Skip to content
First steps with the PortaPack H4M PRO

First steps with the PortaPack H4M PRO

AI Disclosure

This article contains elements processed or created by AI.

  • The screenshots were regenerated via AI from original device photographs.
    They were run through several verification agents, and reviewed by a human before being approved.

For more information on how Lab401 uses AI, please see our AI Policy

If you've just purchased a H4M Pro and looking to get started - or looking to understand the new features of the device, Lab401 has performed a deep-dive into what you need to know before you start.

The following article covers: Flashing Firmware to your PortaPack H4M Pro, configuring the device, running local tests, and a CHANGELOG.

⚠️ Before you tune or transmit

The PortaPack H4M is a wide-band radio device, with transceiver capabilities.
The EU Radio Equipment Directive (2014/53/EU) Annex I places custom-built evaluation kits outside its scope for professional use in research and development contexts.

Restrictions for transmitting and receiving vary. You are responsible for ensuring that your possession and use of these devices complies with the law in your jurisdiction.

Receiving: Several countries restrict monitoring outside broadcast and amateur allocations, and a few restrict what you may do with what you hear. Check the rules where you are before you tune.

Transmitting: Transmit only on bands you are licensed for, at or below the power your licence and national regulations allow. The amateur allocations used later in this article need an amateur licence. Where you hold no licence for a band, work into a dummy load, a shielded enclosure, or a cabled and attenuated link so that nothing reaches the air.

Flashing Mayhem over DFU

Hold the DFU button and connect the unit to a computer over USB. All the indicator lights go out. The HackRF One behaves differently here, and on the HackRF Pro a dark board is the confirmation that DFU mode is active.

Open the firmware directory and run mayhem_flasher.bat. Enter 3 to select HackRF Pro / PortaPack, then 2 to select Flash DFU then Mayhem, which carries out the DFU unbrick and the Mayhem flash in one pass. The script needs no further input.

It loads the HackRF firmware through dfu-util, waits five seconds for the device to re-enumerate and writes the 4MB firmware_hpro.bin image to SPI flash. The line Firmware flashed successfully in the terminal indicates that the flash is complete. The MCU, FPGA and RF LEDs come on and Mayhem loads automatically.

Terminal output from mayhem_flasher.bat showing the two-stage DFU and Mayhem flash completing with the message Firmware flashed successfully
The two-stage flash carried out by mayhem_flasher.bat.

Setting the battery capacity

For power, the Portapack H4M Pro now uses industry standard 18650 Li-Ion batteries. These batteries can be easily obtained, easily replaced, and allow you to carry multiple batteries for extended in-the-field operations.

Depending on the brand and configuration, 18650 batteries can have different capacities and power ratings. In order for your H4M Pro to give you an accurate Battery Remaining estimation, you need to configure the firmware to match your batteries settings.

If you purchased your H4M Pro from Lab401, the battery was included - and the instructions below correspond to the battery you have. If you're using a different battery, you'll need to configure the settings according to your specific battery.

Open the Mayhem home screen and tap the battery icon. The capacity field shows the default of 1500mAh.

The cell supplied with the device is a 3.7V 18650 rated at 9.25Wh. Capacity in mAh is energy divided by voltage and multiplied by 1,000, so 9.25 ÷ 3.7 × 1,000 gives 2500mAh. That matches the figure printed on the label.

Illustration of the supplied green 18650 lithium-ion cell showing 2500mAh rated capacity, 9.25Wh rated energy, 3.7V nominal and 4.2V charge limit
The supplied 18650 cell, rated at 2500mAh and 9.25Wh.

Tap Settings on the battery page, turn the scroll wheel to change 1500 to 2500 and save.

Mayhem battery settings screen with the capacity field set to 2500mAh, override and charge hint checkboxes, and Reset, Save and Cancel buttons
The battery settings page with the capacity changed to 2500mAh.

