English version of this page. อ่านฉบับภาษาไทย · Governance and authorisation policy: Governance & Authorisation
Drone Association Thailand (DAT) delivers airspace security, counter-UAS, and offensive security testing services. Every engagement runs inside a written scope agreed in advance and within Thai law, as set out in our governance and authorisation policy.
Services
1. UAS Threat Assessment
Site survey and risk assessment covering how a drone could be used to observe, disrupt, or cause damage at your facility. The output identifies viable approach paths, gaps in current measures, and a spending order based on risk rather than equipment price.
- Terrain and viable flight-path analysis
- Verification of the site’s status under CAAT no-fly zone announcements
- Risk assessment against drone types actually in regional use
- Prioritised recommendations ranked by effectiveness, not cost
2. Drone Detection
Selection, supply, and deployment of detection systems matched to the site and budget, from handheld units to air surveillance radar.
- Portable RF detection across 100MHz–6GHz for mobile patrol work
- TDOA+AOA positioning where the launch point must be located
- Air surveillance radar for wide areas and targets carrying no control link
- Dedicated FPV detection, which operates on bands separate from commercial drones
Some equipment — signal jamming hardware in particular — is restricted under Thai radio spectrum law and may be limited to authorised agencies. We state the applicable legal restrictions before proposing any option.
3. Incident & Threat Analysis
Analysis of drone-related incidents: identifying the airframe type and its capabilities, assessing intent from flight behaviour, and examining data from recovered hardware. Our published analysis work is public and reflects how we approach these problems.
- Counter-UAS systems and terminology
- Fibre-optic drones: a threat that emits no detectable signal
- Drone swarm tactics analysis
- Teardown: the Promin-13 repeater drone and dual-channel control
4. Training
Courses for security personnel, facility managers, and agencies that must respond to unmanned aircraft, alongside remote pilot training to the regulator’s standard.
5. Regulatory Compliance Advisory
Guidance on aircraft and remote pilot registration, verifying a site’s status against no-fly zone announcements, and preparing documentation for flights requiring prior authorisation.
6. Penetration Testing & Vulnerability Assessment
Security testing of systems within a scope the client defines and authorises in writing, to find vulnerabilities before a real attacker does. Deliverables are written so system owners can act on them — not raw scanner output.
Engagement types
- Web application and API penetration testing
- Internal and internet-facing network penetration testing
- Vulnerability assessment with risk-based prioritisation
- Cloud configuration and access-permission review
- Security assessment of UAS control systems, C2 links, and Ground Control Stations
- Secure SDLC and CI/CD pipeline review
Methodology — Testing follows recognised international frameworks: the OWASP Testing Guide for web and API work, the Penetration Testing Execution Standard (PTES) for engagement structure, and NIST SP 800-115 for technical assessment process. Working to published frameworks means results are comparable and clients can audit our method.
Deliverables
- Executive summary and a separate technical report for system owners
- Severity rating for each finding with stated reasoning and reproducible evidence
- Remediation guidance prioritised by actual risk, not tool score
- Retest after remediation, where agreed in scope
- A log of testing windows and source IPs, so your team can separate our activity from a genuine attack
Preconditions — Every engagement requires written authorisation from a party with authority over the target systems, specifying in-scope assets, permitted testing windows, an emergency contact, and stop conditions. Where target systems sit on third-party infrastructure, the client must also hold that provider’s permission. Full principles are set out in our governance and authorisation policy.
How we work
| Stage | What happens | What you receive |
|---|---|---|
| 1. Scoping | Agree the sites, systems, and activities in scope — and what must not be touched | Scope document signed by both parties |
| 2. Assessment | Field collection and analysis, confined to the agreed scope | Activity log with timestamps and named responsible staff |
| 3. Reporting | Findings written with fact separated from assessment | Report with priorities and stated assessment limitations |
| 4. Handover | Walkthrough with the responsible team and a review schedule | Action plan and agreed review dates |
What we do not do
Stating limits matters as much as stating capability.
- We do not act on any system or aircraft outside the agreed scope
- We do not offer services that require legal powers held solely by state agencies
- We do not conduct penetration testing without written authorisation, even when the request comes from an executive of the organisation concerned
- We do not extract real user data from target systems beyond what is necessary to demonstrate a vulnerability
- We do not publish payloads or attack procedures, per our security publishing principles
- We do not accept work where the client lacks authority over the target system or site
Published research
We publish vulnerability, threat, and offensive-security tooling analysis under Cybersecurity, split into Zero-Day & Vulnerability and AI Pentest. Articles are in Thai.
On the counter-UAS side we also publish technical explainers, such as kinetic-energy drone interceptors for counter-UAS and drone detection technologies in operational use in Thailand. Articles are in Thai.
Contact
To discuss scope or request a quotation, use our contact page. Please state the type of site or system, the nature of your concern, and your timeframe, so we can assess whether the work falls within what we are able to take on.
