Techniques are described at category level only. The matrix records that something happened and where it was reported, never how it was done.
Select a technique to see its cases. Select a tactic header or "Signals" for notes on how requests to an AI assistant map onto that tactic.
Each dot is a documented case. The dark dot marks the earliest case in this dataset for that actor, which is a proxy for first documented use, not proof of first use.
Earliest documented case by actor
Method & sources
What this is
A threat-intelligence matrix of documented non-state misuse of commercial and small drones. Columns are tactics (the goal), cells are techniques (a category of behaviour), and each technique opens the cases that show it. The layout borrows from MITRE ATT&CK, a public knowledge base of adversary behaviour in cyber operations. This project is not affiliated with MITRE.
Inclusion criteria
- The actor is non-state: an armed group, criminal network or individual. State-backed groups (for example the Houthis and Hezbollah) are included but flagged, because sponsor support changes what they can do.
- The aircraft is a commercial, hobby or small drone, or a group-made or sponsor-supplied small UAV. Military programmes of states are out of scope.
- The case is reported by at least one reputable public source: research centres (CTC Sentinel, RAND, CNA, ACLED), UN Panels of Experts, government agencies, or major news organisations. Each URL was opened and checked against the claim during compilation; cases that could not be verified were dropped.
- Descriptions stay at category level. No case includes methods, parts, designs, payloads or defeat techniques.
Confidence coding
- well-documented two or more independent reputable sources, including at least one research or official body or several major outlets, with the core facts not in dispute.
- reported credible outlets report the case, but details rest on official or group claims, or the sources are not independent.
- single-source one verifiable source only. Treat as indicative.
AI-content enforcement notes
Each tactic carries a short note on what kinds of requests to an AI assistant would map onto it, and which nearby requests are legitimate. The notes are category-level labels for reviewers, not a policy. The line they draw is between general information (history, incident data, policy, defensive research) and operational uplift (methods, targeting, procurement, evasion).
Limits
- Reporting bias. High-profile conflicts (Iraq, Syria, Israel and Gaza, Colombia, Myanmar) are covered far better than rural Sahel or Mexican incidents. Counts measure reporting, not prevalence.
- The dataset is a curated sample of illustrative cases, not an event dataset. For counts, use ACLED or national statistics.
- "Earliest case" in the timeline is the earliest case included here, not a claim about first use.
- Group claims and government statements are both interested sources; where a case rests on them, it is coded "reported".
- Russia–Ukraine and other interstate drone warfare is excluded except where it shapes non-state diffusion.
Data
Cases, actors and the taxonomy are plain JSON in data/cases.json, data/actors.json and data/taxonomy.json. Each case carries its source list with publisher, title, date and URL.
How to cite
Walberg, Jonathan. 2026. "Non-State Drone Misuse Matrix." jwalberg.com. Compiled October 2026. Cite the underlying sources for any specific case.
Compiled October 2026 from public reporting. Corrections welcome via the contact details on jwalberg.com.