Digital Corpora
Simson Garfinkel and contributors · Digital Corpora · 2009
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A public repository of forensic disk images, memory dumps, mobile extractions, network packet captures and file corpora assembled for forensic research and teaching. The data is held in Amazon S3 (s3://digitalcorpora/) under the AWS Open Data Sponsorship Program and served from downloads.digitalcorpora.org.
Who it is for, and when
This is the default answer to "where do I get evidence I am allowed to publish about?" — tool validation, method comparison, classroom exercises and writing up a technique without touching a live case. The site states that the disk images, memory dumps and packet captures are freely available and may be used without prior authorization or IRB approval, and its terms of use place original site content, metadata, scenario data and teacher guides under CC0 because they were produced by US government employees in the course of their duties. Papers and reports using the data are expected to cite Garfinkel, Farrell, Roussev and Dinolt, "Bringing Science to Digital Forensics with Standardized Forensic Corpora" (DFRWS 2009).
What it does not cover
CC0 covers only the original site content: copyrighted software and third-party material sitting inside the disk images and packet dumps keep their own terms, so redistribution of an image is not automatically clean. The Real Data Corpus of secondhand drives bought worldwide, which was the site's one collection of genuine third-party personal data, is marked "no longer available" and cannot be obtained.
Go to the source
Open at digitalcorpora.org (opens in a new tab)https://digitalcorpora.org/
Details
- Type
- Dataset
- Written for
- New to the fieldWorking examinerNew to the field, Working examiner
- Author
- Simson Garfinkel and contributors
- Publisher
- Digital Corpora
- Year
- 2009
- Topics
- datasets, imaging, memory-forensics, network, mobile, training
- Checked at source
Related entries
A scripted corporate scenario covering the first four weeks of a fictional patent-search company, from 13 November 2009 to 12 December 2009. It ships daily hard drive images and daily RAM captures for each computer, USB drive images, inbound and outbound packet captures, final-day images of every system, and simulated case paperwork including detective reports, warrants and affidavits.
Hexordia Blog
FreeThe research blog of Hexordia, a mobile forensics training and consulting firm, with posts from a named group of contributors including Jessica Hyde, Adam Hachem, Nicholas Dubois, Elizabeth McPherson, Debbie Garner and Kim Gatson.
A set of eleven numbered DFIR challenges plus additional memory forensics, unallocated-space and Linux cases published by Ali Hadi, each with the scenario and the evidence to work it. Subjects include a breached web server with both disk image and memory dump, Windows user policy violation, alternate data streams, NTFS hidden-file recovery, browser artefacts, a Sysinternals-abuse malware case, encryption, and anti-forensics and data hiding.
Blue Team Labs Online
Partly freeA gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.
The annual research challenges set alongside the DFRWS conferences, with scenario data, documentation and published results kept as repositories in the DFRWS GitHub organisation. Editions available there include 2005 (memory analysis), 2006, 2009 (PlayStation 3), 2012-2013, 2015, 2017 and 2018 (IoT), 2021 (multisource analysis and correlation) and 2023.