Drone forensics: the definitive Australian introduction
Drone forensics is the discipline of identifying, acquiring, analysing and explaining evidence from drones and their connected ecosystem so that findings can stand up to scrutiny in investigations and in court. In practical terms, drone forensics looks at the aircraft, the remote controller, the mobile device or tablet used to fly, the cloud services linked to the account, and any storage media and accessories that may hold data. For Australian readers, this introduction sets a clear, defensible foundation that reflects our regulations and evidentiary rules, uses metric units, and avoids hype. If you work in law enforcement, insurance, legal practice, enterprise security, incident response, or you operate a fleet under a ReOC with pilots holding a RePL, this opening section will show you what drone forensics really is, why it matters, what data typically exists, and how to approach integrity from the first minute.
Why drone forensics matters in Australia
The last decade has seen drones move from niche tools to everyday equipment across construction, media, public safety and agriculture. As usage has grown, so has the frequency with which drones appear in investigations. In Australia, the legal and regulatory setting is straightforward at a high level. Civil operations are governed by CASA under Part 101 of the Civil Aviation Safety Regulations, with baseline rules such as a maximum height of 120 metres above ground level for standard operations and visual line-of-sight. Whether an investigation is civil or criminal, the context for admissibility is the Evidence Act at Commonwealth and state levels, where the central questions are authenticity, reliability and relevance. Drone forensics matters because it helps a decision maker understand what flew, when, where, how and under what configuration, using verifiable artefacts rather than conjecture.
For public safety teams, drone forensics can validate claims about intrusion into restricted airspace, unsafe proximity to people or aircraft, or operations conducted without the required authorisations. For insurers, it can clarify disputes about pilot behaviour and equipment status at the time of a loss. For corporate security and risk managers, it can establish whether a drone was part of a data exfiltration plan, a surveillance attempt, or an innocent flight that triggered an alert. In every case, the same principle applies. A methodical, documented process is far more persuasive than an opinion. That is why a structured approach to drone forensics is valuable even when a matter never reaches a courtroom.
What counts as evidence in drone forensics
Evidence in drone forensics spans several layers. First is the aircraft itself. Modern drones record a wealth of telemetry including GPS tracks, time stamps, battery information, motor status, sensor status, obstacle detection events and control inputs. Depending on platform and firmware, this data may be stored internally on the aircraft, on removable media, and sometimes in encrypted containers. Second is the remote controller. Many newer systems either cache data in the controller or act as a pass-through to the attached device. Third is the handset or tablet used to fly. Companion apps create logs, caches, thumbnails, configuration files and crash reports that can be extremely revealing during timeline reconstruction. Fourth is the cloud. Some platforms synchronise flight records, firmware updates, account metadata and media to vendor servers. Finally, there are associated sources such as microSD cards, SSDs, external recorders and even ground station laptops used for mission planning.
The presence of data does not guarantee accessibility. Manufacturers legitimately protect sensitive content and intellectual property through encryption and signing. That means a core skill in drone forensics is knowing where logs typically exist for a given platform, which artefacts are likely to be encrypted, and which tools are capable of parsing them in a forensically sound manner. In practice, practitioners often combine general digital forensic suites with specialist viewers or parsers designed for particular log formats. Some of these tools can process standard text or CSV flight logs generated by companion apps. Others handle raw data from the aircraft, which can be more granular but also more complex and protected. Understanding that mix helps an investigator set realistic expectations about what can be proven.
Legal and regulatory context for drone forensics in Australia
Drone forensics sits inside two broad frameworks. The first is aviation regulation. Under CASA Part 101, most standard operations are capped at 120 metres above ground level and require the pilot to keep the drone within visual line-of-sight, remain clear of controlled aerodromes, and avoid flying directly over people. Organisations that need to operate outside those parameters generally require approvals, documented risk controls, and robust record keeping. The second framework is evidence law. Australian courts routinely hear digital evidence provided that authenticity and chain of custody are properly addressed. For investigators, that means the procedures you follow can matter as much as the data you acquire. Well written notes, repeatable acquisition, prompt hashing of originals and careful packaging go a long way toward removing doubt later.
It is also useful to understand policy developments that may affect attribution. Remote identification is the idea that drones transmit basic identification and location details to assist authorities. Different jurisdictions have taken different approaches. In Australia, policy work and consultation have been progressing on how a fit-for-purpose model could operate. At the time of writing, there is no nationwide mandate in force. That status may change in future. For the purposes of drone forensics today, the practical takeaway is that investigations still rely on artefacts available from devices, aircraft and networks rather than a universal broadcast identifier.

