Home

Awesome

<p align="center"> <a href="https://github.com/AndrewRathbun/DFIRArtifactMuseum"> <img src="https://raw.githubusercontent.com/AndrewRathbun/DFIRArtifactMuseum/main/DFIRArtifactMuseumLogo.jpg" alt="Logo" width="329" height="250"> </a> <h3 align="center">DFIR Artifact Museum</h3> <p align="center"> <a href="LICENSE" alt="License"> <img src="https://img.shields.io/github/license/AndrewRathbun/DFIRArtifactMuseum?style=flat-square" /></a> <a href="https://github.com/AndrewRathbun/DFIRArtifactMuseum/issues" alt="Issues"> <img src="https://img.shields.io/github/issues/AndrewRathbun/DFIRArtifactMuseum?style=flat-square" /></a> <a href="https://github.com/AndrewRathbun/DFIRArtifactMuseum/graphs/contributors" alt="Contributors"> <img src="https://img.shields.io/github/contributors/AndrewRathbun/DFIRArtifactMuseum?style=flat-square" /></a> <a href="https://github.com/AndrewRathbun/DFIRArtifactMuseum/pulls?q=is%3Apr+is%3Aclosed" alt="Closed PRs"> <img src="https://img.shields.io/github/issues-pr-closed/AndrewRathbun/DFIRArtifactMuseum?style=flat-square" /></a> <a href="https://github.com/AndrewRathbun/DFIRArtifactMuseum/network/members/" alt="Forks"> <img src="https://img.shields.io/github/forks/AndrewRathbun/DFIRArtifactMuseum?style=flat-square" /></a> <a href="https://github.com/AndrewRathbun/DFIRArtifactMuseum/stargazers/" alt="Stars"> <img src="https://img.shields.io/github/stars/AndrewRathbun/DFIRArtifactMuseum?style=flat-square" /></a> <a href="https://github.com/AndrewRathbun/DFIRArtifactMuseum/watchers/" alt="Watchers"> <img src="https://img.shields.io/github/watchers/AndrewRathbun/DFIRArtifactMuseum?style=flat-square" /></a> </p> </p>

Description

The DFIR Artifact Museum is a community-driven archive of DFIR-related artifacts. It was created to provide a centralized location for examples of artifacts from various operating systems.

Purpose

To increase accessibility to sample artifacts without individual researchers having to duplicate efforts to generate data that frankly should be done once and then shared with the community so more time and energy can be spent on analysis rather than artifact generation.

Benefits

Hopefully, with more exposure to artifacts from various operating systems centralized in a single location, someone who never uses Linux might gain more familiarity with what Linux artifacts look like. Same with someone who only uses Linux and doesn't use Windows.

Additionally, with more exposure to artifacts, hopefully those who enjoy creating tools will have sample data from which they can create a parser and share with the community. Having an artifact readily available as sample data takes one major hassle out of the way when it comes to having an idea for a parsing tool to actually creating it and sharing it.

DFIRArtifactMuseum Roadmap

Want to see what the future holds for the DFIRArtifactMuseum repo? Check out the project boards where the to-do lists can be found!

Contributing to DFIRArtifactMuseum

Please check out CONTRIBUTING.md if you want guidance on how you can contribute to the DFIRArtifactMuseum.

Other Projects of Interest

Acknowledgements

Special thank you to Kevin Pagano for the awesome logo!

Licensing/Source Attribution

Please see Digital Corpora's Research Paper on Bringing science to digital forensics with standardized forensic corpora