Digital evidence reference
Digital Forensics and Cyber Security Glossary
210 plain-English definitions for legal teams, organisations and anyone trying to understand digital evidence.
Search for a word or acronym, choose a topic, or browse alphabetically. Each term has a link you can share.
210 of 210 terms
No terms match these filters. Try a shorter word or choose All topics.
A
- Access control #
-
Rules and checks that determine who or what may use a system, account or item of data, and which actions are permitted.
Cyber security
- Acquisition #
-
Collecting digital information into a form that can be preserved and examined. The method may capture an entire device, selected files or a service export.
Evidence handling
- Active Directory #
-
Microsoft's directory service for managing identities, computers and permissions. Directory, authentication and policy records can help reconstruct account activity.
Systems and artefacts
- Admissibility #
-
Whether evidence may be received by a court. Technical reliability can be relevant, but an examiner does not decide admissibility.
Legal and quality
- Advanced persistent threat (APT) #
-
A sustained, targeted threat involving an adversary with the resources and intent to maintain access. The label alone does not establish the attacker's identity.
Cyber security
- Allocated space #
-
Storage currently assigned to files or file-system structures. It contrasts with space the file system marks as available for reuse.
Systems and artefacts
- Alternative hypothesis #
-
Another explanation that could account for an observation. Testing reasonable alternatives helps prevent an investigation from treating its starting assumption as its conclusion.
Legal and quality
- Android #
-
Google-led mobile operating-system platform. Evidence availability varies with the device, Android version, security state, applications and acquisition method.
Mobile and messaging
- Anti-forensics #
-
Actions intended to obstruct digital examination, such as removing or disguising traces. Missing information alone does not establish deliberate interference.
Evidence handling
- API (application programming interface) #
-
A defined way for software to exchange requests and data. Cloud collections often depend on an API's permissions, limits and returned fields.
Systems and artefacts
- Application artefact #
-
A record created or used by an application, such as a database, cache or log. Its evidential meaning depends on the application's behaviour.
Systems and artefacts
- Archive file #
-
A container holding other files, such as ZIP or TAR. An archive can preserve useful structure, but may change or omit source metadata.
Systems and artefacts
- Artefact #
-
A digital trace that may help explain activity or system state. Examples include logs, browser records, thumbnails and file-system entries.
Systems and artefacts
- Attribution #
-
Linking activity to a device, account, organisation or person. Evidence supporting one level of attribution does not automatically establish the others.
Evidence handling
- Audit log #
-
A record of selected actions or changes. Coverage depends on what was enabled, the recording system, retention and access to the relevant logs.
Cyber security
- Authentication #
-
Checking a claimed identity, usually through credentials or another factor. A successful login establishes use of credentials, not necessarily the human operator.
Cyber security
-
Permission to perform an action or access information. Valid credentials do not, by themselves, give authority to collect or examine someone else's data.
Cyber security
B
- Backup #
-
A retained copy used to restore information. Backups may be valuable evidence, but their scope and history differ from a documented forensic acquisition.
Evidence handling
- Beaconing #
-
Repeated communications from a device to another system. Regular traffic can indicate remote control, but legitimate software also makes periodic connections.
Cyber security
- BitLocker #
-
Microsoft's volume-encryption technology. Access to protected data depends on the system state and available credentials or recovery material.
Systems and artefacts
- Bitstream image #
-
A copy of the addressable data stream acquired from storage. Its coverage depends on the device, interface, read errors and acquisition method.
Evidence handling
- Bluetooth #
-
Short-range wireless technology used to connect devices. Pairing or connection records may provide context, but do not necessarily prove data transfer.
Mobile and messaging
- Bootable forensic environment #
-
A controlled operating environment started from separate media for collection or examination. Its operation and any effect on source data should be documented.
Evidence handling
- Browser cache #
-
Locally retained web resources used to speed loading. Cached material can come from background requests or embedded content as well as deliberate browsing.
Systems and artefacts
- Browser history #
-
Records of web navigation retained by a browser or account. Synchronisation, private modes and retention settings affect what the history can show.
Systems and artefacts
- Brute-force attack #
-
Repeated attempts to guess a secret, such as a password. Rate limits, stronger authentication and monitoring can reduce the opportunity for this activity.
