Sarai Hannah Ajai's INCIDENT REPORT — TEMPORARY UNRECONCILED WI-FI CLIENT-COUNT DISCREPANCY Verizon Orbic RC400L Running EFForg/Rayhunter
INCIDENT REPORT — TEMPORARY UNRECONCILED WI-FI CLIENT-COUNT DISCREPANCY
Verizon Orbic RC400L Running EFForg/Rayhunter
Incident Date: August 22, 2026
Prepared By: Sarai Hannah Ajai
Device Under Review: Verizon Orbic RC400L Mobile Hotspot
Security Monitoring Software: EFForg/Rayhunter
Known Connected Device: Apple iPhone 17
Apple Mac Mini M1 Status During Incident: Not connected to the Verizon Orbic RC400L Wi-Fi network
Wi-Fi Network: Verizon-RC400L-7E
Incident Classification: Temporary unexplained Wi-Fi client-count discrepancy / cybersecurity observation
Incident Status as of Approximately 4:00 PM CDT: Expected one-device baseline restored; identity and cause of the temporary second-client indication remain undetermined.
1. PURPOSE OF THIS INCIDENT REPORT
This Incident Report documents a temporary and unreconciled connected-device-count discrepancy observed on my personally controlled Verizon Orbic RC400L mobile hotspot running EFForg/Rayhunter on August 22, 2026.
The purpose of this report is to preserve a chronological and technically accurate record of the device indications, known network configuration, screenshots, subsequent verification, and unresolved technical questions associated with the event.
This report does not state as an established fact that my Apple iPhone 17 was cloned, mirrored, remotely accessed, or duplicated. The available evidence establishes that the Verizon Orbic RC400L temporarily displayed a connected-device count inconsistent with the number of devices I knowingly and intentionally had connected to the hotspot. The technical cause of that discrepancy has not yet been established.
2. DEVICE AND SECURITY-MONITORING CONFIGURATION
The Verizon Orbic RC400L has been configured with EFForg/Rayhunter for personal cybersecurity monitoring, cellular-security review, device-connection reconciliation, and preservation of technical evidence.
Rayhunter is installed directly on the Verizon Orbic RC400L. The Orbic therefore serves as a separate monitoring and network device from my Apple iPhone 17 and Apple Mac Mini M1.
My established device-count reconciliation baseline is:
- No Apple devices connected: expected connected-device count = 0
- Apple iPhone 17 only: expected connected-device count = 1
- Apple Mac Mini M1 only: expected connected-device count = 1
- Apple iPhone 17 and Apple Mac Mini M1: expected connected-device count = 2
The Apple iPhone 17 was the only device I knowingly and intentionally had connected to the Verizon Orbic RC400L Wi-Fi network during the incident described in this report.
The Apple Mac Mini M1 was not connected to the Verizon Orbic RC400L Wi-Fi network during the relevant period.
3. MORNING BASELINE OBSERVATION — APPROXIMATELY 7:35 AM
During the morning of August 22, 2026, at approximately 7:35 AM, I inspected the Verizon Orbic RC400L display.
At that time:
- the Orbic RC400L was powered on;
- EFForg/Rayhunter was operating on the device;
- the Apple iPhone 17 was connected to the Verizon Orbic RC400L Wi-Fi network;
- the Apple Mac Mini M1 was not connected to the Orbic Wi-Fi network; and
- the Orbic displayed the expected single connected-device condition.
This observation was consistent with my established baseline because only my Apple iPhone 17 was intentionally connected.
A photograph was taken and preserved documenting the morning condition.
Evidence file:
“Verizon Orbic RC400L RayHunter & Simulator Does Not Show Any Device Connected to the Apple iPhone 17 Only One Dated 08-22-26 0735AM.jpeg”
The morning observation therefore established the relevant comparison point for later review.
4. SECURITY-CREDENTIAL CHANGES PERFORMED DURING THE DAY
During August 22, 2026, I performed security-related credential changes affecting my Apple devices, including my Apple iPhone 17 and Apple Mac Mini M1.
Those actions were performed as personal device-security measures.
For technical accuracy, Apple Account credentials, iPhone access credentials, and Mac credentials are separate from the Verizon Orbic RC400L Wi-Fi password and Orbic administrative credentials.
