SKIP TO CONTENT
FORENSIC GLOSSARY

Digital Forensics Glossary for Litigators

The vocabulary that turns up in expert reports, ESI protocols and motions about digital evidence, defined for the lawyer reading them rather than for the examiner who wrote them.

TERMS
108 defined
CATEGORIES
7
EVERY ENTRY
What it is · why it matters
ANCHORED
One id per term
SCOPE
Forensics and electronic evidence
COST
Free · no sign-up
IN SHORT

A digital forensics glossary defines the vocabulary that appears in expert reports, ESI protocols and motions about digital evidence — hash values, write blockers, shellbags, Master File Table records, FRE 902(14) certifications. This one has 108 entries, and each says three things: what the term is, why a case turns on it, and what happens in the matter when it is mishandled.

Browse by category

A definition that only says what a thing is has not earned a place on a litigation site. Every entry here answers the question counsel is actually asking, which is what turns on it.

The categories run in the order a litigator meets these things in a matter: how the evidence is handled, what the artifacts are, the tools and formats it is produced in, the cloud and network records that sit off the endpoint, the legal standards that govern it, the people in the engagement, and the credentials behind them. Where a term is routinely overstated in litigation — that an MD5 collision makes MD5 worthless, that metadata is one thing, that a shellbag ties a folder to a particular USB drive — the entry says so.

Evidence handling11 TERMS

Artifacts and file systems32 TERMS

Tools and formats14 TERMS

Cloud and network13 TERMS

Roles and procedure13 TERMS

Credentials and standards bodies9 TERMS

All 108 terms, A to Z

Every term below carries its own anchor, so a definition can be linked, cited or sent on its own — /glossary#write-blocker resolves to the write blocker entry and nothing else. Terms that name a forensic artifact link on to that artifact’s full entry in the artifact index, where what it proves sits beside what it cannot prove.

  • An account is not a person. Shared credentials, an unlocked screen, a remote session and an administrator all produce the same record as the named user.
  • Access is not exfiltration. Opening a file, connecting a device and copying data are three different findings supported by three different records.
  • Absence of a record is not absence of an event. Most of these sources hold a fixed number of values or roll over on a short window, and many are off by default.

A

AD1

TOOLS AND FORMATS

ALSO: AD1 image · FTK logical image

The AccessData logical image format, holding selected files with their metadata, produced by FTK Imager and related tools.

Like the L01 it is a logical container, so the same limits apply: the files chosen are preserved with their metadata, and everything the filesystem was not asked for is absent. It is common in targeted collections and in productions from third parties who imaged only a share or a folder tree. Reading it may require the vendor's tooling, which is worth confirming before agreeing to receive evidence in it.

WHY IT MATTERSAgreeing a container format that the receiving expert cannot open without buying a specific product is an avoidable dispute.

Air gap

EVIDENCE HANDLING

ALSO: air-gapped · isolated network

Physical isolation of a system from any network, used for source-code review rooms, malware handling, and examination environments that must not leak.

In litigation the term usually arrives through a protective order: source code is made available on a standalone, non-networked machine in a secure room, with no internet, no removable media, and printing limited and logged. The same isolation is used on the examiner's side when handling live malware or a ransomware sample. Air gap describes network isolation only; it says nothing about whether the data on the machine is otherwise controlled.

WHY IT MATTERSThe review-environment terms in a protective order determine how many hours a code review takes and therefore what it costs, which is why they are negotiated before anyone opens a file.

AmCache

ARTIFACTS AND FILE SYSTEMS

ALSO: Amcache.hve · Amcache

A Windows registry hive recording application files that were present on a system, with path, size, and a SHA-1 value for many entries.

AmCache establishes presence and identity — this binary, with this hash, existed at this path — which is genuinely useful when the question is whether a particular tool was ever on the machine. It does not establish that the program ran. The distinction gets collapsed constantly, including in expert reports, and it is the single most common overreach in Windows execution analysis.

WHY IT MATTERSThe hash in AmCache can identify a wiping or exfiltration utility by name and version even after the binary is deleted, which is a strong finding stated correctly and a fatal one stated as execution.

Application metadata

ARTIFACTS AND FILE SYSTEMS

ALSO: internal metadata · document metadata · embedded metadata

Metadata stored inside the document by the program that wrote it — author, company, template, revision number, total editing time, and internal timestamps.

It survives copying, because it travels with the file, which makes it more durable than filesystem times and more useful for dating a document. It is also directly editable by anyone with the right tool, so a single internal timestamp establishes very little on its own. The value comes from corroboration across independent stores: the same document held by a mail server, a backup set, or the recipient's machine, where a person editing one copy could not reach the others.

WHY IT MATTERSBackdating cases are decided on whether an independent copy exists, not on what any one file's properties dialog says.

Attorneys' eyes only

LEGAL STANDARDS

ALSO: AEO · highly confidential - attorneys' eyes only

A protective-order designation restricting material to outside counsel and cleared experts, excluding the client's own employees and in-house lawyers.

It exists so competitively sensitive material can be produced between competitors without handing it to the people who would use it. The consequence for an examination is that the expert usually cannot discuss the substance with anyone at the client, so the report has to be written for a reader who has not seen and may never see the underlying material. Expert access typically requires advance disclosure and a period for the producing party to object.

WHY IT MATTERSThe disclosure and objection period has to be built into the schedule, because an expert who is not yet cleared cannot start.

B

Bates number

TOOLS AND FORMATS

ALSO: Bates stamp · Bates numbering · production number

A unique sequential identifier stamped on each produced page or assigned to each produced document, giving every item in a production a stable citation.

Everything downstream depends on it: exhibit lists, deposition citations, expert-report exhibits, and motion cites all resolve through the Bates range. Native files cannot be stamped on their face, so they are assigned a number that travels in the load file and on a placeholder image. Gaps in a range are worth noticing — they may reflect a withheld privileged document, or a production error nobody caught.

WHY IT MATTERSAn expert report that cites documents by filename instead of Bates number cannot be checked against the production without translation, and every reader has to do that work.

Bit-for-bit copy

EVIDENCE HANDLING

ALSO: bitstream copy · physical image · sector-by-sector copy

A copy that reproduces every sector of a source device in order, including areas holding no live file, so the copy and the source hash identically.

