kimo
TemplateKimo Defense

Airspace watch template

Airspace watch is a ready-made Kimo workspace that turns open ADS-B and MLAT feeds into a live air picture with three things analysts need on day one: a confidence-styled map of tracks, an emergency-squawk lane that pages within a minute, and a scored anomaly queue for loitering, holding and geofence entries. Connect a feed, draw your zones, and it is running in under an hour.

Dashboards
3
Data models
5
Metrics
7
Min setup
4
app.getkimo.com/templates/airspace-watch
Airspace watch
Air picture
Active tracks
1,284
+6%(favorable)
MLAT share
18%
+1 pt(favorable)
Feed freshness
2.1 s
−0.4 s(favorable)
Emergency episodes (24 h)
1
+1(unfavorable)

Tracked aircraft, last 24 hours

  • ADS-B
  • MLAT

Simulated air picture

NZONE BKMO412 · 7700
Emergency squawkGeofenceSimulated · fictional callsigns

Simulated data. Callsigns, receivers, hosts and incidents are fictional.

What’s inside

Everything the dashboards need, already modeled

Models join your raw sources, metrics are defined once in the semantic layer, and every dashboard, deck and Ask Kimo answer reads from the same definitions.

Data models

5
  • state_vectors
  • tracks
  • flights
  • zones
  • alert_episodes

Dashboards

3
  • Air picture
  • Alerts and dispositions
  • Feed health

Governed metrics

7
  • Active tracks
  • MLAT share
  • Feed freshness
  • Emergency episodes
  • Anomaly queue depth
  • Alert precision
  • Median time to acknowledge
Connectors

3 sources, read-only

Connect them from the cloud, or keep databases on your own servers with Kimo Bridge — an outbound-only tunnel, so nothing has to be copied to use the template.

Setup

Live in 5 steps

  1. 1

    Connect OpenSky Network or your ADS-B receiver feed (directly, via Kafka, or through Kimo Bridge).

  2. 2

    Pick your region of interest; the template sets the bounding box for state-vector queries.

  3. 3

    Import or draw geofences and set a score for each zone.

  4. 4

    Choose notification channels for the emergency lane and the anomaly queue.

  5. 5

    Review the first 48 hours of dispositions and tune thresholds and allow-lists.

The details

How the template works

§01Who is this template for?

Safety and resilience teams, airport and regional authorities, crisis-response cells, researchers and newsroom verification desks who need a dependable view of cooperative air traffic over a region. It is built on civil, openly broadcast data; all aircraft in the preview are simulated.

§02What is inside the template?

ComponentWhat it does
state_vectors sourceNormalized positions from every feed: icao24, time, position, altitudes, speed, track, vertical rate, squawk, SPI flag, position source
tracks modelDeduplicated, plausibility-checked positions segmented into flights, with confidence and coverage
zones modelYour geofences, plus airports and reference geometry from OpenStreetMap
Air picture dashboardLive map, traffic by altitude band, MLAT share, data freshness per feed
Alerts dashboardEmergency lane, anomaly queue, dispositions, precision and time to acknowledge

Positions are read from the fields OpenSky exposes in its state vectors, including squawk, spi and position_source (0 = ADS-B, 1 = ASTERIX, 2 = MLAT, 3 = FLARM)1. Receiver feeds are mapped to the same schema, as described in the ADS-B ingestion guide.

§03Which alert rules are included?

  • Emergency squawk (P1): 7500, 7600 or 7700 for at least three reports over 20 seconds, grouped into one episode per aircraft. The codes follow SERA.13005: 7700 emergency, 7600 radio-communication failure, 7500 unlawful interference2.
  • Rapid descent (score 60): sustained high descent rate above a configurable flight level.
  • Loitering (score 35) and holding (score 25): low speed or repeated turns in a small area away from airports.
  • Geofence entry (score per zone): entries into polygons you define, with allow-lists that expire.
  • Signal loss (score 20): only in cells with known good receiver coverage.
  • Implausible jump (score 40): implied speed between consecutive reports above a plausibility bound; also feeds the GNSS interference monitor.

The reasoning behind each rule and its thresholds is explained in Emergency squawks and flight anomalies and in Airspace alerting rules that analysts trust.

§04Which metrics does it track?

Active tracks
distinct aircraft seen in the last 60 s
MLAT share
positions computed by the network
Feed freshness
seconds since last report, per feed
Alert precision
share of alerts dispositioned true

§05How do I customize it?

Everything in the template is a regular Kimo object you can edit. Add altitude floors and ceilings to zones, change the plausibility bound for implied speed, or add a rule of your own in YAML next to the built-in ones. Teams with their own receivers usually add a coverage layer (median receivers per cell), which sharpens the signal-loss rule and lets the map shade areas where the absence of traffic means nothing. Measures such as active tracks and alert precision are defined once in the semantic layer, so you can ask Ask Kimo "how many emergency episodes did we see last month, by region?" and get the same answer the dashboard shows.

Required: ADS-B or OpenSky. Recommended: OpenStreetMap for reference geometry, Kimo Bridge to keep receiver data on your own servers.

Once deployed, open Airspace for the live map and Alerts for both lanes. For background on the data itself, read Airspace awareness from open ADS-B data.

Frequently asked questions

Do I need my own ADS-B receivers?

No. The template works with OpenSky state vectors alone. Your own receivers add coverage, lower latency and decoded quality fields such as NIC and NACp.

How fast do emergency alerts fire?

After three reports carrying the code over at least 20 seconds, which is typically well under a minute at 5–10 second feed resolution.

Can I change the anomaly thresholds?

Yes. Every rule is a versioned YAML file with parameters you can edit in Alerts or in your repository.

Is the aircraft data in the preview real?

No. The template preview and screenshots use simulated aircraft. Your deployment shows whatever your connected feeds provide.

Sources

3 references
  1. OpenSky REST API documentation (opens in a new tab)
    OpenSky Networkopenskynetwork.github.io

    State vector fields and position_source values.

  2. SERA.13005 SSR transponder — Mode A code setting (Regulation (EU) No 923/2012) (opens in a new tab)
    UK Civil Aviation Authority regulatory libraryregulatorylibrary.caa.co.uk

    Meaning of codes 7500, 7600, 7700.

  3. On the Security of the Automatic Dependent Surveillance-Broadcast Protocol (opens in a new tab)
    Strohmeier, Lenders, Martinovic — IEEE Communications Surveys & Tutorials (arXiv 1307.3664)2015arxiv.org

External sources were accessed at the time of writing. Kimo product details, customers and figures in examples are illustrative unless a source is cited.

All resources
GuideIntermediate
Defense

Airspace alerting rules that analysts trust

Emergency squawks, loitering, unusual altitude profiles and geofences, tuned to avoid alert fatigue.

Jonas Becker
11 min read
GuideAdvanced
Defense

Ingest ADS-B feeds into Kimo

Connect a receiver network or OpenSky, normalize state vectors, and model flights and tracks.

Hugo Lefèvre
12 min read

More Defense Intelligence templates

All templates

Deploy the airspace watch template in Kimo

Open it on simulated data first, then point it at your own feeds — in Kimo’s cloud or on your infrastructure through Kimo Bridge.