Accordingly, the credential changes performed on my Apple devices are documented as part of the day's chronology but are not, by themselves, evidence establishing the cause of the later Orbic connected-device discrepancy.
5. AFTERNOON DISCREPANCY — APPROXIMATELY 2:36 PM
At approximately 2:36 PM on August 22, 2026, I again inspected the Verizon Orbic RC400L.
At that time:
- my Apple iPhone 17 remained intentionally connected to the Verizon Orbic RC400L Wi-Fi network;
- my Apple Mac Mini M1 was not connected to the Verizon Orbic RC400L Wi-Fi network;
- I was aware of only one authorized device that should have been connected to the hotspot; and
- the Verizon Orbic RC400L nevertheless displayed a condition indicating two connected devices.
Because only one device was knowingly connected by me, the expected count was 1, while the apparent observed count was 2.
This created a temporary discrepancy of:
Expected connected devices: 1
Observed connected devices: 2
Unreconciled difference: 1 additional client indication
A photograph was taken and preserved documenting the 2:36 PM condition.
Evidence file:
“Verizon Orbic RC400L RayHunter & Simulator Does Show One Unknown Device Connected to the Apple iPhone 17 as Two Connected Devices Dated 08-22-26 0236PM.jpeg”
The photograph documents the Orbic's status at that moment. It does not, standing alone, identify the second client or establish the technical reason the device displayed a count of two.
6. APPLE IPHONE 17 WI-FI CONNECTION VERIFICATION
A separate screenshot was preserved from the Apple iPhone 17 Settings application.
The screenshot showed:
Settings → Wi-Fi → Verizon-RC400L-7E
The Apple iPhone 17 therefore showed an active connection to the known Verizon Orbic RC400L Wi-Fi network.
The screenshot also showed that:
- Cellular service remained available;
- Personal Hotspot was shown as Off; and
- the iPhone was associated with Verizon-RC400L-7E.
The iPhone screenshot displayed a device time of approximately 3:48 PM.
Evidence file:
“Sarai Hannah Ajai's iPhone 17 Wifi Connected to the Verizon-RC400L-7E Stringray & Stimulators Hunter Device.jpg”
This screenshot supports the fact that my iPhone was connected to the expected Orbic Wi-Fi network. It does not independently identify any second Wi-Fi client.
7. FOLLOW-UP VERIFICATION — APPROXIMATELY 4:00 PM
At approximately 4:00 PM on August 22, 2026, I again physically checked the Verizon Orbic RC400L.
At that time, the Orbic displayed one connected device.
My Apple iPhone 17 remained the only device I knowingly had connected to the Orbic Wi-Fi network.
My Apple Mac Mini M1 remained disconnected from the Verizon Orbic RC400L Wi-Fi network.
The displayed count had therefore returned to the expected baseline:
Expected connected devices: 1
Observed connected devices: 1
The temporary second-client indication observed at approximately 2:36 PM was no longer present.
8. CHRONOLOGICAL INCIDENT SUMMARY
Time | Known Authorized Devices | Expected Count | Orbic Indication | Observation |
Approximately 7:35 AM | Apple iPhone 17 only | 1 | 1 | Expected baseline |
Approximately 2:36 PM | Apple iPhone 17 only | 1 | 2 | Temporary unreconciled discrepancy |
Approximately 3:48 PM | Apple iPhone 17 shown connected to Verizon-RC400L-7E | 1 | Separate iPhone verification | iPhone connection confirmed |
Approximately 4:00 PM | Apple iPhone 17 only | 1 | 1 | Expected baseline restored |
9. IMPORTANCE OF THE APPLE MAC MINI M1 CONNECTION STATUS
For clarity, the Apple Mac Mini M1 did not account for the second-device indication observed at approximately 2:36 PM.
The Mac Mini M1 was not connected to the Verizon Orbic RC400L Wi-Fi network during the relevant period.
Therefore, the ordinary condition in which both the iPhone and Mac are connected—producing a legitimate count of two—does not explain the observed afternoon discrepancy based upon my known device configuration.
The unresolved technical question is therefore why the Orbic temporarily reported two clients while only one device was knowingly connected by me.
10. TECHNICAL ASSESSMENT
The evidence currently establishes a temporary unreconciled Wi-Fi client-count discrepancy.
