DFRWS Forensic Challenges
DFRWS · 2023
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
The annual research challenges set alongside the DFRWS conferences, with scenario data, documentation and published results kept as repositories in the DFRWS GitHub organisation. Editions available there include 2005 (memory analysis), 2006, 2009 (PlayStation 3), 2012-2013, 2015, 2017 and 2018 (IoT), 2021 (multisource analysis and correlation) and 2023.
Who it is for, and when
Each challenge is deliberately aimed at something the field cannot yet do well, so the datasets are the reference material for method development rather than practice drills. The 2023 "Troubled Elevator" set, for example, provides ICS traffic in one pcapng, eight PLC external RAM dumps, seven PLC on-chip RAM dumps, a desktop memory dump, CCTV footage, a network diagram and the elevator programming manual — the kind of evidence mix you cannot otherwise obtain legally. The repositories are Apache-2.0 licensed and publish SHA256 checksums, and large files are split into compressed segments.
What it does not cover
There is no guided walkthrough and no tool that will simply parse these formats for you; the 2021 and 2023 sets in particular assume you can write your own parsers for embedded memory. The older challenges target platforms nobody encounters any more, and several repositories have not been touched since 2021-2024, so treat them as archived research data rather than a maintained course.
Go to the source
Open at github.com (opens in a new tab)https://github.com/dfrws
Details
- Type
- Dataset
- Written for
- AdvancedAdvanced
- Publisher
- DFRWS
- Year
- 2023
- Topics
- datasets, ctf, research-publishing, memory-forensics, network, validation
- Checked at source
Related entries
Garfinkel, Farrell, Roussev and Dinolt's DFRWS 2009 paper, published in Digital Investigation, arguing that digital forensics could not be a science without shared, redistributable test data, and introducing the corpora — including the real-data disk images and the govdocs document set — that the field went on to use.
A set of eleven numbered DFIR challenges plus additional memory forensics, unallocated-space and Linux cases published by Ali Hadi, each with the scenario and the evidence to work it. Subjects include a breached web server with both disk image and memory dump, Windows user policy violation, alternate data streams, NTFS hidden-file recovery, browser artefacts, a Sysinternals-abuse malware case, encryption, and anti-forensics and data hiding.
Blue Team Labs Online
Partly freeA gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.
Digital Corpora
FreeA public repository of forensic disk images, memory dumps, mobile extractions, network packet captures and file corpora assembled for forensic research and teaching. The data is held in Amazon S3 (s3://digitalcorpora/) under the AWS Open Data Sponsorship Program and served from downloads.digitalcorpora.org.
A scripted corporate scenario covering the first four weeks of a fictional patent-search company, from 13 November 2009 to 12 December 2009. It ships daily hard drive images and daily RAM captures for each computer, USB drive images, inbound and outbound packet captures, final-day images of every system, and simulated case paperwork including detective reports, warrants and affidavits.