Integrity first: foundations that make drone forensics defensible
The technical skill to parse logs is only part of a defensible case. The other part is maintaining integrity from first contact. Start by securing the scene and documenting what is collected from where, by whom, and when. Photograph and label the aircraft, controller, batteries, media cards, cables and any cases or accessories. Where safe and lawful to do so, isolate devices from networks to minimise remote tampering. Use clean write blockers and forensic imaging techniques for media and mobile devices. Generate cryptographic hashes for original images and important exported files. Record versions of every tool used, including parsers and viewers, and keep copies for reproducibility. If you must perform a live acquisition from a powered device, record the reason, the steps taken and any changes observed.
Drone forensics also benefits from a clear plan before the first keystroke. Define the hypotheses you are testing. For example, did this aircraft enter a controlled airspace area at a specific time. Was return to home deliberately disabled. Did the pilot fly beyond visual line-of-sight without approval. Did the firmware log a battery error close to the incident. The plan shapes the triage order. You might start with quick-access app logs to establish a high-level timeline, then move to aircraft data for higher fidelity, then corroborate with media EXIF, network logs, ATC contacts or ground control records as applicable. When findings are assembled, present them with plain English explanations of technical terms so that non-specialist readers can follow the reasoning.
Common data you will see in drone forensics
While every platform differs, several recurring artefacts appear across many brands. Flight logs often contain time series of latitude, longitude and altitude, plus home point coordinates, ground speed, attitude, throttle inputs and distance from the home point. Battery records can show per-cell voltages, temperatures and discharge rates. Event streams may mark take-offs, mode changes, return to home triggers, obstacle warnings and forced landings. Some systems record gimbal angles, camera settings and capture events down to the frame. On the mobile device side, you will often find application preferences, account identifiers, device names, crash reports, cached thumbnails and temporary copies of media. Location services and notification histories can add context.
It is important to match the extraction method to the device. A logical extraction from a modern smartphone may collect app databases and caches without low-level device secrets. A physical or file system extraction may be required to access certain secure stores, which raises legal and policy considerations. The same is true of aircraft storage. Some raw logs are readable with established viewers. Others require vendor cooperation or advanced expertise. The goal is not to prise open everything at any cost. The goal is to preserve integrity, collect what the law allows, and analyse enough material to answer the investigative question with confidence.
How drone forensics supports timelines, attributions and risk decisions
In many matters, the core deliverable is a clear, defensible timeline. Drone forensics can link a specific aircraft identifier and account to a sequence of coordinates and events at known times, supported by media and configuration snapshots. That timeline may then be reconciled with airspace information, NOTAMs, permit records and witness accounts. In an enterprise context, the same approach helps operators learn from incidents. If a flyaway occurred, was it triggered by a configuration change, a magnetic interference warning that went unheeded, or a battery sag under heavy load. If a mapping mission produced gaps, did the GNSS environment degrade or was there a mission planning error. The same practice that makes findings persuasive to a court also makes them useful for safety management systems.
Drone forensics is equally powerful in exonerating pilots. Logs can show that a geofence prevented entry to a sensitive area, that a return to home occurred automatically due to signal loss, or that a reported altitude was in fact relative height above the launch point rather than a breach of the 120 metre rule. Nuanced analysis beats assumptions. That is why articulating units, reference frames and coordinate systems in reports is essential. If altitude is barometric or derived from vision systems, say so. If distances are planar rather than ground distances over terrain, be explicit. Clarity reduces the risk of misinterpretation and helps non-technical audiences trust your findings.
Scope and structure of this series on drone forensics
This introduction sets the stage for deeper sections. Next, we will examine platform-specific artefacts and parsers that are commonly encountered, with clear notes on encryption and version limits. We will also cover practical acquisition workflows for aircraft, controllers and mobile devices, including isolation options, cable sets and power considerations. After that we will walk through reporting structure and visualisation options that make complex timelines legible to decision makers. Throughout, we will keep the focus on Australia, using CASA rules and terminology, metric units, and examples drawn from local practice where possible. The aim is not to turn every reader into a lab specialist. The aim is to help Australian investigators and operators understand what is realistic, what is provable, and how to get there without compromising integrity.
