive Go app on the Android just gets the best / strongest / clearest data the RF front end can deliver.

tl;dr MIMO relies on multipath and uses it to mitigate signal path attenuation.... Just what wardrivers need.

Bottom line.  As a straight phone wardriver - while looking powerful and info packed - for some unknown reason it simply does not provide the raw numbers that the Wigle app does. 
With an external adaptor this Android only app is a wardriving game changer.
Buy a dual band Alfa with the twin antennas and re-drive all your old areas. You WILL find a good amount of new SSIDs.

BOM
Phone - any with a USB-C port
OTG cable (Optional USB M-F extension cable - passive not active)
Alfa AWUS036ACM (This twin antenna version comes with MIMO built in).

tl;dr Plug and play Kismet promiscuous power in a 'Droid.


Do note that 'support' for this app is via Discord. (Link in the app).
Since its closed source, there is no way to see what the app is actually doing, there is no GitHub to leave issues, feedback or ask for feature requests ect, you MUST join their Discord and take what the Pirates dish out.... you won't find tbg there anymore (Hey, he lasted about 4 days).

Update: RocketGod released a snapshot of Wardrive Go on Github: https://github.com/RocketGod-git/wardrive-go/

Aug 2026. More to come. tbg will flesh this section out as he tests and benchmarks the app.

Jump to top

 ----------------------------------------------------------------

Watch Dogs Go Wars

The sole developer has put a TON of time and effort into this platform.
You can read a bit about it without joining up here: https://wdgwars.pl/press

It's great to see a fresh way to introduce a whole new range of folks to the joy of wardriving.
Gamification is a thing and its very much alive and well at WDG. (Perhaps a little too alive, when was the last time you saw any wardriver upload +200k a day for 9 days (tbg stoped keep track after that) in a row?)

While the platform does support solo folks (Called 'Lone Silverback' (the whole thing has a gorilla theme to it)) it really is primally setup for teams (aka gangs).

One of the more interesting aspects is that WDG does not just reward 'new' SSID, but also will 'reinforce' any that you see over and over - for example on your daily commute. This reinforcement makes it harder for another gang to swoop in and take over your turf in a single drive.

The platform also will also accept and track (rank) uploads of aircraft via ADSB and Mesh (packets?).

ADSB leader board - Sept 2026

Do note that this platform is closed source and so you will need to join their Discord for feature requests or bug reports.

Aug 2026. tbg has an account and passively uploads, but the vibe is just not his thing. Your milage may vary.

Jump to top

 

-----------------------------------------------------------------------------

Biscuit Shop

Interesting to see some hardware that helps Wifi (pen)testing with a bit of a wardriving bend.
Sure, Flipper Zero (the Flipper One is dead on arrival to tbg - size, cost and long history of lack of support) can do most of what the Biscuit line offers but needs to be coaxed vs just works out of the box. And honestly, the Flipper is just not as slick as this hardware line up when in wardriving mode.

Hit up biscuitshop.us to check out the offerings from this husband-and-wife team.

The Aug 2026 offerings are:
Biscuit Pro - dual band wifi scanning with internal ESP32 antennas. Internal battery. No GPS
Biscuit Ultra - dual band wifi scanning with external antennas, Battery, SD card slot. No GPS.
Biscuit DIY - Burn this firmware into your hardware and have it be a basic Biscuit.
Crumb or DIY Node. ESP32C5 node to the Pro or Ultra.
All these talk to the Biscuit Manager App which can be found on the Google Play Store and the iOS Apple Store.
The phone GPS is used for all combos.

There are two really interesting aspects about this ecosystem.
1. You can build a node mesh. By adding small 'scanners' that talk back to a manager and then back to the app, you can really achieve some amazing scan speeds. aka, this is a serious wardriving tool.
2. The expandability of the system. This is like the Lego of wardriving. You can start with a DIY single scanner and then just build out almost without limit.

NOTE! The Biscuit Discord is a train wreck of horrifically wrong RF advice and opinions.

What happens is that you put the Pro or Ultra into Manager mode and then the nodes join the manager and the manager 'intelligently' spreads the 2.4g and 5g channels among the nodes, thus boosting scan speed.
99% of folks are using the Pro as the node manager as the Ultra external antennas make it a great node or stand alone device.

tbg wishes the user had some control of the node scanning, perhaps in a future release. Right now, it's a 'trust me' from the Dev that he is splitting the scanning up in a thoughtful manor (that is hidden from the user).
There is talk that the user might be able to dedicate some nodes to 2.4 and some to 5 (just as you can for wifi and BLE at the moment - the only node scanning control given to the user). This band split option will be powerful for those users that have high gain single band antenna setups.


You can have up to 6 nodes in encrypted mode, or 20 nodes in unencrypted.
This is referring to the communications over the 'back channel' that the Nodes talk to the pro or ultra.
Do note that the more nodes you have, the more unstable the system. 8 to 10 seems to be the sweet spot between good scan speed and system stability.

The Biscuit wiki does not mention how to build a Node. But if you go to the web burner ULR, it has a drop-down option at the bottom of the list. (tbg is still a staunch believer that developers should not be the sole authors of documentation - in this case, there is no GitHub to edit or leave feedback - Since when did Discord become a ticket tracking system?).


Most folks are using the Pro as the node manager since its internal only antennas limit range a bit. But it's also very pocketable on its own, so for a discrete non-phone wardriver, it's pretty nice. (When tested, the S20 in the pocket beats the Pro in the pocket by a good margin - tbg just benchmarks this stuff and leaves it to the reader to decide how they use it).

Biscuit Pro guts

They then use the Ultra in node mode in a backpack etc as the external antennas help push the range.

Then you get the hardcore guys that program up to the full 20 DIY nodes and they talk back to either an ultra or pro (most typical a Pro).

Every build tbg has seen is pretty much a hedgehog of antennas. One antenna per ESP32C5 node.
Most builds are DIY 3D printed cases or small project boxes.
This points to the DIY and Lego block nature. It should be fun to build your own custom wardriving rig.

tbg tested the ESP32C5 and found it slightly more sensitive than the SignalSleuth / Wardriver UK and Wifydra ESP's but not as good as the Samsung phones (S20 & S25).

Again, the key to the ESP32C5 is that you can add a real antenna and or LNA, something that is MUCH harder to do on an Android.

To test the scan speed, tbg wanted to test the ESP32C5 Wifi only vs Wifi + BLE scan change (Just like he did with the Android Wigle app and found it phone dependent - scroll around in this blog for more on that)
2 standard drives with Wifi and 2 standard drives with Wifi + BLE
Resetting and noting numbers between each drive. About 30 minutes of tbg life goes into just this one graph...

(More is better - for Wigle)

This is not a bad thing. There are many Biscuit users that only use BLE mode for Flock, Meta camera and Apple tag detection. It's just a heads up for wardrivers that want to max out their scan and numbers using ESP32C5 hardware. (It's a $10 micro - some concessions have to be made somewhere).
It also answers a frequent question 'should I use both when wardriving' - the answer is, it depends on your goals. But at least now you have the data to choose wisely.

However, things change a bit when running 4 or more nodes. At this point, even though they are not as sensitive, they finally have enough scan speed to edge out the S20 in raw numbers.

Once again, the C5 responded well to having an LNA on the front end, or at the very least a real antenna and of course, as per the main focus of this brain dump blog... get the C5 and antenna outside of the faraday cage called a car (with or without window tint).

Do note that because thebaldgeek put his Biscuit Pro on the roof where its going to get warm and because he could not find out how to power it and have it charge at the same time (the dev says a hardware update is coming from this in future Pro builds), he did a really crude but effective 'battery delete' mod by removing the battery and installing two 1N4004 diodes to drop the USB 5v DC to safe levels and thus totally eliminated a spicy pillow from his future.

tbg built an 8 node cluster with Nooelec WB LNA, 8 port splitter fed by an Alfa dual band outdoor antenna, all of which is mounted on the magnetic mount on the roof of the vehicle. One antenna, 8 nodes, nice amount of gain.

USB plug and wardrive

21.5db of ESP32C5 gain

With this setup, we finally see a wardrive rig that well displaces the S20 phone in a WigleFin from the king of the hill.


F Antenna
The question was asked why the biscuit Pro goes better in the car than the Ultra strapped to the head rest with its antennas sticking out horizontally 'in the clear'.... This is a great question to answer and use to cover some antenna basics and get some toes wet in the RF world.....

The Biscuit Pro ESP32C5 uses a meandered inverted F antenna on the edge of the PCB near its metal can.


