M57-Patents Scenario
Digital Corpora · 2009
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A scripted corporate scenario covering the first four weeks of a fictional patent-search company, from 13 November 2009 to 12 December 2009. It ships daily hard drive images and daily RAM captures for each computer, USB drive images, inbound and outbound packet captures, final-day images of every system, and simulated case paperwork including detective reports, warrants and affidavits.
Who it is for, and when
This is the standard teaching case for running a whole investigation end to end rather than one artefact at a time: you can work it as a disk forensics exercise or as a network forensics exercise, and because there are daily images you can practise differencing and building a timeline across machines and days. It is also useful for validating that a new tool or workflow produces the answers you already know are there.
What it does not cover
The answer keys, hash sets and scenario emails are encrypted and released only to faculty at accredited institutions, so a self-studying practitioner has no authoritative marking scheme. The environment is Windows-era 2009 with no mobile, cloud or modern endpoint telemetry, so it teaches method rather than current artefacts.
Go to the source
Open at digitalcorpora.org (opens in a new tab)https://digitalcorpora.org/corpora/scenarios/m57-patents-scenario/
Details
- Type
- Dataset
- Written for
- New to the fieldWorking examinerNew to the field, Working examiner
- Publisher
- Digital Corpora
- Year
- 2009
- Topics
- datasets, training, imaging, memory-forensics, network, timeline, windows
- Checked at source
Related entries
Digital Corpora
FreeA public repository of forensic disk images, memory dumps, mobile extractions, network packet captures and file corpora assembled for forensic research and teaching. The data is held in Amazon S3 (s3://digitalcorpora/) under the AWS Open Data Sponsorship Program and served from downloads.digitalcorpora.org.
A set of eleven numbered DFIR challenges plus additional memory forensics, unallocated-space and Linux cases published by Ali Hadi, each with the scenario and the evidence to work it. Subjects include a breached web server with both disk image and memory dump, Windows user policy violation, alternate data streams, NTFS hidden-file recovery, browser artefacts, a Sysinternals-abuse malware case, encryption, and anti-forensics and data hiding.
13Cubed
Partly freeA YouTube channel and companion training site covering Windows, Linux and macOS endpoint forensics, memory analysis and threat hunting. The YouTube videos are free; the on-demand courses on training.13cubed.com are paid.
Cyber5W Free DFIR Courses
Partly freeA DFIR training company that publishes a substantial block of genuinely free self-paced courses alongside its paid catalogue. Confirmed free titles include C5W-100 Introduction to Digital Forensics, Linux Forensics Distributions, Intro to Linux from a Forensics Perspective (Ubuntu and Tsurugi), Writing Forensics Reports, Computer Data Representation, Working with Files, Prepare Your Forensic Environment, Working with Virtual Hard Disk, several Spanish-language courses on evidence acquisition and Windows forensics, and a set of case-study workshops.
FTK Imager
Partly freeA free Windows imaging and preview tool, originally from AccessData and now distributed by Exterro, which acquired the FTK line. It creates raw, E01, and AD1 images, captures live RAM, previews file systems before acquisition, and produces hash verification reports.