Above all, remember that drone forensics is a multidisciplinary practice. Aeronautical knowledge helps you read flight modes and sensor behaviour. Digital forensics gives you the tools to acquire and validate data. Legal knowledge informs scope and consent. Operational experience tells you which questions actually matter to a case. When those strands are combined and documented, your findings will be much harder to shake on cross-examination and far more useful to safety teams who want to learn from incidents. The rest of this series will build on that mindset. It will stay practical, conservative in its claims, and anchored in Australian requirements so that you can apply it with confidence.
Platform-specific artefacts in drone forensics
Once the fundamentals of drone forensics are understood, the next step is to examine the artefacts produced by specific platforms. Not all drones store data in the same way, and knowing the expected log structures for common systems helps investigators avoid wasting time and ensures that nothing critical is overlooked. In the Australian market, DJI dominates professional and consumer operations, followed by Autel, Parrot, Skydio and a smaller number of specialised enterprise platforms. Each ecosystem has its own quirks that must be recognised if evidence is to be reliable and admissible.
DJI systems
DJI drones are the most common targets in drone forensics. Their flight controllers produce multiple log types. The mobile application logs, often in text or CSV format, provide accessible summaries of flights with GPS points, altitudes, speeds, and pilot inputs. These are widely used for quick reviews but should not be the sole source relied upon. More detailed logs are produced by the aircraft itself in DAT files, which contain high-frequency sensor and control data. These files can be parsed with specialist viewers and provide precise reconstructions of what the aircraft did at sub-second intervals. Investigators should be aware that DJI systems often employ encryption, and firmware changes can alter how artefacts are stored. Maintaining an updated toolkit is essential.
Autel and Parrot
Autel aircraft produce JSON and binary flight records that can be reviewed through Autel software or converted with community tools. Parrot systems, such as the Anafi series, generate flight data that can include GPS tracks, orientation, and media metadata. In both ecosystems, the companion mobile apps retain caches, crash logs, and configuration files that are useful in reconstructing operator behaviour. Autel and Parrot systems are less common in large commercial fleets in Australia, but investigators should still be prepared to process them when they appear in evidence collections.
Skydio and advanced autonomy platforms
Skydio drones use strong autonomy features and their logs capture extensive machine vision data, navigation decisions, and obstacle detection. These platforms are increasingly used in industrial inspections and public safety. Forensic practitioners must handle their logs carefully, as file formats can be complex and may require proprietary viewers or cooperation from the manufacturer. When reviewing Skydio flights, investigators should document how the autonomy stack influenced flight paths, as this can be crucial for understanding whether a pilot or the system was controlling decisions at key moments.
Acquisition workflows in drone forensics
Having identified what artefacts exist, the challenge becomes acquiring them in a defensible way. In Australia, where CASA regulations emphasise documented safety management, the same approach applies to digital handling. Proper acquisition is about preserving the original state, avoiding contamination, and documenting every action.
For aircraft storage such as microSD cards, investigators should use write blockers and forensic imaging tools to create bit-for-bit copies, generating cryptographic hashes to verify integrity. For mobile devices, the method depends on the legal authority and the tools available. Logical acquisitions can often recover application databases and flight summaries, while file system or physical extractions may reveal deeper stores. In every case, careful records should be kept of what was attempted, what succeeded, and what tools were used. Remote controllers and accessories should not be neglected, as some cache logs or event histories locally.
Cloud services require particular care. Many platforms synchronise data to vendor servers, and obtaining those records usually requires account credentials or formal legal processes such as subpoenas or mutual legal assistance requests. Where cloud artefacts are retrieved, it is vital to document the access method and preserve original metadata. Without clear chain of custody, cloud evidence may be challenged in court.
Why workflows and artefact knowledge matter
Drone forensics is not about acquiring the maximum number of files; it is about acquiring the right files in the right way. Understanding how specific platforms log events ensures that investigators can prioritise their efforts. Correct workflows prevent contamination and strengthen the reliability of results. In practical terms, this means Australian investigators can stand in court and confidently state how a dataset was obtained, why it is complete, and how its integrity was preserved. That credibility is what makes drone forensics a recognised discipline rather than an ad-hoc practice.
