Digital Force Protection

Know your environment before your adversary does.

Passive device environment awareness that tells operators what wireless devices are present in their area of operations, detects anomalous infrastructure like rogue access points and IMSI catchers, identifies co-traveling device patterns, and assesses blue-force electronic exposure. Ubiquitous Technical Surveillance (UTS) for sanctioned observation operations - passive collection only, no active electronic warfare - giving you the same wireless picture an adversary would build, so you see it first.

The Problem

Your force radiates. Every phone, every Bluetooth device, every WiFi access point broadcasts presence data that an adversary can collect, correlate, and exploit. Most units have zero visibility into their own electronic signature or the surveillance infrastructure around them. A rogue AP near the TOC exfiltrates data. An IMSI catcher near the gate maps every phone that passes. A co-traveling device follows your patrol across three positions. You don't know because you've never looked. This is Ubiquitous Technical Surveillance - the adversary is already doing it to you. DFP gives you that same passive observation capability under sanctioned, auditable operations. No active EW. No jamming. Observation and assessment only - but with the depth to know what devices are present, where they are, who they belong to, and what that means for your security posture.

Who Has This Problem

Force Protection & Security TeamsCounterintelligence OfficersOPSEC ManagersSOF & Conventional Unit CommandersCritical Infrastructure SecurityMaritime Fleet SecuritySite & Perimeter Security
Digital Force Protection overview showing risk posture, anomaly feed, and environment statistics
Device census with RSSI sparklines, anomaly scores, heatmaps, and manufacturer enrichment
WiFi Position Service overlay with device census detail panel and reverse geocoding from the Location Intelligence Service
Collector onboarding page with self-guided wizard for MQTT and WireGuard provisioning
Cell tower map showing all unique towers connected to by collectors with baseline correlation

Key Workflows

01Device census and triage: every WiFi, Bluetooth, and cellular device in your environment catalogued, triaged (Blue / Flagged / Ignored), and tracked over time with signal history and first-seen/last-seen provenance
02WiFi Position Service (WPS) geolocation: devices spotted by collectors are geocoded through public WPS databases, placing them on the COP with estimated position even from a single collector observation
03Location Intelligence Service (LIS) reverse geocoding: WPS positions are enriched with address-level context from the Empyrean LIS, turning a MAC address sighting into a street address and building identity
04Anomaly detection: statistical scoring engine (per-device RSSI deviation plus aggregate environment energy drift) identifies new devices, signal strength changes, and abnormal device churn without fixed thresholds that false-positive in busy environments
05Cell tower anomaly detection: unknown towers, protocol downgrades, carrier blackouts, and IMSI catcher indicators cross-referenced against OpenCellID and FCC ULS baselines
06GNSS integrity monitoring: per-constellation, per-device AGC and C/N0 baselines detect spoofing and jamming with burn-in calibration that adapts to chipset variance
07Co-traveler correlation: statistical similarity scoring across space-time bins identifies devices that appear together across multiple collector positions, surfacing surveillance tails you did not know were there
08Target Lists: user-defined groupings of devices for persistent monitoring. Group related devices by mission, person, or pattern of life and track the group as a unit on the COP with consolidated alerts
09Kismet integration: AP association history analysis to fingerprint devices by the access points they have previously connected to, enabling identity correlation even when MAC addresses rotate
10Blue-force exposure assessment: detect when friendly devices broadcast identifiable information (device names, unit identifiers, rank patterns) and alert on OPSEC violations before the adversary exploits them

Capabilities

Passive RF/WiFi/Bluetooth/Cellular/GNSS collection from Android phones (Network Survey), Kismet nodes, and EFF Rayhunter
Ubiquitous Technical Surveillance (UTS): sanctioned passive observation giving you the wireless picture an adversary would build - observation only, no active EW
WiFi Position Service (WPS) geolocation with public database correlation for device positioning from single collector observations
Empyrean Location Intelligence Service (LIS) for reverse geocoding: derive street addresses and building identity from WPS coordinates
Statistical anomaly engine with configurable burn-in, triage-aware thresholds, and learning mode
Infrastructure baseline comparison against OpenCellID, FCC ULS, WiGLE, and operator site surveys
Co-traveler detection with multi-collector correlation and targeting ratio analysis
Kismet AP association history: fingerprint devices by their previously-connected access points for identity correlation across MAC rotation
Target Lists: user-defined device groupings for persistent monitoring, map visualization, and consolidated alerting
GNSS spoofing and jamming detection with per-constellation integrity scoring
Approaching sensor detection: know when a device is getting closer to your position, not just that it exists
Multi-collector trilateration: estimate device position from two or more collectors with confidence ellipse
Blue exposure pattern matching with configurable detection rules (substring, regex, exact)
Edge-deployed, air-gappable: works on a single vessel mid-ocean or a FOB with zero internet
Alert lifecycle (new, acknowledged, resolved) with triage dispositions and audit trail
Policy engine integration: 18 DFP condition types for cross-domain compound threat detection
COP overlay with collector-centric clusters, cell tower markers, and WPS-derived device positions
TAK integration via CoT output for exercise and operational interoperability
Collector blue-force tracking on the COP without requiring mesh network radios

