Sarai Hannah Ajai's INCIDENT REPORT — TEMPORARY UNRECONCILED WI-FI CLIENT-COUNT DISCREPANCY Verizon Orbic RC400L Running EFForg/Rayhunter

INCIDENT REPORT — TEMPORARY UNRECONCILED WI-FI CLIENT-COUNT DISCREPANCY

Verizon Orbic RC400L Running EFForg/Rayhunter



Incident Date: August 22, 2026

Prepared By: Sarai Hannah Ajai
Device Under Review: Verizon Orbic RC400L Mobile Hotspot
Security Monitoring Software: EFForg/Rayhunter
Known Connected Device: Apple iPhone 17
Apple Mac Mini M1 Status During Incident: Not connected to the Verizon Orbic RC400L Wi-Fi network
Wi-Fi Network: Verizon-RC400L-7E
Incident Classification: Temporary unexplained Wi-Fi client-count discrepancy / cybersecurity observation
Incident Status as of Approximately 4:00 PM CDT: Expected one-device baseline restored; identity and cause of the temporary second-client indication remain undetermined.


1. PURPOSE OF THIS INCIDENT REPORT

This Incident Report documents a temporary and unreconciled connected-device-count discrepancy observed on my personally controlled Verizon Orbic RC400L mobile hotspot running EFForg/Rayhunter on August 22, 2026.

The purpose of this report is to preserve a chronological and technically accurate record of the device indications, known network configuration, screenshots, subsequent verification, and unresolved technical questions associated with the event.

This report does not state as an established fact that my Apple iPhone 17 was cloned, mirrored, remotely accessed, or duplicated. The available evidence establishes that the Verizon Orbic RC400L temporarily displayed a connected-device count inconsistent with the number of devices I knowingly and intentionally had connected to the hotspot. The technical cause of that discrepancy has not yet been established.


2. DEVICE AND SECURITY-MONITORING CONFIGURATION

The Verizon Orbic RC400L has been configured with EFForg/Rayhunter for personal cybersecurity monitoring, cellular-security review, device-connection reconciliation, and preservation of technical evidence.

Rayhunter is installed directly on the Verizon Orbic RC400L. The Orbic therefore serves as a separate monitoring and network device from my Apple iPhone 17 and Apple Mac Mini M1.

My established device-count reconciliation baseline is:

  • No Apple devices connected: expected connected-device count = 0
  • Apple iPhone 17 only: expected connected-device count = 1
  • Apple Mac Mini M1 only: expected connected-device count = 1
  • Apple iPhone 17 and Apple Mac Mini M1: expected connected-device count = 2

The Apple iPhone 17 was the only device I knowingly and intentionally had connected to the Verizon Orbic RC400L Wi-Fi network during the incident described in this report.

The Apple Mac Mini M1 was not connected to the Verizon Orbic RC400L Wi-Fi network during the relevant period.


3. MORNING BASELINE OBSERVATION — APPROXIMATELY 7:35 AM

During the morning of August 22, 2026, at approximately 7:35 AM, I inspected the Verizon Orbic RC400L display.

At that time:

  • the Orbic RC400L was powered on;
  • EFForg/Rayhunter was operating on the device;
  • the Apple iPhone 17 was connected to the Verizon Orbic RC400L Wi-Fi network;
  • the Apple Mac Mini M1 was not connected to the Orbic Wi-Fi network; and
  • the Orbic displayed the expected single connected-device condition.

This observation was consistent with my established baseline because only my Apple iPhone 17 was intentionally connected.

A photograph was taken and preserved documenting the morning condition.

Evidence file:

“Verizon Orbic RC400L RayHunter & Simulator Does Not Show Any Device Connected to the Apple iPhone 17 Only One Dated 08-22-26 0735AM.jpeg”




The morning observation therefore established the relevant comparison point for later review.


4. SECURITY-CREDENTIAL CHANGES PERFORMED DURING THE DAY

During August 22, 2026, I performed security-related credential changes affecting my Apple devices, including my Apple iPhone 17 and Apple Mac Mini M1.

Those actions were performed as personal device-security measures.

For technical accuracy, Apple Account credentials, iPhone access credentials, and Mac credentials are separate from the Verizon Orbic RC400L Wi-Fi password and Orbic administrative credentials.