This is the physical acquisition, as opposed to a logical acquisition that copies only files the operating system will hand over. The distinction decides whether deleted content, slack space, and unpartitioned regions survive into the evidence set. Some sources cannot be copied this way — a cloud tenant, a locked mobile device, an encrypted volume with no key — and in those matters the collection is logical by necessity and the report should say so rather than imply a completeness the acquisition never had.

WHY IT MATTERSAn examiner who describes a logical export as a forensic image has misdescribed the evidence, and the error usually surfaces when the other side asks for the unallocated space that was never collected.

C

C2PA

TOOLS AND FORMATS

ALSO: Content Credentials · Coalition for Content Provenance and Authenticity

An open specification for cryptographically signed provenance metadata that records how a piece of media was captured or edited and by what software.

Where a C2PA manifest is present and its signature validates, it provides a testable statement about the file's history rather than an inference from its content — which is a materially stronger position than any detector output. Adoption is partial, and the manifest is easily stripped by re-encoding, uploading, or forwarding. Its absence is therefore uninformative: most authentic media in circulation carries no manifest at all.

WHY IT MATTERSPresent and valid, it is strong evidence. Absent, it is no evidence of anything, and treating the absence as suspicious is the error to avoid.

CCE

CREDENTIALS AND STANDARDS BODIES

ALSO: Certified Computer Examiner

Certified Computer Examiner, a vendor-neutral digital forensics certification issued by the International Society of Forensic Computer Examiners.

It is vendor-neutral, which distinguishes it from certifications tied to one product, and it requires a practical examination as well as a written one. Certification establishes that a person met a defined standard at a point in time. It does not establish that the examination in front of the court was performed competently, which is the question Rule 702 actually asks.

WHY IT MATTERSCredentials get an expert qualified. What gets an opinion admitted is the documentation of what was done in this matter.

Chain of custody

EVIDENCE HANDLING

ALSO: custody documentation · evidence log

The documented record of who held an item of evidence, when, and what was done to it, from seizure through analysis to production.

For digital evidence the chain runs alongside the hash: the custody form records the physical handling and the hash records that the content did not change. Each device is normally photographed and logged with make, model and serial at collection, and every transfer is signed. Gaps are not automatically fatal — courts generally treat them as going to weight rather than admissibility — but a gap invites the argument that the evidence is not what it is said to be, and that argument is cheap for the other side to make.

WHY IT MATTERSThe custody form becomes an exhibit. It is written at collection, when nobody is thinking about trial, and read at trial, when everybody is.

Clock drift

ARTIFACTS AND FILE SYSTEMS

ALSO: clock skew · system clock error

The difference between a device's clock and true time, whether from gradual hardware drift, a failed time sync, or a manual change to the clock.

Drift is measured, not assumed: the examiner records the machine's clock against a reference at acquisition and looks for evidence of past changes in time-service records and event logs. Where two devices are being correlated, even a few minutes of offset can reverse the apparent order of events, and order is usually the whole argument. A deliberate clock change is itself a finding.

WHY IT MATTERSAn uncorrected offset between two sources can make the wrong party appear to have acted first, and the correction is arithmetic that either was or was not done.

Code repository

TOOLS AND FORMATS

ALSO: repo · version control · Git repository · SCM

A version-controlled store of source code holding the full history of changes, who committed them, when, and against which branch.

A repository is often better evidence than the code itself, because it records the development history rather than only the end state. Clones carry that history with them, which is how copied code is sometimes traced. The identifying fields in a commit come from the committer's own configuration and are not authenticated by default, so authorship in a repository is a claim recorded by the tool rather than a verified fact.

WHY IT MATTERSGetting the repository rather than an export is the difference between examining how software came to exist and looking at a snapshot of it.

Commit history

TOOLS AND FORMATS

ALSO: revision history · git log · change history

The ordered record of changes in a version control system, each entry carrying an author, a timestamp, a message, and the exact content of the change.

It answers when code appeared, in what state, and alongside what else — which is central to independent-development defences and to dating the arrival of copied material. Its weaknesses are specific and worth stating: author fields and dates are supplied by the committing client and can be set to anything, history can be rewritten, and an import of an entire codebase can appear as a single commit that conceals everything before it. Corroboration comes from server-side records — push logs, code review systems, build servers.

WHY IT MATTERSA single initial commit containing a mature codebase is not evidence of anything on its own, and it is exactly the pattern that requires the server-side records to interpret.

Consulting expert

ROLES AND PROCEDURE

ALSO: non-testifying expert · consulting-only expert

An expert retained to assist counsel without testifying, whose facts known and opinions held are generally protected from discovery under Rule 26(b)(4)(D).

The protection is not absolute — it yields in exceptional circumstances where the same information cannot practicably be obtained by other means, which most often arises where the consulting expert examined something no longer available. Consulting engagement is the usual posture for early assessment, for testing a theory that may not survive, and for work a party may not want to disclose.

WHY IT MATTERSAn examiner who acquired the only image of a device that has since been wiped may not stay protected, however the engagement was labelled.

Custodian

ROLES AND PROCEDURE

ALSO: data custodian · document custodian

A person who holds or controls potentially relevant electronically stored information, and whose devices and accounts are within scope for preservation and collection.

The custodian list drives cost more than any other early decision, because each name adds devices, mailboxes, chat history and cloud storage. It also creates a systematic blind spot: material that belongs to no individual — shared drives, databases, application logs, service accounts — is not reached by a custodian-based collection at all, and has to be scoped separately.

WHY IT MATTERSServer-side records that decide insider-misconduct disputes frequently sit outside every custodian's footprint, so a purely custodian-driven collection never touches them.

D

Data loss prevention (DLP)

CLOUD AND NETWORK

ALSO: DLP · data leak prevention

Software that inspects data in email, uploads, or on endpoints against policy rules and blocks, quarantines, or logs transfers that match.

DLP alerts are among the most useful records in a data-theft matter because they are contemporaneous, name a file and a destination, and were generated by the company's own system without litigation in view. They are only as good as the policy: DLP sees what its rules were written to see, so an absence of alerts means the rules did not match, not that nothing left. Alert data also has its own retention window.

