Downloads provided by UsageCounts
A collection of ProcMon log files (PML) files associated with executions of ransomware binaries downloaded from MalwareBazaar. Files are named after the sha256 hash used on MalwareBazaar. These PML files were processed with the SPADE provenance system and queried to produce a subgraphs that are provided as DOT files. Only a subset of all the executions (n=405) that were performed are in this archive as the PML files are large, all DOT files that were obtained (n=861)are in this dataset.
This work was supported in part by the Office of Naval Research under Grant N00014-21-1-2754.
provenance, ransomware, procmon, spade
provenance, ransomware, procmon, spade
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
| views | 36 | |
| downloads | 10 |

Views provided by UsageCounts
Downloads provided by UsageCounts