Expand description
§forensicnomicon-data
The fast-moving detection knowledge layer of the ForensicNomicon, split out
from the stable engine in forensicnomicon-core so it can release frequently
and independently. It carries the assembled artifact catalog and the lookups
built over it:
catalog— the ~6.5k assembled artifact descriptors and the globalcatalog::CATALOG. The descriptor types and the lookup engine live inforensicnomicon-core; this crate supplies the data and wires it into a compile-timeCATALOGviaForensicCatalog::new. The engine surface is re-exported, soforensicnomicon_data::catalog::*mirrors the core API.evidence/volatility— theEvidenceStrength/VolatilityClassrating enums (re-exported from core) plus the catalog-querying helpers (evidence_for,volatility_for,acquisition_order, …).
The umbrella forensicnomicon crate re-exports this crate, so existing
forensicnomicon::catalog::CATALOG / forensicnomicon::evidence::evidence_for
paths resolve unchanged.
Modules§
- catalog
- Forensic artifact catalog — assembled dataset + global
CATALOG. - evidence
- Evidence strength helpers over the assembled global catalog.
- volatility
- Artifact volatility helpers over the assembled global catalog.