WHY IT MATTERSA DLP alert log is frequently the single best exhibit in a departing-employee case, and equally frequently nobody asks for it until the retention window has passed.

Daubert standard

LEGAL STANDARDS

ALSO: Daubert · Daubert test · Daubert challenge

The federal standard requiring a trial judge to act as gatekeeper and admit expert testimony only where it is both relevant and reliable.

It replaced general acceptance as the federal test and put the reliability question with the judge rather than the field. The factors usually recited — testability, peer review and publication, known or potential error rate, and general acceptance — are guides rather than a checklist, and a court may weigh whichever of them fit the discipline in front of it. Digital forensic testimony is squarely within it.

WHY IT MATTERSDigital forensic opinions are more often excluded for how the method was applied to these facts than for the method itself being unsound.

dd / raw image

TOOLS AND FORMATS

ALSO: raw image · dd image · flat image · bit stream image

An uncompressed sector-for-sector image file with no container structure, no embedded metadata, and no internal checksums.

Its virtue is universality: every tool reads a raw image, and its contents are exactly the bytes of the source. The costs are size — it occupies the full capacity of the source, empty space included — and the absence of any internal integrity check, so verification depends entirely on hash values recorded and kept separately. Acquisition notes for a raw image therefore have to travel with it or the verification story is incomplete.

WHY IT MATTERSIf the hash for a raw image lives only in an examiner's notes, losing the notes means losing the ability to show the image is unaltered.

Deepfake

TOOLS AND FORMATS

ALSO: synthetic media · AI-generated media · face swap

Audio, image or video content generated or altered by machine learning to depict a person saying or doing something they did not.

The litigation problem is asymmetric. Producing convincing synthetic media is cheap, and proving a specific file is synthetic is expensive and rarely certain from the content alone. Detection classifiers give a probability, degrade sharply on compressed or re-uploaded material, and are difficult to defend under a reliability challenge. Cases are more often resolved on where the file came from — device, account, server-side copy, chain of custody — than on analysis of the pixels.

WHY IT MATTERSThe mere availability of the technology has also produced the opposite problem: authentic recordings challenged as fabricated, which likewise turns on provenance.

Deleted file

ARTIFACTS AND FILE SYSTEMS

ALSO: file deletion · recovered file

A file whose directory entry has been removed and whose space is marked available, while its content usually remains until something overwrites it.

Deletion on a conventional filesystem is a bookkeeping change, not an erasure, which is why recovery so often works and why parties are surprised by it. The filesystem record frequently survives even when the content does not, so an examiner may be able to show that a file of a given name and size existed at a given path without being able to produce its contents. Deletion itself carries no intent: it is what a person does at the end of a project and also what they do the night before they resign.

WHY IT MATTERSThe forensic finding is that a file was deleted and when. Why it was deleted is an argument built from surrounding conduct, not a fact the artifact supplies.

Deposition

ROLES AND PROCEDURE

ALSO: depo · expert deposition · sworn testimony

Sworn out-of-court testimony taken on the record before trial, at which an expert's report, methods, materials and qualifications are examined.

For a forensic expert the deposition is where the documentation is tested: which tool and version, which settings, what was verified independently of the tool, what was not examined and why, and what the artifacts do not establish. Answers given here bind the expert at trial and supply the material for a reliability motion, so an undocumented step is more damaging in a deposition than in a report.

WHY IT MATTERSAlmost every successful exclusion motion is built from deposition testimony about how the work was actually done.

E

E01 / Ex01

TOOLS AND FORMATS

ALSO: E01 · Ex01 · EnCase evidence file · expert witness format · EWF

The EnCase forensic image formats, which store the acquired data in compressed segments together with case metadata and per-block checksums.

The embedded checksums make the container self-verifying: corruption in a segment is detectable rather than silent, which a raw image cannot offer. Ex01 is the later format, adding stronger compression and encryption support. Both are widely readable across forensic tools, so choosing one does not lock a party into a vendor — but an ESI protocol should still say which format images will be exchanged in.

WHY IT MATTERSSegment-level verification means a transfer error is found when the image is opened rather than argued about after the analysis is done.

EDR

CLOUD AND NETWORK

ALSO: endpoint detection and response · endpoint agent

Endpoint software that continuously records process, file and network activity on a device and reports it to a central console for detection and investigation.

Where an EDR agent was deployed, its telemetry can be far richer than anything the operating system retained — process ancestry, command lines, file writes, network connections. It is a security product, not an evidence archive: telemetry retention is a licensing and configuration matter, commonly short, and the console holds a processed view rather than a forensic image. Extracting it in a defensible, reproducible form is its own exercise.

WHY IT MATTERSAsking whether an EDR product was running on the custodian's machine, and how long its telemetry is kept, should come before deciding what can be proven.

EnCE

CREDENTIALS AND STANDARDS BODIES

ALSO: EnCase Certified Examiner

EnCase Certified Examiner, a certification demonstrating proficiency with the EnCase forensic suite and the analysis performed using it.

It is product-specific by design, which makes it directly relevant when the work was done in EnCase and less informative about method in the abstract. The strongest position for a testifying examiner is being able to describe the underlying artifact independently of the tool that parsed it, because a tool's output is only as good as the examiner's ability to verify it.

WHY IT MATTERSAn examiner who can only report what a tool displayed, and cannot explain the artifact behind it, is the profile Rule 702 challenges are built around.

Error level analysis (ELA)

TOOLS AND FORMATS

ALSO: ELA · error level analysis

A technique that re-compresses a JPEG and visualises the differences, on the theory that edited regions will show a different compression signature.

It is popular because it is free and produces a striking picture, and it is unreliable as a basis for a conclusion. Ordinary operations — resaving, resizing, platform re-encoding — produce the same patterns as editing, and reading the output is subjective with no established error rate. It may occasionally suggest where to look. An opinion that a file was manipulated resting on ELA is a soft target under a reliability challenge.

WHY IT MATTERSWhere an opposing expert's manipulation finding rests on ELA, the reliability attack largely writes itself.

ESI protocol

ROLES AND PROCEDURE

ALSO: ESI order · e-discovery protocol · Rule 26(f) protocol

The parties' agreement or court order setting out how electronically stored information will be preserved, collected, processed and produced in a matter.