The available screenshots and observations support the following facts:
- The Apple iPhone 17 was intentionally connected to Verizon-RC400L-7E.
- The Apple Mac Mini M1 was not connected to that Wi-Fi network during the incident.
- The expected device count was one.
- The Orbic displayed one connected device during the morning.
- The Orbic later displayed two connected devices at approximately 2:36 PM.
- The Orbic subsequently returned to one connected device by approximately 4:00 PM.
- The identity of the temporary second-client indication was not established from the Orbic display alone.
Several technically possible explanations remain open, including:
- a temporarily associated second Wi-Fi client;
- automatic reconnection by a previously authorized device;
- a stale connected-client entry;
- DHCP or client-table behavior;
- Wi-Fi private-address or MAC-address behavior;
- temporary hotspot firmware accounting behavior; or
- another network condition requiring examination of the Orbic administrative connected-device table.
No one explanation should be characterized as established until additional identifying network information is preserved.
11. RAYHUNTER TECHNICAL LIMITATION
EFForg/Rayhunter operates through the cellular modem of the Verizon Orbic RC400L and is intended to assist with analysis for potentially suspicious cellular-network behavior, including cell-site-simulator or IMSI-catcher indicators.
Rayhunter does not establish that an Apple iPhone has been cloned or mirrored simply because the Orbic Wi-Fi interface temporarily displays an additional connected client.
The Apple iPhone 17 operates as a Wi-Fi client of the Orbic for purposes relevant to this incident. Rayhunter does not directly monitor the internal cellular modem of the Apple iPhone 17.
Accordingly, the temporary two-device indication must be evaluated principally as a Wi-Fi client-reconciliation issueunless additional evidence establishes another technical condition.
12. EVIDENCE PRESERVED
The following evidence has been preserved in connection with this incident:
Exhibit A — Morning Orbic Photograph
Photograph of the Verizon Orbic RC400L at approximately 7:35 AM documenting the expected one-device baseline.
Exhibit B — Afternoon Orbic Photograph
Photograph of the Verizon Orbic RC400L at approximately 2:36 PM documenting the temporary two-device indication.
Exhibit C — Apple iPhone 17 Wi-Fi Settings Screenshot
Screenshot showing the Apple iPhone 17 connected to Verizon-RC400L-7E.
Exhibit D — Existing Rayhunter Installation and Verification Documentation
Existing technical documentation describing:
- installation of EFForg/Rayhunter;
- Verizon Orbic RC400L configuration;
- established Apple-device connection baselines;
- Rayhunter dashboard access;
- device-connection reconciliation procedures;
- evidence-preservation procedures; and
- security-cleanup procedures.
13. ADDITIONAL EVIDENCE TO PRESERVE IF THE CONDITION RECURS
If the Verizon Orbic RC400L again displays two connected clients while only the Apple iPhone 17 is intentionally connected, the following information should be captured before rebooting, resetting, disconnecting, blocking, or changing credentials:
- complete Orbic Connected Devices / Clients page;
- device or host name for each client;
- MAC address for each client;
- local IP address assigned to each client;
- connection type;
- connection status;
- date and time;
- Orbic display photograph;
- Apple iPhone Wi-Fi Settings screenshot;
- Apple iPhone Private Wi-Fi Address for the Verizon-RC400L-7E network;
- confirmation that the Mac Mini M1 remains disconnected;
- applicable Rayhunter recording identifier;
- Rayhunter warning count;
- relevant PCAP/QMDL/ZIP evidence, if technically applicable; and
- written chronology of any change occurring before or after the additional client appears.
No Wi-Fi password, administrative password, Apple Account password, device passcode, authentication recovery code, or other authentication secret should be included in screenshots, public records, GitHub materials, or external reports.
14. SECURITY ACTIONS FOR A CONFIRMED UNIDENTIFIED CLIENT
If a future connected-device table identifies an active client that cannot be reconciled with any authorized device, appropriate follow-up actions may include:
- Preserve screenshots and technical identifiers before making changes.
- Record the unidentified MAC address and assigned IP address.
- Disconnect or block the unidentified Wi-Fi client through the Orbic administrative interface if supported.
- Change the Verizon Orbic RC400L Wi-Fi password.
- Change the Orbic administrative password where supported.
- Disable WPS if enabled and unnecessary.