Platform Integration

DFP is its own analytical domain with its own workspace, ingest pipeline, and engines. It cross-correlates with EMSO (frequency, position, and time join for SDR corroboration), provides cellular RSRP ground-truth that calibrates EMSO propagation models, feeds the Policy Engine with 18 condition types for automated response, and renders collector positions and anomaly clusters on the COP. GNSS integrity observations complement SSA's space-side constellation awareness. Future integration with Cyber Operations via MAC address join and with Narrative Intelligence via geospatial device-to-identity correlation.

← All capabilities

Related Resources & Insights

Resource8 min read

What is Digital Force Protection?

Digital Force Protection explained: countering ubiquitous technical surveillance through device census, co-traveler analysis, signature management, and fused defensive measurement.

Resource11 min read

What is Intelligence Fusion?

Intelligence fusion explained: JDL/DFIG model, multi-INT disciplines, JADC2, and what fusion means for civilian operators.

Resource11 min read

What is Maritime Intelligence?

Maritime intelligence explained: AIS limits, dark vessels, beneficial ownership, sanctions risk, and multi-INT fusion at sea.

Resource7 min read

What is OPSEC?

OPSEC, UTS, and Digital Force Protection explained: the five-step process, five threat vectors, and signature management.

Resource13 min read

What is ATAK?

ATAK explained: TAK clients, EUDs, data packages, mesh networks, federation, plugins, and the CoT protocol that ties it together.

Resource26 min read

Defense & Intelligence Glossary

Defense & intelligence glossary: acronyms and terms for EMSO, C-UAS, JADC2, sensor fusion, SSA, CTF, entity resolution, and TAK.

Resource13 min read

What is Counter Threat Finance?

Counter Threat Finance (CTF) explained: DoDD 5205.14 doctrine, CTF vs. AML, sanctions, shell companies, TBML, and operational software.

Resource10 min read

What is Entity Resolution?

Entity Resolution explained: deterministic, probabilistic, ML, and graph methods for matching records to real-world identities.

Resource13 min read

What is Narrative Intelligence?

Narrative Intelligence (NARINT) explained: detecting and countering influence operations, DISARM framework, CIB, and OSINT.

Resource13 min read

What is EMSO?

EMSO explained: Electronic Warfare, EMBM, JEMSO, Electronic Order of Battle, CEMA, spectrum management, and operational software.

Resource12 min read

What is a Common Operational Picture?

Common Operational Picture (COP) explained: why most COPs fail, display vs. decision surface, edge deployment, and true fusion.

Resource13 min read

What is Space Situational Awareness?

Space Situational Awareness (SSA) explained: orbital tracking, TLEs, the Space Surveillance Network, and counterspace threats.

Resource12 min read

What is Counter-UAS?

Counter-UAS (C-UAS) explained: sensors, fusion, effectors, legal authorities, and layered drone defense for military and critical sites.

Resource12 min read

What is JADC2?

JADC2 explained: why top-down fails, what sensor-up architecture means, and why edge-deployed fusion survives contact.

Resource11 min read

What is Sensor Fusion?

Sensor fusion explained: state estimation, data association, multi-hypothesis tracking, identity provenance, and edge deployment.

Research43 min read

High-Powered Microwave (HPM): From Hard Kill to Residual Risk

3,400 Monte Carlo runs reveal HPM's service-rate ceiling, residual warhead hazard, and cascade failure against 40-400 drone swarms.

Research48 min read

The Devil Dog and the Dragon: USMC IADS vs. PLARF Cruise Missile Saturation

USMC MRIC vs 60 CJ-10 cruise missiles: 92.7% kill rate, then magazine exhaustion at T+28:37. The Marines need more rounds.

Research34 min read

Quantifying Layered Naval Defense Against Hypersonic Glide Vehicles

DF-17 HGV vs Arleigh Burke: 50 Monte Carlo seeds, SM-6 at 23% kill rate, PAC-3 at zero. The timeline is the constraint.

