Home > Features > Counter Surveillance

Counter Surveillance

Counter Surveillance looks for Bluetooth devices that repeatedly appear near you as you move between places. It uses evidence tiers instead of presenting a score as a probability, and it keeps fixed surveillance infrastructure separate from mobile tracking candidates.

All analysis runs locally in the Biscuit Manager app.

During an active wardrive, Counter Surveillance continues processing received observations and locations while the map is closed or the app is in the background. Returning to the map shows the current evidence without restarting the session.


The Counter Surveillance Dashboard

Open Wardrive History, then select the Counter Surveillance tab. The dashboard analyzes eligible observations from saved wardrives and recent Counter Surveillance runs. It defaults to the previous 7 days. To use 7, 14, or 30 days, open Settings > Counter Surveillance > Report History.

The dashboard includes:

  • Data coverage showing wardrives, focused runs, active days, independent sightings, identities, and elevated candidates
  • A date-range activity chart and evidence-tier distribution
  • A source mix separating ordinary wardrive evidence from focused Counter Surveillance runs
  • Most-tracked mobile devices ranked by evidence tier, repeated sightings, separated locations, sessions, and travel span
  • Observed devices that do not yet have enough evidence to suggest tracking
  • Surveillance infrastructure such as Flock and Axon devices, listed separately rather than labeled as followers
  • Trusted devices that you marked as safe
  • A detail view with selected-range totals, the strongest 12-hour evidence window, signal history, source counts, an observation timeline, and color-coded map paths for each session
  • Device-list filters for All, Review, Observed, Infrastructure, and Trusted without changing the report totals or charts
  • Distinct tile accents for BLE, Flock, Axon, and Wi-Fi identities, while evidence-tier colors remain reserved for risk

Existing native wardrives from the previous 30 days are included automatically. Imported and combined sessions are not used for tracking analysis because their identity and timing history may not be comparable to a native Biscuit capture.

The selected report range recalculates rankings, sightings, locations, sessions, coverage, and charts. Thirty days remains the maximum available test history. A tracking tier is still based on the strongest bounded 12-hour episode inside the selected history, so unrelated sightings spread across a month are not presented as one continuous event.

For devices seen in more than one session, the detail map assigns each wardrive or focused run its own line and point color. The legend identifies the source and start time, and lines never connect observations across different sessions.

Each device tile includes its type, the selected-range sighting/location/session totals, a concise evidence reason, recency, signal and travel context, and a visual split between ordinary wardrive and focused Counter Surveillance sightings. Type color identifies what the device is; the Observed / Possible / Likely / Urgent pill identifies the evidence state.


Evidence Tiers

Counter Surveillance uses four plain-language tiers:

  • Observed — the device was seen, but there is not enough separated-location evidence to suggest tracking.
  • Possible — the device recurred over enough time and distance to deserve review.
  • Likely — the device appeared repeatedly at three or more separated locations with a stronger time-and-distance pattern.
  • Urgent — the strongest recent movement-correlated evidence. Review the map and surrounding context promptly.

These tiers are evidence labels, not certainty percentages. Shared commutes, neighboring vehicles, popular Bluetooth accessories, and randomized device identifiers can still create coincidences.

In Settings > Counter Surveillance, you can set the pre-start baseline cooldown, choose the default report range, change how much evidence the sensitivity setting requires, choose whether alerts begin at Possible, Likely (recommended), or Urgent, and configure notification sound. The baseline cooldown is adjustable from 10 to 300 seconds and defaults to 10 seconds. Sensitivity remains available because it actively changes the evidence thresholds used for these tiers. Counter Surveillance appears directly below Wardriving in Settings; these controls are separate from Wardriving settings.

Choosing a Sensitivity

The first time you turn on the Counter Surveillance shield from the Wardrive screen, a compact Choose sensitivity dialog asks you to select High, Medium, or Low. Nothing is selected in advance, and canceling leaves Counter Surveillance off. You can change the setting later under Settings > Counter Surveillance, where the complete thresholds and evidence guidance remain available.

The sensitivity controls when a mobile identity first becomes a Possible tracking candidate:

Sensitivity Independent sightings Separated locations Time span Travel span
High 2 2 5 minutes 250 m
Medium 3 2 10 minutes 500 m
Low 4 2 20 minutes 750 m

Every requirement in the selected row must be met inside the same evidence window. Time alone never declares a follower. For example, leaving Medium running for 10 minutes without seeing the same stable identity at least three times across two separated locations and 500 meters of travel produces no candidate. Likely and Urgent require stronger patterns than the table above, and your alert setting can still wait for one of those higher tiers before notifying you.


