Extended cloud forensic dataset provides raw virtual machine memory dumps acquired at the hypervisor level. The collection includes memory dumps from Linux and Windows benign workloads as well as attack traces involving Emotet malware, ransomware infections, and SSH brute-force attacks. Prasad Purnaye published this dataset via Harvard Dataverse, with a last update recorded on 2026-07-06.
Use Cases
- Conduct memory forensics research based on raw hypervisor-level memory dumps.
- Analyze malware behavior based on attack traces involving Emotet and ransomware.
- Evaluate digital forensic tool performance based on memory dumps from benign and attack scenarios.
- Train machine learning models for incident response based on labeled attack and benign memory states.
Strengths
- Memory dumps are acquired at the hypervisor level, providing a specific system view.
- Dataset includes attack traces for multiple specific scenarios: Emotet malware, ransomware, and SSH brute-force attacks.
- Covers both Linux and Windows operating systems for benign workloads.
Limitations
- Column-level documentation is absent; field semantics must be inferred after download.
- Row count and total dataset size are unknown, which may limit suitability assessment.
- Description metadata is limited; actual data quality and file formats require manual inspection after download.
Provenance
- Source
- Harvard Dataverse
- Collection Method
- Memory dumps acquired at the hypervisor level under benign operation and multiple attack scenarios.
- Freshness
- Last updated 2026-07-06 17:13:55; freshness should be verified.