Counter-surveillance is the practice of detecting, identifying, and neutralizing unauthorized surveillance directed at a person, space, vehicle, or communication system. It encompasses five disciplines: RF detection (finding wireless transmitters), optical detection (finding camera lenses), communication security (encrypting voice and data), position tracking detection (finding GPS devices), and TSCM (Technical Surveillance Countermeasures — professional environment sweeps). This guide covers the methods, equipment, and deployment scenarios for each discipline, written for the operator who needs to act, not the curious reader.
The field has changed faster between 2022 and 2026 than in the previous twenty years. Hidden cameras now ship with 4G modems and run for a month on a coin cell. GSM bugs are smaller than a fingernail and self-power from USB ports they appear to be. IMSI catchers are deployed at protests, conferences, and hotel zones in dozens of countries. The defensive equipment has improved in parallel — but only for buyers who understand which tool answers which threat.
What are the five disciplines of counter-surveillance?
The discipline boundaries matter because each requires different equipment, different methodology, and different operator skill.
RF detection
Locating any device transmitting radio frequency energy in your environment — Wi-Fi cameras, GSM bugs, Bluetooth trackers, analog audio transmitters, GPS-cellular trackers. Equipment range from €30 toys to €3,000 spectrum analyzers; the practical professional band is €400–€1,200. See RF detectors explained for the full architecture comparison.
Optical detection
Finding camera lenses regardless of whether the camera is powered, transmitting, or recording. Works by exploiting the retroreflection of camera lens coatings under tuned LED illumination. Compensates for the blind spots of RF detection.
Communication security
Protecting voice, message, and metadata from interception via end-to-end encryption, dynamic IMEI rotation, IMSI catcher detection, and baseband-level isolation. Hardware-based (encrypted phones) outperforms software-only (Signal, Wickr) where the threat model includes baseband or carrier-level attackers.
Position tracking detection
Finding GPS trackers attached to vehicles, possessions, or persons. Active trackers (cellular backhaul) are detectable by RF scan. Passive trackers (logging only, retrieved physically) require physical inspection.
TSCM (Technical Surveillance Countermeasures)
Professional environment sweeps performed by trained operators using full equipment racks — RF spectrum analyzers, non-linear junction detectors, thermal imagers, optical scanners, telephone line analyzers. Used by corporations, law firms, government, and high-net-worth individuals before sensitive meetings.
How does RF detection find wireless surveillance devices?
RF detection works by scanning the radio spectrum bands most commonly used by transmitting devices and alerting on signal strength or signal type. Coverage differs by instrument, so match the detector to the frequencies you actually need to inspect. Two architectures exist:
- Broadband detection — fast, simple, generates false positives in dense RF environments. Tells you "something is transmitting" without identifying what.
- Superheterodyne / hybrid detection — frequency-discriminating, identifies the modulation and band of the transmitting device. Tells you "a 4G LTE band 20 device is transmitting at this strength from that direction."
What it finds: Wi-Fi cameras (2.4/5 GHz), GSM bugs (850–1900 MHz), Bluetooth devices (2.4 GHz), GPS trackers with cellular backhaul, analog video transmitters (900 MHz, 1.2 GHz, 5.8 GHz), wireless microphones.
The Sentiras SENTINEL covers 40 MHz to 3.8 GHz with signal identification, directional source narrowing, event logging, and silent alert modes.
Limitations: cannot find powered-off devices, wired cameras, or pure passive recorders. Compensate with optical detection and physical inspection.
How does optical detection find hidden cameras?
Camera lenses retroreflect — they return incoming light back along the original path with much higher intensity than the surrounding surface. An optical lens detector emits a tuned LED ring around a viewfinder; you look through the viewfinder and any concealed lens flares as a bright pinpoint regardless of the camera's power state, focal length, or transmission status.
Why this matters operationally:
- Finds cameras storing locally to SD card (no RF to detect)
- Finds cameras that are powered off
- Finds cameras with shielded antennas
- Finds non-camera optics: viewing ports, two-way mirrors, scope objectives
For camera checks, pair RF detection with a careful optical and physical inspection. The full hotel-room sweep methodology is in our hotel room sweep briefing.
How does communication security protect conversations?
Communication security has four independent layers:
- End-to-end encryption of voice and messaging (AES-256 + Twofish cascade, Diffie-Hellman 4096-bit key exchange)
- IMSI catcher detection that recognizes fake cell towers and refuses connection
- Dynamic IMEI rotation that prevents device tracking across network sessions
- Baseband firewall that blocks known firmware-level exploits at the radio processor
Each layer addresses a distinct attacker. App-only solutions (Signal) cover layer 1 well and the others not at all. Hardware solutions (the Sentiras CIPHER) cover all four. The full breakdown is in encrypted phones: what they actually protect you from.
How do you find a GPS tracker on your vehicle?
GPS trackers come in two architectures:
- Active (cellular-backhaul) — combine GPS positioning with GSM/4G transmission. Reports location in real time to a server. Detectable by RF scan because they transmit periodically.
- Passive (logger) — store location internally, must be physically retrieved to read. No RF emission, undetectable except by physical inspection.
Common hiding spots on vehicles:
- Inside wheel wells, magnetically attached to underside steel
- Inside the OBD-II port (powered by the vehicle, transmits continuously)
- Inside fuel filler doors
- Behind plastic bumper covers
- Inside the spare wheel well or trunk lining
- Magnetically attached to the underside of the chassis behind sound deadening
Methodology:
- RF scan with the SENTINEL — walk a slow loop around the vehicle with engine off, doors closed, your phone elsewhere
- Visual and tactile inspection of all magnetic-mountable surfaces
- OBD-II port check for foreign devices
- If the threat profile justifies it, vehicle on a lift for full chassis inspection
What is TSCM and when do you need it?