Reporting, visualisation and evidentiary presentation for drone forensics
Good analysis still fails if the report is unclear or hard to verify. This section sets out a practical structure for Australian readers so that findings in drone forensics can be read and trusted by investigators, counsel and the court. The goals are simple. Keep the narrative understandable for non-technical readers, make methods transparent for experts, and package exhibits so that a third party can reproduce the key steps.
Suggested report structure
1. Executive summary. One to two pages in plain English that answer the central questions, list high level conclusions, and state any material limitations.
2. Scope and instructions. Who engaged you, the questions asked, relevant time bounds, locations and any limits on access or authority.
3. Method overview. Acquisition sources, tools, versions and settings. For every dataset, state whether acquisition was logical, file system or physical. Include a short integrity statement covering hashes, storage and handling.
4. Factual timeline. A neutral chronology of events using consistent time zones and units, cross-referenced to exhibits. Avoid conclusions in this section.
5. Analysis and findings. The reasoning that links artefacts to answers. Use screenshots and figures sparingly, with captions that explain what the image shows without requiring specialist knowledge.
6. Opinions and limitations. Separate facts from expert opinion. Acknowledge gaps, encryption that could not be lawfully bypassed, or datasets you could not obtain.
7. Appendices and exhibits. Hash manifests, chain-of-custody forms, tool outputs, exemplar screenshots, maps and 3D exports.
Time, coordinates and units
Ambiguity around time and location is a common source of dispute. For drone forensics reports in Australia:
- Use ISO 8601 timestamps and declare the primary time zone up front, for example AEST or AEDT. Where source data is UTC, show both UTC and local time once, then state the default for the rest of the report.
- State the coordinate reference system for maps. For national consistency prefer GDA2020 with the appropriate Map Grid of Australia zone for projected products, or WGS 84 for global latitude and longitude.
- Be explicit about altitude references. Clarify whether values are AGL estimated by sensors, barometric altitude, or AMSL. If a platform reports relative height from the launch point, say so.
- Use metric units consistently. Distances in metres and kilometres. Speeds in m/s or km/h. Temperatures in degrees Celsius.
Making complex data legible
Drone forensics often involves dense telemetry. Visualisation helps, provided it is done carefully.
- Orthomosaics and base maps. When presenting overviews, include a scale bar, north arrow and legend. State the source of the base map and the date of capture.
- Flight path plots. Show start, home point, key events and the incident location. Label mode changes, return to home triggers and signal loss with callouts that match event IDs in the logs.
- Timelines. A horizontal event timeline that aligns app logs with aircraft logs, media capture times and any ATC or witness records helps readers reconcile sources at a glance.
- 3D context. If you present a 3D model, add measurement annotations that demonstrate scale. Export a lightweight viewer file where licensing permits so a reader can inspect the scene.
- Media exhibits. For stills or clips, include the original file name, hash and EXIF summary in the caption. Avoid editing beyond redaction boxes and clearly describe any processing.
Integrity artefacts to include
Credibility in drone forensics depends on transparent integrity controls. Include the following as standard:
- A hash manifest using SHA-256 covering all originals and exported analysis files, plus the storage path and verification date.
- Chain-of-custody records listing each transfer, handler, time and storage condition.
- Tooling inventory listing versions, build numbers and operating systems used for parsing, mapping and report generation.
- Acquisition notes that state connectors, cables and power sources used, whether devices were isolated from networks, and any on-screen observations during live capture.
Explaining technical points in plain English
Reports should stand on their own without a glossary. When terms such as RTK, PPK, geofencing, home point or vision positioning appear, include a short parenthetical explanation the first time. Replace jargon with ordinary language wherever possible. For example, instead of writing that the aircraft experienced a GPS position solution degradation, write that satellite reception worsened so the position estimate became less accurate, and show the relevant signal metrics.
Court bundle packaging
When preparing an exhibit set for court, think about reproducibility. Provide a read-only directory tree with originals, working copies and report outputs clearly separated. Include a README that explains how to open viewer files or maps, and provide offline installers or contact details for any freeware required. Where exhibits include sensitive location data, provide an agreed redacted set for open court and a complete set for the court and parties under appropriate orders.
Common pitfalls to avoid
- Mixing facts and opinions. Keep them in separate sections. Do not let conclusions creep into the factual timeline.
- Unclear time handling. Switching between UTC and local time without warning creates confusion. Choose a default and stick to it.
- Assuming altitude meanings. Many platforms report relative height, not true height above ground or sea level. State which applies before drawing any conclusion about a 120 metre limit.