What Counts as an Independent Sighting

Repeated packets received while you remain in one place do not count as repeated tracking encounters. At most one observation per identity per minute can become an independent sighting, and observations within 200 meters of one another belong to the same location cluster. The app then looks for the same mobile identity across separated places inside a rolling 12-hour correlation window.

Counter Surveillance rejects coordinates without a usable fix and observations whose reported GPS accuracy is worse than 75 meters. Moderate or strong signal at multiple separated locations can add useful context, but signal strength alone cannot prove that a device is following you.

Only mobile BLE identities are eligible tracking candidates. Wi-Fi access points are treated as environmental context because they are normally fixed in place, while Flock and Axon detections are shown as surveillance infrastructure rather than followers.

Counter Surveillance must be able to recognize the same identity again. Many phones, wearables, and trackers rotate or randomize their Bluetooth address; when that happens, the app may see one physical device as several unrelated identities and cannot reliably connect their sightings. A missing candidate therefore does not prove that no device traveled with you.


Running a Counter Surveillance Session

  1. On the Wardrive screen, tap the shield button next to Start to turn Counter Surveillance On (a toast confirms it). It works best with the BT Only or All scan mode, since it needs Bluetooth to spot devices following you.
  2. Tap Start. The configured pre-start baseline cooldown runs before the wardrive begins; tap the X on its toast if you want to skip the remaining cooldown and start immediately.
  3. Drive, walk, or bike through multiple meaningfully separated locations.
  4. Expand the CS side panel to review the current evidence summary, then tap View Candidates for the candidate list.
  5. Stop the session and save it. Its wardrive report includes a Counter Surveillance summary card, and the full analysis is on the dashboard.
  6. Open Wardrive History > Counter Surveillance to compare the run with the selected 7-, 14-, or 30-day history.

Short or stationary sessions often remain at Observed, which is expected.

The live Nodes and CS panels share the part of the map previously used by the Node list. Each panel collapses independently into a translucent side button, so the map’s GPS and battery readouts stay visible. A collapsed CS button calls attention to a newly elevated candidate and keeps a count badge available after you review it.

Pre-Start Baseline Cooldown

Every Counter Surveillance start includes its own baseline cooldown. Set its duration once under Settings > Counter Surveillance; the app accepts 10 to 300 seconds and defaults to 10 seconds, so there is no per-run duration dialog.

During the baseline, a compact toast appears at the top of the app. The circular countdown on the left shows the remaining seconds and fills as the baseline approaches its end. Tap the X on the right to skip the remaining cooldown and start the wardrive immediately. Otherwise, the wardrive starts automatically when the countdown finishes.

When the countdown finishes naturally, the completed baseline records devices already present at your starting point. Those identities remain available as starting-point context for Counter Surveillance and use the same High, Medium, or Low tracking-candidate threshold as every other mobile identity. A baseline identity is neither declared safe nor forced to meet a slower evidence tier.

For the ordinary wardrive, every WiFi or Bluetooth identity in a naturally completed baseline is ignored for the rest of the session, even if it is heard again after the countdown. Those identities do not enter the wardrive map, stats, achievements, report, exports, or uploads. Counter Surveillance still uses the completed baseline and later sightings for its own evidence analysis.

Skip starts clean. If you tap the X before the countdown finishes, the app discards all partial baseline observations and partial wardrive-exclusion identities, then begins the wardrive immediately. Time and devices seen before Skip do not count as baseline evidence and do not make later candidates harder to qualify.

This baseline is separate from the wardrive itself: it does not count toward the wardrive duration and is not written to the wardrive session journal.


Marking a Device as Safe

From a device detail view, choose Mark as Safe when you recognize an identity as yours or otherwise trusted. In the live candidate list, you can also swipe a row toward the leading edge to reveal the same action.

Marking a device safe suppresses it from Counter Surveillance rankings and alerts only. The device remains in ordinary wardrive data and exports. You can remove a device from the trusted list from the dashboard.

This is intentionally separate from the wardrive blacklist, which excludes blocked identities from wardrive results and exports.


Interpreting Results Safely

Counter Surveillance provides investigative evidence, not proof of intent or ownership. Before acting on a result:

  • Review whether sightings occurred at genuinely different locations.
  • Check whether the times align with your movement.
  • Consider shared routes, coworkers, neighbors, public transit, or equipment installed in a vehicle.
  • Look for identity changes that could indicate address randomization.
  • If you believe you are in immediate danger, move to a safe public location and contact local emergency services.

Saved reports can still be shared or exported for your own records.