All capabilities
Airspace Watch — RF Noise, Rogue Emitters & Jamming Needs edge adapter

Storm Sentinel

Deauth Storm Sentinel: Management-Frame Flood Watch

Catches the flood of kick-off messages that is what most 'camera jamming' actually is.

Contested Space · Contested capability

What this capability does not do.

Does not act.

Latent emits a reading. It does not switch cameras, unlock cages, cut power or open a ticket. Your VMS, PoE switch or access controller does that, on your side of the boundary. A Latent blueprint contains no executable code, no remote URLs and no device secrets — by schema, not by policy.

Does not identify.

No face, no plate, no MAC, no device identity, no payload. A movement signature is a shape moving through a room, not a person. Nothing stored here resolves to an individual.

Does not survive everything.

A jammer already running when you took the baseline is invisible. The baseline must be captured in a verified-quiet window, and a baseline of unknown provenance is worth nothing.

Observable
Not defined. This capability has no reviewed runtime adapter, so nothing is measured yet.
Retention
Nothing is computed, stored or exported: there is no runtime path for this entry yet.
Node minimum
1 node
Export policy
Pilot only — Not for production evidence. This capability has no reviewed runtime adapter yet.
Chain of custody

Node identity

Each node mints its own key over USB, in your hand. Physical possession is the root authority: a device that cannot prove physical presence is refused enrollment outright. A cloud pairing PIN is a weaker ownership claim and is never treated as liveness.

Reading provenance

Every reading is attributable to a device id, profile id, hardware id and firmware version recorded at install and verified by mutual HMAC-SHA256 proof over an LFW1 nonce exchange. A node whose proof did not verify is marked untrusted, not merely offline.

Install attestation

Completing an installation is a high-risk action. It requires your explicit browser approval, an approval snapshot that still matches, an idempotency key, and heartbeats less than three minutes old. There is no silent commissioning.

How enrollment works

Properties you can map to your own controls

  • No optical sensor is present in this capability’s node set.
  • Raw CSI does not leave the node. Only derived event rows are stored or exported.
  • No stored identifier resolves to a person. Where access events are correlated, that correlation happens in your systems, against your logs.
  • The runtime executes on the node and in your browser. This capability has no cloud inference path.

These are properties, not certifications. Latent does not assert compliance with any framework on your behalf.

A capability description, not an incident record.
Readiness Needs edge adapter

The evidence is proven or strong, but this capability still needs a capability-specific ESP32 or Rust runtime adapter.

Evidence Strong theory Supported hypothesis

Published physics or adjacent results support the hypothesis; capability-specific product and site validation are still required.

Runtime family Not mapped

No browser runtime is assigned to this capability yet.

Why live sensing is unavailable

No capability-specific offline runtime is mapped yet. Keep the feature visible, explain the required edge adapter, and never fabricate a live result.

Intended capability

Validate this target only after a capability-specific adapter and ground-truth study exist: Counts 802.11 deauthentication and disassociation frames on watched channels and pages on a storm, reporting rate, source and target fan-out and the zone of the strongest injection point. Most real-world 'camera jamming' is not RF jamming at all — it is this. Attribution names an injection zone, never an attacker: source addresses in these frames are trivially spoofed. On 802.11w-protected networks forged deauths stop working as an attack and remain countable as evidence that one was attempted. On the opt-in camera-evidence tier, a storm verdict with zone attribution may trigger a single bounded local snapshot of the strongest-injection zone — event-gated, detected on-device, stored locally, never a stream — with its defeat stated: a deauther on a directional antenna can inject from well outside any fixed cone the lens watches.

This describes the intended outcome. Readiness is needs edge adapter, evidence is class B, and a catalog mapping or recording is not proof of this outcome at a real site.

Solution blueprint

See the environment before installing it.

This exact kit is one of 191 first-class designs. It includes geometry, objects, nodes, wording, scenarios, installation, limitations, and catalog-bound readiness.

Needs edge adapter

No rendered revision is available yet.

Bundled recording

A related Airspace scene

This is one recorded vertical scenario. It is not separate validation of every capability in the catalog.

01 The physics

Deauth and disassoc are unencrypted management frames on the same channel as the data traffic they attack, so a promiscuous receiver parked on that channel counts them directly — no inference, no model, just frames. Their per-frame RSSI across the mesh gives the same node-ranking constraint that localizes any other emitter, which is what turns a count into a zone.

02 Shared processing path

Promiscuous management-frame capture on watched channels -> rate and source/target fan-out counters per window -> threshold on rate AND fan-out jointly (mass roaming after an AP reboot trips rate alone) -> MVE zone attribution over per-frame RSSI ranking -> bounded event row with counts, channel and zone -> on the opt-in evidence tier, the storm verdict plus zone gates one bounded local snapshot of the strongest-injection zone.

This is a capability design path. Components may be shared with other catalog entries; it is not presented as a unique algorithm.

03 Validation plan

Blocked on the link-stats host import that exposes management-frame counters to the edge module. Own-hardware plan: three nodes on the camera VLAN's channel, scripted deauth floods at four rates against two targets, plus an AP reboot to generate legitimate mass roaming; report detection latency, injection-zone accuracy, and the false-page rate across a week of normal roaming.

04 Commercial hypothesis

'Storm Sentinel' — the attack this vertical's own threat story names, caught by the cheapest sensor in the catalog, sold to the netsec lead with the channel-coverage trade printed on the box: watching more channels costs either more nodes or scan duty taken from the sensing mesh.

A quiet reading is not an all-clear. If nodes are stale, degraded or jammed, this runtime says so explicitly. It never infers safety from missing data.