U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

  1. Home

National Software Reference Library (NSRL) Reference Data Set (RDS) - NIST Special Database 28

The National Software Reference Library (NSRL) collects software from various sources and incorporates file profiles computed from this software into a Reference Data Set (RDS) of information. The RDS can be used by law enforcement, government, and industry organizations to review files on a computer by matching file profiles in the RDS. This alleviates much of the effort involved in determining which files are important as evidence on computers or file systems that have been seized as part of criminal investigations. The RDS is a collection of digital signatures of known, traceable software applications. There are application hash values in the hash set which may be considered malicious, i.e. steganography tools and hacking scripts. There are no hash values of illicit data, i.e. child abuse images.

About this Dataset

Updated: 2026-08-20
Metadata Last Updated: 2021-12-03 00:00:00
Date Created: N/A
Data Provided by:
Dataset Owner: N/A

Access this data

Contact dataset owner Access URL
Landing Page URL
Table representation of structured data
Title National Software Reference Library (NSRL) Reference Data Set (RDS) - NIST Special Database 28
Description The National Software Reference Library (NSRL) collects software from various sources and incorporates file profiles computed from this software into a Reference Data Set (RDS) of information. The RDS can be used by law enforcement, government, and industry organizations to review files on a computer by matching file profiles in the RDS. This alleviates much of the effort involved in determining which files are important as evidence on computers or file systems that have been seized as part of criminal investigations. The RDS is a collection of digital signatures of known, traceable software applications. There are application hash values in the hash set which may be considered malicious, i.e. steganography tools and hacking scripts. There are no hash values of illicit data, i.e. child abuse images.
Modified 2021-12-03 00:00:00
Publisher Name National Institute of Standards and Technology
Contact mailto:[email protected]
Keywords computer crimes , computer forensics , crimes , cyber crimes , Defense Computer Forensics Laboratory , Federal Bureau of Investigation , file profiles , finger print software , fingerprints , graphics , hash keeper , hashes , investigations , KFF , known file filters , law enforcement , National Institute of Justice , National Software Reference Library , OLES , profiles , reference data set , softwares , US Customs Services
{
    "identifier": "FF429BC178698B3EE0431A570681E858216",
    "accessLevel": "public",
    "contactPoint": {
        "hasEmail": "mailto:[email protected]",
        "fn": "Douglas R. White"
    },
    "programCode": [
        "006:052"
    ],
    "landingPage": "https:\/\/data.nist.gov\/od\/id\/FF429BC178698B3EE0431A570681E858216",
    "title": "National Software Reference Library (NSRL) Reference Data Set (RDS) - NIST Special Database 28",
    "description": "The National Software Reference Library (NSRL)  collects software from various sources and incorporates file profiles computed from this software into a Reference Data Set (RDS) of information. The RDS can be used by law enforcement, government, and industry organizations to review files on a computer by matching file profiles in the RDS. This alleviates much of the effort involved in determining which files are important as evidence on computers or file systems that have been seized as part of criminal investigations. The RDS is a collection of digital signatures of known, traceable software applications. There are application hash values in the hash set which may be considered malicious, i.e. steganography tools and hacking scripts. There are no hash values of illicit data, i.e. child abuse images.",
    "language": [
        "en"
    ],
    "distribution": [
        {
            "accessURL": "https:\/\/www.nist.gov\/software-quality-group\/national-software-reference-library-nsrl",
            "format": "NSRL main page",
            "title": "National Software Reference Library"
        },
        {
            "accessURL": "https:\/\/doi.org\/10.18434\/M3695G"
        }
    ],
    "bureauCode": [
        "006:55"
    ],
    "modified": "2021-12-03 00:00:00",
    "publisher": {
        "@type": "org:Organization",
        "name": "National Institute of Standards and Technology"
    },
    "theme": [
        "Forensics:Digital and multimedia evidence"
    ],
    "keyword": [
        "computer crimes",
        "computer forensics",
        "crimes",
        "cyber crimes",
        "Defense Computer Forensics Laboratory",
        "Federal Bureau of Investigation",
        "file profiles",
        "finger print software",
        "fingerprints",
        "graphics",
        "hash keeper",
        "hashes",
        "investigations",
        "KFF",
        "known file filters",
        "law enforcement",
        "National Institute of Justice",
        "National Software Reference Library",
        "OLES",
        "profiles",
        "reference data set",
        "softwares",
        "US Customs Services"
    ]
}