https://github.com/foxforensics/corpus
A corpus of various file formats for (mostly) forensic testing.
https://github.com/foxforensics/corpus
corpus forensics fox test-files
Last synced: about 1 month ago
JSON representation
A corpus of various file formats for (mostly) forensic testing.
- Host: GitHub
- URL: https://github.com/foxforensics/corpus
- Owner: foxforensics
- Created: 2026-04-25T21:58:43.000Z (3 months ago)
- Default Branch: main
- Last Pushed: 2026-05-27T10:27:52.000Z (about 2 months ago)
- Last Synced: 2026-05-27T12:14:42.213Z (about 2 months ago)
- Topics: corpus, forensics, fox, test-files
- Language: Go
- Homepage:
- Size: 7.85 MB
- Stars: 1
- Watchers: 0
- Forks: 0
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
Awesome Lists containing this project
README
# Forensic Corpus
A corpus of various file formats for (mostly) forensic tool testing.
> Files named `fox` follow the [Fox Standard Test Pattern](FSTP.md).
Sources:
* Sample Active Directory from [Didier Stevens](https://blog.didierstevens.com/2016/07/12/practice-ntds-dit-file-part-1/)
* Sample Outlook file from [DFRWS Rodeo 2009](https://web.archive.org/web/20160402173454/http://dfrws.org/2009/rodeo.shtml)
* Sample PE files from [Corkamis PE File Corpus](https://github.com/corkami/pocs/tree/master/PE)
* Sample Windows artifacts from [NIST Computer Forensic Reference Data Sets](https://cfreds.nist.gov/all/DFIR_AB/ForensicsImageTestimage)