EviPlant
Education and training in digital forensics requires suitable challenge corpora containing realistic features including regular wear-and-tear, background noise, and the actual digital traces to be discovered during investigation.
Typically, the creation of these challenges requires overly arduous effort on behalf of the educator to ensure their viability. Once created, the challenge image needs to be stored and distributed to a class for practical training. This storage and distribution step requires significant resources and time and may not even be possible in an online or distance learning scenario due to the data sizes involved.
EviPlant is a system designed for the efficient creation, manipulation, storage and distribution of challenges for digital forensics education and training. The system relies on the initial distribution of base disk images containing solely bare operating systems. Educators can boot the base system, emulate the desired activity, and perform a diffing of the resultant image and the base image. This diffing process extracts the modified artefacts and associated metadata and stores them in an evidence package.