It settles the questions that decide, months before any examination, whether forensic questions can be answered: forms of production and which metadata fields travel with them, hash algorithm and load-file structure, whether collection is targeted or full-disk, custodian and source scope including collaboration platforms and version history, preservation of unallocated space, and search-term validation. Terms conceded here are effectively unrecoverable later.

WHY IT MATTERSThis is the document a forensic examiner should read before it is signed rather than after, because most of what an examination can establish was decided in it.

Exfiltration

CLOUD AND NETWORK

ALSO: data exfiltration · data theft · data egress

The unauthorised movement of data out of an organisation, whether to removable media, personal cloud storage, webmail, or an external network destination.

No single artifact records exfiltration. It is assembled: device connection history, shortcut and browsing records, personal-account webmail and sync-client activity, network egress volume, and cloud sharing events, each of which records a fragment. Access, copying, and data actually leaving are three separate findings supported by three different sources, and the failure mode in expert reports is collapsing them into one.

WHY IT MATTERSThe strength of an exfiltration case is usually the convergence of independent artifacts, not the strength of any one of them.

EXIF

ARTIFACTS AND FILE SYSTEMS

ALSO: EXIF data · photo metadata · Exchangeable Image File Format

Metadata embedded in photographs and some video by the capturing device — camera make and model, settings, date and time, and often GPS coordinates.

EXIF is powerful when it survives and absent far more often than litigants expect, because messaging apps and social platforms strip it on upload and re-encoding discards it. It is also editable with free tools, so an EXIF date is a claim by whoever last wrote the file rather than an observation. Corroboration comes from the same image held somewhere the editor could not reach, or from provenance records outside the file.

WHY IT MATTERSA photograph produced without EXIF is not suspicious on its own — the platform it travelled through probably removed it — and treating the absence as evidence of tampering is an error in both directions.

Expert report

ROLES AND PROCEDURE

ALSO: forensic report · Rule 26 report · written report

The written statement of an expert's opinions and their bases, which in federal court must satisfy Rule 26(a)(2)(B) for a retained testifying expert.

A defensible forensic report ties every assertion to a specific artifact, names the tool and version that parsed it, records the acquisition and verification, and states what the findings do not establish alongside what they do. Not every matter needs the full report: a declaration or affidavit is the right instrument on a preliminary injunction or a spoliation motion, and arbitration follows the tribunal's directions.

WHY IT MATTERSThe report is the document an opposing expert works from, so anything it leaves undocumented becomes the subject of the deposition.

F

File carving

ARTIFACTS AND FILE SYSTEMS

ALSO: carving · data carving · signature carving

Recovering files from unallocated space by their content signatures rather than their filesystem records, used when the directory entry is gone.

Carving finds the data and loses the bookkeeping. A carved file typically arrives with no filename, no path, and no timestamps, because those lived in the filesystem structure that deletion removed. Fragmented files carve badly and may be recovered only in part. So a carved document can prove content existed on the volume, and it usually cannot show where it sat, when it was written, or which user account put it there without a second artifact tying it down.

WHY IT MATTERSRecovery of a document is not recovery of its history, and an opinion that treats a carved file as though it came with a path and a date is one question away from collapsing.

File slack

ARTIFACTS AND FILE SYSTEMS

ALSO: slack space · residual data

The unused space between the end of a file and the end of the last cluster allocated to it, which can still hold fragments of whatever was there before.

Storage is allocated in clusters, so a file that does not fill its final cluster leaves a remainder that the filesystem ignores and does not clear. Fragments recovered from slack are genuine evidence that data once existed on the volume, and they are usually partial, undated, and unattributable to a user action. Slack is captured by a physical image and lost entirely by a logical copy.

WHY IT MATTERSA fragment in slack can show that a document existed on a machine after every copy of it was deleted, which is sometimes the only surviving proof of possession.

FILETIME

ARTIFACTS AND FILE SYSTEMS

ALSO: Windows FILETIME · Windows 64-bit time

The Windows time format counting 100-nanosecond intervals since 1 January 1601 UTC, used throughout NTFS, the registry, and Windows artifacts.

Its precision is finer than any of the events it records, which is occasionally diagnostic: filesystem timestamps written by ordinary Windows activity carry sub-second detail, and values that are suspiciously round in the low digits can indicate a value that was set rather than observed. Like Unix epoch time it is UTC at the source, and any local time on a report is the tool's rendering.

WHY IT MATTERSSub-second structure is one of the tells that separates a timestamp Windows wrote from one a utility supplied.

Forensic image

EVIDENCE HANDLING

ALSO: forensic copy · disk image · evidence image · acquisition

A verified copy of a storage device that reproduces every sector, including deleted and unallocated areas, not just the files a user can see.

The image is what analysis is performed on; the original device is preserved untouched. Because it captures the whole device rather than the live file set, it preserves the material that ordinary copying discards — unallocated space, file slack, journals, registry hives, shadow copies. A logical copy of the same machine gathers the documents and loses almost everything that answers a question about conduct.

WHY IT MATTERSWhether the collection was a full image or a targeted logical copy determines, months before anyone examines anything, which questions can be answered at all.

Forensic neutral

ROLES AND PROCEDURE

ALSO: neutral examiner · court-appointed examiner · joint expert

An examiner engaged by agreement of the parties or appointed by the court to examine evidence for all sides rather than for one.

Neutral examination is common where a party resists handing its devices to an opponent's expert: the neutral images the device, runs an agreed protocol, and reports to everyone, often with a privilege-review step before anything reaches the requesting party. The value is that findings arrive without the appearance of advocacy. The constraint is the protocol, which is agreed in advance and narrows what the neutral may look at.

WHY IT MATTERSA neutral protocol drafted before anyone understands the data can foreclose the examination that would have answered the question.

FRCP 37(e)

LEGAL STANDARDS

ALSO: Rule 37(e) · spoliation sanctions rule

The federal rule governing lost electronically stored information, setting out what a court may do when ESI that should have been preserved cannot be restored or replaced.

The rule works through findings. Curative measures no greater than necessary require prejudice from the loss; the severe measures — an adverse-inference instruction, dismissal, default — require a finding that the party acted with intent to deprive another party of the information. That intent finding is where forensic evidence carries the weight, because conduct such as running a wiping utility or resetting a device speaks to it in a way that ordinary deletion does not.