- Omitting provenance for screenshots. Every figure should cite its source file and hash in the caption or appendix.
- Over-processing images. Enhancements should be minimal and fully documented. Keep untouched originals.
Where this fits in the workflow
Reporting is not an afterthought. From the moment acquisition begins, think about how each step will be explained and verified later. Save tool outputs in stable formats, preserve configuration files, and write contemporaneous notes. By the time the analysis concludes, the report should almost write itself because the structure mirrors the investigation. That discipline is what makes drone forensics defensible and useful in Australian contexts.
Australian legal notes and courtroom-ready checklist for drone forensics
Drone forensics does not occur in a vacuum. Every stage of acquisition and reporting must align with Australian evidence law and procedural fairness if the material is to withstand scrutiny in court. This section provides a concise set of legal notes and a practical checklist tailored for investigators and practitioners working in Australia.
Legal context
The Evidence Act 1995 (Cth) and state equivalents govern admissibility. Digital material is treated as documentary evidence provided authenticity and relevance are established. Courts are less concerned with the specific technical methods than with whether the evidence is what it purports to be and whether it has been altered. For drone forensics this means:
- Authentication. Demonstrate that logs, media or telemetry came from the aircraft or device in question. Chain of custody records and hashes provide this link.
- Reliability. Show that the tools used are recognised in the field, versions are documented, and results are reproducible. Proprietary formats may need corroboration through multiple tools or vendor documentation.
- Relevance. Tie every dataset to the investigative question. Extraneous data that does not bear on the matter may be excluded or challenged as prejudicial.
- Privacy and consent. Where cloud accounts or personal devices are involved, ensure you have legal authority such as a warrant, subpoena or consent. Australian privacy law and surveillance devices legislation may apply depending on the context.
Courtroom-ready checklist
To make findings in drone forensics defensible in Australian courts, use the following practical checklist:
- Scene documentation. Photographs of all devices, accessories, packaging and labels at the time of collection.
- Chain of custody form. Record each handler, time, date, transfer and storage location. Use a simple table format that travels with the evidence bag.
- Hash manifest. Generate SHA-256 or better hashes of all original storage media and important exported datasets. Store the manifest as a signed PDF and include it in the appendices.
- Time and coordinates boilerplate. State in the methodology section how times and coordinates are handled, including the default time zone, datum and altitude reference. Repeat this in any figure captions that could be ambiguous.
- Tool log. Capture tool versions, build numbers, and operating systems. Where freeware or open source viewers are used, store the installer alongside the case files.
- One-page summary sheet. Prepare a plain-English document with case identifiers, scope, a map of the flight path, and bullet point findings. This assists counsel and the court to orient quickly before diving into the main report.
- Redaction and sensitivity handling. If the dataset includes sensitive location or personal data, prepare a redacted bundle for open court and retain the full set under protective orders. Document exactly what was removed.
- Exhibit packaging. Deliver evidence in a read-only medium such as DVD, Blu-ray or encrypted external drive. Provide checksum values separately for verification.
Templates and quick references
Practitioners often save time by keeping standard templates ready:
- Chain of custody template. A one-page table with fields for description, unique ID, handler, date, time, and storage conditions.
- Hash manifest template. A CSV or PDF form where each file path, file name, hash value and verification date is recorded.
- Time and coordinate statement. A paragraph that can be reused in reports, stating for example: “All times are recorded in AEST (UTC+10) unless noted. Coordinates are reported in GDA2020 latitude and longitude. Altitudes are relative to the launch point unless otherwise stated.”
- One-page case summary. Space for map, identifiers, key events, findings and limitations. This becomes the front sheet in court bundles.
By combining legal awareness with disciplined record keeping, Australian investigators can ensure that drone forensics results are not only technically sound but also procedurally robust. The checklist and templates above provide a practical foundation to achieve that outcome.
Risks, ethics and emerging trends in drone forensics
Like all forensic disciplines, drone forensics carries both opportunities and risks. Practitioners need to balance investigative value with ethical considerations, respect for privacy, and awareness of rapidly evolving technology. This section highlights the main risk factors, outlines ethical boundaries, and points to trends that Australian investigators should monitor over the coming years.
Risks in drone forensics
- Encryption and vendor lock-in. Many aircraft log formats are encrypted or change with firmware updates. Relying on single proprietary tools risks gaps or misinterpretations. Investigators should validate findings with multiple methods where possible.
