UniForeXT
language en

UniForeXT

Release: 2026-02-05

Modified on: 2026-05-28
This version:
http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results/1.1.0
Revision:
1.0.0
Authors:
Robert Louan
Imported Ontologies:
time
Download serialization:
JSON-LD RDF/XML N-Triples TTL
License:
http://insertlicenseURIhere.example.org
Cite as:
Robert Louan. UniForeXT. Revision: 1.0.0. Retrieved from: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results/1.1.0

Ontology Specification Draft

Abstract

This is a placeholder text for the abstract. The abstract should contain a couple of sentences summarizing the ontology and its purpose.

UniForeXT: Overview back to ToC

This ontology has the following classes and properties.

Classes

Object Properties

Data Properties

Named Individuals

UniForeXT: Description back to ToC

UniForeXT: A Unified Model for Cross-Tool Integration in Digital Forensic Triage

Cross-reference for UniForeXT classes, object properties and data properties back to ToC

This section provides details for each class and property defined by UniForeXT.

Classes

Access Detectionc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#AccessDetection

Detection category for access related activity.
has super-classes
Detection c
has sub-classes
AccountTampering c, LateralMovement c, MicrosoftRDS c, RDPAttacks c, RDPEvents c
is disjoint with
Analytics Detection c, Defense Evasion Detection c, Execution Detection c, Persistence Detection c

AccountTamperingc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#AccountTampering

Detection indicating account tampering activity.
has super-classes
Access Detection c
is disjoint with
Antivirus c, IndicatorRemoval c, LateralMovement c, LogTampering c, MicrosoftRDS c, Persistence c, PowershellEngineState c, RDPAttacks c, RDPEvents c, ServiceInstallation c, Sigma c

Analytics Detectionc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#AnalyticsDetection

Detection category for analytics or automated detection signals.
has super-classes
Detection c
has sub-classes
Antivirus c, Sigma c
is disjoint with
Access Detection c, Defense Evasion Detection c, Execution Detection c, Persistence Detection c

Antivirusc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#Antivirus

Detection produced by antivirus software.
has super-classes
Analytics Detection c
is disjoint with
AccountTampering c, IndicatorRemoval c, LateralMovement c, LogTampering c, MicrosoftRDS c, Persistence c, PowershellEngineState c, RDPAttacks c, RDPEvents c, ServiceInstallation c, Sigma c

Attack Tacticc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#AttackTactic

Controlled ATT&CK tactic concept.
has super-classes
Value c
is in domain of
isAttackTacticOf op
is in range of
hasAttackTactic op

Attack Techniquec back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#AttackTechnique

Controlled ATT&CK technique concept.
has super-classes
Value c
is in domain of
isAttackTechniqueOf op
is in range of
hasAttackTechnique op

Audit Policy Change Eventc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#AuditPolicyChange_Event

has super-classes
Configuration Event c

Authentication Eventc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#AuthenticationEvent

Event associated with authentication or logon activity.
has super-classes
Event c
has sub-classes
Logon Event c

Commandc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#Command

Command observed in the forensic context.
has super-classes
Independent Entity c
is in domain of
isCommandOf op
is in range of
hasCommand op
is disjoint with
Computer c, Detection c, Event c, LogFile c, Path c, Process c, Session c, Threat c, User c, Value c

Computerc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#Computer

Computer or host involved in the forensic investigation.
has super-classes
Independent Entity c
is in domain of
hasDomain dp, hasHostname dp, hasIP dp, isComputerOf op
is in range of
hasComputer op
is disjoint with
Command c, Detection c, Event c, LogFile c, Path c, Process c, Session c, Threat c, User c, Value c

Configuration Eventc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#Configuration_event

Superclass for configuration-related events.
has super-classes
Event c
has sub-classes
Audit Policy Change Event c, Log Cleared Event c, Registry Load Configuration Event c, Registry Modification Configuration Event c, Scheduled Task Creation Configuration Event c, Scheduled Task Deletion Configuration Event c, Service Installation Configuration Event c

Defense Evasion Detectionc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#DefenseEvasionDetection

