- Event reconstruction is a fundamental aspect of the investigative process in digital forensics. During this process, one systematically analyzes and organizes evidence to formulate a hypothesis regarding past events. The starting point is often the raw data from forensic timelines (e.g., a table including all parsed events), which may include millions of timeline entries. Various tools and techniques have been proposed to analyze these entries. However, the feasibility of applying process mining solutions remains unexplored. Process mining, with its ability to uncover patterns, deviations, and process flows from event data, can offer valuable insights into forensic event reconstruction. In this study, we explore the utilization of episode mining to generate case identifiers and provide event sequences, visualizations, and evaluation metrics from process models generated by process mining algorithms. As a result, we developed an open-source, web-based prototype application. ExperimentsEvent reconstruction is a fundamental aspect of the investigative process in digital forensics. During this process, one systematically analyzes and organizes evidence to formulate a hypothesis regarding past events. The starting point is often the raw data from forensic timelines (e.g., a table including all parsed events), which may include millions of timeline entries. Various tools and techniques have been proposed to analyze these entries. However, the feasibility of applying process mining solutions remains unexplored. Process mining, with its ability to uncover patterns, deviations, and process flows from event data, can offer valuable insights into forensic event reconstruction. In this study, we explore the utilization of episode mining to generate case identifiers and provide event sequences, visualizations, and evaluation metrics from process models generated by process mining algorithms. As a result, we developed an open-source, web-based prototype application. Experiments and case studies conclude that the proposed method can reconstruct digital forensic events and provide intuitive results to forensic investigators.…

