Projects

DFRWS Supported Projects

Open source community driven projects that grew out of DFRWS Conferences and are actively maintained by members of the DFRWS community:

  1. Advanced Forensic File Format (AFF4)
    AFF4 is the next generation standard forensic container format supporting features such as storage virtualization, metadata storage, extensible compression and hashing schemes, and throughput scalable to high IO rates. AFF4 evolved from the DFRWS Common Digital Evidence Storage Format (CDESF) Working Group in 2006 and was presented in this DFRWS US 2009 paper and this DFRWS US 2010 paper. The AFF4-L extension to support logical imaging was presented in this DFRWS US 2019 paper. Today, the AFF4 Working Group actively collaborates on implementing, updating, and adopting the standard.

  2. Cyber-investigation Analysis Standard Expression (CASE)
    CASE began in 2015 with this DFRWS EU 2015 paper to provide a structured (ontology-based) specification for representing information commonly exchanged and analyzed by people and systems during investigations involving digital evidence. Today CASE is a Linux Foundation Community Project, supported by DFRWS.org, and actively maintained by members of the DFRWS Community.

  3. Systematic Objective-based Listing of Various Established Investigation Techniques (SOLVE-IT)
    SOLVE-IT grew out of community collaboration at the DFRWS US 2023 Conference to establish a resource and tools for systematic error mitigation for digital evidence, presented in this DFRWS EU 2025 paper. SOLVE-IT was inspired by the MITRE ATT&CK® cybersecurity resource, evolved from an initial digital evidence weakness taxonomy, and is actively maintained by members of the DFRWS Community. 

DFRWS Presented Projects

Actively used and maintained community-driven projects that have been presented at DFRWS Conferences:

  1. Artifact Genome Project (AGP)
    Online system for uploading and viewing digital forensic artifacts to be searched using keywords or any word that appears as part of the artifact.

  2. DFIR Outil de Recherche de Compromission (DFIR ORC)
    Collection of specialized tools for performing forensic analysis of IT security incidents impacting Microsoft Windows systems, dedicated to reliably parse and collect critical artefacts such as the MFT, registry hives or event logs.

  3. DFIR Toolkit (https://github.com/dfir-dd/)
    Collection of command line tools for performing forensic analysis of IT security incidents impacting Microsoft Windows systems, dedicated to reliably parse and collect critical artefacts such as the MFT, registry hives or event logs.

  4. Graph-Based Analysis of Network Traffic Data (GRANEF)
    Toolkit that enables graph-based analysis of network traffic and linked data (e.g., OSINT, CTI) to support IT security incident investigations.

  5. Hansken (https://www.hansken.org)
    Digital Forensics as a Service (DFaaS) platform developed by the Netherlands Forensic Institute (NFI) with components that are maintained by the community.

  6. SDHASH Fuzzy Hashing (sdhash)
    Tool that allows two arbitrary blobs of data to be quickly compared for similarity based on common strings of binary data, designed to be fast, scalable, and reliable for use during triage and initial investigation phases.

  7. SSDEEP Fuzzy Hashing (ssdeep)
    Tool for identifying almost identical file content using context triggered piecewise hashing (CTPH), also called fuzzy hashes, that find sequences of identical bytes in the same order, although bytes in between these sequences may be different in both content and length.

  8. VICS Safer Viewing Platform (VICSafer)
    AI-driven system for analysing large volumes of unknown images and videos that investigators encounter in child sexual abuse investigations, automatically finding features such as age, gender, body parts, and actions with customizable viewer safety controls.

  9. CodeSuite® (CodeSuite)
    CodeSuite from SAFE Corporation is a collection of patented computer code analysis tools used for comparing computer source code and executable code to help detect plagiarism, pinpoint copyright infringement, highlight trade secret theft, and measure intellectual property.

Adding a Project

If you presented a project at DFRWS that is being actively maintained and used, and would like to link it here, post the name, URI, and brief description to DFSci mailing list sending an email to one of the addresses detailed below:

subscribe: dfsci+subscribe at dfrws.org
unsubscribe: dfsci+unsubscribe at dfrws.org
post: dfsci at dfrws.org
get help: dfsci+help at dfrws.org

Digital Forensic Researcher and Academic Groups (DFRAG)

The aim of the DFRAG groups is to try and improve regional connections, communication, and collaboration within the digital forensics research community.

The first Digital Forensics Researcher and Academic Group was set up as a result of an impromptu meeting at DFRWS EU, where a small group of UK-based academics decided it would be helpful to be in contact more easily and more regularly.

DFRAG United Kingdom:
DFRAG-UK

Interested in setting up a group for your region? Contact dfrws at dfrws.org