dfiq

DFIQ is a collection of investigative questions and the approaches for answering them


Keywords
dfiq, forensics, dfir, investigative, questions, security, digital
License
Other
Install
pip install dfiq==1.0.1

Documentation

Digital Forensics Investigative Questions

DFIQ Logo

DFIQ is a collection of Digital Forensics Investigative Questions and the approaches to answering them. The goal of the project is to build a comprehensive catalog of investigative knowledge to help drive consistent, thorough, and explainable investigations.

Key Aspects of DFIQ:

  • DFIQ is a catalog of investigative knowledge, centered on Questions
  • Uses the concept of Scenarios to logically group Questions and help structure investigations
  • Stores data in an easily-readable, tool-agnostic format (YAML) to be used by others