Accordingly, the credential changes performed on my Apple devices are documented as part of the day's chronology but are not, by themselves, evidence establishing the cause of the later Orbic connected-device discrepancy.


5. AFTERNOON DISCREPANCY — APPROXIMATELY 2:36 PM

At approximately 2:36 PM on August 22, 2026, I again inspected the Verizon Orbic RC400L.

At that time:

  • my Apple iPhone 17 remained intentionally connected to the Verizon Orbic RC400L Wi-Fi network;
  • my Apple Mac Mini M1 was not connected to the Verizon Orbic RC400L Wi-Fi network;
  • I was aware of only one authorized device that should have been connected to the hotspot; and
  • the Verizon Orbic RC400L nevertheless displayed a condition indicating two connected devices.

Because only one device was knowingly connected by me, the expected count was 1, while the apparent observed count was 2.

This created a temporary discrepancy of:

Expected connected devices: 1
Observed connected devices: 2
Unreconciled difference: 1 additional client indication

A photograph was taken and preserved documenting the 2:36 PM condition.

Evidence file:

“Verizon Orbic RC400L RayHunter & Simulator Does Show One Unknown Device Connected to the Apple iPhone 17 as Two Connected Devices Dated 08-22-26 0236PM.jpeg”




The photograph documents the Orbic's status at that moment. It does not, standing alone, identify the second client or establish the technical reason the device displayed a count of two.


6. APPLE IPHONE 17 WI-FI CONNECTION VERIFICATION

A separate screenshot was preserved from the Apple iPhone 17 Settings application.

The screenshot showed:

Settings → Wi-Fi → Verizon-RC400L-7E

The Apple iPhone 17 therefore showed an active connection to the known Verizon Orbic RC400L Wi-Fi network.

The screenshot also showed that:

  • Cellular service remained available;
  • Personal Hotspot was shown as Off; and
  • the iPhone was associated with Verizon-RC400L-7E.

The iPhone screenshot displayed a device time of approximately 3:48 PM.

Evidence file:

“Sarai Hannah Ajai's iPhone 17 Wifi Connected to the Verizon-RC400L-7E Stringray & Stimulators Hunter Device.jpg”


This screenshot supports the fact that my iPhone was connected to the expected Orbic Wi-Fi network. It does not independently identify any second Wi-Fi client.


7. FOLLOW-UP VERIFICATION — APPROXIMATELY 4:00 PM

At approximately 4:00 PM on August 22, 2026, I again physically checked the Verizon Orbic RC400L.

At that time, the Orbic displayed one connected device.

My Apple iPhone 17 remained the only device I knowingly had connected to the Orbic Wi-Fi network.

My Apple Mac Mini M1 remained disconnected from the Verizon Orbic RC400L Wi-Fi network.

The displayed count had therefore returned to the expected baseline:

Expected connected devices: 1
Observed connected devices: 1

The temporary second-client indication observed at approximately 2:36 PM was no longer present.


8. CHRONOLOGICAL INCIDENT SUMMARY

Time

Known Authorized Devices

Expected Count

Orbic Indication

Observation

Approximately 7:35 AM

Apple iPhone 17 only

1

1

Expected baseline

Approximately 2:36 PM

Apple iPhone 17 only

1

2

Temporary unreconciled discrepancy

Approximately 3:48 PM

Apple iPhone 17 shown connected to Verizon-RC400L-7E

1

Separate iPhone verification

iPhone connection confirmed

Approximately 4:00 PM

Apple iPhone 17 only

1

1

Expected baseline restored


9. IMPORTANCE OF THE APPLE MAC MINI M1 CONNECTION STATUS

For clarity, the Apple Mac Mini M1 did not account for the second-device indication observed at approximately 2:36 PM.

The Mac Mini M1 was not connected to the Verizon Orbic RC400L Wi-Fi network during the relevant period.

Therefore, the ordinary condition in which both the iPhone and Mac are connected—producing a legitimate count of two—does not explain the observed afternoon discrepancy based upon my known device configuration.

The unresolved technical question is therefore why the Orbic temporarily reported two clients while only one device was knowingly connected by me.


10. TECHNICAL ASSESSMENT

The evidence currently establishes a temporary unreconciled Wi-Fi client-count discrepancy.