This antenna is physically shorter given the length of the PCB, but electrically the correct length for 2.4 and 5Ghz by virtue of the wriggly or zig-zag line of the PCB traces.
The end or bottom of the F is grounded and the feed line taps in near the bottom. The zig-zag 'elements' end up being a mix of horizontal and vertical mini antennas.
The tl;dr of this is that you end up with an almost perfect omnidirectional coverage - albeit of low gain. 


This makes the Biscuit Pro (affectionately called the hockey puck) perfect for slipping in the pocket and walking through something like a shopping mall. (An Android phone running Wigle still outperforms it, but you get the idea).
You can toss it in your car and it will perform the same no matter what its orientation.

In contrast, the Ultra comes with something like 3dbi antennas, they have the typical gain pattern of a donut sitting on a stick, or another way to think of it is that the antenna is the axle in a bicycle wheel, and the rubber tire shows the gain direction pattern.


Low gain is like a small diameter huge fat tire mountain bike; high gain is like a really large diameter super skinny road racing bike.


Safe to say? that most Wifi router antennas are vertical, the Pro antenna is omni, the Ultra antennas on the back of the headrest are horizontal. You have a lot of tire pointing to the roof and the road where there is very little WiFi signals. The rest of the tire is pointing out the windshield and the back of the car.

It's generally well accepted that you take a -3db hit in signal strength with cross polarized antennas. If the Ultra antennas really are 3dbi gain (doubtful), then you are back to zero (or worse) db on an already somewhat deaf ESP32. 

Now you can hopefully more easily visualize why the Pro works 'better' than the Ultra when attached to the headrest of a car - a very common mount location going by the photos in the Biscuit Discord.

The 'fix' for the ultra headrest issue is to mount a small tray out the back of the head rest and put the Ultra on that with its antennas vertical - exactly like a wifi router sits in just about every home and business that has one. DONT just move the Ultra antennas to vertical, one will be right next to the other and mess things up RF wise.
Or turn the Ultra 90deg and stick the two antennas such they point to the roof. (If you have two Ultras on the headrest, one points to the roof, the other to the road).
Now your gain pattern is looking out front and sides of the car and matches the pattern of the Wi-fi router you are driving past.

Read the antenna section at the bottom of this blog to see this more clearly.

Downsides to the Biscuit eco systems are that you are using close source hardware, firmware and software. We've really no idea what's going on at any time. Lots of reverse engineering of a black box required.
Feature requests and bug reports must go into a discord channel where they get lost, overlooked and .... 
Is this a bad thing? No. Is this a deal breaker? Depends on your stance.
The dev seems committed to do the right thing for the wardriving community and other platforms (Wigle and WDG for example).

Aug 2026. tbg will update this section as he tests and benchmarks the hardware, but for now, the tl;dr is that stock standard ESP32C5 is cute and cheap and opens a LOT of wardriving rig building doors.
Add some accessories and put some time into the RF signal path and you start to get some respectable performance from them (more so with the WROOM co-processor).

No question that they are a great fun intro to wardriving rig building. This eco-system may well be all you desire. It's one of the best out there. If you can build a minimum of a 4 node system, it will beat an Android S20 and that's not nothing and its something new that only has been seen in this hardware system.

Jump to top

 -----------------------------------------------------------------------------

Scanning (all) the Wi-Fi channels.   

There are ~14 channels on 2.4Ghz and ~24 on 5Ghz. (It's more complicated than that).
The ‘trick’ is to scan _all_ of them looking for the SSID broadcasts while within range of each device while driving down the road at a safe speed.   
The higher your ground speed, the less time you have to catch the SSID broadcast beacon.

If you have spent any time on the https://wigle.net/phpbb/index.php forums you would know that there is a lot of talk about what are the best scan speeds to try and push your phone(s) to pick up the most number of broadcasts for any given ground speed.
Keep reading or skip ahead to the test tbg did to find the best scan speed for each of his Android devices.   

This kismet webpage does a great job of describing all the challenges with the number of WIFI channels, the device scan speed and wardriving road speed.
Required reading!
 https://www.kismetwireless.net/posts/2022-07-71-wardriving/

This other page also explains the SSID broadcast time: https://wardriver.uk/how_it_works_3
Here is the key snip of information from that site:

...scanning WiFi; it scans channels 1-13 and spends 110ms on each channel meaning a full scan takes ~1.4 seconds. Since the average WiFi access point transmits a beacon every ~102ms, every channel hop should yield the vast majority of the WiFi APs in range operating on that channel.

 

Keep reading for information about the Wifydra that gets around the channel hopping speed limit issue - on 2.4Ghz at any rate.   

The limitations of the Android app scanning through all these channels (pausing on each one at a time for a short time) is why most hardcore wardrivers run more than one phone. You will get a helpful overlap of each phone scanning different channels at different times. This is exactly why tbg runs three phones and the wifydra. It significantly increases the odds of successfully catching the broadcast of every 2.4GHz SSID at any given ground speed. Of course, the phones also pick up the 5Ghz and Bluetooth. Building a 5Ghz wifydra is on the hit list for many wardriving folks.
The other issue with the Android setup is that you cant specify the channel dwell time, just the total scan time. Keep reading for a lot more about finding and setting the scan time in the Wigle app.  

Jump to top

--------------------------------------------------

wifhydra - scan ALL the 2.4Ghz channels ALL the time. #allTheWifi

Aug 2026. TBG no longer uses this build.

https://github.com/lozaning/The_Wifydra

Build cost is about $120 to $210 USD, depending on options. (Note that the Wifydra in a box with real antennas is going to cost around the same cost as a refurb Samsung S20 here in the USA).

BOM:
$30 5 x PCB (5 is the min order).
$32 1 x GPS: https://www.adafruit.com/product/746
$9 1 x MicroSD breakout board: https://www.adafruit.com/product/254
$34 1 x Feather board: https://www.digikey.com/en/products/detail/adafruit-industries-llc/5300/16584014
$68 14 x https://www.seeedstudio.com/Seeed-XIAO-ESP32C3-p-5431.html
Note1: the ESP32C3 each come with a small flexible ‘patch’ antenna on a short coax cable.
Note2: the GPS module uses a CR1223 battery to retain time and GPS data between power cycles. Its highly recommended to buy a battery and put in the module as it will make power-up GPS lock a LOT quicker (less SSIDs saved with 000.000 lat / lon).

Extra tbg Options;
$35 2.4Ghz antenna and adaptor 14 x https://www.seeedstudio.com/2-4GHz-2-81dBi-Antenna-for-XIAO-ESP32C3-p-5475.html
GPS active antenna 1 x https://www.amazon.com/Waterproof-Active-Antenna-28dB-3-5VDC/dp/B00LXRQY9A
GPS adaptor cable 1 x https://www.amazon.com/dp/B00XW2LKNO
microSD card extender 1 x https://www.amazon.com/dp/B07WWVBK8V
Hard case 1 x https://www.amazon.com/dp/B094W9266D
Magnets x 1 set: https://www.amazon.com/dp/B0CC5HC4NG

Program the sub.ino into each ESP, make sure you edit the .ino (its a text file) and change the board number - look for the obvious comment a few lines into the file. They MUST be numbered 1 through 14, don’t use any other number system, the numbers are tied to the code in the dom.ino file in the feather board.

tbg labeled the boards so if he had an issue, he’d know which one it was, not required, but not a bad idea. The sub boards are numbered on the main PCB, but any sub can go in any location.

It's slow(ish) to program all 14 subs because the IDE has to compile for every board just due to changing the one-line boardID, and just FYI, we had to set the specific board type in the IDE. It auto-detects as "ESP32 Family Device" but won't compile unless you select "XIAO-ESP32-C3".

The only thing of note is that we had three of the 14 subs throw this message:

 — Failed uploading: uploading error: exit status 2

Thankfully, both worked on retry.
1 Sub ESP32 totally failed. Tip, buy 1-2 extra and save having to reorder and extra shipping.

Program the dom.ino into the feather board.

NOTE!!!! Use the dom.ino code in thebaldgeeks comment. The main github dom.ino WILL NOT WORK with Wigle.

 

Note that we could not get the Dom to compile and download using the local IDE that we used for the Subs. Once we switched to the cloud based IDE, the dom compiled and downloaded without issue. 

Solder up the +v, gnd and two I2C pads on each sub and the pins on the GPS and SD card boards.

Jumper each of the VCC, gnd and both sets of I2C pins on the main PCB.

Apply the three gaks. (1 cut track and three jumpers)
Click on any image to make them bigger/larger.

