Every analyst who has watched a live air picture knows the two failure modes of alerting. Either the system is so quiet that a real emergency goes unnoticed for minutes, or it is so noisy that people mute it by lunchtime. This post is the rulebook we use for the airspace alerting layer in Kimo Defense Intelligence: what to alert on, how to avoid drowning analysts, and how to measure whether it works. It builds on the air-picture model described in Airspace awareness from open ADS-B data.
§01What do squawk codes 7500, 7600 and 7700 mean?
A squawk is the four-digit octal code a pilot sets on the transponder. Mode S encodes it in a 13-bit identity field, covering codes 0000 to 77773Source 3 · Junzi Sun, TU Delft (mode-s.org)The 1090 Megahertz Riddle: Mode S surveillance repliesmode-s.org. Most codes are assigned by air traffic control for identification. Three are reserved for emergencies, and European rules spell out their use in the Standardised European Rules of the Air, SERA.130051Source 1 · UK Civil Aviation Authority regulatory librarySERA.13005 SSR transponder — Mode A code setting (Regulation (EU) No 923/2012)regulatorylibrary.caa.co.uk:
| Code | Meaning | Rule text (SERA.13005) | Alert priority |
|---|---|---|---|
| 7700 | Emergency | Select 7700 to indicate a state of emergency, unless ATC has directed a specific code | P1, page |
| 7600 | Radio-communication failure | Select 7600 to indicate radio-communication failure | P1, page |
| 7500 | Unlawful interference | Attempt to select 7500; use 7700 instead if circumstances warrant | P1, page and escalate |
SKYbrary summarizes the same three special codes: 7500 for unlawful interference, 7600 for loss of communication, and 7700 for a general emergency2Source 2 · SKYbrary Aviation SafetyTransponderskybrary.aero. In open data you also have a second, related signal. In ADS-B, the aircraft status message carries emergency status and the squawk, and its broadcast rate rises from 0.2 Hz to 1.25 Hz when the squawk changes4Source 4 · Junzi Sun, TU Delft (mode-s.org)The 1090 Megahertz Riddle: ADS-B basicsmode-s.org, so a code change propagates quickly to ground receivers. OpenSky state vectors expose squawk and an spi (special purpose indicator) flag directly5Source 5 · OpenSky NetworkOpenSky REST API documentationopenskynetwork.github.io.
§02How should an emergency-squawk alert be designed?
The naive rule, "alert when squawk = 7700", fires on every transient value: a single corrupted decode, a code briefly passed through while the pilot changes settings on older equipment, or a test. The fix is cheap: require persistence.
alert: emergency_squawk
model: tracks
when:
squawk: { in: ['7500', '7600', '7700'] }
persist:
min_reports: 3 # distinct state vectors carrying the code
min_duration: 20s # first to last report
max_gap: 60s
group_by: [icao24]
episode:
close_after: 15m # no emergency code for 15 min ends the episode
severity:
'7500': critical
'7600': high
'7700': high
notify: [pager:airspace-oncall, channel:airspace-watch]
include: [callsign, alt_baro_m, vertical_rate, nearest_airport, position_source, coverage]Three reports over at least 20 seconds keeps latency well under a minute at OpenSky's 5–10 second resolution while eliminating single-frame noise. The episode block is just as important: an aircraft squawking 7700 for forty minutes during a diversion is one incident with updates (altitude, heading, nearest airport), not forty alerts.
§03Which flight anomalies are worth a second look?
Beyond emergency codes, most of what analysts care about is unusual behavior. None of these patterns implies anything by itself: training flights loiter, survey aircraft fly grids, medical helicopters land in fields. That is why they belong in a scored queue.
| Anomaly | Simple rule | Common benign explanation | Default score |
|---|---|---|---|
| Rapid descent | Vertical rate below −3,000 ft/min for 60 s above FL100 | Planned emergency descent, ATC instruction | 60 |
| Holding / circling | Track turns through 720° within 10 km radius in 15 min | ATC holding, sightseeing | 25 |
| Loitering | Ground speed below 120 kt in a 5 km cell for 30 min, not near an airport | Survey, police, medical | 35 |
| Geofence entry | Track enters a configured polygon | Approved operations | 30–70 (per zone) |
| Signal loss mid-flight | No reports for 5 min above FL200 in well-covered cell | Coverage gap, transponder issue | 20 |
| Implausible jump | Implied speed above plausibility bound between reports | Decoding error, GNSS degradation, spoofing | 40 |
The signal-loss rule only applies in cells where coverage is known to be good, which you can compute from the feed itself (median number of receivers per cell). Without that condition, signal loss is dominated by coverage edges. The implausible-jump rule overlaps with GNSS interference mapping: a cluster of jumps in one area on one day is often a navigation-quality problem rather than anything about the individual aircraft.