- Disable any unused guest Wi-Fi network.
- Reconnect only the Apple iPhone 17.
- Confirm that the resulting connected-device count is exactly one.
- Turn off Wi-Fi on the iPhone and verify that the connected-device count returns to zero.
- Reconnect the iPhone and verify that the count returns from zero to one.
- Preserve the resulting screenshots as a new controlled baseline.
15. CURRENT INCIDENT STATUS
As of approximately 4:00 PM CDT on August 22, 2026, the Verizon Orbic RC400L displayed one connected device, consistent with my Apple iPhone 17 being the only intentionally connected device.
Accordingly, there was no continuing second-client indication at the time of the final check.
The earlier 2:36 PM discrepancy remains relevant because its source was not identified while it was present.
The incident should therefore be maintained in the record as:
Temporary Unreconciled Wi-Fi Client-Count Discrepancy — Resolved at Display Level / Technical Cause Undetermined.
16. FORMAL INCIDENT CONCLUSION
On August 22, 2026, my Verizon Orbic RC400L mobile hotspot running EFForg/Rayhunter temporarily displayed a connected-device count inconsistent with the number of devices I knowingly authorized and intentionally connected to the hotspot.
At approximately 7:35 AM, the Orbic displayed the expected one-device condition while my Apple iPhone 17 was connected. At approximately 2:36 PM, the Orbic displayed two connected devices even though my Apple iPhone 17 remained the only device I knowingly had connected and my Apple Mac Mini M1 was not connected to the Orbic Wi-Fi network. A separate Apple iPhone 17 Settings screenshot subsequently confirmed that the iPhone was connected to the Verizon-RC400L-7E Wi-Fi network.
At approximately 4:00 PM, I checked the Verizon Orbic RC400L again and observed that the connected-device count had returned to one, matching the expected iPhone-only baseline.
The temporary second-client indication has not been technically identified. The evidence currently supports documenting an unexplained and temporary Wi-Fi client-count discrepancy; it does not, without additional network-identification or forensic evidence, establish that my Apple iPhone 17 was cloned, mirrored, duplicated, or remotely controlled.
The photographs, iPhone Wi-Fi screenshot, Rayhunter installation documentation, timestamps, and this written chronology should be preserved as part of my cybersecurity records. If the discrepancy occurs again, the priority should be preservation of the Orbic Connected Devices/Clients table while the second client remains active so that the corresponding MAC address, local IP address, host information, and connection status can be compared against my known authorized devices.
Incident Date: August 22, 2026
Status at Last Verification: One authorized device displayed
Unresolved Issue: Identity and technical cause of temporary second-client indication
Evidence Preservation Status: Screenshots and written chronology preserved
Exhibit D
Legal-Professional Installation and Activation Instructions for Verizon Orbic RC400L Rayhunter
Subject: Installation, Activation, Verification, and Apple Device Connection Procedure for Verizon Orbic RC400L Running EFForg/Rayhunter
Prepared For: Sarai Hannah Ajai
Monitoring Device: Verizon Orbic RC400L Mobile Hotspot
Security Software: EFForg/Rayhunter
Computer Used for Installation: Apple Mac Mini M1
Connected Apple Devices: Apple Mac Mini M1; Apple iPhone 17
Purpose: Personal cybersecurity monitoring, cellular-security review, device-connection reconciliation, and preservation of technical evidence.
1. Purpose of the Rayhunter Installation
I installed EFForg/Rayhunter on a Verizon Orbic RC400L mobile hotspot for the lawful purpose of personal cybersecurity monitoring and technical evidence preservation. Rayhunter is an open-source tool created by the Electronic Frontier Foundation to assist with detecting IMSI catchers, also known as cell-site simulators or stingray-type surveillance devices. The EFF Rayhunter project states that Rayhunter was first designed to run on the Orbic RC400L mobile hotspot, and the Rayhunter supported-device documentation states that Rayhunter was built and tested primarily on the Orbic RC400L. (GitHub)
The Verizon Orbic RC400L was used as a dedicated monitoring device because it operates separately from my Apple iPhone 17 and Apple Mac Mini M1. This separation allows the Orbic to serve as an independent cellular-security reference point. The Rayhunter installation was not performed for improper monitoring of other persons. It was installed on a self-owned device to observe the cellular behavior of the Orbic hotspot, review Rayhunter warning results, preserve recordings when needed, and document network-device connection counts during controlled testing.
