kimo

Emergency squawks and flight anomalies: building an alerting layer

The three emergency transponder codes are 7700 (general emergency), 7600 (radio-communication failure) and 7500 (unlawful interference), and they are the highest-signal events in open air-traffic data. A good alerting layer fires on them within seconds, but only after a short persistence check, and it treats everything else (unusual descents, holding, loitering, geofence entries) as lower-priority anomalies that are scored, grouped and rate-limited so analysts are not buried.

Jonas Becker
Defense programs9 min read5 sources

Every analyst who has watched a live air picture knows the two failure modes of alerting. Either the system is so quiet that a real emergency goes unnoticed for minutes, or it is so noisy that people mute it by lunchtime. This post is the rulebook we use for the airspace alerting layer in Kimo Defense Intelligence: what to alert on, how to avoid drowning analysts, and how to measure whether it works. It builds on the air-picture model described in Airspace awareness from open ADS-B data.

§01What do squawk codes 7500, 7600 and 7700 mean?

A squawk is the four-digit octal code a pilot sets on the transponder. Mode S encodes it in a 13-bit identity field, covering codes 0000 to 77773. Most codes are assigned by air traffic control for identification. Three are reserved for emergencies, and European rules spell out their use in the Standardised European Rules of the Air, SERA.130051:

CodeMeaningRule text (SERA.13005)Alert priority
7700EmergencySelect 7700 to indicate a state of emergency, unless ATC has directed a specific codeP1, page
7600Radio-communication failureSelect 7600 to indicate radio-communication failureP1, page
7500Unlawful interferenceAttempt to select 7500; use 7700 instead if circumstances warrantP1, page and escalate
Emergency transponder codes as defined in SERA.13005 (source 1); priorities are Kimo defaults.

SKYbrary summarizes the same three special codes: 7500 for unlawful interference, 7600 for loss of communication, and 7700 for a general emergency2. In open data you also have a second, related signal. In ADS-B, the aircraft status message carries emergency status and the squawk, and its broadcast rate rises from 0.2 Hz to 1.25 Hz when the squawk changes4, so a code change propagates quickly to ground receivers. OpenSky state vectors expose squawk and an spi (special purpose indicator) flag directly5.

§02How should an emergency-squawk alert be designed?

The naive rule, "alert when squawk = 7700", fires on every transient value: a single corrupted decode, a code briefly passed through while the pilot changes settings on older equipment, or a test. The fix is cheap: require persistence.

alerts/emergency-squawk.yaml
yaml
alert: emergency_squawk
model: tracks
when:
  squawk: { in: ['7500', '7600', '7700'] }
persist:
  min_reports: 3        # distinct state vectors carrying the code
  min_duration: 20s     # first to last report
  max_gap: 60s
group_by: [icao24]
episode:
  close_after: 15m      # no emergency code for 15 min ends the episode
severity:
  '7500': critical
  '7600': high
  '7700': high
notify: [pager:airspace-oncall, channel:airspace-watch]
include: [callsign, alt_baro_m, vertical_rate, nearest_airport, position_source, coverage]

Three reports over at least 20 seconds keeps latency well under a minute at OpenSky's 5–10 second resolution while eliminating single-frame noise. The episode block is just as important: an aircraft squawking 7700 for forty minutes during a diversion is one incident with updates (altitude, heading, nearest airport), not forty alerts.

§03Which flight anomalies are worth a second look?

Beyond emergency codes, most of what analysts care about is unusual behavior. None of these patterns implies anything by itself: training flights loiter, survey aircraft fly grids, medical helicopters land in fields. That is why they belong in a scored queue.

