IT Forensics · Drones

Notfallbereitschaft bei Drohnenvorfällen für Unternehmen

Für Unternehmen, die regelmäßig mit Drohnenvorfällen konfrontiert sein können, etwa im Zusammenhang mit dem Schutz von Betriebsgeländen oder kritischer Infrastruktur, kann eine im Vorfeld getroffene Notfallvereinbarung wertvolle Zeit sparen.

Enquire without obligation

This point is particularly important when it comes to drones, as manufacturers, model types, firmware versions and the storage and transmission formats used can vary considerably. A commercial multicopter drone, a fixed-wing drone used for surveying purposes and a homemade model must not be treated according to the same technical approach. Storage location, data format, encryption and connectivity determine which data is accessible and which backup method causes the least disruption.

Eine solche Vorabvereinbarung ermöglicht es, bereits im Vorfeld organisatorische Fragen zu klären, die im akuten Vorfall selbst wertvolle Zeit kosten und zum Verlust flüchtiger Beweismittel führen könnten.

Why LanCologne?

LanCologne does not examine digital traces relating to drone operations according to a blanket standard procedure, but rather on the basis of the specific drone type, the storage and transmission formats used, and the particular issue at hand. Our staff have decades of experience in information technology and many years of practical experience in IT forensics. We assist companies, solicitors and private individuals, as well as regularly supporting courts and public authorities, in the technical investigation of digital matters.

The investigation is generally carried out on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence is either left unchanged or, where technically unavoidable alterations have been made, these are transparently documented and the evidence is stored in a manner that preserves its integrity.

Our working methods and the tools we use

Our investigation does not begin by launching an analysis programme, but by gathering evidence. The drone, storage media, remote control and, where applicable, any connected mobile devices are documented in the condition in which they were found. A decision is then made as to which components need to be secured and in what order this is technically appropriate.

The next step is to define the backup strategy. We distinguish between read-only backups of memory cards, separate backups of remote controls and mobile devices, and the collection of available cloud data. The choice depends not on convenience, but on the storage location, encryption, availability of the components and the specific evidential requirements. Where technically possible, we work in read-only mode; any unavoidable changes to the state of the data are explicitly logged.

The backup created is documented using hash values. The actual analysis is not carried out on the original, but on a working copy or a verified forensic image. This allows searches or specific analysis steps to be carried out without continuously altering the original evidence.

Im Rahmen einer Notfallbereitschaftsvereinbarung klären wir organisatorische und technische Rahmenbedingungen bereits im Vorfeld, um im tatsächlichen Vorfall ohne Zeitverlust mit der forensischen Sicherung beginnen zu können.

For a reader unfamiliar with the subject, one point is particularly important: a forensic programme does not automatically „find" the truth. It reads data structures and interprets them according to known rules. If a new firmware or app version changes a data format, an automated analysis may produce an incomplete or incorrect result. That is why, in the case of crucial findings, we check which file or data structure the result originates from and whether a second technical approach confirms the same findings.

We deliberately do not use any dedicated, manufacturer-specific drone forensics software, as such software is not reliably available for many models and formats anyway. Instead, we analyse storage media, mobile devices and common file and database formats using our established forensic tools, in particular Belkasoft X and X-Ways Forensics. Where proprietary, undocumented binary formats from individual manufacturers prevent a fully automated analysis, we examine the raw data manually and document any technical limitations transparently, rather than claiming an unsubstantiated finding.

Typical areas of application

Judicial and non-judicial expert reports
Securing evidence from drones, storage media, remote controls and companion devices
Investigation of different types of drones and manufacturers’ platforms
Investigation of crashes, collisions and loss of control
Analysis of flight, media, app and system artefacts
Reconstruction of flight routes, usage times and access times
Cross-checking of automated analysis results
Analysis of deleted, historical or only indirectly visible traces
Documentation for courts, solicitors, insurance companies, public authorities and businesses

This is how the forensic investigation is carried out

1Collection of evidence and documentation of the condition

The drone, its storage media, the remote control and, where applicable, any connected mobile devices are first clearly identified and documented either photographically or in writing. We record the physical and electronic condition in which the components were found. This information may prove crucial later on.