Cyber security
- Business email compromise (BEC) #
-
Fraud involving business communications, often used to redirect payments or obtain information. It may involve mailbox compromise, impersonation or lookalike domains.
Cyber security
C
- Cache #
-
A temporary or reusable store intended to improve performance. A cached item may outlast its source, or have a timestamp unrelated to original creation.
Systems and artefacts
- Carving #
-
Recovering candidate content by recognising data patterns rather than relying on complete file-system records. Results may be fragmented, incomplete or lack original filenames.
Evidence handling
- Cell-site evidence #
-
Records relating to mobile-network infrastructure used by a device. They require specialist interpretation and do not usually identify an exact handset location.
Mobile and messaging
- Chain of custody #
-
The documented handling, possession and transfer of evidence. It helps establish continuity between the source, acquired material and items later examined or produced.
Evidence handling
- Checksum #
-
A value calculated from data to help detect differences. The assurance it provides depends on the algorithm and the purpose of the comparison.
Evidence handling
- Cloud audit log #
-
A service-side record of selected cloud activity. Licensing, configuration, retention and event definitions affect the record's availability and meaning.
Cloud and email
- Cloud forensics #
-
Examination of evidence held in or generated by cloud services, combining authorised exports, audit records and related endpoint or account information.
Cloud and email
- Codec #
-
Software or a specification for encoding and decoding media. Re-encoding can change file structure and metadata without necessarily changing the depicted event.
Systems and artefacts
- Command and control (C2) #
-
Infrastructure and communications used by an attacker to direct compromised systems. A connection to suspected infrastructure needs contextual assessment.
Cyber security
- Compromise #
-
A loss of the expected security of a system, account or data. Its scope may involve confidentiality, integrity, availability or several of these.
Cyber security
- Container #
-
A structure holding other data. In media it combines streams and metadata; in computing it can also mean an isolated application environment.
Systems and artefacts
- Containment #
-
Actions taken to limit an incident's spread or impact. They may change evidence, so the actions and their timing should be recorded.
Cyber security
-
A small value a website asks a browser to retain and return. Cookies serve different purposes, including sessions, preferences and measurement.
Cloud and email
- Correlation #
-
Comparing records to identify relationships between events. Matching times or identifiers can support a link, but does not automatically demonstrate causation.
Evidence handling
- Court expert #
-
An expert who assists a court on matters within their expertise. The applicable duties and report requirements depend on the jurisdiction and proceedings.
Legal and quality
- CPR Part 35 #
-
The rules governing experts and assessors in civil proceedings in England and Wales, including the expert's overriding duty to help the court.
Legal and quality
- Credential stuffing #
-
Trying previously exposed username and password combinations against other services. Password reuse can turn one disclosure into compromise of additional accounts.
Cyber security
- CrimPR Part 19 #
-
The Criminal Procedure Rules provisions on expert evidence in England and Wales. They address expert duties, reports and procedural requirements.
Legal and quality
- Cryptographic hash #
-
A fixed-length value derived from data using a cryptographic algorithm. Matching values support a byte-level comparison; they do not establish authorship or earlier history.
Evidence handling
- Custodian #
-
A person or organisational role associated with potentially relevant information. Identifying custodians helps define where to preserve and collect material.
Legal and quality
D
- Dark web #
-
Services accessed through particular overlay networks rather than ordinary web browsing. A reference to stolen data there needs verification; appearance alone proves little.
Cyber security
- Data breach #
-
A security incident affecting information. A personal-data breach has a specific legal meaning and can involve loss, alteration or unauthorised access as well as disclosure.
Cyber security
- Data exfiltration #
-
Moving information out of an environment without authority. Access, preparation, attempted transfer and confirmed transfer are separate evidential propositions.
Cyber security
- Data loss prevention (DLP) #
-
Controls that detect or restrict selected uses or transfers of information. A DLP alert records a rule match, which still needs interpretation.
Cyber security
- Data minimisation #
-
Limiting personal information to what is necessary for the defined purpose. In casework, this informs proportionate scope, access and handling.
Legal and quality
- Data recovery #
-
Attempts to retrieve inaccessible, damaged or deleted information. Recoverability depends on the source, later use, encryption and the condition of the retained data.