WHY IT MATTERSThe forensic record establishes what happened to the data. Intent is a finding the court makes from that record, and the two should never be blurred in a report.

FRE 702

LEGAL STANDARDS

ALSO: Rule 702 · Federal Rule of Evidence 702

The federal rule governing expert testimony, requiring the proponent to show it is more likely than not that the opinion meets each reliability requirement.

As amended effective December 1, 2023, the rule makes the proponent's burden explicit and requires that the opinion reflect a reliable application of the method to the facts of the case, not merely the use of a recognised method. For a forensic examiner that shifts attention from whether hashing and imaging are accepted — they are — to whether this examination was documented, verified and reproducible.

WHY IT MATTERSStating conclusions in calibrated terms is not hedging under the amended rule; it is what the rule asks the proponent to be able to demonstrate.

FRE 901

LEGAL STANDARDS

ALSO: Rule 901 · authentication

The federal rule requiring a proponent to produce evidence sufficient to support a finding that an item is what the proponent claims it is.

The bar is a prima facie showing, not proof — the ultimate question of authenticity goes to the jury. For digital evidence the showing usually comes from a witness with knowledge, distinctive characteristics of the item, or the process that produced it. Rule 901(b)(9) covers evidence describing a process or system and showing it produces an accurate result, which is the provision a forensic acquisition speaks to.

WHY IT MATTERSScreenshots of messages fail here more often than any other form of digital evidence, because nothing about a screenshot describes the process that produced it.

FRE 902(13)

LEGAL STANDARDS

ALSO: Rule 902(13) · self-authenticating machine records

A rule allowing a record generated by an electronic process or system to be self-authenticating on a qualified person's certification, without live testimony.

It removes the need to call a witness merely to authenticate machine-generated records, provided the certification meets the rule's requirements and notice is given so the opponent can object. It authenticates; it does not make the record admissible over hearsay or relevance objections, and it does not vouch for what the record means. The certification has to come from someone qualified to make it.

WHY IT MATTERSUsing the certification route removes a witness from the trial plan, which is why the notice requirement is the part that gets missed.

FRE 902(14)

LEGAL STANDARDS

ALSO: Rule 902(14) · hash certification

A rule allowing data copied from an electronic device or file to be self-authenticating where a qualified person certifies it by hash or other reliable digital identification.

This is the provision that makes hash verification do evidentiary work directly: the certification establishes that the copy is the same as the original, so the copy can be authenticated without the examiner appearing. Notice must be given, and the opponent gets the opportunity to challenge. It reaches authenticity of the copy only — every question about what the data shows remains open.

WHY IT MATTERSIt is why the hash values recorded at acquisition, months before anyone contemplated trial, turn out to be the thing that gets the image in.

Frye standard

LEGAL STANDARDS

ALSO: Frye · general acceptance test

The older admissibility test asking whether a scientific technique has gained general acceptance in its field, still applied in some state courts.

Frye asks about the field's view of the method; Daubert asks the judge to assess reliability directly, including how the method was applied. For digital forensics the difference is practical: imaging and hashing are generally accepted, so a Frye jurisdiction may present a lower barrier to the technique while the application questions get resolved as weight. Which test governs is a question of the forum.

WHY IT MATTERSAn expert who has only ever been qualified under one standard has not been tested by the other, and the difference shows.

G

GCFA

CREDENTIALS AND STANDARDS BODIES

ALSO: GIAC Certified Forensic Analyst

GIAC Certified Forensic Analyst, a certification from Global Information Assurance Certification covering forensic analysis and incident response.

It sits in the GIAC family associated with SANS training and is oriented toward host-based forensic analysis and intrusion investigation. Like every certification it is periodically renewed, so currency is a fair question. It says nothing about testimony experience, which is a separate qualification and the one that matters at deposition.

WHY IT MATTERSTechnical certifications and courtroom experience are independent, and an expert strong in one may have none of the other.

git blame

TOOLS AND FORMATS

ALSO: blame · line annotation · annotate

A command that attributes each line of a file to the commit that last changed it, together with that commit's author and date.

It is the quickest way to ask who last touched a specific passage, and it answers a narrower question than it appears to. Blame attributes the most recent change to a line, so a whitespace pass, a reformat, or a bulk rename reassigns lines wholesale to whoever ran it. Following authorship through those events requires deliberate work, and blame output taken at face value will regularly name the wrong person.

WHY IT MATTERSBlame output offered as proof of who wrote a passage is one automated reformat away from being wrong, and the reformat is in the history for anyone who checks.

GREM

CREDENTIALS AND STANDARDS BODIES

ALSO: GIAC Reverse Engineering Malware

GIAC Reverse Engineering Malware, a certification from Global Information Assurance Certification covering the analysis of malicious software.

It is a specialist credential, relevant where the dispute turns on what a program actually did — a ransomware sample, an exfiltration utility, allegedly malicious code in a contract dispute. It is not a general digital forensics certification and should not be offered as one.

WHY IT MATTERSMatching the credential to the question is part of vetting; a malware analyst and a filesystem examiner are not interchangeable.

H

Hash collision

EVIDENCE HANDLING

ALSO: collision attack

Two different inputs producing the same hash value, which is possible for every hash function and practically constructible only for weak ones such as MD5.

Collisions are unavoidable in principle because a fixed-length output cannot uniquely encode inputs of unbounded length. What matters is whether anyone can produce one on demand. For MD5 they can, given control of both files; for SHA-256 there is no known practical method. Neither fact bears on the ordinary forensic use of a hash, which is to detect whether a copy differs from its source — a scenario with no adversary choosing both sides of the comparison.

WHY IT MATTERSThis is the most common misuse of a real cryptographic result in a digital-evidence dispute: a genuine weakness in MD5 offered as though it undermined an image verification it has nothing to do with.

Hash value

EVIDENCE HANDLING

ALSO: hash · digital fingerprint · message digest · checksum

A fixed-length value computed from a file or drive that changes if any bit of the input changes, used to show a copy matches its source.

