Towerwatch

A rogue cell tower spotter. Browsers can't read your SIM, but they can watch the shape of your mobile connection โ€” and a fake tower (an IMSI catcher) leaves fingerprints. Add the cells your phone sees and Towerwatch scores each one for suspicion.

Everything runs in your browser. Nothing is uploaded, ever.

What a web page can & can't see

Can see

  • Connection type โ€” 2g / 3g / 4g class, speed and latency estimates via the Network Information API (Chrome, Edge, Android).
  • Sudden changes โ€” a drop from 4G to 2G, or the connection dying and returning, is the loudest IMSI-catcher tell there is.
  • Your position โ€” with permission, so sightings can be pinned to a place and compared over time.

Can't see

  • Cell ID, LAC/TAC, MCC/MNC โ€” no browser API exposes the radio layer. Those come from the phone's own field-test screen or a netmonitor app.
  • Signal strength in dBm โ€” same reason.
  • Neighbour cell lists โ€” Android and iOS keep these private to the OS.

So Towerwatch does both halves: it watches live what the browser is allowed to know, and lets you feed in the cell details from a netmonitor app (NetMonster, Cellular-Z, CellMapper, or Android's *#*#4636#*#* menu). The heuristics do the rest.

How to get your cell data (30 seconds)
  1. Install a free netmonitor app โ€” NetMonster or Cellular-Z on Android.
  2. Note the serving cell: MCC, MNC, LAC/TAC, CID, radio type (GSM/UMTS/LTE/NR) and signal in dBm.
  3. Type it into Log a cell below, or export CSV/JSON from the app and drop the file in. Repeat whenever you move, or when something feels off.

Live connection watch

Network class โ€”
Downlink โ€”
Round trip โ€”
Position โ€”

Idle โ€” press Start watching to begin logging connection changes.

Event timeline

Log a cell

Verdict

No cells logged yet โ€” add one above, or press Load demo data to see how a caught IMSI catcher looks.

Cross-check against OpenCelliD optional

A cell that no public database has ever seen is the single strongest sign of a fake tower. Towerwatch can ask OpenCelliD whether each logged cell is known. It needs a free API token, which is kept in this browser only and is sent to opencellid.org and nowhere else. Some browsers block the request (no CORS headers) โ€” if so it fails quietly and every other heuristic still works.

If Towerwatch flags something