# ForensicArtifacts/artifacts

Digital Forensics artifact repository

Repository: https://github.com/ForensicArtifacts/artifacts
Canonical: https://ross.abutalabs.com/products/artifacts
Language: Python
License: Apache-2.0
License Family: permissive
Last push: 2026-07-31T12:40:49+00:00

## Health v2 (maintenance only)
Score: 78/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 95, release rhythm 44, longevity 100
- inputs: {"age_days": 4324, "days_push": 33, "days_rel": 218, "gap_med": 91.0, "n_releases_24m": 3}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1268, forks 227 (observed 2026-08-28T04:04:11.511187+00:00)

## What it is
A community-sourced, machine-readable knowledge base of digital forensic artifact definitions stored as YAML files. It provides standardized descriptions of forensic artifacts (registry keys, log files, file paths) usable across DFIR tools.

## Use cases
- find where windows stores evidence of usb device connections
- get machine-readable definitions of forensic artifacts for my dfir tool
- standardize artifact collection across incident response tooling
- look up which log files indicate program execution
- contribute forensic artifact definitions to a shared knowledge base

## When to choose
- you need a shared, standardized catalog of forensic artifact definitions
- your tool can parse YAML and you want artifact metadata without heavy dependencies
- you are building DFIR collection or analysis tooling

## When to avoid
- you need an actual forensic acquisition or analysis tool rather than a knowledge base
- you need non-forensic configuration data

## Facets
- artifact type: dataset
- maturity: active
- function: security, developer-tools, documentation
- domain: security, operating-systems
- platform: cross-platform, python
- tags: digital-forensics, dfir, yaml, knowledge-base, incident-response, forensics

## Member repositories
- ForensicArtifacts/artifacts (main) score 78

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:11.511187+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T05:03:35.511975+00:00, confidence not recorded.
  - readme: https://github.com/ForensicArtifacts/artifacts (fetched 2026-08-28T04:04:11.511187+00:00, sha a25c01d1f592)
  - registry_pypi: https://pypi.org/pypi/artifacts/json (fetched 2026-08-29T12:15:24.986472+00:00, sha 5de15c158655)
- Data as of 2026-08-30T08:39:29.467469+00:00.