Geofences that do not cry wolf
Geofences are the rule most likely to flood a queue, because the polygons people draw first are usually too large and ignore altitude. Three habits keep them useful. Give every zone a floor and ceiling, not just an outline, so traffic overflying at cruise altitude does not trigger a low-level zone. Give every zone an owner and a reason, stored with the polygon in the zones model. And score zones individually: a hospital helipad buffer and a restricted area around a power plant should not share a number. Reference geometry such as airports and infrastructure can come from OpenStreetMap, which keeps the polygons reproducible.
§04Worked example: one 7700 episode, end to end
Here is how a single (simulated) emergency flows through the layer. The aircraft is a twin-engine airliner at cruise that declares an emergency and diverts.
| Time (UTC) | Feed | What Kimo does |
|---|---|---|
| 10:42:05 | First report with squawk 7700 | Opens a candidate episode, no notification yet |
| 10:42:15 | Second report, 7700, descending | Candidate persists; computes nearest airports |
| 10:42:27 | Third report, 7700 | Persistence met (3 reports, 22 s): pages on-call with position, descent rate, nearest airport |
| 10:44–11:05 | Reports continue, heading change | Updates the same episode; no new alerts |
| 11:06 | Aircraft on ground at diversion airport | Marks episode "landed", keeps it open 15 min |
| 11:21 | No emergency code for 15 min | Closes episode; asks for a disposition |
The analyst received one page and a stream of updates, not thirty notifications. During the same window the anomaly lane would also have flagged a rapid descent for this aircraft; Kimo attaches that anomaly to the open emergency episode instead of raising it separately, because an emergency descent during a declared emergency is expected behavior.
§05How do you keep alerts from drowning analysts?
- Two lanes. Emergency codes page; anomalies go to a queue sorted by score. Never mix the lanes.
- Combine, then threshold. An aircraft that is loitering and inside a geofence and recently lost signal scores higher than any single rule. Sum capped scores and alert at 70.
- Suppress the known. Allow-list recurring benign operations (training areas, survey contracts, published holds) with an expiry date, so the list does not rot.
- Rate-limit per zone. If a zone produces more than N anomalies an hour, raise one "zone is busy" alert and batch the rest.
- Close the loop. Every alert gets a disposition (true, benign, data quality). Rules with a benign rate above 80% for two weeks are reviewed.
- Paged (P1)
- Queued anomalies
§06How do you know the alerting layer works?
Treat alerting as a product with metrics. We track four, all as measures in the Kimo semantic layer so they show up in Ask Kimo and on the Airspace watch template dashboard:
The data-quality share is the one most teams skip. When it rises, the problem is usually upstream (a receiver offline, a decoding change) and the fix belongs in the ingestion model, not in the alert rule.
§07Setting this up in Kimo
Deploy the Airspace watch template to get the tracks model, both alert lanes and the anomaly queue. Rules are YAML files versioned next to the model and editable from Alerts; see the alerts documentation for channels and escalation. For a deeper treatment of thresholds and geofence design, read Airspace alerting rules that analysts trust.
Frequently asked questions
What does squawk 7700 mean?
Squawk 7700 indicates a general emergency. Under SERA.13005 a pilot selects it to signal a state of emergency, unless ATC has already assigned a specific code.
What is the difference between 7600 and 7700?
7600 signals radio-communication failure: the aircraft may be fine but cannot talk to ATC. 7700 signals a general emergency. Both deserve immediate attention, but they imply different follow-up questions.
Why not alert on the first report of an emergency code?
Single reports can be decoding errors or codes passed through briefly while changing transponder settings. Requiring a few reports over 20 seconds removes most false alarms while still alerting in under a minute.
How many anomaly alerts should an analyst see per shift?
There is no universal number, but if analysts cannot disposition every queued alert in a shift, the rules are too loose. Track alerts per analyst per shift and tune until the queue is reliably cleared.
Can I see emergency squawks in OpenSky data?
Yes. OpenSky state vectors include the transponder code (squawk) and the special purpose indicator flag, so emergency codes can be detected directly from the feed.
Sources
5 references- SERA.13005 SSR transponder — Mode A code setting (Regulation (EU) No 923/2012) (opens in a new tab)UK Civil Aviation Authority regulatory libraryregulatorylibrary.caa.co.uk
Rule text for codes 7700, 7600 and 7500.
- The 1090 Megahertz Riddle: Mode S surveillance replies (opens in a new tab)Junzi Sun, TU Delft (mode-s.org)mode-s.org
13-bit identity code encoding squawks 0000–7777.
- The 1090 Megahertz Riddle: ADS-B basics (opens in a new tab)Junzi Sun, TU Delft (mode-s.org)mode-s.org
Aircraft status broadcast rate rises to 1.25 Hz on squawk change.
- OpenSky REST API documentation (opens in a new tab)OpenSky Networkopenskynetwork.github.io
squawk and spi fields; 5–10 s resolution.
External sources were accessed at the time of writing. Kimo product details, customers and figures in examples are illustrative unless a source is cited.
- #ADS-B
- #Alerting
- #Airspace
Writes about ADS-B, Alerting, Airspace, Maritime.
Kimo people and customers mentioned are illustrative; example charts use simulated data unless a source is cited. All aircraft data shown in Kimo is simulated.