The available screenshots and observations support the following facts:

  1. The Apple iPhone 17 was intentionally connected to Verizon-RC400L-7E.
  2. The Apple Mac Mini M1 was not connected to that Wi-Fi network during the incident.
  3. The expected device count was one.
  4. The Orbic displayed one connected device during the morning.
  5. The Orbic later displayed two connected devices at approximately 2:36 PM.
  6. The Orbic subsequently returned to one connected device by approximately 4:00 PM.
  7. The identity of the temporary second-client indication was not established from the Orbic display alone.

Several technically possible explanations remain open, including:

  • a temporarily associated second Wi-Fi client;
  • automatic reconnection by a previously authorized device;
  • a stale connected-client entry;
  • DHCP or client-table behavior;
  • Wi-Fi private-address or MAC-address behavior;
  • temporary hotspot firmware accounting behavior; or
  • another network condition requiring examination of the Orbic administrative connected-device table.

No one explanation should be characterized as established until additional identifying network information is preserved.


11. RAYHUNTER TECHNICAL LIMITATION

EFForg/Rayhunter operates through the cellular modem of the Verizon Orbic RC400L and is intended to assist with analysis for potentially suspicious cellular-network behavior, including cell-site-simulator or IMSI-catcher indicators.

Rayhunter does not establish that an Apple iPhone has been cloned or mirrored simply because the Orbic Wi-Fi interface temporarily displays an additional connected client.

The Apple iPhone 17 operates as a Wi-Fi client of the Orbic for purposes relevant to this incident. Rayhunter does not directly monitor the internal cellular modem of the Apple iPhone 17.

Accordingly, the temporary two-device indication must be evaluated principally as a Wi-Fi client-reconciliation issueunless additional evidence establishes another technical condition.


12. EVIDENCE PRESERVED

The following evidence has been preserved in connection with this incident:

Exhibit A — Morning Orbic Photograph

Photograph of the Verizon Orbic RC400L at approximately 7:35 AM documenting the expected one-device baseline.

Exhibit B — Afternoon Orbic Photograph

Photograph of the Verizon Orbic RC400L at approximately 2:36 PM documenting the temporary two-device indication.

Exhibit C — Apple iPhone 17 Wi-Fi Settings Screenshot

Screenshot showing the Apple iPhone 17 connected to Verizon-RC400L-7E.

Exhibit D — Existing Rayhunter Installation and Verification Documentation

Existing technical documentation describing:

  • installation of EFForg/Rayhunter;
  • Verizon Orbic RC400L configuration;
  • established Apple-device connection baselines;
  • Rayhunter dashboard access;
  • device-connection reconciliation procedures;
  • evidence-preservation procedures; and
  • security-cleanup procedures.

13. ADDITIONAL EVIDENCE TO PRESERVE IF THE CONDITION RECURS

If the Verizon Orbic RC400L again displays two connected clients while only the Apple iPhone 17 is intentionally connected, the following information should be captured before rebooting, resetting, disconnecting, blocking, or changing credentials:

  • complete Orbic Connected Devices / Clients page;
  • device or host name for each client;
  • MAC address for each client;
  • local IP address assigned to each client;
  • connection type;
  • connection status;
  • date and time;
  • Orbic display photograph;
  • Apple iPhone Wi-Fi Settings screenshot;
  • Apple iPhone Private Wi-Fi Address for the Verizon-RC400L-7E network;
  • confirmation that the Mac Mini M1 remains disconnected;
  • applicable Rayhunter recording identifier;
  • Rayhunter warning count;
  • relevant PCAP/QMDL/ZIP evidence, if technically applicable; and
  • written chronology of any change occurring before or after the additional client appears.

No Wi-Fi password, administrative password, Apple Account password, device passcode, authentication recovery code, or other authentication secret should be included in screenshots, public records, GitHub materials, or external reports.


14. SECURITY ACTIONS FOR A CONFIRMED UNIDENTIFIED CLIENT

If a future connected-device table identifies an active client that cannot be reconciled with any authorized device, appropriate follow-up actions may include:

  1. Preserve screenshots and technical identifiers before making changes.
  2. Record the unidentified MAC address and assigned IP address.
  3. Disconnect or block the unidentified Wi-Fi client through the Orbic administrative interface if supported.
  4. Change the Verizon Orbic RC400L Wi-Fi password.
  5. Change the Orbic administrative password where supported.
  6. Disable WPS if enabled and unnecessary.
  7. Disable any unused guest Wi-Fi network.
  8. Reconnect only the Apple iPhone 17.
  9. Confirm that the resulting connected-device count is exactly one.
  10. Turn off Wi-Fi on the iPhone and verify that the connected-device count returns to zero.
  11. Reconnect the iPhone and verify that the count returns from zero to one.
  12. Preserve the resulting screenshots as a new controlled baseline.

