Legal Cyber Academy
DatasetFreeCurrent

Digital Corpora

Simson Garfinkel and contributors · Digital Corpora · 2009

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A public repository of forensic disk images, memory dumps, mobile extractions, network packet captures and file corpora assembled for forensic research and teaching. The data is held in Amazon S3 (s3://digitalcorpora/) under the AWS Open Data Sponsorship Program and served from downloads.digitalcorpora.org.

Who it is for, and when

This is the default answer to "where do I get evidence I am allowed to publish about?" — tool validation, method comparison, classroom exercises and writing up a technique without touching a live case. The site states that the disk images, memory dumps and packet captures are freely available and may be used without prior authorization or IRB approval, and its terms of use place original site content, metadata, scenario data and teacher guides under CC0 because they were produced by US government employees in the course of their duties. Papers and reports using the data are expected to cite Garfinkel, Farrell, Roussev and Dinolt, "Bringing Science to Digital Forensics with Standardized Forensic Corpora" (DFRWS 2009).

What it does not cover

CC0 covers only the original site content: copyrighted software and third-party material sitting inside the disk images and packet dumps keep their own terms, so redistribution of an image is not automatically clean. The Real Data Corpus of secondhand drives bought worldwide, which was the site's one collection of genuine third-party personal data, is marked "no longer available" and cannot be obtained.

Go to the source

Open at digitalcorpora.org (opens in a new tab)

https://digitalcorpora.org/

Details

Type
Dataset
Written for
New to the fieldWorking examinerNew to the field, Working examiner
Author
Simson Garfinkel and contributors
Publisher
Digital Corpora
Year
2009
Topics
datasets, imaging, memory-forensics, network, mobile, training
Checked at source
  • A scripted corporate scenario covering the first four weeks of a fictional patent-search company, from 13 November 2009 to 12 December 2009. It ships daily hard drive images and daily RAM captures for each computer, USB drive images, inbound and outbound packet captures, final-day images of every system, and simulated case paperwork including detective reports, warrants and affidavits.

  • The research blog of Hexordia, a mobile forensics training and consulting firm, with posts from a named group of contributors including Jessica Hyde, Adam Hachem, Nicholas Dubois, Elizabeth McPherson, Debbie Garner and Kim Gatson.

  • A set of eleven numbered DFIR challenges plus additional memory forensics, unallocated-space and Linux cases published by Ali Hadi, each with the scenario and the evidence to work it. Subjects include a breached web server with both disk image and memory dump, Windows user policy violation, alternate data streams, NTFS hidden-file recovery, browser artefacts, a Sysinternals-abuse malware case, encryption, and anti-forensics and data hiding.

  • A gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.

  • The annual research challenges set alongside the DFRWS conferences, with scenario data, documentation and published results kept as repositories in the DFRWS GitHub organisation. Editions available there include 2005 (memory analysis), 2006, 2009 (PlayStation 3), 2012-2013, 2015, 2017 and 2018 (IoT), 2021 (multisource analysis and correlation) and 2023.