Insight73 min read

Ubiquitous Technical Surveillance Will Get You Killed on the Streets

How commercial location data, advertising identifiers, co-travel analysis, and data fusion expose military personnel—and what digital force protection can do.

Insight47 min read

Maritime Domain Awareness: The Complete Field Guide

Maritime domain awareness field guide: spectrum, seabed, ownership, and cyber threats that single-domain tools miss.

Insight25 min read

TAK Server on AWS: From Zero to Operational in Under Ten Minutes

Deploy TAK Server on AWS with CloudFormation: TLS, Docker, hardening, and security best practices in under ten minutes.

Insight8 min read

Release Log Vol. 1: Maritime Intelligence & UAS Traffic Management

Empyrean ships Maritime Intelligence, Air Domain Intelligence, and UAS Traffic Management with 20+ data sources and FAA enrichment.

Insight20 min read

The Environment Is Trying to Kill Your Mission. We Want to Mitigate It.

Weather & environmental intelligence that modifies sensor confidence, route feasibility, and UAS BVLOS risk in real time.

Insight73 min read

EMSO Is Everyone's Problem. Let's Do Something About It.

EMSO deep dive: EW history, doctrinal evolution to CEMA, cross-domain effects, and what operators can do about it today.

Insight23 min read

Would the Real Common Operating Picture (COP) Please Stand Up

Most COPs are PowerPoint and uncorrelated feeds. What a real COP requires: fusion, policy, edge deployment, and echelon logic.

Insight7 min read

Building Physics-Backed, Unclassified, Open-Source Defense Research

Introducing Empyrean Defense Research: unclassified, physics-backed wargaming. First drop: 1,500 Monte Carlo sims of DF-17 vs DDG.

Insight37 min read

How the Space Domain Impacts Your Operations

Space domain impacts on EW, ground, maritime, air, and information ops — and what you can do to counter them.

Insight74 min read

Sense, Make Sense, Act: How to Conduct Counter-UAS From Sensors to Deployments

Counter-UAS playbook: 8 sensor types, fusion methods, jam vs. shoot decisions, and layered drone defense for DDIL environments.

Insight12 min read

Why JADC2 Needs Sensor Fusion at the Edge

JADC2 assumes persistent cloud and top-down authority. Operators have neither. Why sensor fusion must live at the edge.

Resource8 min read

What is Digital Force Protection?

Digital Force Protection explained: countering ubiquitous technical surveillance through device census, co-traveler analysis, signature management, and fused defensive measurement.

Resource11 min read

What is Intelligence Fusion?

Intelligence fusion explained: JDL/DFIG model, multi-INT disciplines, JADC2, and what fusion means for civilian operators.

Resource11 min read

What is Maritime Intelligence?

Maritime intelligence explained: AIS limits, dark vessels, beneficial ownership, sanctions risk, and multi-INT fusion at sea.

Resource7 min read

What is OPSEC?

OPSEC, UTS, and Digital Force Protection explained: the five-step process, five threat vectors, and signature management.

Resource13 min read

What is ATAK?

ATAK explained: TAK clients, EUDs, data packages, mesh networks, federation, plugins, and the CoT protocol that ties it together.

Resource26 min read

Defense & Intelligence Glossary

Defense & intelligence glossary: acronyms and terms for EMSO, C-UAS, JADC2, sensor fusion, SSA, CTF, entity resolution, and TAK.

Resource13 min read

What is Counter Threat Finance?

Counter Threat Finance (CTF) explained: DoDD 5205.14 doctrine, CTF vs. AML, sanctions, shell companies, TBML, and operational software.

Resource10 min read

What is Entity Resolution?

Entity Resolution explained: deterministic, probabilistic, ML, and graph methods for matching records to real-world identities.

Resource13 min read

What is Narrative Intelligence?

Narrative Intelligence (NARINT) explained: detecting and countering influence operations, DISARM framework, CIB, and OSINT.

Resource13 min read

What is EMSO?

EMSO explained: Electronic Warfare, EMBM, JEMSO, Electronic Order of Battle, CEMA, spectrum management, and operational software.

Resource12 min read

What is a Common Operational Picture?

Common Operational Picture (COP) explained: why most COPs fail, display vs. decision surface, edge deployment, and true fusion.

Resource13 min read

What is Space Situational Awareness?

Space Situational Awareness (SSA) explained: orbital tracking, TLEs, the Space Surveillance Network, and counterspace threats.

Resource12 min read

What is Counter-UAS?

Counter-UAS (C-UAS) explained: sensors, fusion, effectors, legal authorities, and layered drone defense for military and critical sites.