Detection category for defense evasion activity.
has super-classes
Detection c
has sub-classes
IndicatorRemoval c, LogTampering c
is disjoint with
Access Detection c, Analytics Detection c, Execution Detection c, Persistence Detection c

Detectionc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#Detection

Independent evidence or alert produced by a security or forensic control.
has super-classes
Independent Entity c
has sub-classes
Access Detection c, Analytics Detection c, Defense Evasion Detection c, Execution Detection c, Persistence Detection c
is in domain of
hasID dp, hasLevel dp, isDetectionOf op
is in range of
hasDetection op
is disjoint with
Command c, Computer c, Event c, LogFile c, Path c, Process c, Session c, Threat c, User c, Value c

Domain Entityc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#Domain_entity

Top-level domain category for all ontology entities.
is equivalent to
Independent Entity c or Value c
has sub-classes
Independent Entity c, Value c
is in domain of
has Forensic Tool op, hasAttackTactic op, hasAttackTechnique op, modifierProperty op, relationalProperty op, relational_property_inverse op
is in range of
isAttackTacticOf op, isAttackTechniqueOf op, modifiedBy_property op, relationalProperty op, relational_property_inverse op

Eventc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#Event

Occurrence recorded in logs or forensic evidence.
has super-classes
Independent Entity c
has sub-classes
Authentication Event c, Configuration Event c
is in domain of
hasDetection op, hasEventID dp
is in range of
isDetectionOf op
is disjoint with
Command c, Computer c, Detection c, LogFile c, Path c, Process c, Session c, Threat c, User c, Value c

Execution Detectionc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#ExecutionDetection

Detection category for execution-related activity.
has super-classes
Detection c
has sub-classes
PowershellEngineState c
is disjoint with
Access Detection c, Analytics Detection c, Defense Evasion Detection c, Persistence Detection c

Filec back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#File

has super-classes
Value c
is in domain of
has Size dp

Forensic Toolc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#ForensicTool

has super-classes
Value c

Independent Entityc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#Independent_entity

Entity representing a concrete forensic object or occurrence.
has super-classes
Domain Entity c
has sub-classes
Command c, Computer c, Detection c, Event c, LogFile c, Path c, Process c, Session c, Threat c, User c
is in domain of
hasCommand op, hasComputer op, hasDescription dp, hasExtraInformation dp, hasLogFile op, hasName dp, hasPath op, hasProcess op, hasTechnique dp, hasTimestamp dp, hasUser op
is in range of
isCommandOf op, isComputerOf op, isLogFileOf op, isProcessOf op, isUserOf op
is disjoint with
Value c

IndicatorRemovalc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#IndicatorRemoval

Detection indicating removal of indicators or traces.
has super-classes
Defense Evasion Detection c
is disjoint with
AccountTampering c, Antivirus c, LateralMovement c, LogTampering c, MicrosoftRDS c, Persistence c, PowershellEngineState c, RDPAttacks c, RDPEvents c, ServiceInstallation c, Sigma c

LateralMovementc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#LateralMovement

Detection indicating lateral movement activity.
has super-classes
Access Detection c
is disjoint with
AccountTampering c, Antivirus c, IndicatorRemoval c, LogTampering c, MicrosoftRDS c, Persistence c, PowershellEngineState c, RDPAttacks c, RDPEvents c, ServiceInstallation c, Sigma c

Log Cleared Eventc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#LogCleared_Event

has super-classes
Configuration Event c

LogFilec back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#LogFile

Log file used as a forensic evidence source.
has super-classes
Independent Entity c
is in domain of
isLogFileOf op
is in range of
hasLogFile op, isPathOf op
is disjoint with
Command c, Computer c, Detection c, Event c, Path c, Process c, Session c, Threat c, User c, Value c

Logon Eventc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#LogonEvent

Event capturing a logon or authentication occurrence.
has super-classes
Authentication Event c
is in domain of
hasLogonType op, isLogonEventOf op
is in range of
hasLogonEvent op, isLogonTypeOf op