Evidence handling
- Database #
-
An organised store of records with a defined structure. Interpreting an export may require its schema, relationships and the application's use of the fields.
Systems and artefacts
- De-duplication #
-
Identifying and grouping or removing duplicate items for a defined task. The method matters: identical files, similar text and repeated messages are different comparisons.
Legal and quality
- Deleted data #
-
Information removed from normal access or marked for reuse. Some content or traces may remain, but deletion does not guarantee either recovery or complete erasure.
Evidence handling
- Denial of service (DoS/DDoS) #
-
Activity that makes a service unavailable or unusable. A distributed attack uses multiple sources; disruption alone does not identify who caused it.
Cyber security
- Device extraction #
-
Data acquired from a device using a particular method. An extraction is a selected technical result, not an assurance that every record was obtained.
Mobile and messaging
- Digital evidence #
-
Information in digital form that may help address a question in an investigation or proceeding. Its relevance and reliability depend on source and context.
Evidence handling
- Digital forensics #
-
The disciplined preservation, examination and interpretation of digital information, with methods and findings documented so their basis can be assessed.
Evidence handling
- Digital signature #
-
A cryptographic mechanism used to check that data was signed using a particular private key and has not changed. The key's identity and trust still matter.
Evidence handling
- Disclosure #
-
The process of identifying and providing information under the applicable legal rules. Its scope and the relevant tests differ between civil and criminal proceedings.
Legal and quality
- Disk image #
-
An acquired representation of storage. It may be a raw stream or a container with compression and metadata; its format does not alone establish completeness.
Evidence handling
- DKIM #
-
DomainKeys Identified Mail: a domain's cryptographic signature over selected email content and headers. Verification supports that signed material, not the truth of the message.
Cloud and email
- DMARC #
-
An email-domain policy and reporting mechanism using alignment with SPF or DKIM. A pass does not rule out a compromised mailbox or authorised sending service.
Cloud and email
- DNS #
-
The Domain Name System translates names into records used to locate services. Records may change, and current DNS does not necessarily show historic configuration.
Cloud and email
E
- E01 / Expert Witness Format #
-
A forensic-image container format that can hold acquired data with compression, segmentation and metadata. The filename or format alone does not establish acquisition quality.
Evidence handling
- eDiscovery / eDisclosure #
-
Processes for locating, preserving, collecting and reviewing electronically stored information for legal matters. The terminology and procedural duties depend on the jurisdiction.
Legal and quality
- EDR #
-
Endpoint detection and response: technology that records and analyses selected device activity and supports response. Its visibility depends on configuration and sensor coverage.
Cyber security
- Email header #
-
Structured fields describing an email and its handling. Some fields are sender-controlled; others are added by servers and need to be assessed in context.
Cloud and email
- EML #
-
A commonly used format for an individual email, including headers, body and attachments. The export method affects which original details are preserved.
Cloud and email
- Encryption #
-
Transforming information so it can be read only with the appropriate key or access mechanism. Encryption can protect evidence and also restrict what can be examined.
Cyber security
- End-to-end encryption #
-
Protection designed so message content is readable at the communicating endpoints. It does not remove all device records, metadata or risks at either endpoint.
Mobile and messaging
- Endpoint #
-
A device or computing environment at which activity occurs, such as a laptop, phone or server. Endpoint evidence can complement network and cloud records.
Cyber security
- ESI #
-
Electronically stored information: digital material such as messages, documents, databases and logs. A legal collection may include context and metadata as well as visible content.
Legal and quality
- Event log #
-
A system or application record of selected events. Event identifiers and timestamps must be interpreted with the provider, configuration and operating context.
Systems and artefacts
- Evidence continuity #
-
The ability to account for an item's handling and its relationship to the original source throughout the examination and reporting process.
Evidence handling
- EXIF #
-
Metadata commonly found in image files, including possible camera and capture information. Fields can be absent, changed or removed, so they require corroboration.
Systems and artefacts
- Expert report #
-
A report explaining an expert's instructed questions, material, methods, findings and opinion. Required declarations and structure depend on the applicable rules.
