Skip to main content

N0RMA

Formerly called Homewatch.

Home counter-surveillance detector for Linux (BlueZ + NetworkManager + iw). Detect-only: no jamming, no spoofing. Run: ./n0rma.sh setup once, then ./n0rma.sh run -> http://127.0.0.1:8777

dashboard with made-up demo data

What's new in 0.4

  • Evidence report: n0rma evidence -o report.txt writes a plain-text, tamper-evident report of everything flagged (30 days by default) for police or an advocate. Every log line is hash-chained to the one before it; check a saved file with n0rma evidence --verify report.txt. Send the final CHAIN END line to someone you trust right away. The Android app makes the same format, and each can verify the other's reports.
  • Device names: the dashboard and n0rma devices show a name for each device (router DNS or mDNS), and you can set your own: n0rma name <mac> Missy iPhone.
  • Dashboard tabs (Status / Nearby / Radar / History), "this is my network" and "I know this device" buttons, and fewer false alerts for virtual bridges and loopback addresses.
  • Renamed from Homewatch: the command is n0rma (the old homewatch still works), the PyPI package is n0rma-sec, and existing data is kept.

What was new in 0.2

  • Dark, muted, low-glare dashboard (no flashing alerts; every status is word + icon + color) with a Night switch (dim red on black)
  • A plain-language banner ("All clear" / "Keeping an eye on something" / "Needs your attention") with a breathing dot and live scan ages, so you can see it is working
  • "This is mine" on trackers: your own Tile/AirTag stops flagging and shows as yours
  • Sister project: n0rma-android (public, with signed APKs on its Releases page) - same detection on a phone, with tap-to-find, room sweeps and survey exports

Install

pip install n0rma-sec (the command it installs is n0rma) (or from source below). System packages are still needed: sudo apt install ieee-data nmap iw network-manager bluez (the vendor database from ieee-data/nmap is required for camera/drone vendor detection - N0RMA warns at startup if it is missing), then python3 -m venv .venv --system-site-packages && .venv/bin/pip install bleak. Optional RF module: sudo apt install rtl-sdr + an RTL-SDR dongle (24 MHz-1.7 GHz only; not 2.4/5.8 GHz).

Commands

Command What
setup first-run walkthrough: your Wi-Fi, home position, which devices are yours
run [--lan] all detectors + dashboard (type b+Enter to log a sensor beep)
scan one-shot scan
beep [--ago MIN] / report log sensor beeps / line them up against detections (with background baseline)
devices / trust all|<mac> LAN inventory; the first scan auto-trusts everything - review it
find <BLE addr> hot/cold locator
home <lat> <lon> home position for the drone map (west longitude is negative)
ntfy setup|test|on|off phone alerts (generic text only, via ntfy.sh)
selftest unit tests

Read this first

  • This is not a guarantee of safety. A quiet dashboard means "nothing seen by these radios", not "nothing is there". Blind spots: drones without Remote ID, SD-card-only cameras, cellular/GPS trackers, anything on 2.4/5.8 GHz video.
  • Remote ID is unauthenticated. Anyone can broadcast a fake one, so a red drone alert means a broadcast claims a drone. Position and operator location are whatever the sender says. Operator coordinates are shown live and are never written to disk; events are pruned after 30 days.
  • Do not interfere with a drone (shooting at, jamming or spoofing one is a federal crime). Report it to law enforcement or the FAA.
  • The radar is a rough estimate. Signal strength gives only a crude distance, badly distorted indoors, and no direction.
  • If you find something: don't touch or move it, photograph it where it is, note the time, and contact local law enforcement. A tracker you don't own: Apple/Android show unknown-tracker alerts and can help identify it.
  • --lan is plain HTTP. Anyone sniffing your Wi-Fi can see the private link/token. Use it only on a network you trust. Localhost mode only accepts Host: 127.0.0.1/localhost (blocks DNS rebinding) and state-changing requests need an X-Homewatch header.
  • Your Wi-Fi name, home position, tokens and the ntfy topic live in ~/.local/share/n0rma/config.json (mode 600), never in the code.

Metadata

Release files for n0rma-sec 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for n0rma-sec 0.4.0
File Size Uploaded
n0rma_sec-0.4.0.tar.gz 43.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for n0rma-sec 0.4.0
File Interpreter ABI Platform
n0rma_sec-0.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 84.0 kB

Release files / n0rma_sec-0.4.0.tar.gz

Download URL n0rma_sec-0.4.0.tar.gz
Size 43.3 kB
Tags Source
SHA-256 checksum
How to use checksums
57357c0b3cbb4746b5a13b033cf86e39fa9c305a19088f1e6c5b9f9ccac1b7ba
BLAKE2b-256 checksum
How to use checksums
ee646d54851be4b26b5e106e27361215bdd3d9976afe7ea4492abfbc2950a6c1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / n0rma_sec-0.4.0-py3-none-any.whl

Download URL n0rma_sec-0.4.0-py3-none-any.whl
Size 40.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
76a42ec05fe4f1a3904f67552e4597fca4428286090f4ebdef57f01079759ff3
BLAKE2b-256 checksum
How to use checksums
ff88c762877ca4e0daf9c634c0bb4457253da48a9d14bb04df08c81d8d203397
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release history Release notifications | RSS feed

0.4.1

2 release files

This release

0.4.0 This release

2 release files

0.3.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page