LogonTypec back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#LogonType

Controlled value representing the logon type.
has super-classes
Value c
is in domain of
isLogonTypeOf op
is in range of
hasLogonType op
has members
localLogon ni, networkLogon ni, rdpLogon ni

LogTamperingc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#LogTampering

Detection indicating tampering with log data.
has super-classes
Defense Evasion Detection c
is disjoint with
AccountTampering c, Antivirus c, IndicatorRemoval c, LateralMovement c, MicrosoftRDS c, Persistence c, PowershellEngineState c, RDPAttacks c, RDPEvents c, ServiceInstallation c, Sigma c

MicrosoftRDSc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#MicrosoftRDS

Detection related to Microsoft Remote Desktop Services activity.
has super-classes
Access Detection c
is disjoint with
AccountTampering c, Antivirus c, IndicatorRemoval c, LateralMovement c, LogTampering c, Persistence c, PowershellEngineState c, RDPAttacks c, RDPEvents c, ServiceInstallation c, Sigma c

Pathc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#Path

File system path or path-like string used in forensic evidence.
has super-classes
Independent Entity c
is in domain of
hasContent dp, isPathOf op
is in range of
hasPath op
is disjoint with
Command c, Computer c, Detection c, Event c, LogFile c, Process c, Session c, Threat c, User c, Value c

Persistencec back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#Persistence

Detection indicating persistence-related activity.
has super-classes
Persistence Detection c
is disjoint with
AccountTampering c, Antivirus c, IndicatorRemoval c, LateralMovement c, LogTampering c, MicrosoftRDS c, PowershellEngineState c, RDPAttacks c, RDPEvents c, ServiceInstallation c, Sigma c

Persistence Detectionc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#PersistenceDetection

Detection category for persistence-related activity.
has super-classes
Detection c
has sub-classes
Persistence c, ServiceInstallation c
is disjoint with
Access Detection c, Analytics Detection c, Defense Evasion Detection c, Execution Detection c

PowershellEngineStatec back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#PowershellEngineState

Detection indicating a PowerShell engine state or execution context.
has super-classes
Execution Detection c
is disjoint with
AccountTampering c, Antivirus c, IndicatorRemoval c, LateralMovement c, LogTampering c, MicrosoftRDS c, Persistence c, RDPAttacks c, RDPEvents c, ServiceInstallation c, Sigma c

Processc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#Process

Operating system process observed in the forensic context.
has super-classes
Independent Entity c
is in domain of
hasChildrenProcess op, hasParentProcess op, isProcessOf op
is in range of
hasChildrenProcess op, hasParentProcess op, hasProcess op
is disjoint with
Command c, Computer c, Detection c, Event c, LogFile c, Path c, Session c, Threat c, User c, Value c

RDPAttacksc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#RDPAttacks

Detection related to RDP attack activity.
has super-classes
Access Detection c
is disjoint with
AccountTampering c, Antivirus c, IndicatorRemoval c, LateralMovement c, LogTampering c, MicrosoftRDS c, Persistence c, PowershellEngineState c, RDPEvents c, ServiceInstallation c, Sigma c

RDPEventsc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#RDPEvent

Detection related to Remote Desktop Protocol events.
has super-classes
Access Detection c
is disjoint with
AccountTampering c, Antivirus c, IndicatorRemoval c, LateralMovement c, LogTampering c, MicrosoftRDS c, Persistence c, PowershellEngineState c, RDPAttacks c, ServiceInstallation c, Sigma c

Registry Load Configuration Eventc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#RegistryLoad_configuration_event

Configuration event for registry loading activity.
has super-classes
Configuration Event c

Registry Modification Configuration Eventc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#RegistryModification_configuration_event

Configuration event for registry modification activity.
has super-classes
Configuration Event c
is in domain of
hasValue dp

Scheduled Task Creation Configuration Eventc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#ScheduledTaskCreation_configuration_event

Configuration event for scheduled task creation.
has super-classes
Configuration Event c

Scheduled Task Deletion Configuration Eventc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#ScheduledTaskDeletion_configuration_event

Configuration event for scheduled task deletion.
has super-classes
Configuration Event c