Legal and quality
- Exploit #
-
A technique or item of code that takes advantage of a weakness. Evidence that a weakness existed does not, by itself, show it was exploited.
Cyber security
F
- False positive #
-
A result that incorrectly indicates the condition being tested. The significance of an alert depends on the test, its context and further examination.
Cyber security
- File extension #
-
The suffix commonly used to indicate a file's type, such as .pdf. It can be changed and is not a reliable substitute for inspecting file content.
Systems and artefacts
- File signature #
-
A recognisable pattern in a file's contents that helps identify its format. It differs from a cryptographic digital signature and may not identify the whole file.
Systems and artefacts
- File system #
-
The structures an operating system uses to organise stored data, including filenames, directories, allocation information and timestamps.
Systems and artefacts
- File-system extraction #
-
An acquisition of files and directories exposed by a device and method. The term's scope varies; it does not necessarily include deleted or inaccessible data.
Mobile and messaging
- FileVault #
-
Apple's macOS storage-encryption feature. Acquisition options depend on the Mac, its current state and the available authorised access.
Systems and artefacts
- Firewall #
-
A control that permits or blocks selected communications according to rules. A firewall log may show a decision or connection, rather than the data transferred.
Cyber security
- Forensic image verification #
-
Checking an acquired image against the relevant source stream or recorded verification values, while accounting for read errors and the acquisition method.
Evidence handling
- Forensic triage #
-
A focused initial assessment to identify relevant sources, risks and priorities. It supports decisions about further work and does not replace a complete examination.
Evidence handling
- Frame rate #
-
The rate at which video frames are presented. A file may use constant or variable timing, so frame count alone may not establish duration or continuity.
Systems and artefacts
- Free space #
-
Storage the file system considers available for allocation. It may contain remnants of earlier data, or it may have been cleared or affected by device management.
Systems and artefacts
- FSR Code #
-
The Forensic Science Regulator's statutory code for specified forensic activities in England and Wales. Applicability depends on the activity and its circumstances.
Legal and quality
- Full-disk encryption #
-
Encryption covering a storage device or volume's data. The practical protection and available acquisition routes depend on the implementation and system state.
Systems and artefacts
G
- Geolocation #
-
Information suggesting a location, derived from sources such as satellite positioning, networks or account activity. Accuracy, source and time basis must be assessed separately.
Mobile and messaging
H
- Hash collision #
-
Two different inputs producing the same hash value. Algorithm choice and the purpose of comparison determine the practical significance of that possibility.
Evidence handling
- Hash value #
-
The result of a hash calculation, often represented as hexadecimal text. A recorded value is useful only when the algorithm and the data compared are clear.
Evidence handling
- Hibernation file #
-
Stored system state used to support hibernation or related features. It can contain useful memory-related material, depending on the operating system and configuration.
Systems and artefacts
- Hyperlink #
-
A reference that points to another resource or location. The displayed text and the actual destination can differ.
Cloud and email
I
- Identity provider (IdP) #
-
A service that authenticates users and supplies identity information to other systems. Its logs can help explain sign-ins, sessions and access decisions.
Cloud and email
- IMEI #
-
International Mobile Equipment Identity: an identifier associated with mobile equipment. It is distinct from a telephone number, subscriber identity and the person using the device.
Mobile and messaging
- Impersonation #
-
Presenting as another person or organisation. It can occur without taking over their genuine account, for example through a similar domain or display name.
Cyber security
- IMSI #
-
International Mobile Subscriber Identity: an identifier associated with a mobile subscription. Subscriber records and device-use evidence answer different attribution questions.
Mobile and messaging
- Incident response #
-
Coordinated work to assess and manage a security incident, including containment and recovery. Forensic examination can support it while addressing separate evidence questions.
Cyber security
- Indicator of compromise (IOC) #
-
An observable item associated with possible compromise, such as a file hash or network address. Its reliability depends on context, freshness and corroboration.
Cyber security
- Inference #
-
A conclusion drawn from observations and assumptions. A report should make the reasoning visible and distinguish inference from directly recorded events.
Evidence handling
- Integrity #
-
The property of information remaining complete and unaltered in the relevant sense. An integrity check's meaning depends on what was checked and when.
