UAAT: Universal Acquisition and Analysis Tool for IoT Digital Forensics — Source Code and Evaluation Data
Description
Unified Acquisition and Analysis Tool (UAAT), an all-in-one IoT forensic acquisition platform enabling law enforcement personnel to acquire, examine, analyse, and report on digital evidence while maintaining integrity and chain of custody
Files
Steps to reproduce
The data were produced using a structured network-forensics workflow implemented in the UAAT Forensic Tool. Public benchmark cybersecurity datasets (CICIDS-style traffic, IoT-23/DAD-derived files, and CoAP attack CSVs) were collected, checked for format/label consistency, and imported into the tool’s acquisition modules. During ingestion, records were parsed, normalized, and stored in a MySQL database (uaat_db) for analysis. The workflow included dataset preparation, automated ingestion, feature extraction, forensic event generation, alert/threat evaluation, and dashboard analytics. Machine-learning-assisted analysis was performed using Weka-based components integrated in the software. Apache Kafka (localhost:9092) was used where streaming/log workflows were required. Reproducibility is supported through the provided project files (src/, src/datasets/, pom.xml, and config files in src/main/resources/config/) and documented execution steps in README.txt (mvn clean package, mvn javafx:run), using Java 17, Maven 3.x, MySQL, JavaFX, and Kafka.
Institutions
- Mount Kenya UniversityNairobi County, Thika