Group Purchasing
Group Purchasing

EvidenceForge

Last updated: 17 Jun, 2026
Created by:
David Bianco
David Bianco

EvidenceForge is an open-source project for creating realistic synthetic digital forensics and incident response (DFIR) datasets for testing, training, and threat hunting practice. You describe the malicious activity you want to simulate, from a simple phishing intrusion to a full multi-stage attack chain, and AI-assisted scenario authoring helps turn that story into a structured, reproducible plan. EvidenceForge then renders the scenario from a single canonical event model, producing causally ordered evidence across 20+ Windows, Linux, network, and EDR log formats. The result is a coherent investigation package with realistic background noise, cross-source correlations, ground truth documentation, and an analyst briefing.

EvidenceForge is not trying to create synthetic data that is indistinguishable from production in every detail. Its goal is practical fidelity: datasets realistic enough to exercise tools, teach analysts, and support repeatable research without needing access to sensitive real-world telemetry.

Learn more about the tool

Author

David Bianco
David Bianco

David Bianco

Certified Instructor

David has 20+ years of experience in the information security field, primarily in incident detection and response, threat hunting, and Cyber Threat Intelligence. He is the creator the Pyramid of Pain and the Threat Hunting Maturity Model.

Read more about David Bianco
EvidenceForge | SANS Institute