Related Experiment Video
Updated: Jun 30, 2026

Analyzing Dendritic Morphology in Columns and Layers
Published on: March 23, 2017
Dataset of Windows operating system forensics artefacts
Eva Marková1, Pavol Sokol1, Sophia Petra Krišáková1
1Pavol Jozef Šafárik University in Košice, Faculty of Science, Institute of Computer Science, Slovakia.
Abstract:
The dataset consists of records from the NTFS file system and event logs. In this study, we used images of devices from capture the flags competitions focused on the digital forensic of Windows operating systems and user activities. We created timelines of the security incident from the disk images using the Plaso tool, which we then processed and transformed the attributes of the timelines into binary values to simplify the application of data analysis and machine learning methods. The data are divided into 12 different files, and they are saved in CSV format.
Related Concept Videos
Statistical Software for Data Analysis and Clinical Trials
Overview of Microsoft Excel as a Data Analysis Tool