Evidence handling
- Internet Protocol address (IP address) #
-
An address used for network communication. Shared connections, address reassignment, proxies and VPNs limit what an address alone can establish about a person.
Cloud and email
- iOS #
-
Apple's iPhone operating system. Access to evidence depends on the model, software, security state, applications and available acquisition method.
Mobile and messaging
- ISO/IEC 17025 #
-
The international standard for the competence of testing and calibration laboratories. Accreditation relates to a defined scope, not every possible service or conclusion.
Legal and quality
J
- Joint statement #
-
A document recording experts' areas of agreement and disagreement, usually with reasons. Its preparation and use follow the applicable court directions and rules.
Legal and quality
- JSON #
-
A structured text format used for data exchange. Fields may be nested, optional or service-specific, so their meaning requires the relevant schema or documentation.
Systems and artefacts
- Jump List #
-
A Windows feature recording selected recent or frequent application items and tasks. Its contents depend on the application and system behaviour.
Systems and artefacts
K
- Keylogger #
-
Software or hardware that records keystrokes. Its presence, operation and any resulting data need to be established from evidence.
Cyber security
L
- Lateral movement #
-
Movement from an initially accessed system or account to other parts of an environment. Authentication, endpoint and network records may help reconstruct it.
Cyber security
- Legal hold / preservation hold #
-
A direction to preserve potentially relevant information and suspend relevant routine deletion. Its scope should be defined, communicated and reviewed by the responsible team.
Legal and quality
- Linked device #
-
Another device connected to an account or messaging service. Linking and synchronisation can affect where records appear and what can be attributed to one device.
Mobile and messaging
- Linux #
-
A family of operating systems using the Linux kernel. Relevant evidence varies with the distribution, file systems, services and logging configuration.
Systems and artefacts
- Live acquisition #
-
Collection while a system is running. It can preserve volatile or accessible decrypted data, but the collection itself interacts with and changes the system.
Evidence handling
- LNK file #
-
A Windows shortcut that can retain information about a target and its location. Interpretation depends on how and when the shortcut was created or updated.
Systems and artefacts
- Log retention #
-
How long records are kept and under what conditions they are replaced or deleted. Limited retention can leave gaps even where an event occurred.
Cyber security
- Logical acquisition #
-
Collection through a system's logical view of available data, such as files or records. It may omit material outside that view.
Evidence handling
- Lookalike domain #
-
A domain chosen to resemble a trusted name. Similar spelling or appearance can support impersonation without compromising the genuine domain.
Cyber security
M
- MAC address #
-
A link-layer identifier used by network interfaces. It may be changed or randomised and does not, on its own, identify a person.
Cloud and email
- Malware #
-
Software designed to perform harmful or unauthorised activity. A detection label needs to be checked against the actual file, behaviour and context.
Cyber security
- Manifest #
-
A structured inventory of collected or supplied material, often including identifiers, paths, sizes and hash values. It helps document scope and transfers.
Evidence handling
- Master File Table (MFT) #
-
A central NTFS structure containing records about files and directories. Entries can include allocation, naming and time information requiring file-system-aware interpretation.
Systems and artefacts
- MBOX #
-
A family of formats for storing messages in a mailbox file. Variants and export choices can affect message boundaries and retained information.
Cloud and email
- MD5 #
-
An older cryptographic hash algorithm with known collision weaknesses. It can assist comparisons, but should not be the sole security basis where deliberate collision is relevant.
Evidence handling
- Memory forensics #
-
Examination of captured volatile memory for relevant processes, connections and other state. Capture quality and the operating environment affect interpretation.
Evidence handling
- Metadata #
-
Information describing another item, such as a document's recorded author or timestamps. A field may reflect software behaviour rather than an independently verified fact.
Systems and artefacts
- MFA (multi-factor authentication) #
-
Authentication using more than one type of factor. It improves protection, but implementation choices, session theft and recovery routes can still affect security.
Cyber security
- MIME #
-
A set of conventions describing the structure and content types of messages and other data. Email MIME structure can help distinguish body parts and attachments.
Cloud and email
- Mobile device forensics #
-
Preserving and examining information from phones, tablets and related sources. A device, extraction, backup and cloud account may each hold different evidence.
