Reference

The vocabulary of digital evidence, in plain English.

Twenty-five terms you will meet in our reports, in proceedings and on this site, defined the way we would explain them across a table.

Digital forensics
The structured identification, preservation, analysis and reporting of electronic evidence so it can be relied upon in legal, regulatory or internal proceedings, using repeatable, documented methods.
Forensic image
A complete, bit-for-bit copy of a device or data source, fixed with cryptographic hashes so any expert can verify the copy is faithful. Analysis happens on the image; the original stays untouched.
Hash (MD5 / SHA-256)
A cryptographic fingerprint of data. If a single bit changes, the hash changes, which is how forensic copies are proven identical to their source and how tampering is exposed.
Chain of custody
The documented record of who held an item of evidence, when, and what was done to it, from collection to reporting. Gaps in the chain are where admissibility challenges begin.
Write blocker
Hardware or software that permits reading a storage device while making writing to it physically impossible, ensuring examination cannot alter the evidence.
Unallocated space
Areas of a disk not currently assigned to files. Deleted content frequently persists there until overwritten, which is why deleted rarely means gone.
File carving
Recovering files from raw disk data by their internal structure rather than the file system's records, used when the records themselves are deleted or damaged.
Metadata
Data about data: creation and modification times, authorship, device details, GPS coordinates in a photograph. Often more probative than the file's visible content.
Volume shadow copy
Windows snapshots of earlier disk states. A wiped document sometimes survives, intact and dated, in a shadow copy nobody thought about.
File system journal
The file system's own running log of changes, which can evidence when files were created, renamed or destroyed even after the files themselves are gone.
USB artefacts
Records the operating system keeps of every storage device ever connected: identifiers, first and last connection times. Central to most data-theft matters.
Windows artefacts recording which files and folders a user actually opened, and when, including files that lived on now-absent external drives.
Cloud audit log
Platform records of sign-ins, access, sharing and administration in services like Microsoft 365 and Google Workspace. Ages out on fixed schedules; preserve early.
Mailbox forwarding rule
An instruction inside a mailbox that copies mail elsewhere. A hidden rule is the signature move of business email compromise.
Business email compromise (BEC)
Fraud built on a compromised or impersonated mailbox, typically diverting invoice payments. The audit trail usually identifies the intrusion, the watching period and the strike.
Data exfiltration
The unauthorised movement of data out of an organisation: USB copies, personal-cloud uploads, mass downloads, forwarded mail. Each route leaves distinct artefacts.
eDiscovery
The identification, preservation, collection, processing, review and production of electronically stored information for legal proceedings.
De-duplication
Removing identical documents from a review population so each item is reviewed once. Documented de-duplication cuts cost without losing content.
Technology-assisted review (TAR)
Machine-learning-assisted prioritisation of documents in review, trained by human decisions, used to find the relevant material faster in large populations.
Expert witness
A specialist permitted to give opinion evidence, whose overriding duty is to the court rather than the instructing party, and whose report must meet Order 38 requirements.
Order 38 (Rules of the High Court)
The Hong Kong rules governing expert evidence: the report's required content, the expert's declaration and the duty owed to the court.
Spoliation
The destruction or alteration of evidence, deliberate or careless. The traces destruction leaves are themselves evidence, and tribunals may draw adverse inferences from it.
Spyware / stalkerware
Software covertly installed on a phone or computer to monitor its user. Detection and, critically, evidential documentation are part of a device compromise assessment.
Preservation
Securing evidence in its current state before it degrades: isolating devices, suspending deletion policies, capturing cloud data. The step timing decides.
Proportionality
Scoping forensic and discovery work to what the issues genuinely require. The discipline that keeps evidence exercises affordable and courts satisfied.
Litigation hold
A platform setting that preserves mailbox and file content beyond normal retention once litigation is anticipated. Switching it on early is often the difference between evidence and absence.
Unified audit log
Microsoft 365's record of who did what: sign-ins, mailbox actions, rule changes, deletions and exports. Retention varies by licence, and the window is shorter than most incidents are old.
Google Vault
Google Workspace's retention and legal-hold service, holding mail and files against deletion where configured, and the first place to look when a Workspace mailbox matters.
PST file
A local Outlook data file holding mail outside the server. PSTs on laptops, shares and backups frequently contain material the platform deleted years ago.
Faraday bag
A shielded pouch that cuts a device off from all networks, preventing remote wipe or alteration between seizure and examination.
Logical extraction
Collection of the data a device's operating system agrees to hand over: files, messages, media. Faster and widely supported, but it does not reach deleted content the way physical methods can.
Physical extraction
A deeper acquisition of a device's storage, capable of recovering deleted material, but available only for some device, model and software combinations; feasibility is assessed per handset.
Deduplication
Removing identical copies of documents and messages from a collection so reviewers read each item once. Done with documented method, it cuts review cost without cutting evidence.
De-NISTing
Filtering known system files from a collection using reference hash lists, leaving only material a human could have created or changed.
Custodian
A person whose devices and accounts may hold relevant evidence. Discovery is scoped custodian by custodian, which is why early, accurate custodian lists save money.
Message-ID
A unique identifier stamped on an email at creation. Consistency between Message-IDs, server logs and timestamps is central to testing whether a produced email is genuine.
DKIM
A cryptographic signature applied by a sending mail system. An intact DKIM signature ties a message to its origin; its absence or failure is a fact worth explaining.
Recoverable items
The holding area where Microsoft 365 keeps deleted mailbox content for a period after deletion, and a routine source of material the user believed was gone.
Backdating
Presenting a document or message as older than it is. Metadata, system records and internal consistency usually betray it; testing for it is a standard authenticity examination.
Protection for lawyer-client communications. Engagements can be structured under direction of counsel so forensic work product attracts privilege from the outset.

A term you have met elsewhere and do not see here? Ask during a case review; if it matters to your matter, we will explain it without the mystique.