A hash is computed over the source at acquisition and again over the image at verification; the two values matching is what lets an examiner say the copy is the evidence. It is also how identical files are identified across a production without comparing them byte by byte. What a hash does not carry is any information about where a file came from, when it arrived, or who put it there — matching hashes establish identical content and nothing else.

WHY IT MATTERSA hash match between a departing employee's drive and the company's files proves the content is the same, not that it was copied, or by whom. Opposing counsel will make that distinction if you do not.

I

Indicator of compromise (IOC)

CLOUD AND NETWORK

ALSO: IOC · indicator · IoC

An observable artifact associated with an intrusion — a file hash, a domain, an address, a registry key — used to search an environment for related activity.

Indicators are how a known incident is scoped across systems, and they are a searching tool rather than a conclusion. A hit means the indicator was present, which may reflect the same actor, a shared commodity tool, or a false positive on something benign; a clean sweep means the indicators searched for were not found, not that the environment is clean. Attribution built on indicator overlap alone is weak.

WHY IT MATTERSIndicator hits are frequently presented as identifying who was responsible, when what they establish is that something matching a published pattern was there.

IP address

CLOUD AND NETWORK

ALSO: internet protocol address · source address

A network address identifying an interface on a network, which does not identify a device or a person and often does not identify a location.

Residential addresses are reassigned, corporate networks translate many internal devices to one external address, mobile carriers share addresses across many subscribers, and VPN or proxy services stand between the address and the user entirely. Geolocation databases return the registrant's or provider's location, not the user's. An address plus a timestamp plus a provider's own records can sometimes reach a subscriber account — which is still an account, not a person.

WHY IT MATTERSAttribution from an address is a chain of inferences, each of which can be attacked separately, and reports that state it as a single fact invite exactly that.

Ipse dixit

LEGAL STANDARDS

ALSO: ipse dixit of the expert · analytical gap

An assertion resting on the expert's say-so alone, which a court need not admit where too great an analytical gap separates the data from the opinion.

In digital forensics the gap almost always appears at the inference rather than the acquisition: the artifacts are documented, and the conclusion drawn from them travels further than they reach. An opinion that a device was connected and that files were therefore copied is the archetype. The repair is not more confidence; it is stating the finding the artifact supports and identifying what would be needed to close the remaining distance.

WHY IT MATTERSThis is the phrase in an exclusion motion that signals the challenge is aimed at the reasoning, which is where forensic opinions are most often vulnerable.

ISFCE

CREDENTIALS AND STANDARDS BODIES

ALSO: International Society of Forensic Computer Examiners

The International Society of Forensic Computer Examiners, the body that issues the Certified Computer Examiner (CCE) certification.

It is a certifying body rather than a standards organisation: it defines the requirements for its certification, administers the examination, and maintains a code of ethics for holders. It does not publish forensic method standards, which is the role that SWGDE and NIST occupy.

WHY IT MATTERSKnowing which body issues which credential prevents the common error of describing a certification as a standard, or its issuer as an accreditation body.

ISO/IEC 17025

CREDENTIALS AND STANDARDS BODIES

ALSO: 17025 · laboratory accreditation

The international standard for the competence of testing and calibration laboratories, under which some digital forensic laboratories are accredited.

Accreditation covers the laboratory's management system — documented procedures, competence records, equipment control, method validation — for a defined scope of testing. It attaches to an organisation, not to an individual, and it is not required in order to testify. It is common in public crime laboratories and much less common among private digital forensic practices, so its absence is unremarkable while its presence is worth understanding the scope of.

WHY IT MATTERSAccreditation to a defined scope says nothing about work outside that scope, so the question to ask is what the accreditation actually covers.

J

Journaling

ARTIFACTS AND FILE SYSTEMS

ALSO: journaled filesystem · write-ahead log

A filesystem technique of recording intended changes before making them, so an interrupted write can be completed or rolled back after a crash.

Journaling is a reliability feature that produces a forensic side effect: a short-lived record of recent activity that nobody designed as an audit trail and nobody configured to be retained. NTFS, ext3 and ext4, and APFS all journal in some form, with different content and different windows. Because the purpose is recovery, journals are sized for that purpose and recycle aggressively.

WHY IT MATTERSEvery journal-derived finding carries an implicit retention caveat, and an expert who states one without it has claimed a history the artifact never kept.

Jumplist

ARTIFACTS AND FILE SYSTEMS

ALSO: jump list · AutomaticDestinations · CustomDestinations

Per-application Windows records of recently and frequently used files, storing shortcut data for each entry and associating it with the program that opened it.

A jumplist adds the application dimension that a bare shortcut lacks: not just that a path was opened, but through what. Automatic lists are maintained by Windows and hold a bounded number of entries per application, so older activity falls off; custom lists are written by the application itself and vary in what they keep. Like LNK records, they show a path being opened through the shell and do not distinguish opening from copying.

WHY IT MATTERSBecause the lists are capped, an absence in a jumplist is weak evidence of anything, and an argument built on absence needs a source that was actually retaining the period in question.

K

Kumho Tire

LEGAL STANDARDS

ALSO: Kumho Tire Co. v. Carmichael · Kumho

The decision extending the trial judge's gatekeeping duty beyond scientific testimony to technical and other specialized knowledge.

It settles the threshold objection an examiner occasionally raises — that digital forensics is a technical craft rather than a laboratory science and so falls outside Daubert. It does not. The Court also gave trial courts broad latitude in deciding how to test reliability, which is why the factors applied to a forensic examiner look different from those applied to a toxicologist while the gate is the same gate.

WHY IT MATTERSThere is no category of technical expertise that escapes the reliability screen by not being science.

L

L01

TOOLS AND FORMATS

ALSO: logical evidence file · LEF · Lx01

An EnCase logical evidence file containing selected files and their metadata rather than a full physical image of a device.

It is the right container when only part of a device is being collected — a custodian's user profile under a targeted-collection agreement, or the subset a protective order permits. What it does not carry is everything outside the selected files: no unallocated space, no slack, no journals. An L01 is a defensible collection of what it contains and silent about what it does not.

WHY IT MATTERSReceiving an L01 where the protocol contemplated a physical image means the deleted-file questions were foreclosed at collection, not at analysis.

