National Software Reference Library (NSRL) and Reference Data Set (RDS)
National Institute of Standards and Technology
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A NIST library of collected software, supported by DHS and law enforcement partners, from which file profiles are computed and published as the Reference Data Set: digital signatures of known, traceable application files. The site distributes current RDS hash sets, separate non-RDS hash sets and legacy tooling, under a stated NIST redistribution policy.
Who it is for, and when
Load the RDS into your forensic suite to suppress known operating system and application files so triage and keyword work focus on user-created data. It is also the citable authority when you need to say in a report that a given file is a known, unmodified vendor-distributed file rather than something the user created.
What it does not cover
The RDS is a known-file list, not a malware or contraband list — presence means 'known software', never 'benign', and absence means 'not in the library', never 'suspicious'. Coverage of niche, bespoke, non-English and very recent software is patchy, and the published sets and formats change between releases, so record which release you used.
Go to the source
Open at nist.gov (opens in a new tab)https://www.nist.gov/itl/ssd/software-quality-group/national-software-reference-library-nsrl
Details
- Type
- Dataset
- Written for
- Working examinerWorking examiner
- Publisher
- National Institute of Standards and Technology
- Topics
- hash-sets, datasets, triage, validation, us-federal
- Checked at source
Related entries
A NIST repository of documented simulated digital evidence — images and data sets with known ground truth — developed with National Institute of Justice support. Holdings include scenario images (hacking case, data leakage case), Windows registry and Unicode string-search sets, Mac and mobile images, memory images, file carving and deleted-file-recovery sets, and reference/control drives.
Garfinkel, Farrell, Roussev and Dinolt's DFRWS 2009 paper, published in Digital Investigation, arguing that digital forensics could not be a science without shared, redistributable test data, and introducing the corpora — including the real-data disk images and the govdocs document set — that the field went on to use.
NIST's long-running programme that builds tool specifications, test assertions, test procedures and test data for categories of forensic function — disk imaging, hardware and software write blocking, deleted file recovery, file carving, string searching, media preparation, mobile device and cloud data extraction, Windows registry and SQLite tools — and publishes the resulting test reports with DHS Science and Technology.
The decision holding that the Federal Rules of Evidence, not Frye's general-acceptance test, govern expert scientific testimony, and that the trial judge acts as a gatekeeper for reliability and fit. It offers a non-exclusive list of considerations: testability, peer review and publication, known or potential error rate, standards controlling the technique's operation, and general acceptance.
NIST's scientific foundation review of digital forensics, examining the peer-reviewed literature, academic material and practitioner guidance behind digital investigation techniques. It concludes the techniques rest on established computer science methods and are reliable when properly applied, while naming specific limits.