 

Cut track and reminder to bridge

Three jumpers need to be added

tbg never figured out why, but he could not power the board from the Gnd and Vcc pins just above the Dom Feather module.

 

The board will pull about 1.38 amps at 5 vDC. This is about 7 Watts.

 


The board worked when powered via the USB-C connector on the Dom Feather module. 

 

(Not sure about why the tiny font on the Dom, if tbg ever works it out, will update this page).

When there is no satellite lock, the GPS will flash its fix LED every second. When the GPS has a fix, it will flash every 15 seconds.

There is no ‘safely remove’ the SD card requirement; the code writes each new SSID to the CSV log file and closes the file, so the card can be ejected at any time that its activity LED is not on. tbg just powers the rig off and pops the card.

After the drive, remove the SD card and put it in a reader on your computer, open the latest CSV and remove all the top entries that have 0,0 for the lat lon. They get logged as soon as you turn the board on and before the GPS has lock. You DONT want to upload these to Wigle.
Once you remove the top X number of entries (but NOT the first line with the descriptions), save that file either back to the SD card, or on your computer.
Log in to Wigle and upload all the CSV files created during the run. Best to wipe them out of the SD card once uploaded so you can keep track of what you have sent after each wardrive.

Wardriving on an electric longboard.

Top speed of 15mph, easy to quietly move around apartment complexes and other tight spaces.

 

 

The 'fun' thing about the Wifydra is that you don't have to go slow.
Since its scanning every channel very fast all at once, you can really move down the road and still catch every beacon.
thebaldgeek has found that the ESP32s are pretty deaf (keep reading) and need a really good high gain antenna and clear signal path (ie, on the roof).

The Wifydra has become his main freeway rig since +60MPH does not phase it at all. At the usual wardrving speeds of 10 to 30 MPH speeds and the Androids are significantly better than the Wifydra.

Jump further down to read why the Wifydra is now unused and in the wardriving corner of shame...

September 2025 update.

New town, new stresses, wardrive to the rescue.
Not going to go into it, but thebaldgeek has a chance to wardrive, but not do as much ACARS website / hardware work as he would like. When the winter snow hits, that may flip 180 deg, but for now....
The brain dump on wardrving continues.

The Wigle forums are hit and miss for good information (Sep 2025 they have been down for well over a week), but some folks do some handwavy testing and tbg got sucked into one thread that proclaimed the Samsung Note 20 Ultra was the next big thing (better even than the astounding G20). So he dug deep (money is very tight) and got one off Amazon.
Doing the same drive 3-5 times quicky shows the difference between devices. The Note 20 is thousands of SSIDs behind every other phone. When mounted on the roof, it was about the same as an in car Droid. This is just unacceptable given it's price point (~300 USD). So it was returned. 

Jump to top

--------------------------------------------------------------

Wigle scan speed setting

While the SS kit is in the mail, lets first settle the major Wigle forum question.

Time after time, post after post, people ask what the best scan speed is (in the dropdown of Wigle app) to pick up the most SSID broadcasts.
Most of the time, it's not answered. tbg thinks it's because it's a phone-by-phone setting and also / mostly because no one has come up with an easy-to-follow reproducible method to find out the best setting.
You can't just take someone's scan speed, stick it in the app on your phone and replicate their wardrive results.

So, let's think about how to find that number. Not so that you can just copy it and blindly put it in your phone - please don't do that - but so that you have a method of finding it for YOUR phone(s).

Here is the thing. It seems that not all Androids are the same (pretend shock). You can Google the term "Silicon Lottery" for some thoughts on the variations.
Firstly, it seems clear that there are changes in chips for any given phone during the manufacturing run, but also in how folks set them up.
No two users are the same. Different apps, different background processes are running etc. (This is less of an issue for a dedicated wardriving Android - it should not be running ANY other apps besides WiGLE).

How do you find YOUR device best scan speed setting?
No one is saying tbg has _THE_ method, but here is how he went about it...

Wigle settings with scan speeds selected and the ones tbg tested highlighted

Mount the Android in a fixed position. Does not have to be in the final position, but it would be best if it was. But being in a fixed position for every drive during this test is important. You want to reduce the number of variables to just one - changing the scan speed in the app. 

In short. Drive the same route twice. Change only the scan speed between runs.

So, pick a route that is a least about 10 minutes in length and pretty typical of your ground speed.
Does not have to be based on your house location. Just two fixed points with a fixed route between them (that you can easily do over and over again - in other words, an out-and-back route is best) and should include a solid section of typical wardriving in your style.
Your typical wardrive speed is important. So make sure your chosen route is mostly at your typical wardriving speed because as you move past the SSID broadcast, you need to hear it and log it. Too fast of a ground speed with too slow of a scan rate and you will miss some. You need to test YOUR phones at YOUR typical speed so the ONLY variable is the scan speed change in the App.

Here is the process thebaldgeek took.
Three droids were tested. S20 on the roof. P5 and P9PXL in the car.

Set the first scan speed you want to measure.
Drive the route.
Note the number of 'Run'. Force close the app. Start the app.
Drive the route.
Note the number of 'Run'. Force close the app. Start the app

Change the scan speed.
Drive the route.
Note the number of 'Run'. Force close the app. Start the app
Drive the route.
Note the number of 'Run'. Force close the app. Start the app

Change the scan speed.
Rince, lather, repeat for as many scan speeds you want to test.

Note the number of beacons seen from each run

You are force closing the app between runs to reset this counter.

You get the idea.
tbg did three different scan times as per the above screenshot - so 6 drives of the same route - yes, its going to take some time, but we are talking about quantifying and ensuring our wardrives are yielding the best results they can and giving us confidence we have tuned our rigs to the their very best performance.
Also keep in mind that once you do this for all your Androids, you should not need to do it again and no matter where you mount it or where you wardrive with it, you will know its scanning the Wi-Fi to its maximin! #AllTheWifi

tbg thinks driving the exact same route at the exact same speed twice per test is important to ensure you have something to average. It is a good sanity check to see both drives have very similar numbers, so you know any change you are seeing over the whole process is a result of changing the scan speed vs some other anomaly in the (one) drive.
For example, the two drives on each phone at each scan speed only varied by about 10 to 20 Wi-Fi SSID's. Very consistent.

Now, lets dive into the numbers....

You should have a table or list of numbers now that each device saw during each run.
They should only change by a few 10's at most. The variation is largely due to Wi-Fi hotspots in cars and trucks. If you drive the test route at 3am, the variation between drives is stunningly low.

REMINDER: You are NOT looking for new SSIDs here in this test. You are looking to see the changes to the app settings or phone placement changing the number of beacons you see over the run distance.

So, with your numbers now clear, see what the average of your two drives per scan rate are and review or perhaps plot like them like tbg has here:

 

Samsung S20

Pixel 5

Pixel 9 Pro XL

Safe to say, thebaldgeek is going to be leaving his Androids on 'nonstop' and take the battery life hit.
Your Droid(s) might be different. Your ground speed might be different. Your battery management needs might be different. Regardless, plan a route and get wardriving to find out your best scan speed setting.

NOTE: The main setting tbg is changing is the last of the three ground speed ranges, the 'faster than 8km/h or 5 mph'.
That is the most typical speed tbg is moving at. The other two speeds, stopped is set for 3 seconds and very slow he just leaves at 1 second.

 

Last graph on this topic....


Here tbg took the average of all three drives from each device.
The roof top mounted S20 is a solid choice for wardriving as a second (or primary) option.

-----------------------------------------------------

CPU throttling

Since it seems clear that tbg's devices catch the most amount of SSID broadcasts while running `nonstop`, he wanted to make sure it really was not bound by any choke points, so if you dig into the Samsung settings, you will find this option....

 


To be clear, tbg has not done the 'drive test' with it on and off and looked at the two drive count to see if it made any difference, but in the sprit of this blog, sharing all the contents of thebaldgeeks brain, this is what he found and has done.

 

The Pixels sort of have something like it with backgrounding / (deep) sleep tasks and such, so you can mess with those to push WiGLE to the top of the CPU list.

-----------------------------------------------------

Scanning Bluetooth impacts Wi-Fi count?


The next question that gets asked a ton is if turning on Bluetooth scanning impacts the number of WiFi that is picked up.
Again, don't copy paste tbg's answer here, just copy this method and find out for YOUR phone.

Same process as the Wi-Fi scan speed test.
Do two drives with BLE on.
Toggle the option, do two drives (restarting the app to reset the 'run' counts between each drive) and see what the numbers tell you.

tbg just cant stress enough the power of having a 4-5 mile loop that you can consistently drive over and over and benchmark these app and any rig hardware changes.