2. Required Materials
The following materials were required for installation and verification:
Item | Purpose |
Verizon Orbic RC400L mobile hotspot | Device on which Rayhunter runs |
Apple Mac Mini M1 | Computer used to download and install Rayhunter |
Orbic Wi-Fi password | Used to connect Apple devices to Orbic Wi-Fi |
Orbic admin password | Used for Orbic admin login and Rayhunter installation |
Rayhunter macOS ARM release package | Correct Rayhunter package for Apple Silicon/M1 |
USB cable | Optional; used for charging or possible USB access |
Browser | Used to access Orbic admin page and Rayhunter dashboard |
For an Apple Mac Mini M1, the correct Rayhunter release package is the macOS ARM package, because Apple Silicon Macs use ARM architecture. The Rayhunter installation documentation lists macos-arm as the correct package for M1/M2-style Macs. (Electronic Frontier Foundation)
3. Downloading the Correct Rayhunter Package
From the official EFForg/Rayhunter release page, I selected the Rayhunter release package for macOS ARM.
The correct file name used for the installation was:
rayhunter-v0.10.2-macos-arm.zip
The following files were not selected for the Apple Mac Mini M1 installation:
File Type | Reason Not Used |
macos-intel.zip | Intended for Intel-based Macs |
linux-aarch64.zip | Intended for Linux ARM64 systems |
linux-x64.zip | Intended for Linux Intel/AMD systems |
.sha256 files | Checksum files, not the installer package |
Source code ZIP/TAR files | Developer source package, not the ready-to-run release package |
If Safari automatically extracted the ZIP file, the Downloads folder showed the extracted folder instead of the ZIP file. In this case, the correct extracted folder was:
rayhunter-v0.10.2-macos-arm
4. Opening Terminal and Confirming the Installer
On the Apple Mac Mini M1, I opened Terminal and entered the extracted Rayhunter folder:
cd ~/Downloads/rayhunter-v0.10.2-macos-arm
I confirmed that the installer file existed by running:
pwd
ls -lah installer
The expected file was:
installer
The installer file was present in the extracted Rayhunter folder.
5. Allowing the Installer to Run on macOS
Before running the installer, I used the macOS permission command recommended for the Rayhunter installer:
xattr -d com.apple.quarantine installer
If macOS returned the following result, it was not treated as an installation failure:
No such xattr: com.apple.quarantine
That message only means macOS did not place the quarantine flag on the installer.
I then ensured the installer was executable:
chmod +x installer
The Rayhunter installation documentation includes the macOS xattr step before running the installer. (Electronic Frontier Foundation)
6. Connecting the Apple Mac Mini M1 to the Verizon Orbic RC400L Wi-Fi
Before running the Rayhunter installer, I connected the Apple Mac Mini M1 to the Verizon Orbic RC400L Wi-Fi network.
The correct connection sequence was:
- Power on the Verizon Orbic RC400L.
- Open the Mac Wi-Fi menu.
- Disconnect from the normal NETGEAR/home Wi-Fi network.
- Select the Orbic / Verizon / RC400L Wi-Fi network.
- Enter the Orbic Wi-Fi password.
- Confirm the Mac was connected to the Orbic Wi-Fi network.
This step is important because both the NETGEAR router and Orbic hotspot may use the same local router address:
192.168.1.1
If the Mac is connected to the NETGEAR Wi-Fi, opening 192.168.1.1 may display the NETGEAR admin page instead of the Orbic admin page. Therefore, the Mac must be connected to the Orbic Wi-Fi before installing Rayhunter or accessing the Orbic admin interface.
7. Confirming the Orbic Admin Page
After connecting the Mac Mini to the Orbic Wi-Fi, I opened the Orbic admin page in a browser:
The page must show the Orbic hotspot admin portal, not the NETGEAR router page.