Return to the battery page. The capacity now reads 2500mAh. The unit shown here is at 72% and 3.908V, drawing 352mA, with 4 hours 55 minutes remaining. Method reads IC, which means the fuel gauge is measuring rather than inferring the figure from voltage.

Mayhem battery status screen reading 72%, 3.908V, method IC, capacity 2500mAh, current minus 352mA, discharging, time to empty 4 hours 55 minutes
The battery page after the change, showing a capacity of 2500mAh.

Transmit and receive tests

Mayhem transmits and receives WFM, NFM, APRS, ADS-B, POCSAG and BLE, with the mode, frequency and bandwidth set by the operator. Each test below used two H4M Pro units, one transmitting and one receiving.

⚠️ Before you tune or transmit

Transmitting: Transmit only on bands you are licensed for, at or below the power your licence and national regulations allow.

The following images are illustrative only. Do NOT transmit in restricted spectrum space. Use a dummy load, a shielded enclosure, or a cabled and attenuated link to prevent transmission.

WFM broadcast reception

Open Receive from the home screen, select Audio, then set the playback standard to WFM. The frequency is arbitrary. This test used 100.6MHz with the gains left at their default values.

PortaPack H4M Pro showing the Mayhem Audio RX screen in WFM mode tuned to 100.6000MHz with spectrum trace and waterfall
Audio RX in WFM mode on 100.6MHz.

NFM voice

On the receiving unit, open Receive, select the Audio channel and switch to NFM demodulation. On the transmitting unit, open Transmit and select Signal Generator. Set both units to 466.1750MHz. Point-to-point working requires the same frequency at each end, so set the receiver rather than assuming it has followed. The gains stay at their defaults, which puts transmit gain at 16.

Once transmission starts, audio reaches the receiver immediately. The generator defaults to CW, which applies no modulation. Switching it to FM before transmitting changes the timbre of the demodulated audio noticeably.

Two PortaPack H4M Pro units side by side, the left in Audio RX NFM on 466.1750MHz, the right on the Signal Generator transmit screen with CW modulation and gain 16
Audio RX in NFM on the left, the signal generator on the right, both on 466.1750MHz.

APRS messaging

Open APRS TX on the transmitting unit and APRS RX on the receiving unit, and set both to 144.3900MHz. The source and destination SSIDs can be set arbitrarily, and the gains stay at their defaults. Tap Set on the transmitting side, enter the message and confirm with OK. The text appears on the receiving list immediately.

In North America, APRS runs on 144.3900MHz. In Region 1 of the International Amateur Radio Union, which covers Europe, Africa and the Middle East, it operates on 144.8000MHz. Both frequencies fall within the two-metre amateur band and require an amateur licence.

Two PortaPack H4M Pro units side by side, the left showing the APRS RX list with received packets on 144.3900MHz, the right showing the APRS TX configuration screen with source and destination SSIDs
APRS RX with received packets on the left, the APRS TX page on the right.

ADS-B position reporting

Switch the receiving unit to ADS-B from the Receive menu and open the ADS-B TX page on the transmitting unit. The mode fixes both units on 1090MHz, and transmit gain is 16. That frequency carries live aviation traffic, so the link between the two units must be cabled and shielded. Tick Transmit position and enter simulated position data. This test used a simulated aircraft identified as TEST1234 at 36,000ft over the Niger delta, at 5°N and 6°E, on ICAO24 address 000001. The receiver plots that aircraft at those coordinates after a short delay.

Two PortaPack H4M Pro units side by side, the left showing the Mayhem map view with a TEST1234 aircraft plotted over the Niger delta at 36,000ft, the right showing the ADS-B TX position configuration
The map view on the left, the ADS-B TX position page on the right.

Setting both the LNA and VGA gains on the receiver to 24 removes that delay. On restarting transmission the receiver captures immediately, the callsign and altitude populate, and the hit count passes a thousand.

