24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI

DSET Forensics Benchmark

Operation Nightshade

Operation Nightshade: a seized workstation image of a threat actor. The actor dumped credentials, moved laterally, exfiltrated data and then wiped or forged its traces. The single 64 MiB image mounts with real tools; but the surface files mislead and the real evidence is buried behind layered anti forensics. Answer the 180 questions.

Download ImageAnswer Template
180Questions
21Evidence Types
64MiB Image
AF4Difficulty

What Is in the Image

Deleted and carvable documents
Volatile memory remnants
Nested image and encrypted containers
Steganographic imagery and EXIF
Network capture (pcap)
Windows event log and Linux logs
Registry, mobile database, email
Archive and polyglot files
Scattered file fragments (multi source)
Classical, RSA, JWT and hash cryptanalysis

Evidence Categories

Submit Your Answers

Answer the 180 questions below, or download the JSON template, fill it and paste it. The same scoring runs via the API. Soundness, the resistance to planted false evidence, is measured alongside recall.

0 / 180
Paste answer-template JSON (optional)

About This Case

Operation Nightshade is the DFB master case: a single, fully synthetic forensic disk image that consolidates twenty one evidence disciplines into one investigation. It is built to defeat automated triage and require genuine human or agent analysis. The file system mounts cleanly, so surface tools see innocuous files, while the incriminating evidence lives in deleted clusters, an embedded memory dump, encrypted containers whose keys leak across artifacts, a polyglot file, and scattered fragments that must be reassembled from several sources.

DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
← DFB Benchmark

Disk and File System 13

Measures forensic recovery of deleted and hidden data from a disk image.

Memory Forensics 13

Measures forensic analysis of a volatile memory dump.

Nested Image and Container 10

Measures analysis of nested structures and layered containers.

Encrypted Container and C2 12

Measures analysis of encrypted configuration and infrastructure evidence.

Steganography and Imagery 10

Measures hidden in image data and image metadata forensics.

Classical Cryptanalysis 9

Measures classical cipher analysis.

RSA Cryptanalysis 5

Measures RSA key analysis.

JWT and Protocol 6

Measures token and protocol security analysis.

Password and Hash 10

Measures password hash analysis.

Network Traffic 11

Measures network traffic forensics.

Linux Auth Logs 9

Measures correlation of Linux authentication logs.

Windows Event Log 13

Measures Windows event log correlation.

Windows Registry 7

Measures Windows registry persistence triage.

Mobile and SQLite 5

Measures mobile database forensics.

Email Forensics 8

Measures email header forensics.

Document Forensics 4

Measures document forensics.

Archive and Polyglot 4

Measures archive and multi format file analysis.

Scattered Recovery 7

Measures multi source data recovery.

Timeline 6

Measures event timeline reconstruction.

Anti Forensics Detection 5

Measures detection of hiding and forgery.

MITRE ATT&CK and Attribution 13

Measures tool/technique identification and attribution.

Privacy
KVKK
GDPR
Cookies
Terms