Exodus
Protocol notes · October 2026

Reading the instruments
nobody documented.

Captured on one boat, from one set of instruments, in one night. Every number below was measured. Where something is inferred rather than proven, it says so.

Why this exists

The short version

Marine radar and sonar imagery are not encrypted. They are simply undocumented. The formats are private, they differ per manufacturer, and no one publishes them, so every open-source effort starts from nothing.

Radar was rescued years ago by one person who refused to let it go. Sonar never was. There is still no open-source sonar display for Signal K or OpenCPN. These notes are a small contribution toward changing that.

Raymarine Quantum radar

232.1.216.1:2574 · run-length compressed spokes

The thing that fooled us first

The stream looked far too small to be an image. Six kilobytes a second, where uncompressed spokes should be megabytes. We nearly wrote it off as status chatter.

It wasn't. Quantum spokes are run-length compressed, and on mostly-empty water that compresses enormously. A second trap sat behind it: the switch only forwards a multicast group to ports that have asked for it, so passive sniffing with tcpdump will never show you the whole picture. You have to actually join the group, and for a 232.x address that means an IGMPv3 source-specific join.

Spoke header

OffsetSizeMeaningObserved
0u32message type03 00 28 00
8u16range cells per spoke173
10u16spokes per revolution250
16u16bearing, 0–249, +1 per spokewraps each turn
18u16payload lengthmatched 4500 / 4500

Payload

0x5c introduces a 16-bit little-endian run of empty cells. Anything else is one cell's echo strength, 0x00 to 0xfd. A spoke may stop early; the remaining cells are empty.

seq 55155  bearing 78/250  18 bytes
5c 26 00 5f fd 5c 16 00 39 5c 2d 00 60 fd aa 5c 3e 00

skip 38 empty - echo 95 - echo 253 (hard return) - skip 22 -
echo 57 - skip 45 - echo 96, 253, 170 - skip 62, nothing further out
Not fully pinned down. 0x5c is also a legal echo strength, so escape and data are not perfectly separable. Where treating it as an escape would overrun the known cell count, we read it as a literal. That fallback fires on about 29% of spokes. It does not visibly change the picture, but the codec is not solved.

Discovery

The radar announces itself on 224.0.0.1:5800 as QuantumRadar and Quantum_W3, and advertises its own channels — report group and command port — inside those beacons.

One practical trap worth recording: commands are unicast to the radar's own address on the 198.18.0.0/16 network. If your computer has no address on that network, the kernel hands those packets to the default gateway and they go nowhere. Everything looks fine — the software sends, the radar is visibly reachable by multicast — and nothing works. Adding a secondary address on the radar's subnet fixes it instantly.

Raymarine Axiom fishfinder

226.192.224.0:3221 · ~157 kB/s · 71 pings a second

It isn't there until you ask

The sonar stream does not exist on the network until a sonar page is open on the multifunction display. Same lesson as the radar: nothing on the wire until something wants it.

OffsetSizeMeaningObserved
2u16header length42
4u32packet length2107, matched every packet
21u32ping counter+1 on 100% of pings
30asciichannel name"Auto (50/200kHz)"
56–128—sonar settingsconstant while settings are

The channel name is plain text

This is the part worth pausing on. Sitting in every single packet, seventy-one times a second:

41 75 74 6f 20 28 35 30 2f 32 30 30 6b 48 7a 29
A  u  t  o     (  5  0  /  2  0  0  k  H  z  )

The sounder announces its own frequency setting, in English, in a field nobody was ever expected to read.

Two gotchas. The header layout shifts when the packet size changes — it went from 2107 to 2701 bytes when a sonar setting changed, and fixed offsets broke immediately. Find the ping counter and the name string dynamically. And the same multicast group carries small status packets; mixing sizes into a waterfall pads blank columns through the image.
Unsolved. Exactly where the echo samples begin and how they scale is inferred, not proven. Ping-to-ping variance puts the noisy region roughly between bytes 512 and 1760. Our display exposes sample-range and gain as sliders rather than pretending to a calibrated depth scale. If you work this out properly, please publish it.

Why sonar never got opened

Four reasons, none of them "impossible"

The hard half is analogue. Decoding a format is a weekend. Building a transmitter is hundreds of volts into a ceramic disc, a switch fast enough that your own ping doesn't destroy your own receiver, and an amplifier spanning about 100 dB — an echo from 200 ft is almost nothing beside one from 10 ft. The people who write chart software are mostly not the people who do power electronics.

Depth is the number that sinks boats. Nobody wants to publish an uncalibrated sounder.

Radar had a champion. Sonar didn't.

Every brand is a separate job. What's above is Raymarine's. Garmin and Humminbird are different formats again.

And the transducers aren't even the lock-in

Airmar manufactures transducers for Raymarine, Garmin, Simrad, Furuno and Humminbird, and the internals of their CHIRP transducers are the same part across brands. What differs is the connector, a resistor so the brand recognises its own, and the network format.

The lock-in is a connector, a resistor and a file format.

Corrections

Things we got wrong on the way, kept on purpose

Left here deliberately. Protocol work is mostly being wrong in progressively better ways, and a write-up that hides that is less useful to the next person.