The Rayhunter installation documentation states that a user knows the device is connected correctly when the Orbic admin page is reachable at 192.168.1.1. The same documentation explains that for Verizon Orbic devices, the installer uses the password for the Orbic admin menu, and the default admin password is usually the Wi-Fi password unless changed. (Electronic Frontier Foundation)
8. Important Password Distinction
During the setup, I confirmed that there are two separate password categories:
Password | Used For |
Orbic Wi-Fi password | Connecting Apple iPhone 17 and Mac Mini M1 to the Orbic Wi-Fi |
Orbic admin password | Logging into the Orbic admin portal and running the Rayhunter installer |
These two passwords may be the same by default, but they may also differ if either password was changed. This distinction became important when the Apple iPhone 17 initially returned an incorrect password message. The issue was resolved by confirming the correct Wi-Fi password and reconnecting the iPhone to the Orbic Wi-Fi network.
No password should be included in screenshots, written reports, GitHub records, legal filings, or shared messages.
9. Installing Rayhunter on the Verizon Orbic RC400L
After confirming that the Mac Mini was connected to the Orbic Wi-Fi and that the installer file was present, I ran the Rayhunter Orbic installation command from inside the Rayhunter folder:
./installer orbic --admin-password 'YOUR_ORBIC_ADMIN_PASSWORD'
The real Orbic admin password was entered locally in Terminal and should not be disclosed in any report.
If the Orbic admin username had been changed from the default, the installer command could include the username:
./installer orbic --admin-username 'admin' --admin-password 'YOUR_ORBIC_ADMIN_PASSWORD'
If the Orbic admin IP address had been changed from the default, the installer command could include the admin IP address:
./installer orbic --admin-ip '192.168.1.1' --admin-username 'admin' --admin-password 'YOUR_ORBIC_ADMIN_PASSWORD'
The Rayhunter installation documentation identifies the Orbic installation command and explains that changed username, password, or IP settings must be provided to the installer. (Electronic Frontier Foundation)
10. Activating and Verifying Rayhunter
After the installer completed, the Orbic restarted and Rayhunter became active. The Rayhunter installation was verified through two main indicators:
Verification Item | Result |
Green bar on Orbic display | Confirmed Rayhunter was running |
Rayhunter dashboard in browser | Confirmed Rayhunter web interface was active |
The Rayhunter dashboard was accessed through the Orbic Wi-Fi network at:
The Rayhunter documentation explains that the Orbic web UI can be accessed at 192.168.1.1:8080 after installation and that the interface provides access to recordings, downloads, and analysis results. (Electronic Frontier Foundation)
11. Rayhunter Dashboard Verification
Once the dashboard loaded, I verified the following:
Dashboard Field | Verification Purpose |
Rayhunter Version | Confirms installed software version |
Current Recording | Confirms Rayhunter is recording |
Recording ID | Identifies a specific recording session |
Start Time | Documents when the recording began |
Last Message | Documents the latest recorded modem message |
Warning Count | Shows whether Rayhunter identified warning results |
History | Shows prior recordings |
PCAP / QMDL / ZIP downloads | Allows preservation of recording files |
Battery / Storage / Memory | Confirms device operating condition |
The dashboard showed Rayhunter version 0.10.2, active recordings, historical recordings, available downloads, and warning results. The reviewed recordings displayed 0 warnings. The expanded Rayhunter analysis stated “No warnings to display” for the reviewed capture.
12. Expanding Rayhunter Analysis Results
To review the details of a recording, I clicked the dropdown arrow beside the 0 warnings analysis label.
The expanded analysis showed:
Analysis Detail | Meaning |
No warnings to display | No Rayhunter warning was identified for that recording |
Analysis by Rayhunter version 0.10.2 | Confirms analysis software version |
Device system OS: Linux 3.18.48 | Identifies the Orbic internal system environment |
Analyzer list | Shows the types of checks applied to the recording |
The listed analyzers included checks for suspicious identity requests, downgrade behavior, null cipher behavior, incomplete SIB behavior, NAS null cipher behavior, and diagnostic cellular messages. Rayhunter’s heuristic documentation describes analyzers for potential IMSI-catcher behavior, including identity requests, downgrade behavior, null cipher behavior, incomplete SIB indicators, and diagnostic review. (Electronic Frontier Foundation)
A result of 0 warnings does not prove that no security issue exists anywhere. It only means that the specific Orbic cellular recording did not produce Rayhunter warnings under the enabled analyzers. Rayhunter monitors the Orbic hotspot’s cellular modem behavior, not the internal cellular modem of the Apple iPhone 17.