Mobile and messaging
- MSG #
-
A Microsoft Outlook message format that can retain message properties and attachments. It differs from EML and from the full context of a mailbox.
Cloud and email
N
- Native file #
-
An item in its originating application's format, rather than a printout or rendered copy. Native files may retain useful structure, formulas or metadata.
Evidence handling
- Network capture (PCAP) #
-
A record of captured network packets. Capture location, filtering, packet loss and encryption determine what it can reveal.
Cloud and email
- NTFS #
-
A Windows file system with structures such as the MFT and transaction-related records. Different artefacts can record different aspects of file activity.
Systems and artefacts
- NTP #
-
Network Time Protocol: a mechanism for synchronising clocks. Use of a time service does not eliminate every clock error or timestamp ambiguity.
Cloud and email
O
- OAuth #
-
A framework for granting software access to resources without sharing a user's password with it. Grants, tokens and permissions can be relevant to account investigations.
Cloud and email
- OneDrive #
-
Microsoft's cloud file-storage and synchronisation service. Local files, cloud versions and service-side activity records may provide different parts of a history.
Cloud and email
- Open-source intelligence (OSINT) #
-
Information gathered and assessed from lawfully accessible public sources. Reliability depends on provenance, timing, corroboration and the limits of the collection.
Cyber security
- Operating-system artefact #
-
A record generated by an operating system, such as a log, shortcut or configuration entry. Its meaning depends on the feature that created it.
Systems and artefacts
- Overwriting #
-
Replacing data at a storage location with other data. The effects differ between storage technologies and cannot always be inferred from a file's apparent deletion.
Evidence handling
P
- Pagefile / swap #
-
Storage used to support virtual memory. It may contain fragments of process data, but is not a complete or orderly substitute for a memory capture.
Systems and artefacts
- Parser #
-
Software that interprets a data format and presents its contents. Parsed output can be incomplete or wrong and should be checked against relevant source material.
Evidence handling
- Password manager #
-
Software that stores or generates credentials under an access mechanism. Its security depends on the product, configuration, account protection and device state.
Cyber security
- Persistence #
-
A means of retaining access or execution after events such as a restart or credential change. Evidence is needed to distinguish malicious persistence from normal configuration.
Cyber security
- Phishing #
-
Deceptive communication intended to induce an unsafe action, such as disclosing information or visiting a fraudulent service. It can use email, messages, calls or other channels.
Cyber security
- Physical acquisition #
-
A term commonly used for collection at a storage or memory level. Its meaning varies by device and tool and does not guarantee access to decrypted or deleted content.
Mobile and messaging
- Prefetch #
-
Windows data used to support faster application startup. Relevant files may contain useful execution-related information, subject to the Windows version and feature settings.
Systems and artefacts
- Preservation #
-
Steps taken to reduce the risk that relevant information is lost or altered. The appropriate approach depends on the source, authority and immediate operational risks.
Evidence handling
- Privilege #
-
In legal contexts, protection that may attach to certain communications or material. Its application is for the legal team to determine, not a software label.
Legal and quality
- Privilege escalation #
-
Obtaining greater system permissions than were initially available or authorised. Account, process and configuration records can help establish how it occurred.
Cyber security
- Provenance #
-
An item's origin and history, including how it was created, obtained or transformed. A reliable copy does not, by itself, establish the source's earlier provenance.
Evidence handling
- PST / OST #
-
Microsoft Outlook data formats used for stored or cached mailbox information. Coverage depends on account configuration, synchronisation and how the file was obtained.
Cloud and email
R
- Ransomware #
-
Malware used to disrupt access or support extortion, often through encryption. Data theft may occur alongside it, but encryption alone does not prove exfiltration.
Cyber security
- Read receipt #
-
A service-generated indication about message handling or display. It does not necessarily prove that a particular person read or understood the content.
Mobile and messaging
- Registry #
-
Windows databases containing configuration and state information. Keys and values can be useful artefacts, but require attention to their source, timing and semantics.
Systems and artefacts
- Remote acquisition #
-
Collection performed over a network or with guided local assistance. Authority, operator actions, source state, verification and transfer arrangements remain important.
