The 2009-M57-Patents scenario tracks the first four weeks of corporate history of the M57 Patents company. The company started operation on Friday, November 13th, 2009, and ceased operation on Saturday, December 12, 2009. As might be imagined in the business of outsourced patent searching, lots of other activities were going on at M57-Patents.
Two ways of working the scenario are as a disk forensics exercise (students are provided with disk images of all the systems as they were on the last day) and as a network forensics exercise (students are provided with all of the packets in and out of the corporate network). The scenario data can also be used to support computer forensics research, as the hard drive of each computer and each computer’s memory were imaged every day.
Please do not post solutions to our scenarios! They are being used in academic courses.
Instructor Materials and Answer Keys (encrypted):
Detective reports, warrant and affidavit:
Individual items from the corpus organized by calendar date as they were produced during the scenario can also be found here:
- Friday, 13 November has no images, because the scenario did not officially start until the following Monday (16 November). Your data may contain drive images from Thursday, 12 November. These are for reference (e.g. prior to any employee activity).
- Friday, 20 December has images for two separate drives for Jo and Terry. See the scenario information for that date.
Finally, we have made available some files resulting from processing the corpus with our other research tools:
We have prepared a variety of supporting materials for this scenario, including sample exercises, instructor slides, simulated detective reports and associated warrant, and encrypted scenario guides, hash tables, and answer keys for instructors (email Simson Garfinkel or Kam Woods for the passphrase).
The solution is distributed as an encrypted PDF file.
Please see our note onobtaining solutions.