TSCM (Technical Surveillance Countermeasures) is the professional discipline of sweeping environments for surveillance devices. A TSCM sweep involves:
- Full RF spectrum analysis (typically 0–18 GHz or higher) with a calibrated spectrum analyzer
- Non-linear junction detection (finds semiconductors regardless of power state — finds even a switched-off bug)
- Thermal imaging (active electronics generate heat signatures)
- Telephone line and network cable analysis
- Physical inspection of every modifiable surface
- Optical scanning of all lens-bearing locations
Equipment spectrum:
- Handheld field detectors — suitable for room sweeps, vehicle clearance, and hotel verification when matched to the relevant frequency range and used with a documented inspection process.
- Professional handheld kits — €3,000 to €8,000. Add narrowband superheterodyne, NLJD, and signal recording.
- Spectrum analyzers (Aaronia, Anritsu, Rohde & Schwarz) — €15,000 to €120,000. Used by professional TSCM operators and government teams.
Who hires TSCM teams: Fortune 500 corporations before board meetings, M&A negotiations, IP-sensitive R&D facilities; law firms before litigation; government and political offices; high-net-worth families with active threat profiles.
When to hire vs do it yourself: handheld sweeps clear hotel rooms, vehicles, and home offices in routine threat profiles. Professional TSCM is justified when you are a known intelligence target, have evidence of prior compromise, or need legally admissible documentation. For consultation, talk to a Sentiras specialist.
How do you build a counter-surveillance capability?
Step one is honest threat assessment. Most buyers over-equip for theatrical threats and under-equip for real ones.
Common threat profiles:
- Frequent traveller — hotel rooms, rental cars, conference venues. Equipment: a compact RF detector plus visual and physical inspection workflow.
- Executive with personal security profile — adds vehicle inspection, home office sweeps, communication security. Equipment: SENTINEL + LENS + CIPHER (the EXECUTIVE configuration).
- Journalist or activist in hostile environment — primary risk is communication interception and source exposure. Equipment: CIPHER plus situational SENTINEL deployment.
- High-risk household — fixed-environment checks, vehicle protection, and escalation to a qualified professional when evidence or safety risk justifies it.
- Corporate IP-sensitive office — scheduled TSCM with handheld augmentation. Equipment: handheld kit on-site, professional TSCM quarterly.
Sentiras DETECT catalog covers the handheld layer. The SECURE catalog covers offensive audio devices for security audit and red-team use.
Ongoing vigilance:
- Hotel rooms: sweep on arrival, before sleep, after housekeeping
- Vehicles: weekly visual inspection, monthly RF scan
- Offices: monthly RF scan, annual full TSCM if threat profile warrants
- Communication: continuous (the encrypted phone is always-on)
Counter-surveillance for executives and high-net-worth individuals
The executive threat surface is broader than the typical buyer realizes. Documented incidents from the 2023–2025 period:
- Corporate espionage via hotel-room audio capture during M&A travel
- IMSI catcher deployment at industry conferences targeting C-suite attendees
- GPS trackers attached to executive vehicles by activist groups, divorce-litigation investigators, and competitor intelligence
- Hidden cameras in executive homes following domestic-staff turnover
Executive protocol:
- Travel security — sweep every hotel room on arrival, every rental vehicle, every meeting venue before sensitive discussion
- Meeting room clearance — RF + optical sweep before any board-level discussion in unfamiliar venues
- Vehicle inspection — weekly RF scan + visual; full inspection after vehicle has been out of personal control (valet, dealership, airport long-term)
- Communication hygiene — encrypted phone for sensitive calls, never discuss material non-public information on standard cellular voice
- Personal device discipline — phone in faraday pouch during sensitive meetings
The Sentiras DETECT catalog supports this profile end to end.
Counter-surveillance for journalists and activists
The threat model is different. Source protection is the operating constraint, not personal property protection.
- Source protection — never store source identity on a device that has touched a hostile network. Use compartmentalized devices.
- Device security in hostile environments — assume border crossings result in covert device access. Carry burner devices; the encrypted device travels separately.
- Encrypted communications — Signal at minimum; CIPHER-class hardware when the threat actor has carrier-level access (state intelligence).
- Physical security awareness — RF-sweep accommodation and meeting locations. Visual surveillance counter-detection (vary routes, observe for repeating vehicles).
The category overlaps significantly with executive protection but has higher urgency on communication anonymity and lower urgency on physical-property protection.
What is the future of surveillance and counter-surveillance?
Five trends shaping the 2026–2030 period:
- AI-enabled surveillance devices — cameras with onboard inference selectively recording when faces, license plates, or audio keywords match. Lower power draw, smaller storage, harder to detect by behavioral analysis.
- 5G and IoT attack surface expansion — every connected appliance becomes a potential listening post. The "smart" hotel room is a counter-surveillance nightmare.
- Advanced concealment — cameras embedded in OLED screens, microphones in ceramic surfaces, GPS trackers indistinguishable from passive RFID
- Lower-cost IMSI catchers — software-defined radio kits under €500 enable amateur and criminal deployment
- Quantum-resistant cryptography — pre-positioning for the harvest-now-decrypt-later attack model
The defensive answer is the same as it has always been: rotate equipment, refresh discipline, assume the previous generation is now the attacker's baseline. Sentiras product lifecycles target 18–24 months because that is the threat-evolution cycle.
End-of-briefing CTA
Sentiras provides counter-surveillance equipment for lawful security work, including RF detection (SENTINEL), secure communications (CIPHER), and GPS tracking tools (TRACER). Product guidance is included. View the DETECT catalog →
Continue with the discipline-specific briefings: hotel room sweep, RF detectors explained, encrypted phones, and GSM listening devices.
Need the right configuration? Talk to a specialist.