Evidence handling
- Remote desktop (RDP) #
-
Microsoft's protocol for interacting with a remote desktop session. Log entries can support session reconstruction, but require careful account and time interpretation.
Cyber security
- Retention policy #
-
Rules governing how long information is kept and what happens afterwards. Routine retention may need to be adjusted where a preservation obligation applies.
Legal and quality
- Rootkit #
-
Software designed to conceal activity or maintain privileged access. Apparent anomalies need technical examination before they are attributed to a rootkit.
Cyber security
S
- Scope #
-
The agreed questions, sources, boundaries and outputs of an examination. Clear scope helps keep work proportionate and makes exclusions visible.
Evidence handling
- Screenshot #
-
A captured view of displayed content. It can be useful evidence, but usually omits underlying structure, wider context and some metadata.
Mobile and messaging
- Secure transfer #
-
A controlled method of moving information to an authorised recipient. Appropriate protection includes access control, encryption and checks suited to the material.
Evidence handling
- Session token #
-
A value used to maintain authenticated access. Use of a token can differ from a fresh password login, which matters when reconstructing account activity.
Cloud and email
- SHA-1 #
-
An older cryptographic hash algorithm with known collision weaknesses. A recorded SHA-1 value may support comparison, but stronger algorithms are preferable for new security-sensitive verification.
Evidence handling
- SHA-256 #
-
A cryptographic hash algorithm producing a 256-bit value. It is commonly used for evidence comparisons, with the compared data and acquisition context recorded.
Evidence handling
-
Microsoft's collaboration and document-management platform. Content, version history, sharing and audit records may have different collection and retention requirements.
Cloud and email
- SIEM #
-
Security information and event management: technology that collects and correlates security records. Its conclusions depend on the source data, rules and configuration.
Cyber security
- Single joint expert #
-
In civil proceedings in England and Wales, an expert instructed for two or more parties to prepare evidence for the court under the applicable rules.
Legal and quality
- Slack space #
-
Unused bytes within allocated storage units, depending on the file system. It may contain residual data, but its meaning and availability require source-specific assessment.
Systems and artefacts
-
Manipulating people into actions that undermine security or disclose information. Technical records may show part of the event but not the whole interaction.
Cyber security
- Source code #
-
Human-readable instructions from which software is run or built. Code review can explain possible behaviour; execution evidence is needed to establish what happened in a case.
Systems and artefacts
- SPF #
-
Sender Policy Framework: DNS-based information identifying permitted senders for a domain's envelope identity. SPF does not authenticate every visible email field.
Cloud and email
- Spoofing #
-
Falsifying an apparent identity or origin, such as an email sender or network source. A displayed identity should be assessed against independent records.
Cyber security
- SQL injection #
-
A weakness where input is improperly treated as part of a database command. It can permit unintended database actions when the surrounding conditions allow it.
Cyber security
- SQLite #
-
A database engine widely used by applications and devices. Relevant information may exist in the main database and associated journal or write-ahead log files.
Systems and artefacts
- SSD #
-
A solid-state storage device. Controller behaviour, encryption, TRIM and later use can substantially affect whether deleted data remains recoverable.
Systems and artefacts
- Steganography #
-
Concealing information within other material. Unusual file properties can justify examination, but do not themselves establish hidden content.
Cyber security
T
- Targeted collection #
-
Acquiring selected information relevant to defined questions, dates or sources. Selection criteria and any material omitted should be documented.
Evidence handling
- Threat actor #
-
A person, group or organisation capable of harmful activity. A label used in intelligence reporting is not proof of responsibility for a particular incident.
Cyber security
- Threat hunting #
-
A structured search for signs of threats that existing alerts may have missed. Its findings still require corroboration and interpretation.
Cyber security
- Time zone #
-
A convention for expressing local time relative to a reference such as UTC. Daylight-saving changes and source settings can complicate comparisons.
Systems and artefacts
- Timeline #
-
An ordered presentation of relevant events. A useful timeline records sources, time conversions and uncertainty rather than implying every timestamp has equal precision.
Evidence handling
- Timestamp #
-
A recorded time value associated with an event or item. Its meaning depends on the field, clock, time zone and operation that produced it.
Systems and artefacts
- TLS #
-
Transport Layer Security: a protocol used to protect communications in transit. It does not establish that the endpoint or the information supplied is trustworthy.