- Data contamination. Handling devices without isolation may alter logs, timestamps or caches. The risk increases if mobile devices automatically connect to networks and sync data before acquisition. Standard practice is to isolate, image, and hash at the earliest point.
- Misinterpretation of technical terms. Altitude, distance and speed may be relative, barometric, or derived differently across platforms. Drawing legal conclusions without clarifying reference frames risks errors in court.
- Over-collection. Gathering data beyond scope raises privacy concerns and may complicate proceedings. Focus on proportionality and relevance.
- Chain of custody gaps. Any undocumented transfer or unexplained access creates grounds for challenge. Meticulous record keeping is critical.
Ethical considerations
Drone forensics often touches sensitive personal and commercial data. Ethical practice in Australia requires investigators to go beyond technical compliance and actively consider privacy, fairness and proportionality.
- Privacy. Respect the privacy of uninvolved individuals. Avoid unnecessary retention of images that capture private backyards, faces or vehicle plates unless they are directly relevant.
- Transparency. Be upfront about limitations, including encryption you could not bypass or artefacts you could not interpret. Overstating certainty damages credibility.
- Fairness. Present exculpatory findings as clearly as incriminating ones. Drone forensics can and should show when a pilot followed the rules as well as when they breached them.
- Consent and authority. Ensure appropriate legal authority is in place before examining personal devices or cloud accounts. This includes respecting conditions on warrants and subpoenas.
- Retention and disposal. Securely store datasets for the required retention period, then dispose of them in line with organisational policy and legal obligations.
Emerging trends to monitor
- Remote ID implementation. Australia is consulting on a national model for drone identification. Once adopted, Remote ID data may supplement traditional logs in forensic work.
- Autonomy and AI flight modes. Systems with obstacle avoidance, follow-me and fully autonomous mission planning create new artefacts. Parsing machine vision data and autonomy logs will become more important.
- Integration with broader digital forensics. Drone artefacts increasingly overlap with mobile device forensics, cloud forensics and even vehicle forensics. Expect multidisciplinary teams to handle cases jointly.
- Underwater and specialised platforms. ROVs and heavy-lift drones for delivery or firefighting bring new data types and safety considerations that forensic practice must adapt to.
- Tool standardisation. Professional bodies and working groups are moving toward agreed standards for parsing and reporting. Australian practitioners should align with these to maintain credibility internationally.
Keeping pace with these risks and trends ensures that drone forensics remains a robust and ethical practice. By treating privacy and integrity as core values, and by continually updating technical knowledge, Australian investigators can deliver evidence that is both persuasive and responsible.
Conclusion and future outlook for drone forensics
Drone forensics in Australia is firmly establishing itself as a necessary branch of digital investigation. From reconstructing accident scenes to clarifying airspace breaches, its value has already been demonstrated in law enforcement, insurance, corporate security and aviation safety. The sections above have explained the sources of evidence, the importance of integrity, workflows for acquisition and reporting, legal requirements, and the ethical obligations that must be observed. Taken together, they form a practical guide for investigators who want to ensure their work is both credible and useful.
The future outlook points to even greater relevance. Remote ID is expected to be implemented in Australia, providing additional attribution data to supplement flight logs. Advances in autonomy and artificial intelligence will create new types of artefacts, requiring investigators to interpret vision and navigation logs, sensor fusion outputs and automated decision traces with the same care they apply to traditional flight telemetry. As drones grow in size and capability, including specialised roles such as delivery or firefighting, forensic practice must adapt to new hardware and software environments.
What will not change is the need for integrity. Courts and organisations will continue to demand clear provenance, transparent reporting, and defensible methods. By applying consistent checklists, careful documentation, and an ethical approach, practitioners in Australia can keep drone forensics on solid ground. This will not only support justice and accountability but also contribute to safer skies and more responsible use of drones across the country.
As the field evolves, staying connected with professional communities, following CASA policy developments, and investing in ongoing technical training will be essential. Drone forensics is multidisciplinary by nature, and collaboration between aeronautical experts, digital forensic specialists, lawyers and policymakers will ensure it matures in a way that benefits both investigators and the wider public. The outlook is clear. Drone forensics is here to stay, and those who master it will be at the forefront of a critical investigative capability in Australia. Check out our article on Aerial photography in forensic investigation to find out more about this adjacent topic.