13. Connecting the Apple iPhone 17 to the Orbic Rayhunter Wi-Fi
To connect the Apple iPhone 17:
- Open Settings on the iPhone.
- Open Wi-Fi.
- Select the Verizon Orbic RC400L Wi-Fi network.
- Enter the Orbic Wi-Fi password, not the Rayhunter installer command and not necessarily the admin password.
- Confirm the iPhone shows a checkmark beside the Orbic Wi-Fi network.
- Open Safari on the iPhone.
- Enter:
After successful connection, the iPhone could view the Rayhunter dashboard. The iPhone acted as a Wi-Fi client and dashboard viewer. It did not become the device Rayhunter directly monitors at the cellular modem level.
If the iPhone shows Incorrect Password, the recommended correction is:
- Tap the information icon beside the Orbic network.
- Select Forget This Network.
- Confirm the actual Orbic Wi-Fi password through the Orbic admin portal or device display.
- Rejoin the Orbic Wi-Fi using the correct Wi-Fi password.
14. Connecting the Apple Mac Mini M1 to the Orbic Rayhunter Wi-Fi
To connect the Mac Mini M1:
- Open the macOS Wi-Fi menu.
- Select the Verizon Orbic RC400L Wi-Fi network.
- Enter the Orbic Wi-Fi password.
- Open a browser.
- Enter:
The Mac Mini M1 can view the Rayhunter dashboard when connected to the Orbic Wi-Fi. If the Mac Mini is connected to the NETGEAR router instead, the Rayhunter dashboard may not open because the NETGEAR router may also use 192.168.1.1.
15. Apple Device Connection Reconciliation
After Rayhunter was installed and the Apple devices were connected, I reviewed the Orbic connected-device count. The controlled test eventually confirmed the following expected baseline:
Test Condition | Expected Count | Observed Count | Interpretation |
No Apple devices connected | 0 | 0 | Normal baseline |
Apple iPhone 17 only connected | 1 | 1 | Normal iPhone-only connection |
Apple Mac Mini M1 only connected | 1 | To be verified if needed | Expected normal result |
Apple iPhone 17 and Mac Mini M1 connected | 2 | 2 | Normal two-device connection |
During earlier testing, an initial device-count discrepancy appeared. At one point, the Orbic appeared to show more connected devices than expected. After confirming the correct Wi-Fi password and reconnecting the Apple iPhone 17 and Apple Mac Mini M1 under controlled conditions, the device count matched the known devices. The corrected baseline showed that the iPhone-only connection displayed one connected device and the iPhone-plus-Mac connection displayed two connected devices.
The earlier discrepancy should remain documented as a technical observation, but the later controlled test reduced the immediate concern of an unknown active Wi-Fi client.
16. Optional USB / ADB Access Attempt
I also attempted to prepare the Apple Mac Mini M1 for USB access to Rayhunter by installing Android Platform Tools through Homebrew. Although the package name references Android, it installs the adb tool on macOS.
The command used was:
brew install --cask android-platform-tools
The installation was verified by running:
adb version
The Mac reported that ADB was installed and running on Darwin ARM64. However, when attempting USB forwarding:
adb forward tcp:8080 tcp:8080
ADB returned:
adb: no devices/emulators found
This means the Mac did not detect the Orbic as an ADB USB device at that time. This did not affect the working Rayhunter Wi-Fi dashboard. The Rayhunter installation remained functional through Orbic Wi-Fi at:
The USB method remains optional. It is not required for ordinary Rayhunter dashboard access when the Mac or iPhone is connected directly to the Orbic Wi-Fi.
17. Optional Configuration Review
The Rayhunter dashboard includes a Configuration section. The configuration area may include settings such as device UI behavior, notification options, analyzer settings, and Wi-Fi client mode. Rayhunter documentation describes configuration options available through the web interface, including device display behavior, notification configuration, analyzer settings, and Wi-Fi client mode. (Electronic Frontier Foundation)
The most useful optional configuration for my setup may be Wi-Fi Client Mode, if available and stable. Wi-Fi Client Mode may allow the Orbic to connect to the NETGEAR network while still keeping the Rayhunter dashboard accessible from a device on the same network. This could reduce the need to disconnect the Mac Mini from NETGEAR Wi-Fi just to view the Rayhunter dashboard.