Cloud and email
- Token theft #
-
Unauthorised acquisition of a value that grants or maintains access. A stolen session or access token may be usable without a new password entry.
Cyber security
- Tool validation #
-
Establishing, with appropriate evidence, that a tool or method is fit for its intended use. Validation is tied to the task and relevant operating conditions.
Legal and quality
- TRIM #
-
A mechanism for informing compatible storage that certain blocks are no longer needed. Subsequent device processing can affect the availability of deleted data.
Systems and artefacts
- Two-factor authentication (2FA) #
-
Authentication using two different types of factor, such as a password and a possession factor. Two passwords alone are not two different factor types.
Cyber security
U
- UFDR #
-
A Cellebrite report package that can be reviewed in compatible software. It contains the exported selection and should not be assumed to contain every acquired record.
Mobile and messaging
- Unallocated space #
-
Storage not currently assigned to active files or structures by the file system. It may hold remnants, but recoverability is not assured.
Systems and artefacts
- Uncertainty #
-
A limit on how precisely or confidently a result can be expressed. It can arise from measurement, data gaps, ambiguity or the method used.
Legal and quality
- USB artefacts #
-
Records associated with USB devices and their use. Connection evidence alone does not establish which files, if any, were copied.
Systems and artefacts
- USN journal #
-
An NTFS change journal containing selected file-system change records. It is not a complete record of every user action or the contents of changed files.
Systems and artefacts
- UTC #
-
Coordinated Universal Time, commonly used as a reference for comparing events. Converting to UTC does not correct an inaccurate source clock.
Systems and artefacts
V
- Validation #
-
Demonstrating that a process is suitable for a defined purpose. The evidence required depends on the method, intended use and applicable requirements.
Legal and quality
- Verification #
-
Checking that specified requirements or expected properties are met. In casework, the term should identify the actual check performed and its limits.
Evidence handling
- Virtual machine #
-
A software-defined computer running within another environment. Evidence can exist both inside the guest and in host-side files, snapshots or logs.
Systems and artefacts
- Volatile data #
-
Information that may be lost quickly through shutdown or changes in system state, such as some memory and connection data.
Evidence handling
- VPN #
-
A virtual private network that carries traffic through a protected connection. It can change the apparent network source without establishing the identity of the user.
Cloud and email
- Vulnerability #
-
A weakness that could be used to undermine security. Its presence, exploitability and relevance to an observed incident are separate questions.
Cyber security
W
- WAL (write-ahead log) #
-
A database mechanism that records changes separately before they are incorporated into the main database. Omitting it can produce an incomplete view of some databases.
Systems and artefacts
- Web application firewall (WAF) #
-
A control that inspects selected web requests and may block suspicious traffic. It supplements, but does not replace, secure code and maintenance.
Cyber security
- Web shell #
-
Server-side code used to provide remote interaction with a web server. Establishing its presence and use requires examination of the file and related records.
Cyber security
- Write blocker #
-
Hardware or software intended to prevent writes through a specified acquisition route. Its effectiveness depends on the device, configuration and validated use.
Evidence handling
X
- XSS (cross-site scripting) #
-
A weakness that permits attacker-controlled script to run in a website's context in another person's browser. Impact depends on the page, controls and user access.
Cyber security
Z
- Zero trust #
-
An approach that avoids granting access solely because a user or device is inside a network. Access decisions use explicit checks appropriate to the resource.
Cyber security
- Zero-day #
-
A vulnerability used or disclosed before an effective fix is available, depending on context. The term does not describe every newly noticed incident.
Cyber security
Using these definitions
These are general explanations. A record’s meaning depends on the device, software, collection method and surrounding evidence. Legal duties and terminology can differ by jurisdiction.
Further reading
- NCSC cyber security glossary
- NIST: integrating forensic techniques into incident response
- Civil Procedure Rules, Part 35: experts and assessors
- Criminal Procedure Rules, including Part 19 on expert evidence
- Forensic Science Regulator’s Code of Practice, version 2
Last reviewed: 6 September 2026.
For a case-specific question, contact Alistair Ewing. For instruction and fee questions, see the FAQs.
