Computer Forensic Reference Data Sets (CFReDS)
National Institute of Standards and Technology
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A NIST repository of documented simulated digital evidence — images and data sets with known ground truth — developed with National Institute of Justice support. Holdings include scenario images (hacking case, data leakage case), Windows registry and Unicode string-search sets, Mac and mobile images, memory images, file carving and deleted-file-recovery sets, and reference/control drives.
Who it is for, and when
Use it to validate a tool or a workflow against known answers, to run proficiency tests for accreditation, and to train staff on realistic images you are allowed to publish about. For an expert, working a CFReDS set is the cheapest way to establish measured familiarity with a technique before applying it to a real exhibit.
What it does not cover
These are constructed data sets, not real casework: they will not reproduce the scale, messiness or encryption of a live exhibit, and NIST states the portal is under development and may be reorganised. Most sets are explicitly not the Federated Testing data, so do not substitute one for the other.
Go to the source
Open at cfreds.nist.gov (opens in a new tab)https://cfreds.nist.gov/
Details
- Type
- Dataset
- Written for
- Working examinerNew to the fieldWorking examiner, New to the field
- Publisher
- National Institute of Standards and Technology
- Topics
- datasets, validation, tool-testing, training, us-federal
- Checked at source
Related entries
Garfinkel, Farrell, Roussev and Dinolt's DFRWS 2009 paper, published in Digital Investigation, arguing that digital forensics could not be a science without shared, redistributable test data, and introducing the corpora — including the real-data disk images and the govdocs document set — that the field went on to use.
NIST's long-running programme that builds tool specifications, test assertions, test procedures and test data for categories of forensic function — disk imaging, hardware and software write blocking, deleted file recovery, file carving, string searching, media preparation, mobile device and cloud data extraction, Windows registry and SQLite tools — and publishes the resulting test reports with DHS Science and Technology.
A CFTT offshoot that packages NIST's test methodology so labs can run it themselves and optionally share results: distributed as bootable Linux ISOs and a portable Windows web-server build, with report templates. Current suites cover disk imaging, forensic media preparation, hardware write blocking, string searching, SQLite recovery, mobile device acquisition and cloud data extraction, with companion datasets in CFReDS.
SWGDE's statement of the minimum a laboratory must do to test a tool before using it in casework, including what to record about the tool, the test data and the outcome. The version verified here is 18-Q-001-2.1 dated 7 March 2024.
A corpus of 986,278 real files harvested from US government web servers, distributed as numbered archives on Digital Corpora. The published statistical report (contributed by Forensic Innovations, Inc.) breaks the collection down by type and originating platform — hundreds of thousands of documents, text files, images and hypertext files across Windows, UNIX, DOS and Macintosh origins.