Lateral movement

CLOUD AND NETWORK

ALSO: pivoting · east-west movement

Moving from one compromised or accessed system to others inside the same environment, typically using credentials or trust relationships already present.

Reconstructing it means correlating records across many hosts — authentication events, remote session records, service creation, administrative tool use — and that correlation is only sound once the clocks and time zones of all the sources have been reconciled. Because it uses legitimate credentials and administrative tools, lateral movement often looks exactly like ordinary administration until the pattern is assembled.

WHY IT MATTERSThe scope of a compromise, and therefore the scope of any notification or damages argument, turns on how far the movement reached and on which logs survived to show it.

Litigation hold

LEGAL STANDARDS

ALSO: legal hold · hold notice · preservation obligation

A party's suspension of routine deletion and instruction to custodians to preserve relevant material once litigation is reasonably anticipated.

Issuing the notice is the visible half. The half that determines outcomes is technical: suspending automatic mailbox and message expiry, stopping device refresh and reimaging for the custodians named, and preserving system-side logs whose retention windows are measured in days. A hold that reaches documents while a chat platform keeps deleting messages on a thirty-day cycle has not preserved the evidence.

WHY IT MATTERSThe interval between the duty attaching and the technical suspension actually taking effect is where the recoverable evidence in most spoliation disputes disappeared.

LNK file

ARTIFACTS AND FILE SYSTEMS

ALSO: shortcut file · link file · Windows shortcut

A Windows shortcut file, created automatically when a document is opened, that embeds the target path, its size, timestamps, and the volume serial number.

The embedded volume serial number is what makes LNK files valuable: it ties a file that was opened to a specific piece of media, which shellbags cannot do. The record persists after the target file and its drive are gone. What an LNK does not distinguish is opening from copying, and its absence does not show a file was never accessed — automatic shortcut creation can be disabled, and the recent-items store holds a limited number of entries and discards the rest.

WHY IT MATTERSAn LNK pointing at a document on an external volume places that volume on the machine with that file on it — which is often the strongest single artifact in a departing-employee matter, and still not proof of a copy.

Load file

TOOLS AND FORMATS

ALSO: DAT file · OPT file · production load file

A delimited file accompanying a document production that carries the metadata fields and image or text file paths a review platform needs to load it.

The load file is where the metadata negotiated in the ESI protocol actually arrives, or fails to. Which fields it carries, how multi-value fields are delimited, how parent-child family relationships are expressed, and how dates are formatted all determine whether the production is usable on receipt. Load-file defects are common, mechanical, and fixable — but only if they are found before the review is built on top of them.

WHY IT MATTERSA production whose load file omits an agreed field has not complied with the protocol, and that is a much easier motion than one about substance.

Log retention

CLOUD AND NETWORK

ALSO: retention period · log rollover · retention policy

How long a system keeps its log records before deleting or overwriting them, which is a configuration choice and frequently measured in days or weeks.

Retention decides more digital-evidence disputes than analysis does. VPN concentrators, firewalls, endpoint tools and cloud audit logs all age out on schedules set for operational reasons long before any dispute, and once a record rolls over no order brings it back. This is also why absence of a log entry is weak evidence that an event did not occur: the question is always whether the system was retaining that period at all.

WHY IT MATTERSThe first substantive question in a matter involving system logs is what the retention windows are, because it sets the deadline for everything else.

M

MACB times

ARTIFACTS AND FILE SYSTEMS

ALSO: MAC times · modified accessed created · MACE times

The four filesystem timestamps commonly abbreviated as modified, accessed, changed (metadata change) and born (created), whose meaning varies between filesystems.

The letters do not mean the same thing everywhere. NTFS, APFS and ext4 differ in what updates each value and when, and NTFS keeps a second copy of all four in the $FILE_NAME attribute that ordinary tools do not update. Access-time updating is commonly limited or disabled for performance, so a stale access time may mean nothing was opened or may mean the system stopped recording it.

WHY IT MATTERSAn opinion that reads a MACB set without saying which filesystem produced it, and how that filesystem behaves, has skipped the step the other side will start with.

Master File Table ($MFT)

ARTIFACTS AND FILE SYSTEMS

ALSO: $MFT · MFT · master file table

The NTFS index holding a record for every file and directory on the volume, including name, size, location, and two independent sets of timestamps.

Each record carries timestamps in a $STANDARD_INFORMATION attribute and again in $FILE_NAME, written by different code paths. A discrepancy between the two sets is the classic signature of timestamp manipulation, because the common tools rewrite one and not the other. MFT records for deleted files often persist after the content is gone, so the table can establish that a file existed at a path and size when nothing else on the volume can.

WHY IT MATTERSThe $MFT is where a timeline usually starts and where the first serious attack on a timeline usually lands.

MD5

EVIDENCE HANDLING

ALSO: MD5 hash · message digest 5

A 128-bit hash algorithm, long used to verify forensic images, that is broken for adversarial use but still reliable for detecting accidental change.

MD5 is not collision-resistant: an attacker who controls both inputs can construct two different files with the same MD5. That defeats MD5 as a signature but does not defeat it as a verification check, because nobody is crafting a collision against a drive image mid-acquisition. Standard practice is to record MD5 alongside SHA-256 so the older value stays comparable with legacy tooling and productions while the stronger value carries the argument.

WHY IT MATTERSAn opposing expert who says MD5 verification is worthless because MD5 is broken has conflated collision resistance with error detection. The answer is on the record already: both values were computed, and they both match.

Metadata

ARTIFACTS AND FILE SYSTEMS

ALSO: data about data

Data describing a file rather than its content — timestamps, authorship, paths, revision counts — recorded in several independent places that can disagree.

Treating metadata as a single thing is the most common error in an ESI negotiation. Filesystem metadata is kept by the operating system, application metadata is kept inside the document, and platform metadata is kept by a mail or collaboration server, and the three are written by different software at different moments. When they disagree, the disagreement is itself evidence. When a production strips one of them, no amount of later argument brings it back.

WHY IT MATTERSWhich metadata fields travel with a production is decided in the ESI protocol, usually before anyone knows which field will matter.

Motion in limine

ROLES AND PROCEDURE

ALSO: in limine motion · motion to exclude

A pretrial motion asking the court to rule evidence or testimony inadmissible before it is offered in front of the jury.

