Forensic Investigation of SDRSharp and RTL-SDR Dongle in Eavesdropping Radio Communications Academic Article uri icon

Abstract

  • Software-defined radio applications such as SDRSharp are misused by criminals to capture, demodulate, and eavesdrop on confidential information from radars, military radio systems, satellite transmissions, local and federal police radio communications using an RTL-SDR dongle. This study examines the forensic artifacts generated by SDRSharp and RTL-SDR dongle on Windows 11 Pro, identifying traces left behind in memory and data repositories. Using Magnet AXIOM, we investigated Browser History, Hardware Device Interfaces, Windows Event Logs, Registry, AppData, Downloads, ProgramData, System32, SDRSharp Installer Folder, Prefetch, Recycle Bin, and RAM content. Our findings revealed artifacts, including web links, package installation directories, hardware interfaces, drivers, event logs, configuration files, prefetch files, and memory exhibits, which can aid digital forensic investigators in proving or disproving software-defined radio usage. This study highlights the importance of software-defined radio forensics in modern cybersecurity, law enforcement, and military security, emphasizing the need for forensic methodologies, tools, and expertise.

Publication Date

  • 2026-03-01