Resource12 min read

What is JADC2?

JADC2 explained: why top-down fails, what sensor-up architecture means, and why edge-deployed fusion survives contact.

Resource11 min read

What is Sensor Fusion?

Sensor fusion explained: state estimation, data association, multi-hypothesis tracking, identity provenance, and edge deployment.

Research43 min read

High-Powered Microwave (HPM): From Hard Kill to Residual Risk

3,400 Monte Carlo runs reveal HPM's service-rate ceiling, residual warhead hazard, and cascade failure against 40-400 drone swarms.

Research48 min read

The Devil Dog and the Dragon: USMC IADS vs. PLARF Cruise Missile Saturation

USMC MRIC vs 60 CJ-10 cruise missiles: 92.7% kill rate, then magazine exhaustion at T+28:37. The Marines need more rounds.

Research34 min read

Quantifying Layered Naval Defense Against Hypersonic Glide Vehicles

DF-17 HGV vs Arleigh Burke: 50 Monte Carlo seeds, SM-6 at 23% kill rate, PAC-3 at zero. The timeline is the constraint.

Insight73 min read

Ubiquitous Technical Surveillance Will Get You Killed on the Streets

How commercial location data, advertising identifiers, co-travel analysis, and data fusion expose military personnel—and what digital force protection can do.

Insight47 min read

Maritime Domain Awareness: The Complete Field Guide

Maritime domain awareness field guide: spectrum, seabed, ownership, and cyber threats that single-domain tools miss.

Insight25 min read

TAK Server on AWS: From Zero to Operational in Under Ten Minutes

Deploy TAK Server on AWS with CloudFormation: TLS, Docker, hardening, and security best practices in under ten minutes.

Insight8 min read

Release Log Vol. 1: Maritime Intelligence & UAS Traffic Management

Empyrean ships Maritime Intelligence, Air Domain Intelligence, and UAS Traffic Management with 20+ data sources and FAA enrichment.

Insight20 min read

The Environment Is Trying to Kill Your Mission. We Want to Mitigate It.

Weather & environmental intelligence that modifies sensor confidence, route feasibility, and UAS BVLOS risk in real time.

Insight73 min read

EMSO Is Everyone's Problem. Let's Do Something About It.

EMSO deep dive: EW history, doctrinal evolution to CEMA, cross-domain effects, and what operators can do about it today.

Insight23 min read

Would the Real Common Operating Picture (COP) Please Stand Up

Most COPs are PowerPoint and uncorrelated feeds. What a real COP requires: fusion, policy, edge deployment, and echelon logic.

Insight7 min read

Building Physics-Backed, Unclassified, Open-Source Defense Research

Introducing Empyrean Defense Research: unclassified, physics-backed wargaming. First drop: 1,500 Monte Carlo sims of DF-17 vs DDG.

Insight37 min read

How the Space Domain Impacts Your Operations

Space domain impacts on EW, ground, maritime, air, and information ops — and what you can do to counter them.

Insight74 min read

Sense, Make Sense, Act: How to Conduct Counter-UAS From Sensors to Deployments

Counter-UAS playbook: 8 sensor types, fusion methods, jam vs. shoot decisions, and layered drone defense for DDIL environments.

Insight12 min read

Why JADC2 Needs Sensor Fusion at the Edge

JADC2 assumes persistent cloud and top-down authority. Operators have neither. Why sensor fusion must live at the edge.

Resource8 min read

What is Digital Force Protection?

Digital Force Protection explained: countering ubiquitous technical surveillance through device census, co-traveler analysis, signature management, and fused defensive measurement.

Resource11 min read

What is Intelligence Fusion?

Intelligence fusion explained: JDL/DFIG model, multi-INT disciplines, JADC2, and what fusion means for civilian operators.

Resource11 min read

What is Maritime Intelligence?

Maritime intelligence explained: AIS limits, dark vessels, beneficial ownership, sanctions risk, and multi-INT fusion at sea.

Resource7 min read

What is OPSEC?

OPSEC, UTS, and Digital Force Protection explained: the five-step process, five threat vectors, and signature management.

Resource13 min read

What is ATAK?

ATAK explained: TAK clients, EUDs, data packages, mesh networks, federation, plugins, and the CoT protocol that ties it together.

Resource26 min read

Defense & Intelligence Glossary

Defense & intelligence glossary: acronyms and terms for EMSO, C-UAS, JADC2, sensor fusion, SSA, CTF, entity resolution, and TAK.

Resource13 min read

What is Counter Threat Finance?

