DigitalCorpora.org is a website of digital corpora for use in computer forensics education research. All of the disk images, memory dumps, and network packet captures available on this website are freely available and may be used without prior authorization or IRB approval. We also have available a research corpus of real data acquired from around the world. Use of that dataset is possible under special arrangement.
From here you can view the available:
Most of the disk images are distributed in EnCase E01 format. We also make available a Digital Forensics XML file for many of the disk images that describes the files contained within each volume, and packets in PCAP format. Other files are available as well.
Accessing the Corpus!
All of our site data is stored in the Amazon S3 bucket s3://digitalcorpora/. You can download from that bucket. We recommend using the bucket directly in Amazon’s cloud. We get free data storage and transfer from Amazon as part of the Amazon Open Data Program, for which we are thankful!
You can also access this resource from the AWS command line interface with the command:
$ aws s3 ls s3://digitalcorpora/corpora/ PRE bin/ PRE drives/ PRE drives_bulk_extractor/ PRE drives_dfxml/ PRE files/ PRE hashes/ PRE mobile/ PRE packets/ PRE ram/ PRE scenarios/ PRE sql/ 2020-11-21 10:56:19 43 README.txt 2020-11-21 10:56:20 1783404 digitalcorpora.org-hashdeep-2020-04-01.csv 2020-11-21 10:56:19 1787101 digitalcorpora.org-hashdeep-2020-05-01.csv 2020-11-21 10:56:19 1794086 digitalcorpora.org-hashdeep-2020-06-01.csv 2020-11-21 10:56:19 1794914 digitalcorpora.org-hashdeep-2020-07-01.csv 2020-11-21 10:56:20 1796103 digitalcorpora.org-hashdeep-2020-08-01.csv 2020-11-21 10:56:20 1796275 digitalcorpora.org-hashdeep-2020-09-01.csv 2020-11-21 10:56:20 1796447 digitalcorpora.org-hashdeep-2020-10-01.csv 2020-11-21 10:56:20 1796619 digitalcorpora.org-hashdeep-2020-11-01.csv $
Publications describing these corpora and our related research can be found on our publications page.
Some of our scenarios have solutions available! In general, solutions are restricted to:
- Faculty members of accredited non-profit educational institutions.
- Individuals who are employees of the US Government or US Government contractors who are engaged in digital forensics training or research.
In some circumstances, the teacher’s solutions will also be made available to individuals working with foreign partners of the US government.
Solutions are distributed as PDF and ZIP files that are encrypted with a password; they are only available to faculty at accredited educational institutions and employees of government or law enforcement organizations that are working as researchers or trainers.
Information on obtaining the solutions can be found here: Obtaining Solutions.
- New Android 11 and 12 Images!2022-09-06 00:00:23
- 19 New Scenarios!2022-07-24 00:52:01
- New Wordpress2022-07-24 00:18:17
- Downloads has been transitioned from GMU to S3!2021-02-03 00:30:58
- Please try the new corpora browser2021-01-31 13:04:03
Citing the corpora
If you are writing a research article in which you are using data from this cite, please cite our paper:
Garfinkel, Farrell, Roussev and Dinolt, Bringing Science to Digital Forensics with Standardized Forensic Corpora, DFRWS 2009, Montreal, Canada.