Indicator of Inconsistency
Framework
A formal framework for detecting cross-artifact contradictions in digital forensic investigations using ontology-driven SPARQL signatures.
Anti-forensic scenarios
View all →Browser history selective removal
Chrome History SQLite manipulation detected via IndexedDB cache and USN journal corroboration.
Volume Shadow Copy deletion
VSS infrastructure files present but GUID snapshot directories absent; USN confirms deletion.
Security event log clearance
Event 1102 and USN DataTruncation ordering reveals log-clearing followed by continued activity.
Timestamp forging via timestomper
LNK shortcut timestamps diverge from forged $SI timestamps; $FN timestamps remain intact.
Office metadata timestamp contradiction
Embedded Office core.xml creation time predates forged filesystem timestamp after cross-graph join.
IoI rules library
View all →Reusable SPARQL signatures encoding invariant predicates over CASE/UCO knowledge graphs. Each rule is case-agnostic and can be executed against any conformant graph by substituting named graph IRIs.
IndexedDB ↔ History URL check
Detects missing History entries for cached domains with USN corroboration.
VSS directory presence check
Flags absent GUID shadow directories when VSS infrastructure files exist.
Event 1102 + USN ordering
Validates temporal ordering of log-clear event against USN truncation timestamp.