AnomalySimple ruleCommon benign explanationDefault score
Rapid descentVertical rate below −3,000 ft/min for 60 s above FL100Planned emergency descent, ATC instruction60
Holding / circlingTrack turns through 720° within 10 km radius in 15 minATC holding, sightseeing25
LoiteringGround speed below 120 kt in a 5 km cell for 30 min, not near an airportSurvey, police, medical35
Geofence entryTrack enters a configured polygonApproved operations30–70 (per zone)
Signal loss mid-flightNo reports for 5 min above FL200 in well-covered cellCoverage gap, transponder issue20
Implausible jumpImplied speed above plausibility bound between reportsDecoding error, GNSS degradation, spoofing40
Kimo default anomaly rules and scores; thresholds are starting points to tune per region.

The signal-loss rule only applies in cells where coverage is known to be good, which you can compute from the feed itself (median number of receivers per cell). Without that condition, signal loss is dominated by coverage edges. The implausible-jump rule overlaps with GNSS interference mapping: a cluster of jumps in one area on one day is often a navigation-quality problem rather than anything about the individual aircraft.

Geofences that do not cry wolf

Geofences are the rule most likely to flood a queue, because the polygons people draw first are usually too large and ignore altitude. Three habits keep them useful. Give every zone a floor and ceiling, not just an outline, so traffic overflying at cruise altitude does not trigger a low-level zone. Give every zone an owner and a reason, stored with the polygon in the zones model. And score zones individually: a hospital helipad buffer and a restricted area around a power plant should not share a number. Reference geometry such as airports and infrastructure can come from OpenStreetMap, which keeps the polygons reproducible.

§04Worked example: one 7700 episode, end to end

Here is how a single (simulated) emergency flows through the layer. The aircraft is a twin-engine airliner at cruise that declares an emergency and diverts.

Time (UTC)FeedWhat Kimo does
10:42:05First report with squawk 7700Opens a candidate episode, no notification yet
10:42:15Second report, 7700, descendingCandidate persists; computes nearest airports
10:42:27Third report, 7700Persistence met (3 reports, 22 s): pages on-call with position, descent rate, nearest airport
10:44–11:05Reports continue, heading changeUpdates the same episode; no new alerts
11:06Aircraft on ground at diversion airportMarks episode "landed", keeps it open 15 min
11:21No emergency code for 15 minCloses episode; asks for a disposition
Simulated timeline. Real-world timings depend on receiver coverage and feed resolution.

The analyst received one page and a stream of updates, not thirty notifications. During the same window the anomaly lane would also have flagged a rapid descent for this aircraft; Kimo attaches that anomaly to the open emergency episode instead of raising it separately, because an emergency descent during a declared emergency is expected behavior.

§05How do you keep alerts from drowning analysts?

  1. Two lanes. Emergency codes page; anomalies go to a queue sorted by score. Never mix the lanes.
  2. Combine, then threshold. An aircraft that is loitering and inside a geofence and recently lost signal scores higher than any single rule. Sum capped scores and alert at 70.
  3. Suppress the known. Allow-list recurring benign operations (training areas, survey contracts, published holds) with an expiry date, so the list does not rot.
  4. Rate-limit per zone. If a zone produces more than N anomalies an hour, raise one "zone is busy" alert and batch the rest.
  5. Close the loop. Every alert gets a disposition (true, benign, data quality). Rules with a benign rate above 80% for two weeks are reviewed.
Alerts reaching analysts per 8-hour shift
  • Paged (P1)
  • Queued anomalies
Figure. Illustrative data: simulated deployment, alerts per shift before and after persistence checks, episodes and score thresholds were introduced.

§06How do you know the alerting layer works?

Treat alerting as a product with metrics. We track four, all as measures in the Kimo semantic layer so they show up in Ask Kimo and on the Airspace watch template dashboard:

Precision
share of alerts dispositioned "true"
Time to ack
median, per priority lane
Alerts / shift
per analyst, per lane
Data-quality share
alerts caused by feed issues

The data-quality share is the one most teams skip. When it rises, the problem is usually upstream (a receiver offline, a decoding change) and the fix belongs in the ingestion model, not in the alert rule.

§07Setting this up in Kimo

Deploy the Airspace watch template to get the tracks model, both alert lanes and the anomaly queue. Rules are YAML files versioned next to the model and editable from Alerts; see the alerts documentation for channels and escalation. For a deeper treatment of thresholds and geofence design, read Airspace alerting rules that analysts trust.