2Technical classification

The manufacturer, model, firmware version, storage media used and connectivity are identified. Only then can it be determined which data is generally accessible and which backup method is appropriate.

3Secure storage that preserves evidence

Data is backed up in such a way that the original state is altered as little as possible. Depending on the circumstances, memory cards are read in write-protected mode, controllers and mobile devices are backed up separately, and any available cloud data is captured with the authorised person’s consent. Every step is logged.

4Integrity check

Any images or copies created are given unique names, assigned hash values and verified. Analysis and searches are then carried out exclusively on working copies.

5Multi-stage evaluation

Existing data is analysed in a structured manner using our established forensic tools. Where standard software does not fully support a particular format, this is documented rather than being tacitly ignored.

6Manual validation

In the case of findings that are particularly relevant to the evidence or unusual, we manually check the raw data, file structures and metadata to rule out any automated misinterpretations.

7Report and reference to evidence

At the end, we do not merely list what could be gleaned from the data. We explain the technical source on which the findings are based, what conclusions can be drawn, and where the limitations lie.

Why is this area of investigation relevant to forensics?

Für Unternehmen, die regelmäßig mit Drohnenvorfällen konfrontiert sein können, etwa im Zusammenhang mit dem Schutz von Betriebsgeländen oder kritischer Infrastruktur, kann eine im Vorfeld getroffene Notfallvereinbarung wertvolle Zeit sparen.

The forensic value lies not solely in the volume of data found, but in its origin and reliability. A file name, a timestamp or a log entry can be misleading without context. That is why we document how an artefact may have come into being, what alternative explanations exist and what further evidence supports the findings.

Eine solche Vorabvereinbarung ermöglicht es, bereits im Vorfeld organisatorische Fragen zu klären, die im akuten Vorfall selbst wertvolle Zeit kosten und zum Verlust flüchtiger Beweismittel führen könnten.

In the case of drones in particular, attempts to carry out a comprehensive technical analysis may also reach their limits if manufacturers use proprietary, unpublished data formats. A lack of documentation, encrypted storage areas and manufacturer-specific cloud connections highlight why it is so important to carry out a proper backup and to communicate existing limitations transparently before the actual analysis begins. Errors made at this stage cannot always be rectified later on.

Frequently Asked Questions

Do you use specialised drone forensics software?+
We deliberately do not use any dedicated, manufacturer-specific drone forensics software; instead, we analyse storage media, mobile devices and file formats using our established forensic tools. Where proprietary, undocumented formats prevent a full analysis, we communicate this transparently.
Which tools do you actually use?+
For our analysis, we primarily use Belkasoft X and X-Ways Forensics, which offer extensive support for storage media, mobile devices and common file and database formats.
Can you carry out a full assessment of every drone model?+
No. The scope of the analysis depends on the manufacturer in question, the file formats used and the relevant documentation. Any existing technical limitations are clearly stated in the report.
Why don’t you analyse the original storage medium directly?+
Because analysis software and operating systems can alter data. The actual analysis is therefore always carried out on a verified forensic copy.
Is it always possible to fully recover deleted flight data?+
No. Overwritten storage, damaged memory cards or proprietary encryption may impose technical limitations. Such limitations are openly documented.
Do you also review the companion app on your smartphone?+
Yes, provided it is available and you have the necessary authorisation, as the companion app often contains additional flight and usage data that is not stored on the drone itself.
How do you deal with different manufacturer formats?+
We assess on a case-by-case basis which data formats are available and which of our tools can be used to analyse them. Unsupported, proprietary formats are documented as such.
How do you explain the results to non-technical people?+
We do not merely describe raw technical data; we also explain what an artefact signifies, how it may have arisen, and what conclusions can actually be drawn from it.

LanCologne – IT Forensics Drones Cologne

Sie benötigen eine professionelle Untersuchung zu „Notfallbereitschaft bei Drohnenvorfällen für Unternehmen"? LanCologne unterstützt Sie bei der beweissicheren Sicherung, mehrstufigen Auswertung und nachvollziehbaren Dokumentation digitaler Spuren im Zusammenhang mit Drohneneinsätzen. Entscheidend ist dabei nicht, möglichst viele automatische Treffer zu erzeugen, sondern technisch belastbare und überprüfbare Beweise zu sichern.

Get in touch now