15. CURRENT INCIDENT STATUS

As of approximately 4:00 PM CDT on August 22, 2026, the Verizon Orbic RC400L displayed one connected device, consistent with my Apple iPhone 17 being the only intentionally connected device.

Accordingly, there was no continuing second-client indication at the time of the final check.

The earlier 2:36 PM discrepancy remains relevant because its source was not identified while it was present.

The incident should therefore be maintained in the record as:

Temporary Unreconciled Wi-Fi Client-Count Discrepancy — Resolved at Display Level / Technical Cause Undetermined.

16. FORMAL INCIDENT CONCLUSION

On August 22, 2026, my Verizon Orbic RC400L mobile hotspot running EFForg/Rayhunter temporarily displayed a connected-device count inconsistent with the number of devices I knowingly authorized and intentionally connected to the hotspot.

At approximately 7:35 AM, the Orbic displayed the expected one-device condition while my Apple iPhone 17 was connected. At approximately 2:36 PM, the Orbic displayed two connected devices even though my Apple iPhone 17 remained the only device I knowingly had connected and my Apple Mac Mini M1 was not connected to the Orbic Wi-Fi network. A separate Apple iPhone 17 Settings screenshot subsequently confirmed that the iPhone was connected to the Verizon-RC400L-7E Wi-Fi network.

At approximately 4:00 PM, I checked the Verizon Orbic RC400L again and observed that the connected-device count had returned to one, matching the expected iPhone-only baseline.

The temporary second-client indication has not been technically identified. The evidence currently supports documenting an unexplained and temporary Wi-Fi client-count discrepancy; it does not, without additional network-identification or forensic evidence, establish that my Apple iPhone 17 was cloned, mirrored, duplicated, or remotely controlled.

The photographs, iPhone Wi-Fi screenshot, Rayhunter installation documentation, timestamps, and this written chronology should be preserved as part of my cybersecurity records. If the discrepancy occurs again, the priority should be preservation of the Orbic Connected Devices/Clients table while the second client remains active so that the corresponding MAC address, local IP address, host information, and connection status can be compared against my known authorized devices.

Incident Date: August 22, 2026
Status at Last Verification: One authorized device displayed
Unresolved Issue: Identity and technical cause of temporary second-client indication
Evidence Preservation Status: Screenshots and written chronology preserved



Exhibit D

Legal-Professional Installation and Activation Instructions for Verizon Orbic RC400L Rayhunter

Subject: Installation, Activation, Verification, and Apple Device Connection Procedure for Verizon Orbic RC400L Running EFForg/Rayhunter

Prepared For: Sarai Hannah Ajai
Monitoring Device: Verizon Orbic RC400L Mobile Hotspot
Security Software: EFForg/Rayhunter
Computer Used for Installation: Apple Mac Mini M1
Connected Apple Devices: Apple Mac Mini M1; Apple iPhone 17
Purpose: Personal cybersecurity monitoring, cellular-security review, device-connection reconciliation, and preservation of technical evidence.


1. Purpose of the Rayhunter Installation

I installed EFForg/Rayhunter on a Verizon Orbic RC400L mobile hotspot for the lawful purpose of personal cybersecurity monitoring and technical evidence preservation. Rayhunter is an open-source tool created by the Electronic Frontier Foundation to assist with detecting IMSI catchers, also known as cell-site simulators or stingray-type surveillance devices. The EFF Rayhunter project states that Rayhunter was first designed to run on the Orbic RC400L mobile hotspot, and the Rayhunter supported-device documentation states that Rayhunter was built and tested primarily on the Orbic RC400L. (GitHub)

The Verizon Orbic RC400L was used as a dedicated monitoring device because it operates separately from my Apple iPhone 17 and Apple Mac Mini M1. This separation allows the Orbic to serve as an independent cellular-security reference point. The Rayhunter installation was not performed for improper monitoring of other persons. It was installed on a self-owned device to observe the cellular behavior of the Orbic hotspot, review Rayhunter warning results, preserve recordings when needed, and document network-device connection counts during controlled testing.