Service Installation Configuration Eventc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#ServiceInstallation_configuration_event

Configuration event for service installation.
has super-classes
Configuration Event c

ServiceInstallationc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#ServiceInstallation

Detection indicating service installation activity.
has super-classes
Persistence Detection c
is disjoint with
AccountTampering c, Antivirus c, IndicatorRemoval c, LateralMovement c, LogTampering c, MicrosoftRDS c, Persistence c, PowershellEngineState c, RDPAttacks c, RDPEvents c, Sigma c

Sessionc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#Session

User session associated with a logon event.
has super-classes
Independent Entity c
is in domain of
hasLogonEvent op
is in range of
isLogonEventOf op
is disjoint with
Command c, Computer c, Detection c, Event c, LogFile c, Path c, Process c, Threat c, User c, Value c

Sigmac back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#Sigma

Detection produced from Sigma rules or Sigma-based content.
has super-classes
Analytics Detection c
is disjoint with
AccountTampering c, Antivirus c, IndicatorRemoval c, LateralMovement c, LogTampering c, MicrosoftRDS c, Persistence c, PowershellEngineState c, RDPAttacks c, RDPEvents c, ServiceInstallation c

Threatc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#Threat

Suspected malicious activity or adversary-driven behavior.
has super-classes
Independent Entity c
is disjoint with
Command c, Computer c, Detection c, Event c, LogFile c, Path c, Process c, Session c, User c, Value c

Userc back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#User

User account or person associated with an event or entity.
has super-classes
Independent Entity c
is in domain of
isUserOf op
is in range of
hasUser op
is disjoint with
Command c, Computer c, Detection c, Event c, LogFile c, Path c, Process c, Session c, Threat c, Value c

Valuec back to ToC or Class ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#Value

Controlled conceptual value used to classify domain entities.
has super-classes
Domain Entity c
has sub-classes
Attack Tactic c, Attack Technique c, File c, Forensic Tool c, LogonType c
is in domain of
modifiedBy_property op
is in range of
modifierProperty op
is disjoint with
Independent Entity c, Command c, Computer c, Detection c, Event c, LogFile c, Path c, Process c, Session c, Threat c, User c

Object Properties

has Fileop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasFile

has super-properties
relationalProperty op

has Forensic Toolop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasForensicTool

has super-properties
relationalProperty op
has domain
Domain Entity c

has Target Userop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasTargetUser

has super-properties
relationalProperty op
has range
has Target User op some User c

hasAttackTacticop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasAttackTactic

Links an element to the ATT&CK tactic it is associated with.
has super-properties
relationalProperty op
has domain
Domain Entity c
has range
Attack Tactic c
is inverse of
isAttackTacticOf op

hasAttackTechniqueop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasAttackTechnique

Links an element to the ATT&CK technique it is associated with.
has super-properties
relationalProperty op
has domain
Domain Entity c
has range
Attack Technique c
is inverse of
isAttackTechniqueOf op

hasChildrenProcessop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasChildrenProcess

Relates a process to one of its child processes.
has super-properties
hasProcess op
has domain
Process c
has range
Process c
is inverse of
hasParentProcess op

hasCommandop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasCommand

Relates an entity to the command associated with it.

has characteristics: functional

has super-properties
relationalProperty op
has domain
Independent Entity c
has range
Command c
is inverse of
isCommandOf op

hasComputerop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasComputer

Relates an entity to the computer on which it occurred or was observed.

has characteristics: functional

has super-properties
relationalProperty op
has domain
Independent Entity c
has range
Computer c
is inverse of
isComputerOf op

hasDetectionop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasDetection

Links an event to the detection that identified it.
has super-properties
relationalProperty op
has domain
Event c
has range
Detection c
is inverse of
isDetectionOf op

hasLogFileop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasLogFile

Links an entity to the log file used as evidence or source.
has super-properties
relationalProperty op
has domain
Independent Entity c
has range
LogFile c
is inverse of
isLogFileOf op

hasLogonEventop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasLogonEvent

Associates a session with its logon event.