Don't forget to double check your Android settings. You can toggle the checkbox in the app settings page, but if its not turned on/off in the control panel, you don't get a warning - sanity check: Look at the WiGLE dashboard for 0 when off and hundreds or more BLE when turned on.

Pixel 5

Pixel 9 Pro XL

Samsung G20
With the three phones that thebaldgeek runs, the older it is, the more its impacted to some extent.
BTW, the ONLY 'use' for Bluetooth data that tbg has seen is (see the links section above) the discovery of FLOCK cameras. If you know of some other uses, please drop a comment to this blog.
Since it makes zero impact on the G20 and very little on the P9PXL, tbg is going to keep that data flowing via those two devices. Turning it off on the Pixel 5.

If you did not know, tbg picks up a bit of ACARS (text messages from aircraft), some of them are really cryptic and of no use right now, but what if we have a breakthrough and can understand them in 3 months time. Sure would be nice to have a deep data bucket to go back to.
If you don't scan it and log it, you can never ever made use of it.
If scanning and logging is has zero impact on your wardrive, then why not add to the data bucket that may end up being gold at some point down the road.

There are already a ton of requests for it, but yeah, tbg wishes there was an easy way to turn off BLE scanning in the wardriver dot uk and the Signal Sleuth. He just does not need 4+ devices scanning BLE and would rather his Signal Sleuth focus its scan speed on 5GHz Wi-Fi.

UPDATE: tbg was told that BLE scanning on thewardriver.uk and Signal Sleuth does not impact the scan speed at all.

Jump to top
 
----------------------------------------------------------------

Programming the Signal Sleuth.

 Aug 2026. TBG no longer uses this hardware.

Signal Sleuth Slim kit

First job is to program the three units.
A, B ESP32 and BW16.

BW16 is the unit in front

If, unlike thebaldgeek, you'd rather watch a video about how to do this, I recommend you start with this video for an overview: https://www.youtube.com/watch?v=xgQsn6YhqSk
DONT action any of programming from the first 30 minutes, just watch it, but don't take too many detailed notes.
The main programming process is in the v1.1 YouTube: https://www.youtube.com/watch?v=h77B8F7grRE

tbg finds frame by frame working though videos tedious and would rather read and look at screenshots of how-do stuff....
Use what ever method your brain likes best. You have choices. (tbg has been told these writeups are useless and unreadable as they are not in PDF format - Sorry you don't have that choice)

 

First up. Download the Arduino IDE and load up the board profiles.
Click on File -> Preferences -> Settings tab.
At the bottom of the settings tab, click on the icon for "additional Boards manager URLS":



Add the following two URLs

 

 

https://raw.githubusercontent.com/Ameba-AIoT/ameba-arduino-d/master/Arduino_package/package_realtek_amebad_index.json

https://raw.githubusercontent.com/espressif/arduino-esp32/gh-pages/package_esp32_index.json

 

Click Ok, to close that dialog.
Click Ok to close the preferences dialog.

Next is to load the libraries we need.
Hit up wardriver.uk github and get the versions mentioned.
The only variation is that you will need to get v2.3.8 of the OneWire library. NOT the v2.3.7 mentioned.
Just download the zips. You don't need to unzip them. You actually upload the zips to the Arduino IDE.

 

tbg has added the zip libraries needed already in this screenshot

Keep the wardriver.uk page open as you need to setup the IDE correctly.
But, first, there are more files to get.
Download the a.ino and b.ino from the wardriver Github

 


Download the BW16.ino from: https://github.com/CoD-Segfault/BW16-Open-AT

 

With that, we are finally ready to start programming.

Start with the BW16.
In the IDE...



Point to the BW16 ino file and it will open it up in a new IDE.
Next, click on the board manger icon and type in 'bw' to find the correct board type.
And then select the known working version from the drop down list.


At this point, you will need to plug in the BW16 to the computer USB port.

 

 



If your computer does not find the BW16 board it probably also won't find the A or B board...
 
Same missing driver issue with the A&B boards.


So add the driver for them as well.
Both types of boards use the same driver.
Hit this webpage, download the driver files for your OS.
tbg made a 'wardrive' subdirectory and put everything in there.

https://www.silabs.com/software-and-tools/usb-to-uart-bridge-vcp-drivers?tab=downloads

 

Unzip, make sure your board(s) are unplugged.
Find the right .inf and right click it, select install.


Plug your BW16 board in.
Once your board shows up in the IDE with a comm port, you can start getting the settings correct for the programming.

First, select the correct comm port.
Note that your computer may have a different number. You can use the device manager to find it if you are unsure.



First, erase the BW16.



During the count down, hold the boot button, then press and release the reset, then release the boot.
You have about 5 seconds to do that dance, so make sure the BW16 is on a firm surface and you are ready to do that button sequence.
 

After it erases, remove the check from the erase option (back to disable).
Once you disable that, you can click the > arrow button on the IDE again and this time the sketch will upload and just make sure there are no errors reported.
 

Ok, swap out your USB-C for a USB-Micro and you can start on the A&B boards.
You PC will probably load them with a different comm port number, so after you load each A and B ino, be sure and select the correct comm port number in the IDE.
Next, make sure you select the known working board version. Chose a higher version at your own risk.


Now we have to make 100% sure that all the IDE configuration is spot on for programming the A&B boards.
You can see the strict requirements at wardrive.uk, they are as follows.


So, first up, the board type.


Next, the upload speed.


Then the CPU Frequency.


Then the Flash Frequency. 


Then the Flash Mode.


Then the Flash Size.
 

Then the Partition Scheme.


Then the PSRAM.



Then the Arduino Runs On.
 

Finally the last one, the Events Run On.
 

Ok, now click the blue arrow button and program the A board.
If you get any compile errors, read them carefully.
thebaldgeek got two sets of errors from missing files.
The two missing ones were:
https://github.com/adafruit/Adafruit_BusIO/blob/master/Adafruit_I2CDevice.h
and
https://github.com/adafruit/Adafruit_BusIO/blob/master/Adafruit_SPIDevice.h

Download the missing files and put them in the A and B directories.


You will need to copy paste those two Adafruit files to the B directory to take care of compile errors as well.

 
-------------------------------------------------

Building the Signal Sleuth

Aug 2026 tbg no longer uses this hardware.

Ok, programming done. Finally, thebaldgeeks favorite and fun part, soldering!
 

Slight deburr with a straight file of the side of the GPS was needed to better fit against the SD card board.

One thing to note that tbg has not seen mentioned anywhere on any of the wardriver.uk or SS pages is that the GPS has 3.3vDC on the antenna socket. So you should use either an active antenna or an antenna that is NOT a DC short.


This means that you can run the tiny 'chip' GPS antenna that the SS comes with, or something a bit bigger that can attach to the roof of the car. These external antennas really perform better with a ground plane, even a paint tin lid will do wonders. On the outside of the car, looking up at the sky, the extra length of coax is even less of an issue since the signal to the puck is cleaner and its inbuilt amplifier easily over comes any coax loss.


The GPS Bias-T can source up to 50mA of current (at 3.3V). Keep that in mind if you plan on running an external active antenna.

tbg has removed the hydra from its case and put the SS in it to run some tests, so knowing the GPS has a bias-T voltage, he was able to run the same little active puck GPS antenna on the case and the SS picks up GPS lock very quicky and keeps solid sub 0.5 HDOP fix.


Back to the build.
You can see its a tight fit between the GPS and the SD card, but just removing the burr from the edge of the GPS is all that is needed for a night flush fit.


tbg wanted to put the antenna sockets on the same side as the parts so that the back of the SS was more flush - to do this, the display sits a little high.
 

Removing the pin spacer after the pins are soldered helps drop it closer to the main PCB.
 

Installing the antennas and keeping them straight while soldering the sockets ensures a nice neat final look on them.
 

The kit soldered together really really well.
Its a quick clean build with zero issues along the way.
 
Just one thing to keep an eye out for....


The GPS plug (no matter what GPS plug, coax or antenna you use) can far to easily swing over and short (the GPS plug is ground) the positive of the GPS back up battery.
Either put some tape between them, or route the GPS coax such that the plug can not swing back toward the battery.
 

Last thing to do....
 
Grab your SD card.
Plug it into a reader and into your computer.
Make sure its formatted to FAT32. No larger than 16Gb.
Make sure its blank.
Right click (on Windows) and create a new txt file.