2. Required Materials

The following materials were required for installation and verification:

Item

Purpose

Verizon Orbic RC400L mobile hotspot

Device on which Rayhunter runs

Apple Mac Mini M1

Computer used to download and install Rayhunter

Orbic Wi-Fi password

Used to connect Apple devices to Orbic Wi-Fi

Orbic admin password

Used for Orbic admin login and Rayhunter installation

Rayhunter macOS ARM release package

Correct Rayhunter package for Apple Silicon/M1

USB cable

Optional; used for charging or possible USB access

Browser

Used to access Orbic admin page and Rayhunter dashboard

For an Apple Mac Mini M1, the correct Rayhunter release package is the macOS ARM package, because Apple Silicon Macs use ARM architecture. The Rayhunter installation documentation lists macos-arm as the correct package for M1/M2-style Macs. (Electronic Frontier Foundation)


3. Downloading the Correct Rayhunter Package

From the official EFForg/Rayhunter release page, I selected the Rayhunter release package for macOS ARM.

The correct file name used for the installation was:

rayhunter-v0.10.2-macos-arm.zip

The following files were not selected for the Apple Mac Mini M1 installation:

File Type

Reason Not Used

macos-intel.zip

Intended for Intel-based Macs

linux-aarch64.zip

Intended for Linux ARM64 systems

linux-x64.zip

Intended for Linux Intel/AMD systems

.sha256 files

Checksum files, not the installer package

Source code ZIP/TAR files

Developer source package, not the ready-to-run release package

If Safari automatically extracted the ZIP file, the Downloads folder showed the extracted folder instead of the ZIP file. In this case, the correct extracted folder was:

rayhunter-v0.10.2-macos-arm


4. Opening Terminal and Confirming the Installer

On the Apple Mac Mini M1, I opened Terminal and entered the extracted Rayhunter folder:

cd ~/Downloads/rayhunter-v0.10.2-macos-arm

I confirmed that the installer file existed by running:

pwd

ls -lah installer

The expected file was:

installer

The installer file was present in the extracted Rayhunter folder.


5. Allowing the Installer to Run on macOS

Before running the installer, I used the macOS permission command recommended for the Rayhunter installer:

xattr -d com.apple.quarantine installer

If macOS returned the following result, it was not treated as an installation failure:

No such xattr: com.apple.quarantine

That message only means macOS did not place the quarantine flag on the installer.

I then ensured the installer was executable:

chmod +x installer

The Rayhunter installation documentation includes the macOS xattr step before running the installer. (Electronic Frontier Foundation)


6. Connecting the Apple Mac Mini M1 to the Verizon Orbic RC400L Wi-Fi

Before running the Rayhunter installer, I connected the Apple Mac Mini M1 to the Verizon Orbic RC400L Wi-Fi network.

The correct connection sequence was:

  1. Power on the Verizon Orbic RC400L.
  2. Open the Mac Wi-Fi menu.
  3. Disconnect from the normal NETGEAR/home Wi-Fi network.
  4. Select the Orbic / Verizon / RC400L Wi-Fi network.
  5. Enter the Orbic Wi-Fi password.
  6. Confirm the Mac was connected to the Orbic Wi-Fi network.

This step is important because both the NETGEAR router and Orbic hotspot may use the same local router address:

192.168.1.1

If the Mac is connected to the NETGEAR Wi-Fi, opening 192.168.1.1 may display the NETGEAR admin page instead of the Orbic admin page. Therefore, the Mac must be connected to the Orbic Wi-Fi before installing Rayhunter or accessing the Orbic admin interface.


7. Confirming the Orbic Admin Page

After connecting the Mac Mini to the Orbic Wi-Fi, I opened the Orbic admin page in a browser:

http://192.168.1.1

The page must show the Orbic hotspot admin portal, not the NETGEAR router page.