Counter Threat Finance (CTF) explained: DoDD 5205.14 doctrine, CTF vs. AML, sanctions, shell companies, TBML, and operational software.

Resource10 min read

What is Entity Resolution?

Entity Resolution explained: deterministic, probabilistic, ML, and graph methods for matching records to real-world identities.

Resource13 min read

What is Narrative Intelligence?

Narrative Intelligence (NARINT) explained: detecting and countering influence operations, DISARM framework, CIB, and OSINT.

Resource13 min read

What is EMSO?

EMSO explained: Electronic Warfare, EMBM, JEMSO, Electronic Order of Battle, CEMA, spectrum management, and operational software.

Resource12 min read

What is a Common Operational Picture?

Common Operational Picture (COP) explained: why most COPs fail, display vs. decision surface, edge deployment, and true fusion.

Resource13 min read

What is Space Situational Awareness?

Space Situational Awareness (SSA) explained: orbital tracking, TLEs, the Space Surveillance Network, and counterspace threats.

Resource12 min read

What is Counter-UAS?

Counter-UAS (C-UAS) explained: sensors, fusion, effectors, legal authorities, and layered drone defense for military and critical sites.

Resource12 min read

What is JADC2?

JADC2 explained: why top-down fails, what sensor-up architecture means, and why edge-deployed fusion survives contact.

Resource11 min read

What is Sensor Fusion?

Sensor fusion explained: state estimation, data association, multi-hypothesis tracking, identity provenance, and edge deployment.

Research43 min read

High-Powered Microwave (HPM): From Hard Kill to Residual Risk

3,400 Monte Carlo runs reveal HPM's service-rate ceiling, residual warhead hazard, and cascade failure against 40-400 drone swarms.

Research48 min read

The Devil Dog and the Dragon: USMC IADS vs. PLARF Cruise Missile Saturation

USMC MRIC vs 60 CJ-10 cruise missiles: 92.7% kill rate, then magazine exhaustion at T+28:37. The Marines need more rounds.

Research34 min read

Quantifying Layered Naval Defense Against Hypersonic Glide Vehicles

DF-17 HGV vs Arleigh Burke: 50 Monte Carlo seeds, SM-6 at 23% kill rate, PAC-3 at zero. The timeline is the constraint.

Insight73 min read

Ubiquitous Technical Surveillance Will Get You Killed on the Streets

How commercial location data, advertising identifiers, co-travel analysis, and data fusion expose military personnel—and what digital force protection can do.

Insight47 min read

Maritime Domain Awareness: The Complete Field Guide

Maritime domain awareness field guide: spectrum, seabed, ownership, and cyber threats that single-domain tools miss.

Insight25 min read

TAK Server on AWS: From Zero to Operational in Under Ten Minutes

Deploy TAK Server on AWS with CloudFormation: TLS, Docker, hardening, and security best practices in under ten minutes.

Insight8 min read

Release Log Vol. 1: Maritime Intelligence & UAS Traffic Management

Empyrean ships Maritime Intelligence, Air Domain Intelligence, and UAS Traffic Management with 20+ data sources and FAA enrichment.

Insight20 min read

The Environment Is Trying to Kill Your Mission. We Want to Mitigate It.

Weather & environmental intelligence that modifies sensor confidence, route feasibility, and UAS BVLOS risk in real time.

Insight73 min read

EMSO Is Everyone's Problem. Let's Do Something About It.

EMSO deep dive: EW history, doctrinal evolution to CEMA, cross-domain effects, and what operators can do about it today.

Insight23 min read

Would the Real Common Operating Picture (COP) Please Stand Up

Most COPs are PowerPoint and uncorrelated feeds. What a real COP requires: fusion, policy, edge deployment, and echelon logic.

Insight7 min read

Building Physics-Backed, Unclassified, Open-Source Defense Research

Introducing Empyrean Defense Research: unclassified, physics-backed wargaming. First drop: 1,500 Monte Carlo sims of DF-17 vs DDG.

Insight37 min read

How the Space Domain Impacts Your Operations

Space domain impacts on EW, ground, maritime, air, and information ops — and what you can do to counter them.

Insight74 min read

Sense, Make Sense, Act: How to Conduct Counter-UAS From Sensors to Deployments

Counter-UAS playbook: 8 sensor types, fusion methods, jam vs. shoot decisions, and layered drone defense for DDIL environments.

Insight12 min read

Why JADC2 Needs Sensor Fusion at the Edge

JADC2 assumes persistent cloud and top-down authority. Operators have neither. Why sensor fusion must live at the edge.

Empyrean Defense

See Digital Force Protection

Schedule a walkthrough to see this capability in action.