A Rayhunter device records the low-level radio conversation between a phone/hotspot and nearby cell towers to detect IMSI catchers — fake base stations (also called cell-site simulators or Stingrays) that impersonate real towers to identify, track, or intercept phones nearby.
The capture is checked by rayhunter-check, EFF's detector for IMSI-catcher behaviour: forced 2G downgrades, disabled encryption (null cipher), suspicious identity requests, incomplete broadcast messages.
0 warnings means none of the known suspicious patterns were seen — a normal, "clean" capture.
From the broadcast messages, the app extracts which cells the device talked to: the country and operator (MCC/MNC), tracking area (TAC), the cell's identity (ECI) and its frequency (EARFCN → band). Each unique combination becomes a tower candidate card.
high — position from the OpenCelliD database
approximate — cell not located; pin falls back to the country centre
very-low — only a frequency was seen, not enough to identify a tower
Everything is analysed and stored on this machine. The only network request is the optional tower-position lookup to OpenCelliD.