Know what’s in the air around you.

ArgusZero is a Spatial Awareness Platform. It listens to Wi-Fi and Bluetooth, learns what is normal for your space, and flags what is not. Everything stays on your machine.

Pre-release. No tagged version yet.

Rings contracting toward a listening hub Concentric rings contract toward a hub at the center while dots mark nearby radios. Two dots are highlighted as flagged. This is an illustration, not live data. listening

Illustration, not live data. The rings contract because the hub only listens; a radar pulse would move the other way.

Built for people with real reason to ask what is watching them.

Stalking and domestic violence survivors, journalists, activists, and the advocates and practitioners who support them.

Quietly watching. Plainly reporting.

Listens, and only listens.

Wi-Fi capture has no transmit path in the code, and a standing test keeps it that way. Bluetooth scanning is passive by default. It records management frames and advertisements, and it does not read the contents of your traffic.

Learns the room.

A baseline of the devices and networks in your space, so a new or unusual one stands out.

Flags attacks.

Deauthentication floods, rogue and cloned access points (evil twins), KARMA-style probe answering, and handshake-capture attempts, as they happen.

Recognizes hardware.

Checks radios against an offline vendor registry and curated fingerprints for drones, trackers, and cameras, and says how sure it is.

Notices who keeps turning up.

Register your own devices, and it reports unfamiliar ones that repeatedly appear beside them. In a fixed space that is recurring presence; in motion, a possible follower.

Says when it can’t see.

When capture has stopped or a check could not run, the screen says status unknown instead of all clear. A standing test checks the operator pages for this.

One machine. No cloud.

A receive-only capture feeds a local database. Analysis turns that into one screen.

  1. RadioWi-Fi on 2.4 and 5 GHz, and Bluetooth Low Energy.
  2. CaptureA receive-only socket for Wi-Fi and a passive scanner for Bluetooth.
  3. DatabasePostgreSQL, on the same machine.
  4. AnalysisBaselines, attack detection, fingerprints, recurring presence.
  5. VerdictOne screen: what needs a look, and why.

No phone-home.

No cloud service, no telemetry, no remote calls. The vendor registry and the web assets ship inside the repository.

Optional sensor nodes.

A second receiver can add position context. The hub detects the same things without any node.

Four answers. One of them is “I don’t know.”

The top of the dashboard answers in four tiers. The fourth exists on purpose.

ALL CLEAR

No high or critical alerts in the last 24 hours.

REVIEW

At least one high-priority alert to read.

ATTENTION

At least one active critical alert.

STATUS UNKNOWN

The alert check did not complete. This is not an all-clear.

Without the fourth tier, a failed check and a clean room look the same. The platform treats that as a defect.

What it sees. And what it can’t.

It covers the Wi-Fi and Bluetooth bands. Everything else is a physical limit of the antenna and the radio, and the platform says so.

The chart below is a visual summary of the three lists that follow it.

Sees

  • Deauthentication floods
  • Rogue and cloned access points (evil twins)
  • KARMA-style probe answering

Sees in part

  • Handshake-capture attacks The active kind only. A purely passive capture emits nothing to see.
  • Drone Wi-Fi control links Matched by vendor and network name patterns, so imperfect.
  • Bluetooth trackers Noticed, but rotating addresses limit how well one can be followed.
  • Drone Remote ID Broadcasts are noticed, not decoded yet.

Cannot see

  • Cellular devices and IMSI catchers
  • Sub-GHz radios
  • Software-defined radios, and anything that does not emit valid Wi-Fi or Bluetooth frames
  • Devices that only listen
  • Wired cameras and microphones
  • 6 GHz Wi-Fi, for now The software is ready; the current adapter is not.

The platform detects radios, so it detects a person carrying a phone. That is a useful primitive, not a fence.

Honest about its limits.

These come from the project’s own documentation, and they apply before anything else on this page.

  • It cannot tell that two changing addresses belong to one device.Modern phones rotate their Wi-Fi and Bluetooth addresses. The project tried to link them, found the approach cannot work with the signals available, and closed that work. It does not claim to re-identify rotating devices.
  • Bluetooth supports Wi-Fi findings. It does not stand alone.The fields that survive address rotation carry too little information to alert on by themselves.
  • It has been trained and tuned in an ultra-dense environment, and no others yet.
  • Silence is not safety.Capture gaps, out-of-band radios, and wired devices all look the same as a quiet room.
  • The machine holds the evidence.The hub keeps a record of nearby device addresses. Against an adversary with physical access, full-disk encryption matters.

Common questions.

Does ArgusZero transmit anything?

Wi-Fi capture has no transmit path in the code, and a standing test keeps it that way. Bluetooth scanning is passive by default. An opt-in setting turns on active Bluetooth scanning, which does transmit, so leave it off if the machine has to stay invisible.

Can it find hidden cameras and bugs?

Only devices that radiate Wi-Fi or Bluetooth. It recognizes some camera hardware by vendor and fingerprint, but a wired camera, or a recorder that never transmits, is invisible to it. It complements a physical sweep and does not replace one.

Can it tell me who is following me?

It reports unfamiliar devices that repeatedly appear beside your own registered devices. That is a signal, not proof. It detects radios, not people, and rotating addresses limit what it can link.

Does it work offline?

Yes. There is no cloud service, no telemetry, and no phone-home. Installing it needs a connection to fetch dependencies and container images. Running it does not.

Is it free?

Yes. ArgusZero is free software under the GNU Affero General Public License v3.0 or later, and the full source is in the repository. It is pre-release software.

Run it on your own hardware.

ArgusZero is pre-release software. Read the install guide, including the section on what silence means, before relying on it.

What you need

  • A 64-bit Linux machine that can stay on. Ubuntu 24.04 and Debian 12 are the tested distributions.
  • Docker with the Compose plugin, and git.
  • A USB Wi-Fi adapter that supports monitor mode. The MT76, RTL8812AU, ATH9K_HTC, and MT7601U chipset families are named as working.
  • An SSD or NVMe drive. Budget at least 16 GB.
  • A Bluetooth 5.x controller is optional.

Install

git clone https://github.com/arguszero/arguszero.git arguszero
cd arguszero
scripts/provision_db_password.sh
docker compose -f deploy/docker-compose.yml up -d
./install.sh

Then open http://127.0.0.1:8000/ on the machine itself. The install guide covers first run, verification, and troubleshooting.