Wireless networks broadcast identifiers everywhere, and volunteers have mapped hundreds of millions of them to physical locations. That means a network name (SSID) or, more reliably, its hardware address (BSSID) can sometimes be turned into a point on a map — a distinctive pivot built on public wardriving data.
What you'll need
- The network's SSID and, ideally, its BSSID (the access point's MAC address)
- Wireless-mapping databases and the OSINT Maps category for cross-referencing
- Privacy & Security tools if you are auditing your own exposure
Steps
- Obtain the identifier. Capture the SSID from a photo, screenshot, or listing — and, if available, the BSSID, which is far more precise because it is unique to one device.
- Query a wardriving database. Search the BSSID in a public wireless-geolocation database; a match returns the coordinates where volunteers last observed that access point.
- Fall back to the SSID. If you only have the network name, search it — but expect many matches, since names are not unique, and use surrounding clues to narrow down.
- Cross-reference the location. Confirm any candidate coordinates against satellite and street imagery in the OSINT Maps tools to see whether the setting fits.
- Corroborate with context. Tie the result to other evidence — a visible landmark, a known address, a timestamp — before treating the location as confirmed.
Common pitfalls
- Assuming SSIDs are unique. Common names like "linksys" or a café chain appear thousands of times; a name alone rarely pinpoints anything.
- Stale or moved access points. Routers get replaced or relocated, so database coordinates can be out of date.
- Randomised identifiers. Modern phones and hotspots randomise addresses, which defeats this technique by design.
Verify your result
You have geolocated a network when a unique BSSID resolves to coordinates that independent imagery and contextual clues both support — not when a common SSID merely returns a plausible guess.