Skip to content

ZeroTrace Echo

Rolling-Code Handling

Echo captures and classifies rolling-code remotes, it never decrypts them and never replays them.

Rolling-Code Handling

Rolling-code remotes change their code on every press, using a secret manufacturer key. Echo treats them as read-only: it can capture them, identify the make, and break out the readable parts, but it never decrypts the changing security part and never replays them.

Capture and classify only, by design

The rolling security code is never decrypted, Echo holds no manufacturer keys and is designed so it can never gain a way to transmit a rolling-code remote. Replay, the standalone button, and automation rules all refuse rolling-code signals. This is a deliberate limit, not a missing feature.

Reference: what Echo shows per scheme

KeeLoq (HCS-family)Serial number and button read in plain. The rolling security code itself is shown only as an opaque block, never decrypted.
Somfy RTSAddress, button/command name (Up, Down, My/Stop, Prog, and combinations), and the rolling counter value read in plain.
Security+ (v1)Chamberlain / LiftMaster Security+ 1.0, recognised and field-split like KeeLoq and Somfy above.
Security+ (v2)Chamberlain / LiftMaster Security+ 2.0, recognised and field-split like KeeLoq and Somfy above.
CAME AtomoRecognised by make and captured, no field breakdown.
Nice FloR-SRecognised by make and captured, no field breakdown.
FAAC SLHRecognised by make and captured, no field breakdown.
AN-MotorsRecognised by make and captured, no field breakdown.
GenieRecognised by make and captured, no field breakdown.

So while a remote like Somfy RTS or KeeLoq is broken down in detail, CAME Atomo, Nice FloR-S, FAAC SLH, AN-Motors and Genie are recognised by make only. In every case the remote is captured and classified, never defeated.

What "field-split" actually means

For the four detailed makes, Echo separates a capture into the parts that are safe and useful to read, without ever touching the part that provides the security:

Serial / addressThe fixed identifier for that specific remote, unchanged press to press
Button / commandWhich button was pressed, shown by name for Somfy (Up, Down, My/Stop, Prog, Sun+Flag, Flag, and two-button combinations)
Rolling counterSomfy's press counter, increments every press, readable in plain text on the wire
Hopping / security codeKeeLoq's encrypted portion, shown only as an opaque block, this is what actually authorises the door or gate and is never decrypted
Why the security code stays opaque

KeeLoq's hopping code is encrypted with a manufacturer key that isn't public and that Echo doesn't have. There's no partial decode to offer, and building a path toward one is explicitly designed against, not just left undone.

Why this matters for defence

Because Echo can recognise a rolling-code remote and spot a duplicate of one, it can power the RollJam detector, warning you that a rolling remote may have been captured, without ever needing to break its security.

Command Palette

Search for a command to run...