has characteristics: functional

has super-properties
relationalProperty op
has domain
Session c
has range
Logon Event c
is inverse of
isLogonEventOf op

hasLogonTypeop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasLogonType

Specifies the logon type associated with a logon event.

has characteristics: functional

has super-properties
relationalProperty op
has domain
Logon Event c
has range
LogonType c
is inverse of
isLogonTypeOf op

hasParentProcessop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasParentProcess

Relates a process to its parent process.

has characteristics: functional

has super-properties
hasProcess op
has domain
Process c
has range
Process c
is inverse of
hasChildrenProcess op

hasPathop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasPath

Relates a file to its file system path.
has super-properties
relationalProperty op
has domain
Independent Entity c
has range
Path c
is inverse of
isPathOf op

hasProcessop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasProcess

Relates an entity to a process associated with it.
has super-properties
relationalProperty op
has sub-properties
hasChildrenProcess op, hasParentProcess op
has domain
Independent Entity c
has range
Process c
is inverse of
isProcessOf op

hasUserop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasUser

Relates an entity to the user associated with it.

has characteristics: functional

has super-properties
relationalProperty op
has domain
Independent Entity c
has range
User c
is inverse of
isUserOf op

isAttackTacticOfop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#isAttackTacticOf

Inverse of hasAttackTactic; associates an ATT&CK tactic to entities using it.
has super-properties
relational_property_inverse op
has domain
Attack Tactic c
has range
Domain Entity c
is inverse of
hasAttackTactic op

isAttackTechniqueOfop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#isAttackTechniqueOf

Inverse of hasAttackTechnique; associates an ATT&CK technique to entities using it.
has super-properties
relational_property_inverse op
has domain
Attack Technique c
has range
Domain Entity c
is inverse of
hasAttackTechnique op

isCommandOfop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#isCommandOf

Inverse of hasCommand; associates a command to entities that used it.
has super-properties
relational_property_inverse op
has domain
Command c
has range
Independent Entity c
is inverse of
hasCommand op

isComputerOfop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#isComputerOf

Inverse of hasComputer; associates a computer to entities observed on it.
has super-properties
relational_property_inverse op
has domain
Computer c
has range
Independent Entity c
is inverse of
hasComputer op

isDetectionOfop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#isDetectionOf

Inverse of hasDetection; associates a detection to the events it identified.
has super-properties
relational_property_inverse op
has domain
Detection c
has range
Event c
is inverse of
hasDetection op

isLogFileOfop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#isLogFileOf

Inverse of hasLogFile; associates a log file to entities that reference it.
has super-properties
relational_property_inverse op
has domain
LogFile c
has range
Independent Entity c
is inverse of
hasLogFile op

isLogonEventOfop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#isLogonEventOf

Inverse of hasLogonEvent; associates a logon event to the session it created.
has super-properties
relational_property_inverse op
has domain
Logon Event c
has range
Session c
is inverse of
hasLogonEvent op

isLogonTypeOfop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#isLogonTypeOf

Inverse of hasLogonType; associates a logon type to events using it.
has super-properties
relational_property_inverse op
has domain
LogonType c
has range
Logon Event c
is inverse of
hasLogonType op

isPathOfop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#isPathOf

Inverse of hasPath; associates a path to the file it belongs to.
has super-properties
relational_property_inverse op
has domain
Path c
has range
LogFile c
is inverse of
hasPath op

isProcessOfop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#isProcessOf

Inverse of hasProcess; associates a process to entities that reference it.
has super-properties
relational_property_inverse op
has domain
Process c
has range
Independent Entity c
is inverse of
hasProcess op

isUserOfop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#isUserOf

Inverse of hasUser; associates a user to entities related to them.
has super-properties
relational_property_inverse op
has domain
User c
has range
Independent Entity c
is inverse of
hasUser op

modifiedBy_propertyop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#modifiedBy_property

Inverse of modifier_property; associates values to entities that use them as modifiers.
has domain
Value c
has range
Domain Entity c
is inverse of
modifierProperty op

modifierPropertyop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#modifier_property