Name it `cfg.txt`.
Edit the file and add the following since the Signal Sleuth has this extra 5GHz module.
sb_bw16=yes
 
thebaldgeek added one more line to the cfg file, your final setup goal might be different.
tbg did not want the Signal Sleuth spinning up a softAP (software Access Point) every time it booted. 
He also did not want it connecting to his home wifi as that also would have caused the SS to transmit.
tbg wanted the SS to be as close to receive only as possible (for explained reasons to come).
So tbg added the following line under that last one...

block_reconfigure=yes

This disables that whole first time bootup 'connect to this IP address' thing and disables the 1 minute softAP timer.
On power up, the SS will see this option in the file and drop straight into passive wardriving mode.

But do note it will mean you have to pop the SD card out and manually upload them via a card reader every time you want up upload your wardrive data.

Ok, drop the SD card into the Signal Sleuth and go for a drive!

 
Horrible placement, but will do as a rough proof of life....

S20 828
P9 737
SS 693
P5 522
Hydra 375

The Signal Sleuth is at least in the game. Its not great, but its got potential. 
The Hydra, as expected for a long time, is just not acceptable by any benchmark.
Its officially been retired from thebaldgeek's wardriving arsenal in the short term.
 
The SS seems to run pretty warm. tbg sees double ambient temperatures with this thermal camera.



The heat generated is really quite a lot when it's enclosed. More so when it is exposed to sun (on the dash or roof of a car). Something to keep in mind when mounting in a case or car roof top mounting the unit.
 
Power wise, the Signal Sleuth pulls about 1 watt in the boot up phase, then once it drops into wardrive mode (scanning) it jumps to a very consistent 2 watts, 0.4 amps from a 5vDC power brick.
 

Moved the Signal Sleuth off the back seat and onto the roof for a few drives.
Do note that tbg used more than just a single rubber band for the drive tests, but wanted to give you the idea of the antenna size / gain and counts...

With good 3ish db gain antennas the SS is still (back seat test as shown earlier) only just above the Pixel 5 (3-year older phone!), but still below the Pixel 9 and well below the S20.
 

Bumping the antennas to his best 6ish db antennas moved its SSID count to slightly above the Pixel 9, but still a lot below the S20.
 

To thebaldgeek this clearly showed that the ESP32's and to some extent the BW16 are just a bit deaf and might just reward the wardive rig builder with good numbers if the signal can be pumped a little harder into the SMA connector. (tbg suspects the same issue is plaguing the Wifydra).
So lets turn up the volume to 11.....
 
 
-------------------------------------------------------

thebaldgeek insanity build of the Signal Sleuth / wardriver.uk

Mid 2026. After this exchange, tbg gave up on this hardware and firmware.


The 9db Alfa outdoor antenna showed up, so put it on the A side of the SS and the Wifi went from 3 to 18. Nice jump.
Then put it on the B side and the WiFi went from 3 to 3.... uh...oh.
Moved it over to the BW16 and the 5GHz went from 1 to 4.

tbg wonders how many builders have done this test and if there some builds that are out there (not just of the SS and not just of the wardriver . uk, but every ESP32 Wifi build) that are deaf in one or both ears....


Its a simple A/B/C test and it really showed up a problem?
Looks like the Signal Sleuth / the wardriver build is going to take a pause while thebaldgeek waits for replacement parts to arrive.
BTW, the 'how it works' page is here: https://wardriver.uk/how_it_works_3
Here is tbg's GitHub ticket / solution: https://github.com/JosephHewitt/wardriver_rev3/issues/202
 
----------
Turns out the live count on the 'B' ESP works very differently vs the 'A'  ESP.
tbg ended up attaching the antenna for 1 minute on each SMA and then looking at the logged SSIDs on the SD card file.
Sure enough, the B side was working great. It just shows poor live numbers (unlike the A side), but the totals are what matters, and the SD card file showed plenty of B side SSIDs.
------------
Ok with that glitch sorted.... next up is to yell in the ESP32 SMA connectors a bit louder....
Starting with the antenna.

tbg has found Alfa gear to be reliable in their specs and build quality.
As such he chose this 9dbi omni for the signal stick.
Do note they make a longer higher db one, but you quicky end up with a very narrow vertical beamwidth and that's not great for suburbs. Might be Ok for wide open country where you need a bit more reach. Also its almost 3 times as long . This 9dbi is about 12 inches. Perfect for around town wardriving and not screaming 'look at my hedgehog car!'




For the 'volume to 11' part, we need to run an antenna mounted LNA. Low Noise Amplifier.

Minor tbg rant....
The key to this whole build is to have the amplifier mounted AT THE ANTENNA.
You cant just put an amplifier in the car at the wifi stick and call it amplified. Its not even close to effective when mounted in front of the Wifi dongle.... In fact, many ADSB/ACARS installs have shown that often times putting the amp _at_ the stick is actually worse than no amp at all. The amp just overpowers the stick. Its AGC kicks in and the reception / decoding suffers.
tbg has the following analogy to help visualize this and drive the point home.

A loud hailer. The cone shaped mic > amp > speaker setup.
They work pretty good in a big crowd. Now, walk up to one person and put the speaker end of the cone against their ear, key up and say something.
Can you say over driven distorted induced deafness? Same device, different distance away from the listener.
You want the loud hailer at the antenna yelling in to the coax. It needs to be that distance away from the electronic ear that needs the actual information.
Not to mention that when mounting the LNA at the receiver, you simply amplify all the noise the coax picks up as well. 
/rant

tbg wanted to test the Zeenko and also have the Nooelec wide band be part of the test.
The key here is that you need at least 2GHz to 8GHz bandwidth, low noise and high stability.


A quick A/B test showed the Nooelec has a good edge (you get what you pay for), so thebaldgeek went with that amp.
Also the Zeenko has a rechargeable battery built in, so that's a ticking time clock for a spicy pillow in your future. Also, it's yet another thing to charge and who knows about how it handles hot sun. The nooelec have proven to be robust in that regard.
 

And yes, every SMA is torqued. Its the only way to get both reliability and consistency.
More about tbg SMA wrench adventures here: https://community.airframes.io/t/sma-torque-wrench/70
Short section on SMA torque wrench's here:
https://k6thebaldgeek.blogspot.com/2025/09/wardriving.html#smatorquewrench

Now to split the one coax signal into 4....


Again, make sure your splitter covers from 2GHz to 6GHz at the very least.
And yes, we know, splitters have loss, hence putting the LNA AT THE ANTENNA and having the antenna OUTSIDE the RF shield.
That extra clear gain will more than make up for the splitter loss.
Did you not read the rant? Go back a few paragraphs and read the rant.....

A quick word on the DC block.
Recall the 3.3V DC on the GPS output so it can drive an active antenna?
You DON'T want that voltage showing up on the input the ESPs. Also, it does not provide enough current to run the Nooelec LNA, if we try, the GPS might burn out or at the very least go into current limit and the LNA will not work as expected, so... we fit the DC block, and everything works great.
 

tbg still wants to use bias-t to drive the Nooelec, so using the external Bias-T injector gets the job done.
Again, make sure you get a 6GHz rated injector, not all of them go that high.
Your desired signal needs to go through the Bias-T, so make it a quality one.
 

Front view is messy but functional.
 


Side view is messy but functional.
 

Back view is about the best.
 

Fits in the center cup holder just as planned from the very first solder joint.


Pretty clean. Coax from the back door in the bottom of the Bias-T injector, USB-A to the cig lighter USB for power and we are ready to wardrive!
 


The semi-ridged coax should not be forced on any 90deg bend, so just run it parallel to the door and it will just naturally compress the rubber seal and enter the car with no kinks.

thebaldgeek enhanced Signal Sleuth
BOM:
3 magnet truck mount: https://www.amazon.com/dp/B07W5NPVG3
 
Update: October 2025
After some failed attempts of getting the OTA update working (it took 8.5 hours to update the B ESP (this is normal apparently) and the update resetting all the SS webserver and WiGLE API key and after the OTA tbg can no longer connect to the units webserver for some unknown reason, the SS will just NOT connect to any of the 4 Wifi's tbg has running and thus it will never auto upload, and after failing to get the SS to see the same or better number of beacons over the test drive (and longer), thebaldgeek has semi-retired the SS and is refocusing on the Android's which are consistently better in numbers and are much easier and less stressful to use.
-----------------------------------------------------

Shorten GPS and Wi-Fi coax cables

The typical GPS puck and Amazon Wi-Fi antennas come with 1/2 a mile of cheap thin very fragile and lossy coax cable that is usually waaaaaay too long for the typical wardriver's needs.