The Rayhunter installation documentation states that a user knows the device is connected correctly when the Orbic admin page is reachable at 192.168.1.1. The same documentation explains that for Verizon Orbic devices, the installer uses the password for the Orbic admin menu, and the default admin password is usually the Wi-Fi password unless changed. (Electronic Frontier Foundation)


8. Important Password Distinction

During the setup, I confirmed that there are two separate password categories:

Password

Used For

Orbic Wi-Fi password

Connecting Apple iPhone 17 and Mac Mini M1 to the Orbic Wi-Fi

Orbic admin password

Logging into the Orbic admin portal and running the Rayhunter installer

These two passwords may be the same by default, but they may also differ if either password was changed. This distinction became important when the Apple iPhone 17 initially returned an incorrect password message. The issue was resolved by confirming the correct Wi-Fi password and reconnecting the iPhone to the Orbic Wi-Fi network.

No password should be included in screenshots, written reports, GitHub records, legal filings, or shared messages.


9. Installing Rayhunter on the Verizon Orbic RC400L

After confirming that the Mac Mini was connected to the Orbic Wi-Fi and that the installer file was present, I ran the Rayhunter Orbic installation command from inside the Rayhunter folder:

./installer orbic --admin-password 'YOUR_ORBIC_ADMIN_PASSWORD'

The real Orbic admin password was entered locally in Terminal and should not be disclosed in any report.

If the Orbic admin username had been changed from the default, the installer command could include the username:

./installer orbic --admin-username 'admin' --admin-password 'YOUR_ORBIC_ADMIN_PASSWORD'

If the Orbic admin IP address had been changed from the default, the installer command could include the admin IP address:

./installer orbic --admin-ip '192.168.1.1' --admin-username 'admin' --admin-password 'YOUR_ORBIC_ADMIN_PASSWORD'

The Rayhunter installation documentation identifies the Orbic installation command and explains that changed username, password, or IP settings must be provided to the installer. (Electronic Frontier Foundation)


10. Activating and Verifying Rayhunter

After the installer completed, the Orbic restarted and Rayhunter became active. The Rayhunter installation was verified through two main indicators:

Verification Item

Result

Green bar on Orbic display

Confirmed Rayhunter was running

Rayhunter dashboard in browser

Confirmed Rayhunter web interface was active

The Rayhunter dashboard was accessed through the Orbic Wi-Fi network at:

http://192.168.1.1:8080

The Rayhunter documentation explains that the Orbic web UI can be accessed at 192.168.1.1:8080 after installation and that the interface provides access to recordings, downloads, and analysis results. (Electronic Frontier Foundation)


11. Rayhunter Dashboard Verification

Once the dashboard loaded, I verified the following:

Dashboard Field

Verification Purpose

Rayhunter Version

Confirms installed software version

Current Recording

Confirms Rayhunter is recording

Recording ID

Identifies a specific recording session

Start Time

Documents when the recording began

Last Message

Documents the latest recorded modem message

Warning Count

Shows whether Rayhunter identified warning results

History

Shows prior recordings

PCAP / QMDL / ZIP downloads

Allows preservation of recording files

Battery / Storage / Memory

Confirms device operating condition

The dashboard showed Rayhunter version 0.10.2, active recordings, historical recordings, available downloads, and warning results. The reviewed recordings displayed 0 warnings. The expanded Rayhunter analysis stated “No warnings to display” for the reviewed capture.


12. Expanding Rayhunter Analysis Results

To review the details of a recording, I clicked the dropdown arrow beside the 0 warnings analysis label.

The expanded analysis showed:

Analysis Detail

Meaning

No warnings to display

No Rayhunter warning was identified for that recording

Analysis by Rayhunter version 0.10.2

Confirms analysis software version

Device system OS: Linux 3.18.48

Identifies the Orbic internal system environment

Analyzer list

Shows the types of checks applied to the recording

The listed analyzers included checks for suspicious identity requests, downgrade behavior, null cipher behavior, incomplete SIB behavior, NAS null cipher behavior, and diagnostic cellular messages. Rayhunter’s heuristic documentation describes analyzers for potential IMSI-catcher behavior, including identity requests, downgrade behavior, null cipher behavior, incomplete SIB indicators, and diagnostic review. (Electronic Frontier Foundation)

A result of 0 warnings does not prove that no security issue exists anywhere. It only means that the specific Orbic cellular recording did not produce Rayhunter warnings under the enabled analyzers. Rayhunter monitors the Orbic hotspot’s cellular modem behavior, not the internal cellular modem of the Apple iPhone 17.