Feeds behind the alerting layer: receiver data, OpenSky state vectors and OpenStreetMap reference geometry.

Frequently asked questions

What does squawk 7700 mean?

Squawk 7700 indicates a general emergency. Under SERA.13005 a pilot selects it to signal a state of emergency, unless ATC has already assigned a specific code.

What is the difference between 7600 and 7700?

7600 signals radio-communication failure: the aircraft may be fine but cannot talk to ATC. 7700 signals a general emergency. Both deserve immediate attention, but they imply different follow-up questions.

Why not alert on the first report of an emergency code?

Single reports can be decoding errors or codes passed through briefly while changing transponder settings. Requiring a few reports over 20 seconds removes most false alarms while still alerting in under a minute.

How many anomaly alerts should an analyst see per shift?

There is no universal number, but if analysts cannot disposition every queued alert in a shift, the rules are too loose. Track alerts per analyst per shift and tune until the queue is reliably cleared.

Can I see emergency squawks in OpenSky data?

Yes. OpenSky state vectors include the transponder code (squawk) and the special purpose indicator flag, so emergency codes can be detected directly from the feed.

Sources

5 references
  1. SERA.13005 SSR transponder — Mode A code setting (Regulation (EU) No 923/2012) (opens in a new tab)
    UK Civil Aviation Authority regulatory libraryregulatorylibrary.caa.co.uk

    Rule text for codes 7700, 7600 and 7500.

  2. Transponder (opens in a new tab)
    SKYbrary Aviation Safetyskybrary.aero

    Special codes for emergencies.

  3. The 1090 Megahertz Riddle: Mode S surveillance replies (opens in a new tab)
    Junzi Sun, TU Delft (mode-s.org)mode-s.org

    13-bit identity code encoding squawks 0000–7777.

  4. The 1090 Megahertz Riddle: ADS-B basics (opens in a new tab)
    Junzi Sun, TU Delft (mode-s.org)mode-s.org

    Aircraft status broadcast rate rises to 1.25 Hz on squawk change.

  5. OpenSky REST API documentation (opens in a new tab)
    OpenSky Networkopenskynetwork.github.io

    squawk and spi fields; 5–10 s resolution.

External sources were accessed at the time of writing. Kimo product details, customers and figures in examples are illustrative unless a source is cited.

  • #ADS-B
  • #Alerting
  • #Airspace
Found this useful? Pass it on.
Written by
Jonas Becker
Defense programs at Kimo · 2 articles

Writes about ADS-B, Alerting, Airspace, Maritime.

Kimo people and customers mentioned are illustrative; example charts use simulated data unless a source is cited. All aircraft data shown in Kimo is simulated.

Put it to work

Go deeper

Whitepaper

Airspace Awareness from Open Data

ADS-B, Mode-S and GNSS interference: what open aviation data can reveal, its limits, and how to fuse it responsibly.

32 pages
Template

Airspace watch

Live air picture with emergency squawks, loitering and geofence alerts.

4 min setup
Live demo

Open Airspace

Tracks, emergency squawks and a GNSS-interference map on a simulated feed.

Simulated data · no sign-up

All resources
GuideIntermediate
Defense

Airspace alerting rules that analysts trust

Emergency squawks, loitering, unusual altitude profiles and geofences, tuned to avoid alert fatigue.

Jonas Becker
11 min read
Template
Defense

Airspace watch

Live air picture with emergency squawks, loitering and geofence alerts.

Kimo team
4 min setup
ArticleEngineering
Defense

Airspace awareness from open ADS-B data

How ADS-B works, what open receiver networks can and cannot tell you, and how to fuse it into one air picture.

Hugo Lefèvre
12 min read

Airspace awareness from open data.

Fuse ADS-B, AIS and OSINT feeds on your own infrastructure. The demo runs entirely on simulated data.