All coax cable will leak signal, the longer the coax, the more you lose. Look for your cables loss in db per feet.
The higher the frequency, the more you lose. Note, its not always linear, so you don't automatically lose twice as much at 5GHz vs 2.4GHz, but its not a bad way to think about it.

Generally, the thicker the coax, the less lossy it is. To the point where really important installs have what's called 'hardline'. Its coax that is about 2-3 inches thick and very hard to bend in any way.
Clearly, not something a wardriver can squeeze through a sunroof.

Point is, the super thin coax that comes with just about every Wi-Fi antenna is, well, crap. In short, it has so much loss, that any gain the antenna has, the thin coax will soak up and either come out at almost zero, or worse - a negative signal strength. (Which is why tbg talks about LNA's and their placement so much).

Two options.
1. Shorter cable
2 Better quality cable.

Shorter cable

Two options for the shorter cable option. Ok, three.
1. Soldering iron and heat shrink.
2. SMA crimp tool and new connector
3. Put up with it.
 
If you chose to go with option 3, coiling the excess length is best done loosely. The real key is that the coax is so thin that it does not take much to crimp, kink or crush it, all of which result in even worse signal strength.

Fun tip: Most other radio setups have a way of viewing the signal and thus confirming the coax integrity. Wardring, not so much. You may have a badly crushed coax cable and still get some SSID's but nothing like what you should be, but you have no clear cut way of telling (again, having a 'standard drive' to check your gear comes into play).
 
Tip, put the coax through the door seal running almost parallel. Not at a sharp angle and NOT through an almost closed window.
 


Option 2 requires the correct crimping tool. Somewhat expensive and if you are only ever going to do a few, might not be worth it.

Option 1 depends on if you have a soldering iron, are comfortable using it and are willing to shrug off all the hard core RF engineers that are going to yell at you for doing something that they would never do and swore that it will never work, but in the real world, it works better than just fine....

Leave about 4-6 inches of coax at the SMA end and cut what you don't need out of the total length of the coax able. (Measure twice, cut once).
Slip on your outer heat shrink.
Strip back about 1 inch of the outer coax on each end.
Strip a tiny bit off of center coax on the SMA end.
Cut the center coax back about 1/2 inch in total length on the antenna end, strip a tiny bit off.
Thread on a short length of center coax heat shrink.
Solder the two coax centers together and put your heat shrink over and shrink it.
Fan out the braid of the coax and re form the 'shield' around the bit of heat shrink in the center.
Don't cut it short, you want it to overlap and form a full shield.
Solder it in just a few places.
Slider the outer heat shrink over the whole thing and shrink it.
 


Trust thebaldgeek. VNA etc measurements have proven that the 'horror' join just described is actually less lossy than the big chunk of cable removed. Wardriving is receive only and even the little upload that the WDUK and SS try to do the power is not an issue for that join.

Better quality cable option.

tbg finds KMR240 coax an acceptable compromise. -2.65db loss per 25 feet at 1.8GHz. Its stiff, but not unworkably so. He has 100's of feet of the stuff for his satcom, ACARS, VHF, GPS and wardriving builds.
 
 
--------------------------------------------------------------------------

SMA and Reverse (RP) SMA

Just to make things even more annoying for the wardriver, there are two SMA standards.
Male and female or pin and socket.
 
Why two? Because the FCC thought that flipping the pin and socket would stop folks from attaching the 'wrong' (ie, high gain) antennas on Wi-Fi routers. That 'ruling' went out the window before it ever really got ratified, so here we are.

Depending on your device (USB stick, WDUK/SS/Biscuit etc), both will screw on just fine at least a few turns (male to male can get started, but stands a good chance to damage one end or both without trying), but only one combination works the way it should.

Solution? Keep a bunch of converters on hand. Exactly which ones you will need will be the exact one you don't have when you need it.
 
Here are some assorted photos from Amazon of converters that tbg has bought and used over the years.








To be fair, this cornucopia of adaptors is really only needed if you are churning your builds or antennas very frequently. If you just have the one rig and are happy with it, then there is no need to have them on hand. Better still if you have them on hand before you need them, as in, plan your rig out and order the parts before you are rushing to compete in the 24 hour hard hat WiGLE madness.


And you have the same madness with FL connectors (typically used by the ESP32 wardriver rig builder) to both SMA, RP SMA and both female and male options.

Closing thought, some really cool Wi-Fi antennas have a TNC connector, perhaps even a BNC. External / outdoor antennas might even have an N-connector (male or female). If you are getting into that sort of madness, you know what you need... More adaptors....

 
--------------------------------------------------------------------------

SMA Torque Wrench

Since we are on the topic of SMA connectors. You really should do them up to the correct tightness and not just finger tight and not plier / wrench / spanner tight.
If you want them to last and you want consistent RF performance out of each and every connector, then you really need to ensure that each SMA is done up to the 'perfect' amount each and every time.
 
Not that your typical wardriver is going to have this issue, but the SMA connector is rated for around 500 mating cycles, but ONLY if done up to the correct torque.
 
If you want all these SMA's to work right, use the pink tool

Most wardrivers will use brass SMA's, but do know that stainless steel SMAs are a thing and require a different torque setting.
Your SMA wrench should be set to 3–5 in·lbf (0.3 to 0.6 N·m) for brass, and 7–10 in·lbf (0.8 to 1.1 N·m) for stainless steel connectors.

More about SMA torque wrench used by thebaldgeek can be found on the airframes community forum here: https://community.airframes.io/t/sma-torque-wrench/70
 
And yes, every single connector in every photo in this blog taken by thebaldgeek has been tightened up with this very wrench. Every. Single. One. Every. Single. Time.
 
 
--------------------------------------------------------------------------

tbg insanity Wifyda build

Aug 2026 tbg no longer uses this hardware

tbg has been eyeing off the Wifydra sitting in the corner of shame and decided to give it a second chance.
We now know that the ESP32s are pretty deaf, so lets also turn it up to 11 for the Wifydra....

As already mentioned in this blog, tbg does not normally run high gain antennas and especially directional ones as most devices don't have the scan speed to get 3+ samples as the SSID beacon location flies through their narrow beamwidth and so you don't get very many GPS tags vs signal strength readings to feed to the WiGLE machine to chew on and plot the SSID location accurately. 
But.
In the case of the Wifydra, its 14 individual receivers are scanning very fast (rate unknow), there is no CPU core or receiver sharing at all (unlike the wardriver.uk and Signal Sleuth).

Lets yell into the coax and see what we get.

First up, lets do the usual 2 drive average with this nice 20dBi Yagi-Uda array.


Photo of said Yagi with the tinted window closed.

For all these tests, the output goes into a 4 channel splitter - tbg can not afford a bigger one at this time, so he used WiGLE stats to check which are the top four 2.4GHz channels in use and saw that they were: 1, 3, 6 and 11.
The 4 way splitter was thus attached to those receivers on the Wifydra.



Antennas were left on the other channels because why not.
 
The usual loop was driven twice and the 4 channels were added together and then averaged.
636.

Ok, lets now add the Nooelec LNA to the back of the Yagi.
836.
 
Next, lets see what the 20dBi panel antenna can do for us.
 

Here is the link to the panel antenna tbg is using: https://www.tupavco.com/products/panel-antenna-24ghz-wifi-20dbi-wireless-outdoor-18-directional-n-f

Reference drive count: 874.

Lastly, lets wind down the window.
887.
 
Numbers are not tbg's friend, so lets bar graph them....
 

 

Not as big a gap between window up and window down as tbg expected, but there you have it.
 
 
---------------------------------------------------------------

Waterproofing (temporally) the roof omni antenna

 
Going to get some rain in North Idaho over the next few days.
thebaldgeek is not done tinkering up there, so he needs a quick fix. The main thing is the SMA connectors and Nooelec LNA need protecting from the water.

Latex balloons are cheap and should do the job:
The main bit at the bottom needs protection from the wet

Close up of the temporary mess

Cut the tail off for the coax exit




 
One is none, two is one and so three balloons were put over the base. Probably overkill, but eh. Winter is coming.

 
--------------------------------------------------------------

Planning and driving a wardrive

There is no one right way to wardrive. What follows is just a continuation of thebaldgeeks brain dump.
If you warrun, warwalk, warcycle, warbus, warmotorbike, war-E-anything, you are going to figure out what works for you over time. Just be thinking about how you are moving through space and collecting your beacons and you are on the right track to optimization.