13. Connecting the Apple iPhone 17 to the Orbic Rayhunter Wi-Fi

To connect the Apple iPhone 17:

  1. Open Settings on the iPhone.
  2. Open Wi-Fi.
  3. Select the Verizon Orbic RC400L Wi-Fi network.
  4. Enter the Orbic Wi-Fi password, not the Rayhunter installer command and not necessarily the admin password.
  5. Confirm the iPhone shows a checkmark beside the Orbic Wi-Fi network.
  6. Open Safari on the iPhone.
  7. Enter:

http://192.168.1.1:8080

After successful connection, the iPhone could view the Rayhunter dashboard. The iPhone acted as a Wi-Fi client and dashboard viewer. It did not become the device Rayhunter directly monitors at the cellular modem level.

If the iPhone shows Incorrect Password, the recommended correction is:

  1. Tap the information icon beside the Orbic network.
  2. Select Forget This Network.
  3. Confirm the actual Orbic Wi-Fi password through the Orbic admin portal or device display.
  4. Rejoin the Orbic Wi-Fi using the correct Wi-Fi password.

14. Connecting the Apple Mac Mini M1 to the Orbic Rayhunter Wi-Fi

To connect the Mac Mini M1:

  1. Open the macOS Wi-Fi menu.
  2. Select the Verizon Orbic RC400L Wi-Fi network.
  3. Enter the Orbic Wi-Fi password.
  4. Open a browser.
  5. Enter:

http://192.168.1.1:8080

The Mac Mini M1 can view the Rayhunter dashboard when connected to the Orbic Wi-Fi. If the Mac Mini is connected to the NETGEAR router instead, the Rayhunter dashboard may not open because the NETGEAR router may also use 192.168.1.1.


15. Apple Device Connection Reconciliation

After Rayhunter was installed and the Apple devices were connected, I reviewed the Orbic connected-device count. The controlled test eventually confirmed the following expected baseline:

Test Condition

Expected Count

Observed Count

Interpretation

No Apple devices connected

0

0

Normal baseline

Apple iPhone 17 only connected

1

1

Normal iPhone-only connection

Apple Mac Mini M1 only connected

1

To be verified if needed

Expected normal result

Apple iPhone 17 and Mac Mini M1 connected

2

2

Normal two-device connection

During earlier testing, an initial device-count discrepancy appeared. At one point, the Orbic appeared to show more connected devices than expected. After confirming the correct Wi-Fi password and reconnecting the Apple iPhone 17 and Apple Mac Mini M1 under controlled conditions, the device count matched the known devices. The corrected baseline showed that the iPhone-only connection displayed one connected device and the iPhone-plus-Mac connection displayed two connected devices.

The earlier discrepancy should remain documented as a technical observation, but the later controlled test reduced the immediate concern of an unknown active Wi-Fi client.


16. Optional USB / ADB Access Attempt

I also attempted to prepare the Apple Mac Mini M1 for USB access to Rayhunter by installing Android Platform Tools through Homebrew. Although the package name references Android, it installs the adb tool on macOS.

The command used was:

brew install --cask android-platform-tools

The installation was verified by running:

adb version

The Mac reported that ADB was installed and running on Darwin ARM64. However, when attempting USB forwarding:

adb forward tcp:8080 tcp:8080

ADB returned:

adb: no devices/emulators found

This means the Mac did not detect the Orbic as an ADB USB device at that time. This did not affect the working Rayhunter Wi-Fi dashboard. The Rayhunter installation remained functional through Orbic Wi-Fi at:

http://192.168.1.1:8080

The USB method remains optional. It is not required for ordinary Rayhunter dashboard access when the Mac or iPhone is connected directly to the Orbic Wi-Fi.


17. Optional Configuration Review

The Rayhunter dashboard includes a Configuration section. The configuration area may include settings such as device UI behavior, notification options, analyzer settings, and Wi-Fi client mode. Rayhunter documentation describes configuration options available through the web interface, including device display behavior, notification configuration, analyzer settings, and Wi-Fi client mode. (Electronic Frontier Foundation)

The most useful optional configuration for my setup may be Wi-Fi Client Mode, if available and stable. Wi-Fi Client Mode may allow the Orbic to connect to the NETGEAR network while still keeping the Rayhunter dashboard accessible from a device on the same network. This could reduce the need to disconnect the Mac Mini from NETGEAR Wi-Fi just to view the Rayhunter dashboard.