Auxiliary property group for modifier relations.
has super-properties
top Object Property op
has domain
Domain Entity c
has range
Value c
is inverse of
modifiedBy_property op

relational_property_inverseop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#relational_property_inverse

Inverse of relational_property; generic super-property for inverse relational links.

relationalPropertyop back to ToC or Object Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#relational_property

Auxiliary super-property for relational links between ontology entities.
has super-properties
top Object Property op
has sub-properties
has File op, has Forensic Tool op, has Target User op, hasAttackTactic op, hasAttackTechnique op, hasCommand op, hasComputer op, hasDetection op, hasLogFile op, hasLogonEvent op, hasLogonType op, hasPath op, hasProcess op, hasUser op
has domain
Domain Entity c
has range
Domain Entity c
is inverse of
relational_property_inverse op

Data Properties

has Sizedp back to ToC or Data Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasSize

has domain
File c

hasContentdp back to ToC or Data Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasContent

Stores the string content of a path-like value.
has domain
Path c
has range
string

hasDescriptiondp back to ToC or Data Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasDescription

Provides a human-readable description of an entity.

has characteristics: functional

has super-properties
top Data Property dp
has domain
Independent Entity c
has range
string

hasDomaindp back to ToC or Data Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasDomain

Stores the domain name associated with a computer.

has characteristics: functional

has domain
Computer c
has range
string

hasEventIDdp back to ToC or Data Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasEventID

Stores the identifier of an event in the source log or system.

has characteristics: functional

has domain
Event c
has range
unsigned Long

hasExtraInformationdp back to ToC or Data Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasExtraInformation

Stores additional free-text information for an entity.
has domain
Independent Entity c
has range
string

hasHostnamedp back to ToC or Data Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasHostname

Stores the hostname of a computer.

has characteristics: functional

has domain
Computer c
has range
string

hasIDdp back to ToC or Data Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasID

Stores the identifier of a detection record.

has characteristics: functional

has domain
Detection c
has range
unsigned Long

hasIPdp back to ToC or Data Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasIP

Stores the IP address associated with a computer.

has characteristics: functional

has domain
Computer c
has range
string

hasLeveldp back to ToC or Data Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasLevel

Stores the severity level associated with a detection.

has characteristics: functional

has domain
Detection c
has range
{ "High" , "Info" , "Low" , "Medium" }

hasNamedp back to ToC or Data Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasName

Stores the name of an ontology entity.

has characteristics: functional

has domain
Independent Entity c
has range
string

hasTechniquedp back to ToC or Data Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasTechnique

Stores a technique identifier in string form.

has characteristics: functional

has domain
Independent Entity c
has range
string

hasTimestampdp back to ToC or Data Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasTimestamp

Stores the timestamp associated with an entity or event.

has characteristics: functional

has domain
Independent Entity c
has range
date Time Stamp

hasValuedp back to ToC or Data Property ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#hasValue

Stores the value used in registry modification events.

has characteristics: functional

has domain
Registry Modification Configuration Event c
has range
decimal

Named Individuals

localLogonni back to ToC or Named Individual ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#OWLNamedIndividual_8f290e9f_caa8_4bf1_8af5_788a34262633

belongs to
LogonType c

networkLogonni back to ToC or Named Individual ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#OWLNamedIndividual_67b22c88_bcfe_4030_80ce_6b2d3bbd15b8

belongs to
LogonType c

rdpLogonni back to ToC or Named Individual ToC

IRI: http://www.semanticweb.org/robert_louan/ontologies/2026/1/unified-forensics-results#OWLNamedIndividual_1ab4667c_f883_41f9_aac5_5e82403e85ec

belongs to
LogonType c

Legend back to ToC

c: Classes
op: Object Properties
dp: Data Properties
ni: Named Individuals

References back to ToC

Add your references here. It is recommended to have them as a list.

Acknowledgments back to ToC

The authors would like to thank Silvio Peroni for developing LODE, a Live OWL Documentation Environment, which is used for representing the Cross Referencing Section of this document and Daniel Garijo for developing Widoco, the program used to create the template used in this documentation.