Over complicating it, your trying to figure out how to drive every road in a suburban network with little to no backtracking or overlap (wasted mileage). Suburban layout types include grids, cul-de-sacs, loops, and dead-ends. This sort of variation can complicate things.
In short, you want to find the shortest path that traverses every road at least once. Or do you?
 
Some folks like to use something like http://www.everystreetchallenge.com/ or perhaps https://citystrides.com/ to plan their route.
tbg find's both of them complicated, pointlessly time consuming and suboptimal for driving. 
 
tbg starts with the WiGLE map. Look for a gap, a patch of roads that is not covered in purple dots.
Think about how much time you have for the drive, is it a quicky or a long soak.
tbg also thinks about what areas to drive for times of day he's planning to drive it.

Once on your drive...
Break your desired area into smaller chunks.
Pause between the smaller chunks. Do a self-check. Are you tired, distracted, annoyed. How's the gear working? Everything still have GPS lock and seems to be logging data? You don't want to spend the whole time doing a large area only to find at the end something failed and you have no idea when/where.
At the end of the big chunk, do you need to do an upload, or can you get home and do it there?
 
tbg has found the best urban road speed to be between 20mph (32kph) to 30mph (48kph). (Or slower).
Much slower in and around apartment blocks or high rise areas.

Some areas lend themselves to 3am drives (dense suburbs), some to early morning (city), some to any times of the day (open country).
Note if there are any schools in the ground zero or nearby. They can get so busy as to be dangerous for a wardrive, so be aware of school hours.
Lastly, are the wife / kids or SO on board? That can change the type of drive you do at any given time.

Ok, so you have an area in mind that is somewhat void of purple dots, or the dots that are there are 2+ years old.... Looking at the 'last update' date will give a feel for the last time the area was war driven and the older the date, the more likely you are to pick up a lot of those sweet 'new' points in your total, so even if an area looks purplish, don't despair if they are old plots.

The first few times, you are not going to know how much area you can cover in x amount of time, so just 'send it' and recalibrate as needed over time.
Take a look for clear bounding major roads. Its helpful to know them to box the area in... And you don't want to have to cross them more times than absolutely necessary - more on that in a moment.
Figure out the best way to get to ground zero. ie, how to get from your recon location to the desired area such that you arrive facing in the direction you need to be attacking it.
Look at the road layout. Is it a grid, is it just random. Are there any major roads in the mix.

Next, open up Google Maps. tbg finds he can get Wigleblocked if he mucks about with their map too much, so he pulls it up, gets it roughly zoomed, switches the view to 'nightvision' to see the roads and then does not touch it.

tbg rant.
The Wigle app and website colors are appalling. White roads on a white background just don't work.
Dark purple dots on a black background just don't work. You either cant see the roads, or you cant see driven areas.
We love the work they put into the site and Android app. Major respect. Just hard to use/see.
/rant

Flick google maps between normal and satellite while looking at the area of interest. Are there any high-density bits that you really wanna hit slow and hard. Are there any oddly open parts, like parks or undeveloped areas.
Once you have a big picture overview, now take a look at some of the finer details.
Many dead ends?
These can be tricky. If they are just 2-3 houses down them, they may not be worth the time (they take quite a bit of time in the turn (and double-back)

Some dead end tips.
Is there a clear turn around at the end - like garbage/trash truck sized turn arounds. If so, drive them regardless of their length. (These are 'fast' turns).

Here is a dead end that tbg might skip...


No place to smoothly turn around, only 2 houses deep and those two houses have roads on the other side that can be easily wardriven.
 

tbg will for sure wardrive down this dead end. There are a few houses that don't back onto other roads and there is a clear spot to turn around smoothy without raising eyebrows or losing too much speed.
 
Regarding dead ends. Tip: look at the trashcans / wheely bins. If they are lines up at the end of the street, that often means the dump truck can't get down there, so perhaps the wardriver should not enter. 
Mailboxes are a mixed tip, they are often clustered at the end of a really sweet high value dead end, so don't bank on them tipping you off either way.

Another tbg tip... 
 

Always turn left on main roads (when not in the USA). That way you are not crossing traffic more than needed. It will make a grid drive so much safer and faster. Drive the north south streets in the number order shown for example. You may have to deliberately drive to the other side of your area before working the grid but it will be worth the drive to only pop out on this main road and have to turn WITH the traffic flow, not across it each and every time.
(Obviously flip it if you are USA based).
 
Gated community / apartment's.
Your call, but if the gate is open (Do NOT follow anyone in), tbg drives them.
Here is a tip, at certain times the gate will be opened and left open, tbg has found mornings to be the most common time - lots of people driving to work between say 6am and 8am, so the gates are just left open. In the afternoon, its back to needing the keypad or RFID card each time.

Another tip...


tbg has sometimes to often found side gates are just left open 24 x 7. This is why its worth looking at Google maps to see if there are any back or side entry roads to these sorts of target rich environments.
 
Just the one map tip...
 

tbg likes running the split screen / dual app feature of the Android, the WiGLE map up top zoomed out so its easy to see what blank parts he has in mind to drive.
Then a second map (Google Map for example) which is zoomed up for finer detail including street names. (tbg typically uses his Giger counter mapping app as it also shows a history of driven roads).
The top WiGLE map makes it clear the big picture, the focus of the 'blank patch' that he had in mind to wardrive.
Both maps auto rotate for track up so they are both showing the same way all the time.
tbg would love to buy one of the fold phones once they become affordable and more robust just to use in this mode while wardrving. For now, the Pixel 9 Pro XL is doing the job.
 
Goes without saying, but going to say it away, always always always observe the road rules including speed limits at all times.
Always do a solid stop at stop signs. tbg has seen many police cars watching random stops at all hours of the day and night (yes, 3 or 4am!). Its just never worth floating through them.

Follow the pilots mantra. Aviate, navigate, communicate.
Dive the warmobile first and foremost.
Then look at the map, know where you are and where you are headed.
Only then listen to the radio or talk to the co-pilot. Don't be on the phone while driving. Just. Don't.

---------------------------------------------------

Radicode (Geiger counter)

thebaldgeek has a strong interest in making visible the invisible 'signals' around us.
That's part of the attraction to wardriving.
He figures if he is out and about collecting Wi-Fi visualization data, may as well add radiation into the mix.
Here is the USA amazon link to the device he uses - tons of information there and lots of search terms if you want to jump into the rabbit hole...
 
Just like WiGLE has a map, the Geiger counter folks also have a map. Its called Radiaverse.

Random suburb in Southern California - note, the red bit is super safe, its just the map scale.



Here is another random wardrive radiation example. Interesting how parts of a city can change.
To be SUPER clear, the change is soooo tiny and all of the places that tbg has radiation driven have had normal amounts of background radiation - that's the whole point, looking for places that are not - but after 20,000 miles tbg is yet to find one... But hey, if you don't scan, you never know....

As as aside, some folks use the Radiacode to look for hot rocks, some use it to hunt down uranium glass (the unique red / orange colored ones), thebaldgeek is looking for old aircraft gauges with the glowing dials - he's not found any yet, but yeah, that's what his interest with the Radiacode is. (Along with wide area mapping). 

tbg has two mount options for the Radiacode depending on what data he is after.
For run of the mill wardrives, the pool noodle cup holder is the goto.


Or, for something lower to the ground, tbg uses this Pelican case with magnets to clip on the lower panel door, or even underbody.




Jump to top
-------------------------------------

Antenna Gain

No free lunch. Again.
The antenna is the first thing the SSID beacon hits, so it is the single most critical part of your wardrving rig.
Antenna's are typically selected in wardriving by their gain. The higher the gain, the better right?
Well, no, not really, yes, sorta, it depends.
Quick brain dump for wardrivng with out getting into the weeds of RF (radio frequency) black art....


Typical 2.4 or dual band antenna that we screw onto our USB sticks or wardriving UK / Signal Sleuth builds have 3dbi gain.
They are shortish. (The super short stubby ones have either zero dbi gain, or worse - yes, negative gain is a thing).
As you go up in gain with an omni, the antenna will get physically longer. Inside the antennas are smaller stacked antennas one above the other, each often adding around 3dbi, so that's how you get the gain and often why they jump in gain from 3 to 6 to 9 to 12. Sometimes, they are honest and say its an 8dbi antenna as you don't get a clean 3dbi jump each time you stack them internally.

Best way to visualize it is like a donut with a stick in the middle of the hole.
The stick is your antenna.
The 3dbi antennas are nice, round, and fat type donuts. 
As you go up in gain, you have to get the gain from somewhere, so the donut flattens out, till its a pancake
A lot like this....