However, analyzer settings should not be changed without a clear reason, because changing analyzer settings may affect the consistency of future Rayhunter warning results.


18. Evidence Preservation Procedure

For documentation purposes, the following evidence should be preserved:

Evidence Item

Purpose

Screenshot of Rayhunter dashboard

Shows Rayhunter active and recording

Screenshot of green bar on Orbic display

Shows Rayhunter running on the device

Screenshot of expanded analysis dropdown

Shows warning count and analyzer details

Screenshot of Orbic connected-device list

Shows device-count reconciliation

Recording ZIP files

Preserves Rayhunter capture data

PCAP and QMDL files

Preserves technical capture formats

Date/time notes

Provides chronological record

Device-count reconciliation table

Shows expected vs. observed device count

Router context notes

Identifies whether Mac was on Orbic or NETGEAR

Password-change notes

Documents later security cleanup without disclosing passwords

Recommended file naming format:

Rayhunter_Recording_[RecordingID]_[YYYY-MM-DD]_[WarningStatus].zip

Example:

Rayhunter_Recording_1778189388_2026-05-07_ZeroWarnings.zip


19. Security Cleanup

After installation and connection testing, the following security steps are recommended:

  1. Change the Orbic Wi-Fi password.
  2. Change the Orbic admin password, if the Orbic admin portal allows it.
  3. Save the new password only in a secure password manager or private written record.
  4. Do not include the password in screenshots or legal exhibits.
  5. Reconnect only known devices.
  6. Reconfirm the device-count baseline:
    • no devices connected = 0,
    • iPhone only = 1,
    • Mac only = 1,
    • iPhone plus Mac = 2.

This creates a cleaner future baseline for any later device-count review.


20. Legal-Professional Summary Statement

The Verizon Orbic RC400L Rayhunter installation was completed for lawful personal cybersecurity monitoring and technical evidence preservation. The Orbic RC400L was selected because Rayhunter was first designed for and primarily tested on the Orbic RC400L device. The Apple Mac Mini M1 was used to install Rayhunter using the macOS ARM release package. After installation, the Orbic displayed the green Rayhunter status bar, and the Rayhunter dashboard became accessible through the Orbic Wi-Fi network at the local Rayhunter web interface.

The Apple iPhone 17 and Apple Mac Mini M1 were later connected to the Orbic Wi-Fi network to view the Rayhunter dashboard and to test connected-device counts. After correcting the Wi-Fi password issue and reconnecting the devices under controlled conditions, the Orbic connected-device count matched the expected number of known Apple devices. The iPhone-only connection showed one connected device, and the iPhone-plus-Mac connection showed two connected devices.

Rayhunter recordings were active, available for download, and showed 0 warnings in the reviewed expanded analysis. This means Rayhunter did not identify warning results in the reviewed Orbic cellular recordings. The result is useful evidence that Rayhunter was operating and applying its analyzers, but it should not be overstated as a complete forensic conclusion regarding all possible device-security concerns.

cid:clip_image001.png

Quick Installation Command Reference

Use these commands only from inside the extracted Rayhunter macOS ARM folder:

cd ~/Downloads/rayhunter-v0.10.2-macos-arm

xattr -d com.apple.quarantine installer

chmod +x installer

./installer orbic --admin-password 'YOUR_ORBIC_ADMIN_PASSWORD'

Then open the Rayhunter dashboard while connected to the Orbic Wi-Fi:

http://192.168.1.1:8080

For iPhone or Mac connection, use the Orbic Wi-Fi password to join the Orbic network, then open the same dashboard address in Safari or Chrome.

 

The Verizon Orbic RC400L mobile hotspot may be purchased through authorized carrier channels, including Verizon when available, or through third-party resale marketplaces such as eBay. When purchased through Verizon, the device is sold as an Orbic Speed Mobile Hotspot and may require separate service activation or a data plan depending on the user’s intended use. When purchased through eBay or another resale marketplace, the device may be listed as a used, refurbished, open-box, or preconfigured Orbic RC400L unit. Some third-party sellers may advertise the device with Rayhunter already installed; however, Rayhunter is open-source software developed by EFForg and is not a Verizon-branded product. For documentation purposes, the device should be described as a Verizon Orbic RC400L mobile hotspot running EFForg/Rayhunter, rather than as an official “Verizon Rayhunter” device.


Comments