Technical field guide

The sections below preserve the service-specific depth behind Automobile & ECU Forensics, edited for the current national practice and its documented engagement model. Methods are selected for the source, authorization, system state and assigned specialty. No single tool or artifact establishes a conclusion, and legal, regulatory or certification decisions remain with the responsible authority.

A vehicle is a network of possible evidence sources

Automobile forensics may involve an event data recorder, infotainment unit, telematics module, navigation system, body or powertrain controller, camera, key record or a paired mobile device. The available data varies sharply by make, model, year, trim, software version, subscription status and event. A source map comes before acquisition so the engagement does not assume that one module contains the complete record.

The examiner records the vehicle and module identifiers, power and damage condition, prior repair or download activity, time settings and any step that could alter retained data. Manufacturer information and supported-tool documentation are checked for the exact implementation. Unsupported access can damage a module, change volatile state or produce a file that looks complete but is not interpretable.

Event data recorder and crash-related records

When an EDR is present and a qualifying event was recorded, it may retain a short window of pre-event or event data. Potential elements can include speed, brake status, throttle, restraint status, airbag deployment timing or change in velocity. Availability and meaning are vehicle-specific. For vehicles within its scope, 49 CFR Part 563 addresses specified EDR elements and retrieval disclosures, but the applicable rule and implementation must be confirmed for the model year at issue.

EDR data does not replace a crash reconstruction. It may require correlation with roadway evidence, vehicle inspection, photographs, camera footage, telematics and time-base analysis. The report identifies conversion assumptions, supported fields, missing records and any reason a module clock or trigger may not align with another source.

Infotainment, navigation and telematics

Depending on the system and retention state, an infotainment or telematics unit may retain device-pairing identifiers, call or message artifacts, navigation destinations, recent locations, media activity, Wi-Fi records, application data or vehicle events. A cloud account or paired phone may hold related records with different timestamps and retention. Correlation can help determine whether two artifacts describe the same trip or user interaction.

These records are not uniform. A listed phone does not prove who was driving. A destination does not prove the vehicle reached it. A stored coordinate may describe a search, route, last position or service event. Interpretation belongs with the system documentation and corroborating evidence.

ECU, CAN and diagnostic evidence

Controller Area Network buses carry messages among vehicle modules, but they are not a universal trip recorder. Diagnostic trouble codes, freeze-frame values, counters, configuration and event history may be retained by individual modules. A live bus capture shows communications during the capture window, while a module image or diagnostic download may address earlier state. The report should not confuse those two kinds of evidence.

Module-level work may use a supported diagnostic interface, bench setup or specialist laboratory method. The acquisition record identifies connectors, power conditions, software and database versions, session steps, output files and integrity checks. Any reconstruction opinion remains separate from the extracted record.

Vehicle forensic deliverables

Deliverables can include a source and module inventory, acquisition log, decoded records, normalized timeline, maps, paired-device correlation and a technical report with limitations. Where a system is unsupported or damaged, the exception record explains what was attempted and what remains unknown.