Here is a plot which includes the 3D image of a higher gain omni.
See how to get the gain, the elevation has to be flatter.

Note: these polar plots are for a vertical orientated antenna... Just like a Wi-Fi router usually has.
 


Yagi or patch antenna 
These antennas have elements in them and often tend to be longer or bigger in every dimension vs the omni.
Their polar plots tend to look something like this:


Notice more gain out the front than the back.
The vertical beamwidth can be circular like this one shows, or it can be flattened - again, like the pancake idea, but still usually teardrop shaped.
 
So, high gain omni or not?
Depends. If you are mostly country driving, then yes, high gain with a very narrow vertical beamwidth can be really helpful. Reach far out either side of the road and get all you can. tbg has seen some of the kismet rigs have two Yagi antennas pointed left and right to try and achieve just this sort of laser focus.
If you are in a city with a LOT of high rises or around a lot of multi-story apartments, then no, the narrow beamwidth will miss a lot of the top floor SSID emitters. 
This is why a lot of folks will run 2 builds of the wardriver UK / SS, one with 3dbi antennas and one with 6 or 8, perhaps even 12dbi stick antennas attached.

Cross polarization.
If one antenna is vertical, and the other is horizontal, you should be able to see now how the two patterns don't line up. You will lose at least around 3db (half your signal).
Its generally accepted that 99.9999% of WiFi antennas are vertically polarized, so the receiving antenna should be the same.

Knowing all this now, can you start to get a feel for not only what gain each of these antennas in this photo has, but also what their patterns might look like and what sort of wardriving each would be best suited for?

 

----------------------------------------------------------------------------

Bingfu '9dbi' dualband magmount

One antenna that tbg almost constantly sees in photos and talked about breathlessly on Discord.

tl;dr This is a horrible antenna on 2.4 and a random bit of wire on 5. Toss it in the trash.



As soon as he saw it, tbg knew it was an ugly mess.
It is a dead nuts copy of the ADSB antennas from 10 years ago that many aircraft tracking folks bought in large numbers and tossed out in short time.

The issues with this antenna are many fold.
Starting here.....

Peel the base sticker off to see the magnets. Yes, there are two of them.



The metal base of the antenna really should be touching the ground plane of the thing that it's on.
The sticker stops that, but also the bottom most magnet is actually recessed below the base of the other magnet. The job of the sticker is to retain the magnet!
Many folks have complained about these antennas blowing off the roof at low road speeds, its because the magnet is crap (and below the edge of the base).
Also, the two magnets bouncing around on the car roof create noise as they click together. (If you use SDR software in waterfall mode you can clearly see this happen)

Next up is the way they 'attach' the coax to the base.



Half the antennas thebaldgeek has pulled apart over the years to replace the coax, the original has not been touching the alloy base.
It's just been floating around in the base. Thus, the ground wire becomes an open circuit 'antenna' for noise.


The coax is not even coax. It's just stranded wire.
Horrible at 1090Mhz that ADSB uses, imagine how horrific it is at 2.4Ghz and 5Ghz.....


Hard to see, but under the heat shrink the die used to crimp the SMA on is the wrong size and really the heat shrink is doing more work than it should.

tbg knows all this because using ADSB as the signal source is easier to quantify than war driving, and they are much the same antenna.

At 2.4Ghz the antenna dimensions are so so. The dual coils and top loading sleeve give it about 5db gain at most. The size of the coils are about spot on for 2.4 WiFi, like wise the space between the coils is about right to keep things in phase and push the radiation pattern down from the sky and thus make a bit of gain out and around the antenna.

At 5Ghz, its utter crap. Everything is wrong with this antenna on 5g WiFi. The coils do not make sense and the length is very wrong in every way. This will cause the 'gain' pattern to totally fall apart. At best this antenna has around 0db gain at 5Ghz, probably less.
The 'coax' at 5Ghz will be so lossy that any 5g WiFi signal is pretty much a fluke or only AP's very close to the antenna.

This antenna should NOT be thought of as a dual band option. 

Quick war walk with a DIY ESP32C5 Biscuit and an Alfa dual band antenna (from the MIMO USB adaptor) sees 29 SSIDs in tbgs back yard. The BugFoo antenna sees 4.

A lot of folks point to this antenna test repo: https://github.com/FusedStamen/antenna-database

I have quite a bit of respect for Mr Fused, he really seems to know what he's doing. I am not sure how the test of these antennas came up so well. I would have thought his test process that is so clearly laid out would have shown up these issues.

tbg suspects these antennas are praised for two reasons.
1. Folks don't quantify their rig builds with a reference drive.
2. Folks put one of these antennas on the roof of the car and even though it performs like crap, just having SOME antenna OUTSIDE the car makes it go 'wow' numbers wise and so the antenna gets the (misplaced) praise. 

So now you have a problem.... If you have them, have you quantified them? If you are looking to buy them, do you feel confident in testing them and repairing them and then testing your repair?

Speaking of repairing them.....
thebaldgeek has been asked for a link to the SMA coax crimping tool he uses.... BUT, he knows if he drops the link here, people will just buy it without reading.

The issue is more complicated than the crimping tool.
You HAVE to look at the signal chain backwards!

Start at the antenna.
1. What sort of coax can be used on the antenna?
What sort of coax are YOU going to standardize on?
How long are your runs in general? Do you use an LNA mounted AT the antenna every time?
How are you going to get the coax from the roof into the car?
Is your coax of choice future proof? We already have Wifi 6,7 and 8 is in the works....
2. Once you decide on the type of coax, that sets your outer diameter that you then need to buy the SMA crimp connector to match said coax. In other words, you MUST buy an SMA crimp connector that matches the coax!
3. NOW you can buy a crimp tool with matching jaws for that size SMA collar.

Ahhh, the joys of building a wardriving rig. Never a dull non-learning moment.


Acceltex antenna

<Sept 2026 tbg to flesh this section out>
The Acceltex antenna (the white dome ones) also gets a lot of wardrive community praise. tbg would like to go on record for sitting on the fence about this style.


They claim to offer 4dbi gain on 2.4 and 6dbi on 5Ghz.
Perhaps. They seem a bit short for those sorts of numbers. (tbg also suspects that gain is at the antenna, NOT at the end of the coax!)

The fact that you have 4 or 6 of them in a very tight space is Ok for receive only. The manufacturer is at least upfront with polar plots of the weirdness that goes on jamming them together.

There is nothing printed about the total end-to-end coax length, so tbg is not sure about using them on MIMO adaptors where exact matching length is pretty critical.

They use RG58 coax. Meh at best on 5Ghz. (KMR400 loss at 5ghz at 6 feet = 1.5db, RG58 = 3.5db - Acceltex just kissed half your gain goodbye)

No way to fit an LNA (or six) in that tight of space under the dome.

They are about $50 each and tbg just does not have the coin to spare to buy and test one and after the test will probably never use it. He MUCH prefers to use one quality antenna (Alfa dual band outdoor vertical stick), quality LNA (Nooelec WB), quality coax (KMR400) and a 4, 8 or 16 port RF splitter in the car. That simpler/cleaner setup will have quite a bit more gain and higher SNR than running a few of the Acceltex antennas.

Jump to top

--------------------------------------------------

Comments

  1. Very much appreciate this post. Thanks.
    Read something about a Wigle Fin v2 being on the horizon. Any results to look forward too?

    ReplyDelete
  2. Note that wardriver.uk code 1.3 (hopefully an official build coming soon) will have a new option to disable Bluetooth scanning on the "B" side of the wardriver. This makes the unit concentrate solely on WiFi, and helps detection as the channel order is slightly different on that radio. @pejacoby

    ReplyDelete
  3. RTL8812BU is NOT the same as RTL8821AU :-) Won't even show up on the phone. Should've read my Amazon order closer.

    I've had good results from the Alfa AWUS036NH as ancient 2G adapters go.

    The Panda PAU0D dual antenna is rocking it in 5G, looking forward to comparing with the Alfa AWUS036ACM

    ReplyDelete
    Replies
    1. I fun both the Panda and the alfa ACM. It is a coin toss on any given day which wireless card is going to produce better results. I havent used the magmount to place the antenna outside of the vehicle; but some magnets and a small box could easily do just as well for the alfa as the included magmount does for the Panda, if someone wanted to run exterior to the passenger compartment.

      Great job on the write-up (as always); thanks TBG 🤙🤓

      Delete

Post a Comment

Popular posts from this blog

tbg.airframes.io Users Guide

Call signs on tbg.airframes