This module introduces techniques for reviewing sUAS evidence using open-source and commercial forensic tools, with an emphasis on structured workflows and defensible analysis. Students examine UAV-resident data, focusing on file system considerations, registered user information, aircraft identifiers, configuration data, and flight log analysis techniques used to reconstruct operational activity.
The module explores the interpretation of data stored on flash media devices, including examination of media folder structures, EXIF metadata associated with images, and embedded telemetry and metadata inserted into graphics and video files by manufacturers such as DJI. Emphasis is placed on understanding how flight, location, and sensor data are persistently embedded within media artifacts.
The module concludes with analysis of data from portable devices used to control sUAS, covering default Android and iOS application folder structures, synchronized versus local logs, error log analysis, and media file examination for geolocation and temporal context. Students are introduced to workflows for correlating offline artifacts across aircraft, controllers, and mobile devices to support comprehensive forensic reconstruction.