https://ontology.solveit-df.org/solveit/analysisSOLVE-IT Project
Analytic results for SOLVE-IT digital forensics, including hypothesised events and forensic tool reports.
SOLVE-IT Analysis Module
https://ontology.unifiedcyberontology.org/uco/analysis/1.4.0
https://ontology.unifiedcyberontology.org/uco/core/1.4.0
https://ontology.unifiedcyberontology.org/uco/observable/1.4.0
https://ontology.solveit-df.org/solveit/analysis/0.0.5
0.0.5
http://www.w3.org/2002/07/owl#Ontology
SOLVE-IT Analysis Module
https://ontology.solveit-df.org/solveit/coreSOLVE-IT Project
A modular ontology extending UCO/CASE for the SOLVE-IT digital forensics project. This core ontology defines fundamental SOLVE-IT classes (Technique, Weakness, Mitigation) and imports modules for observables and analysis.
SOLVE-IT Digital Forensics Ontology
https://ontology.caseontology.org/case/investigation/1.4.0
https://ontology.solveit-df.org/solveit/analysis
https://ontology.solveit-df.org/solveit/observable
https://ontology.solveit-df.org/solveit/tool-profile
https://ontology.unifiedcyberontology.org/uco/action/1.4.0
https://ontology.unifiedcyberontology.org/uco/core/1.4.0
https://ontology.unifiedcyberontology.org/uco/observable/1.4.0
https://ontology.solveit-df.org/solveit/core/0.0.5
0.0.5
http://www.w3.org/2002/07/owl#Ontology
Core ontology file with fundamental SOLVE-IT classes. Use this file to import the complete SOLVE-IT ontology.
SOLVE-IT Ontology
https://ontology.solveit-df.org/solveit/examples/acquisitionhttps://ontology.solveit-df.org/solveit/observable
https://ontology.solveit-df.org/solveit/examples/acquisition/0.0.1
http://www.w3.org/2002/07/owl#Ontology
Example instances demonstrating forensic acquisition classes.
SOLVE-IT Acquisition Examples
https://ontology.solveit-df.org/solveit/examples/corehttps://ontology.solveit-df.org/solveit/core
https://ontology.solveit-df.org/solveit/examples/core/0.0.1
http://www.w3.org/2002/07/owl#Ontology
Example instances demonstrating the core SOLVE-IT ontology classes.
SOLVE-IT Core Classes Examples
https://ontology.solveit-df.org/solveit/examples/observableshttps://ontology.solveit-df.org/solveit/observable
https://ontology.solveit-df.org/solveit/examples/observables/0.0.1
http://www.w3.org/2002/07/owl#Ontology
Example instances demonstrating SOLVE-IT observable classes.
SOLVE-IT Observable Examples
https://ontology.solveit-df.org/solveit/examples/sqlitehttps://ontology.solveit-df.org/solveit/observable
https://ontology.solveit-df.org/solveit/examples/sqlite/1.0.0
http://www.w3.org/2002/07/owl#Ontology
Minimal example: a hello.db with one table and two records.
SOLVE-IT SQLite Examples
https://ontology.solveit-df.org/solveit/examples/timeline-resolutionhttps://ontology.solveit-df.org/solveit/data
https://ontology.solveit-df.org/solveit/observable
https://ontology.solveit-df.org/solveit/examples/timeline-resolution/0.0.1
http://www.w3.org/2002/07/owl#Ontology
Example instances demonstrating Timeline usage with DateTimeStamp values of different resolutions (e.g., FAT filesystem). References techniques from the SOLVE-IT knowledge base.
SOLVE-IT Timeline Resolution Examples
https://ontology.solveit-df.org/solveit/examples/timeline-sequencehttps://ontology.solveit-df.org/solveit/data
https://ontology.solveit-df.org/solveit/observable
https://ontology.solveit-df.org/solveit/examples/timeline-sequence/0.0.1
http://www.w3.org/2002/07/owl#Ontology
Example instances demonstrating Timeline usage with ImplicitTimingInformation for sequence-based ordering (e.g., cluster allocation order). References techniques from the SOLVE-IT knowledge base.
