Lab Overview
This practical lab guides you through the complete drone forensics workflow from evidence collection to report preparation. You will apply the concepts learned in previous parts to realistic scenarios.
Complete hands-on exercises covering: evidence seizure and documentation, flight log extraction, GPS data analysis, flight path reconstruction, media evidence examination, and forensic report preparation for court.
Exercise 1: Evidence Collection
Exercise 2: Flight Log Extraction
Sample DatCon Command Line Usage
# Basic conversion
java -jar DatCon.jar -i FLY001.DAT -o flight001.csv
# With specific parameters
java -jar DatCon.jar -i FLY001.DAT -o flight001.csv --gps --osd --battery
# Export KML for Google Earth
java -jar DatCon.jar -i FLY001.DAT --kml flight001.kml
Exercise 3: Flight Path Reconstruction
10:23:45
10:35:12
Key Analysis Points
| Analysis Area | What to Look For | Forensic Significance |
|---|---|---|
| Home Point | Initial coordinates, any updates | Pilot location at takeoff |
| Maximum Distance | Furthest point from home | Intent and reach of operation |
| Maximum Altitude | Peak altitude reached | Regulatory compliance (120m limit) |
| Hovering Points | Locations with stationary positions | Areas of surveillance interest |
| Speed Patterns | Rapid movements, sport mode | Evasion attempts, reckless operation |
| Signal Loss Events | RC signal strength drops | Extended range attempts, jamming |
Exercise 4: Media Evidence Examination
ExifTool Commands
# Extract all metadata from a single file
exiftool -a -G DJI_0001.JPG
# Extract GPS coordinates
exiftool -gpslatitude -gpslongitude -gpsaltitude DJI_0001.JPG
# Export metadata from all files to CSV
exiftool -csv -r DCIM/ > media_metadata.csv
# Extract XMP drone data
exiftool -xmp:all DJI_0001.JPG
Exercise 5: Forensic Report Preparation
Report Structure Template
1. Executive Summary (1 page)
2. Case Information - Case number, dates, examiner details
3. Evidence Description - Items received, condition, identifiers
4. Chain of Custody - Complete custody documentation
5. Examination Environment - Tools, versions, workstation
6. Methodology - Procedures followed, standards applied
7. Findings
7.1 Device Information (make, model, serial, firmware)
7.2 Flight Log Analysis (dates, times, locations)
7.3 Flight Path Reconstruction (maps, timelines)
7.4 Media Evidence (inventory, metadata, content)
7.5 Mobile App Analysis (account, history)
8. Conclusions - Summary of factual findings
9. Appendices
A. Section 63 BSA Certificate
B. Hash Values
C. Flight Path Maps
D. Media Thumbnails
E. Raw Data Exports
- Evidence collection requires systematic documentation: scene photos, serial numbers, component inventory, and proper packaging
- Always create forensic images before analysis; verify with hash values
- DatCon converts DJI DAT/TXT files to CSV for analysis and KML for mapping
- Flight path reconstruction combines GPS data, altitude charts, and event correlation
- Media analysis includes EXIF extraction, SRT parsing, and geo-correlation with flight logs
- Forensic reports must include Section 63 BSA certificate for electronic evidence admissibility
- Use clear, objective language and distinguish facts from interpretation in reports