However, analyzer settings should not be changed without a clear reason, because changing analyzer settings may affect the consistency of future Rayhunter warning results.
18. Evidence Preservation Procedure
For documentation purposes, the following evidence should be preserved:
Evidence Item | Purpose |
Screenshot of Rayhunter dashboard | Shows Rayhunter active and recording |
Screenshot of green bar on Orbic display | Shows Rayhunter running on the device |
Screenshot of expanded analysis dropdown | Shows warning count and analyzer details |
Screenshot of Orbic connected-device list | Shows device-count reconciliation |
Recording ZIP files | Preserves Rayhunter capture data |
PCAP and QMDL files | Preserves technical capture formats |
Date/time notes | Provides chronological record |
Device-count reconciliation table | Shows expected vs. observed device count |
Router context notes | Identifies whether Mac was on Orbic or NETGEAR |
Password-change notes | Documents later security cleanup without disclosing passwords |
Recommended file naming format:
Rayhunter_Recording_[RecordingID]_[YYYY-MM-DD]_[WarningStatus].zip
Example:
Rayhunter_Recording_1778189388_2026-05-07_ZeroWarnings.zip
19. Security Cleanup
After installation and connection testing, the following security steps are recommended:
- Change the Orbic Wi-Fi password.
- Change the Orbic admin password, if the Orbic admin portal allows it.
- Save the new password only in a secure password manager or private written record.
- Do not include the password in screenshots or legal exhibits.
- Reconnect only known devices.
- Reconfirm the device-count baseline:
- no devices connected = 0,
- iPhone only = 1,
- Mac only = 1,
- iPhone plus Mac = 2.
This creates a cleaner future baseline for any later device-count review.
20. Legal-Professional Summary Statement
The Verizon Orbic RC400L Rayhunter installation was completed for lawful personal cybersecurity monitoring and technical evidence preservation. The Orbic RC400L was selected because Rayhunter was first designed for and primarily tested on the Orbic RC400L device. The Apple Mac Mini M1 was used to install Rayhunter using the macOS ARM release package. After installation, the Orbic displayed the green Rayhunter status bar, and the Rayhunter dashboard became accessible through the Orbic Wi-Fi network at the local Rayhunter web interface.
The Apple iPhone 17 and Apple Mac Mini M1 were later connected to the Orbic Wi-Fi network to view the Rayhunter dashboard and to test connected-device counts. After correcting the Wi-Fi password issue and reconnecting the devices under controlled conditions, the Orbic connected-device count matched the expected number of known Apple devices. The iPhone-only connection showed one connected device, and the iPhone-plus-Mac connection showed two connected devices.
Rayhunter recordings were active, available for download, and showed 0 warnings in the reviewed expanded analysis. This means Rayhunter did not identify warning results in the reviewed Orbic cellular recordings. The result is useful evidence that Rayhunter was operating and applying its analyzers, but it should not be overstated as a complete forensic conclusion regarding all possible device-security concerns.
Quick Installation Command Reference
Use these commands only from inside the extracted Rayhunter macOS ARM folder:
cd ~/Downloads/rayhunter-v0.10.2-macos-arm
xattr -d com.apple.quarantine installer
chmod +x installer
./installer orbic --admin-password 'YOUR_ORBIC_ADMIN_PASSWORD'
Then open the Rayhunter dashboard while connected to the Orbic Wi-Fi:
For iPhone or Mac connection, use the Orbic Wi-Fi password to join the Orbic network, then open the same dashboard address in Safari or Chrome.
The Verizon Orbic RC400L mobile hotspot may be purchased through authorized carrier channels, including Verizon when available, or through third-party resale marketplaces such as eBay. When purchased through Verizon, the device is sold as an Orbic Speed Mobile Hotspot and may require separate service activation or a data plan depending on the user’s intended use. When purchased through eBay or another resale marketplace, the device may be listed as a used, refurbished, open-box, or preconfigured Orbic RC400L unit. Some third-party sellers may advertise the device with Rayhunter already installed; however, Rayhunter is open-source software developed by EFForg and is not a Verizon-branded product. For documentation purposes, the device should be described as a Verizon Orbic RC400L mobile hotspot running EFForg/Rayhunter, rather than as an official “Verizon Rayhunter” device.






Comments
Post a Comment