Two PortaPack H4M Pro units side by side, the left showing the ADS-B RX table with TEST1234 decoded and over a thousand hits at LNA 24 and VGA 24, the right showing the ADS-B TX screen transmitting on 1090.0000MHz
ADS-B RX with LNA and VGA at 24 on the left, the transmitting unit on the right.

POCSAG paging

Select POCSAG RX on the receiving unit and open POCSAG TX on the transmitting unit. The defaults are enough for the test. They are alphanumeric at 1200bps, address 0000000, function D and standard polarity, with PORTAPACK as the message. Both units share 466.1750MHz at default gain.

The receiver logs the message with its timestamp, bitrate and function code. POCSAG is sensitive to bitrate and polarity, so a clean decode indicates that the transmit chain is correctly timed.

Two PortaPack H4M Pro units side by side, the left showing the POCSAG RX log with decoded PORTAPACK messages at 1200bps, the right showing the POCSAG TX configuration with the message PORTAPACK ready to send
The POCSAG RX log on the left, the POCSAG TX page on the right.

BLE advertising

Open BLE TX on the transmitting unit and BLE RX on the receiving unit, setting the receiver to Auto with Sort set to Hits. Both operate on 2402MHz. On the transmitting side, load any file through Open file, enable BLE TX, set the gain to 16 and turn Loop on. On the receiving side, tap Clear to empty the existing records and refresh the list.

MAC address 01:02:03:04:05:06 then accumulates hits at the top of the list, matching the address the transmitter advertises. A receiver gain of 24 gives the fastest capture, and moving it in either direction slows the hit rate.

Mayhem BLE RX screen in Auto mode sorted by hits, showing filter MAC, checkbox options and a table of MAC addresses with hit counts and dBm values
BLE RX in Auto mode, sorted by hits.

Changes in v2.4.0.1

Version 2.4.0.1 alters wideband FM reception and BLE. The operating procedure is unchanged in both cases.

Wideband FM

The route through the menus is the same as in v2.4.0: Receive, then Audio, then WFM, tuned to 100.6MHz with default gains. The waterfall is cleaner, with the carrier and its sidebands better separated, and speech is more intelligible.

Mayhem v2.4.0.1 Audio RX screen in WFM on 100.6000MHz showing a cleaner waterfall display with 25kHz step and sharper carrier definition
Audio RX in WFM on 100.6MHz under v2.4.0.1.

BLE

The intermittent reception failures present in v2.4.0 have been corrected. Setup is otherwise unchanged, though the release notes now give transmit gain as 24 rather than 16. A receiver gain of 24 remains the fastest setting for capture.

Summary of settings

After flashing, calibration and testing, the unit receives and demodulates broadcast and narrowband voice, carries text over APRS, decodes ADS-B position reports, handles POCSAG paging, and tracks BLE advertisements by hit count. Runtime estimates match the cell. Two settings need raising from their defaults. ADS-B needs the LNA and VGA gains at 24, and BLE needs a receiver gain of 24.

The table below lists the settings used in each test.

Test Frequency Mode Gains
WFM broadcast 100.6MHz Audio RX, WFM Default
NFM voice 466.1750MHz Audio RX / Signal Generator TX 16, RX default
APRS 144.3900MHz (144.8000MHz in Region 1) APRS TX / APRS RX Default
ADS-B 1090MHz ADS-B TX / ADS-B RX TX 16, RX LNA 24 and VGA 24
POCSAG 466.1750MHz POCSAG TX / POCSAG RX Default
BLE 2402MHz BLE TX / BLE RX TX 16 (24 in the v2.4.0.1 notes), RX 24

Tools Used:

Firmware and Further Reading:

Procedures and measured values in this article follow the OpenSourceSDRLab technical note "HackRF Pro and PortaPack H4M Pro: Parameter Settings and Firmware Operations".

Next article Point of Fail: Hacking a POS Device with WHIDBOARD

Leave a comment

Comments must be approved before appearing

* Required fields