Reference
The vocabulary of digital evidence, in plain English.
Twenty-five terms you will meet in our reports, in proceedings and on this site, defined the way we would explain them across a table.
- Digital forensics
- The structured identification, preservation, analysis and reporting of electronic evidence so it can be relied upon in legal, regulatory or internal proceedings, using repeatable, documented methods.
- Forensic image
- A complete, bit-for-bit copy of a device or data source, fixed with cryptographic hashes so any expert can verify the copy is faithful. Analysis happens on the image; the original stays untouched.
- Hash (MD5 / SHA-256)
- A cryptographic fingerprint of data. If a single bit changes, the hash changes, which is how forensic copies are proven identical to their source and how tampering is exposed.
- Chain of custody
- The documented record of who held an item of evidence, when, and what was done to it, from collection to reporting. Gaps in the chain are where admissibility challenges begin.
- Write blocker
- Hardware or software that permits reading a storage device while making writing to it physically impossible, ensuring examination cannot alter the evidence.
- Unallocated space
- Areas of a disk not currently assigned to files. Deleted content frequently persists there until overwritten, which is why deleted rarely means gone.
- File carving
- Recovering files from raw disk data by their internal structure rather than the file system's records, used when the records themselves are deleted or damaged.
- Metadata
- Data about data: creation and modification times, authorship, device details, GPS coordinates in a photograph. Often more probative than the file's visible content.
- Volume shadow copy
- Windows snapshots of earlier disk states. A wiped document sometimes survives, intact and dated, in a shadow copy nobody thought about.
- File system journal
- The file system's own running log of changes, which can evidence when files were created, renamed or destroyed even after the files themselves are gone.
- USB artefacts
- Records the operating system keeps of every storage device ever connected: identifiers, first and last connection times. Central to most data-theft matters.
- Link files and jump lists
- Windows artefacts recording which files and folders a user actually opened, and when, including files that lived on now-absent external drives.
- Cloud audit log
- Platform records of sign-ins, access, sharing and administration in services like Microsoft 365 and Google Workspace. Ages out on fixed schedules; preserve early.
- Mailbox forwarding rule
- An instruction inside a mailbox that copies mail elsewhere. A hidden rule is the signature move of business email compromise.
- Business email compromise (BEC)
- Fraud built on a compromised or impersonated mailbox, typically diverting invoice payments. The audit trail usually identifies the intrusion, the watching period and the strike.
- Data exfiltration
- The unauthorised movement of data out of an organisation: USB copies, personal-cloud uploads, mass downloads, forwarded mail. Each route leaves distinct artefacts.
- eDiscovery
- The identification, preservation, collection, processing, review and production of electronically stored information for legal proceedings.
- De-duplication
- Removing identical documents from a review population so each item is reviewed once. Documented de-duplication cuts cost without losing content.
- Technology-assisted review (TAR)
- Machine-learning-assisted prioritisation of documents in review, trained by human decisions, used to find the relevant material faster in large populations.
- Expert witness
- A specialist permitted to give opinion evidence, whose overriding duty is to the court rather than the instructing party, and whose report must meet Order 38 requirements.
- Order 38 (Rules of the High Court)
- The Hong Kong rules governing expert evidence: the report's required content, the expert's declaration and the duty owed to the court.
- Spoliation
- The destruction or alteration of evidence, deliberate or careless. The traces destruction leaves are themselves evidence, and tribunals may draw adverse inferences from it.
- Spyware / stalkerware
- Software covertly installed on a phone or computer to monitor its user. Detection and, critically, evidential documentation are part of a device compromise assessment.
- Preservation
- Securing evidence in its current state before it degrades: isolating devices, suspending deletion policies, capturing cloud data. The step timing decides.
- Proportionality
- Scoping forensic and discovery work to what the issues genuinely require. The discipline that keeps evidence exercises affordable and courts satisfied.
- Litigation hold
- A platform setting that preserves mailbox and file content beyond normal retention once litigation is anticipated. Switching it on early is often the difference between evidence and absence.
- Unified audit log
- Microsoft 365's record of who did what: sign-ins, mailbox actions, rule changes, deletions and exports. Retention varies by licence, and the window is shorter than most incidents are old.
- Google Vault
- Google Workspace's retention and legal-hold service, holding mail and files against deletion where configured, and the first place to look when a Workspace mailbox matters.
- PST file
- A local Outlook data file holding mail outside the server. PSTs on laptops, shares and backups frequently contain material the platform deleted years ago.
- Faraday bag
- A shielded pouch that cuts a device off from all networks, preventing remote wipe or alteration between seizure and examination.
- Logical extraction
- Collection of the data a device's operating system agrees to hand over: files, messages, media. Faster and widely supported, but it does not reach deleted content the way physical methods can.
- Physical extraction
- A deeper acquisition of a device's storage, capable of recovering deleted material, but available only for some device, model and software combinations; feasibility is assessed per handset.
- Deduplication
- Removing identical copies of documents and messages from a collection so reviewers read each item once. Done with documented method, it cuts review cost without cutting evidence.
- De-NISTing
- Filtering known system files from a collection using reference hash lists, leaving only material a human could have created or changed.
- Custodian
- A person whose devices and accounts may hold relevant evidence. Discovery is scoped custodian by custodian, which is why early, accurate custodian lists save money.
- Message-ID
- A unique identifier stamped on an email at creation. Consistency between Message-IDs, server logs and timestamps is central to testing whether a produced email is genuine.
- DKIM
- A cryptographic signature applied by a sending mail system. An intact DKIM signature ties a message to its origin; its absence or failure is a fact worth explaining.
- Recoverable items
- The holding area where Microsoft 365 keeps deleted mailbox content for a period after deletion, and a routine source of material the user believed was gone.
- Backdating
- Presenting a document or message as older than it is. Metadata, system records and internal consistency usually betray it; testing for it is a standard authenticity examination.
- Legal professional privilege
- Protection for lawyer-client communications. Engagements can be structured under direction of counsel so forensic work product attracts privilege from the outset.
A term you have met elsewhere and do not see here? Ask during a case review; if it matters to your matter, we will explain it without the mystique.