SOLVE-IT Timeline Sequence Examples
https://ontology.solveit-df.org/solveit/examples/triaged-deviceshttps://ontology.solveit-df.org/solveit/core
https://ontology.solveit-df.org/solveit/data
https://ontology.solveit-df.org/solveit/observable
https://ontology.solveit-df.org/solveit/examples/triaged-devices/0.0.1
http://www.w3.org/2002/07/owl#Ontology
Example instances demonstrating device triage workflow: grouping seized devices into a DeviceSet, applying triage (T1001), and producing a PrioritizedDeviceSet with per-device priorities.
SOLVE-IT Device Triage Examples
https://ontology.solveit-df.org/solveit/observableSOLVE-IT Project
Observable objects for SOLVE-IT digital forensics, including video frames and other forensic artifacts. This module imports sub-modules for acquisition, timeline, and search observables.
SOLVE-IT Observable Module
https://ontology.solveit-df.org/solveit/observable/acquisition
https://ontology.solveit-df.org/solveit/observable/search
https://ontology.solveit-df.org/solveit/observable/timeline
https://ontology.unifiedcyberontology.org/uco/core/1.4.0
https://ontology.unifiedcyberontology.org/uco/observable/1.4.0
https://ontology.solveit-df.org/solveit/observable/0.0.5
0.0.5
http://www.w3.org/2002/07/owl#Ontology
SOLVE-IT Observable Module
https://ontology.solveit-df.org/solveit/observable/acquisitionSOLVE-IT Project
Classes for forensic data acquisition including forensic images, live captures, and extraction methods.
SOLVE-IT Observable Acquisition Module
https://ontology.unifiedcyberontology.org/uco/observable/1.4.0
https://ontology.solveit-df.org/solveit/observable/acquisition/0.0.5
0.0.5
http://www.w3.org/2002/07/owl#Ontology
SOLVE-IT Observable Acquisition Module
https://ontology.solveit-df.org/solveit/observable/searchSOLVE-IT Project
Classes for keyword search, indexing, and file system analysis.
SOLVE-IT Observable Search Module
https://ontology.unifiedcyberontology.org/uco/observable/1.4.0
https://ontology.solveit-df.org/solveit/observable/search/0.0.5
0.0.5
http://www.w3.org/2002/07/owl#Ontology
SOLVE-IT Observable Search Module
https://ontology.solveit-df.org/solveit/observable/sqliteSOLVE-IT Project
SQLite database structural representation for digital forensic analysis, including logical structure (tables, schemas, records), physical structure (pages), and WAL/journal representations.
SOLVE-IT SQLite Module
https://ontology.unifiedcyberontology.org/uco/core/1.4.0
https://ontology.unifiedcyberontology.org/uco/observable/1.4.0
https://ontology.solveit-df.org/solveit/observable/sqlite/0.0.5
0.0.5
http://www.w3.org/2002/07/owl#Ontology
SOLVE-IT SQLite Module
https://ontology.solveit-df.org/solveit/observable/timelineSOLVE-IT Project
Classes for forensic timeline analysis including timestamps, timeline entries, and temporal ordering.
SOLVE-IT Observable Timeline Module
https://ontology.unifiedcyberontology.org/uco/observable/1.4.0
https://ontology.solveit-df.org/solveit/observable/timeline/0.0.5
0.0.5
http://www.w3.org/2002/07/owl#Ontology
SOLVE-IT Observable Timeline Module
https://ontology.solveit-df.org/solveit/tool-profileSOLVE-IT Project
Capability profiles for forensic tools, enabling conditional mitigation declarations that are version-specific and attributable.
SOLVE-IT Tool Profile Module
https://ontology.solveit-df.org/solveit/core
https://ontology.unifiedcyberontology.org/uco/core/1.4.0
https://ontology.unifiedcyberontology.org/uco/observable/1.4.0
https://ontology.unifiedcyberontology.org/uco/tool/1.4.0
https://ontology.solveit-df.org/solveit/tool-profile/0.0.5
0.0.5
http://www.w3.org/2002/07/owl#Ontology
SOLVE-IT Tool Profile Module