Challenges to expert testimony commonly arrive this way, and the deadline is set by the scheduling order rather than by any rule of evidence. A motion aimed at part of an opinion — conceding a clean acquisition and attacking the inference drawn from it — reads as credible and courts trim opinions more readily than they strike experts. A motion attacking everything invites the court to treat the whole filing as argument about weight.

WHY IT MATTERSNarrowing an expert is usually more achievable than excluding one, and often just as useful.

N

Native format

TOOLS AND FORMATS

ALSO: native production · native files

Production of a document as the file the application created, preserving formulas, tracked changes, embedded metadata, and the ability to examine it forensically.

A spreadsheet produced as an image loses its formulas, a presentation loses its speaker notes, and every document loses its internal metadata. For any question about how a document was made or when, native production is not a preference but a precondition. Producing parties resist it because native files are harder to redact and cannot carry a stamp on their face, which is why the compromise usually pairs native files with a separate Bates-numbered placeholder.

WHY IT MATTERSAlmost every document-authenticity question in a matter depends on whether native files were produced, and that is settled in the ESI protocol before the questions are known.

NIST CFTT

CREDENTIALS AND STANDARDS BODIES

ALSO: Computer Forensics Tool Testing · CFTT

The Computer Forensic Tool Testing project at the National Institute of Standards and Technology, which publishes test methodologies and results for forensic tools.

CFTT tests specific tool functions — imaging, write blocking, deleted file recovery — against published specifications and reports how a named version performed. That gives a court something concrete on the reliability of a tool, which is otherwise a matter of assertion. It covers the tool, not the examiner: a validated imager in untrained hands produces an unreliable acquisition, and the reliability inquiry under Rule 702 reaches the application as well as the method.

WHY IT MATTERSIndependent tool validation converts one Daubert factor from argument into a citation, which is why the tool and version used belong in the report.

NTFS transaction log ($LogFile)

ARTIFACTS AND FILE SYSTEMS

ALSO: $LogFile · LogFile · NTFS journal

The NTFS metadata transaction log used to keep the filesystem consistent after a crash, which incidentally records recent filesystem operations in detail.

It exists for recovery, not for evidence, and that shapes what it is good for. The detail is finer than the change journal — individual metadata transactions rather than summarised file events — and the window is much shorter, often hours on an active system, because the log is a small fixed-size circular buffer. Where the timing lines up it can corroborate or contradict a $MFT timestamp independently, which is exactly what a contested timeline needs.

WHY IT MATTERSIt is the shortest-lived of the NTFS records, so it is only ever available when preservation happened quickly.

P

Prefetch

ARTIFACTS AND FILE SYSTEMS

ALSO: Prefetch files · .pf files

Windows files created to speed up program launches, which record that an executable ran, a run count, and recent run times.

Prefetch is the strongest ordinary support for an execution inference on Windows, which is why it matters when a wiping utility or an archiving tool is in issue. It is not universally available: it is commonly disabled on servers and can be switched off elsewhere, the store holds a limited number of entries, and only a bounded set of recent run times is kept per program. Absence of a prefetch entry therefore proves nothing about whether a program ran.

WHY IT MATTERSAmCache and ShimCache are frequently offered as proof of execution. Prefetch is the artifact that actually supports it, and even then it supports execution — not what the program did.

Preservation letter

LEGAL STANDARDS

ALSO: preservation demand · spoliation letter · preservation notice

A letter to an opposing party identifying the material to be preserved and putting them on notice that failing to preserve it may carry consequences.

Its practical value depends on specificity. A letter naming devices, systems, accounts, log sources and retention settings tells the recipient what to suspend and later shows the court exactly what they were told; a generic demand to preserve all relevant documents does neither. Where system logs with short retention are at issue, the letter is only useful if it arrives inside that window.

WHY IT MATTERSThe letter becomes the exhibit establishing what the other side knew and when, which is why it is drafted with the eventual motion in mind.

Privilege escalation

CLOUD AND NETWORK

ALSO: escalation of privilege · admin escalation

Gaining rights beyond those assigned to an account, whether by exploiting a flaw or by using credentials and group memberships obtained along the way.

It matters in litigation because it changes what the record can be trusted to say. An account with administrative rights can clear logs, change auditing, alter timestamps and impersonate other users, so evidence generated after an escalation carries a caveat that evidence before it does not. Group membership changes and administrative-action logs are usually where an escalation becomes visible.

WHY IT MATTERSOnce an actor holds administrative rights, the absence of evidence on that system stops being informative.

Privilege log

ROLES AND PROCEDURE

ALSO: privilege index · withholding log

A list of documents withheld or redacted on privilege grounds, describing each entry in enough detail for the other side to assess the claim.

Metadata does most of the work: dates, participants, subject lines and document types come from the same extracted fields that drive the production, which is why log quality tracks processing quality. Two recurring problems have forensic consequences — an entry whose description does not match the document behind it, and a gap in a Bates range that no log entry accounts for.

WHY IT MATTERSA Bates gap with no corresponding log entry is either a withheld document nobody logged or a production error, and both are worth resolving early.

Protective order

LEGAL STANDARDS

ALSO: confidentiality order · stipulated protective order

A court order controlling how confidential material produced in discovery may be handled, who may see it, and what happens to it at the end of the case.

For forensic work the order is operational, not background: it sets the designation tiers, whether an expert must be disclosed and cleared before access, where source code or trade-secret material may be examined, whether notes may leave the room, and how printing is limited. Those terms determine how many hours an examination takes. They are negotiated before the evidence is understood, and they are difficult to revisit afterwards.

WHY IT MATTERSA review-environment clause agreed without an examiner's input routinely produces a review that costs several times what it needed to.

Provenance

EVIDENCE HANDLING

ALSO: origin metadata · content provenance

The recorded history of where a file came from and what was done to it, as opposed to inferences drawn from the content of the file itself.

In media authentication, provenance evidence — a signed capture record, a chain of custody from the device that made the file, server-side copies that predate the dispute — is generally stronger than the output of a detection classifier, because it can be tested and reproduced rather than believed. The weakness of provenance is that it is easy to strip: re-encoding, uploading to a platform, or forwarding a file usually removes it, and its absence therefore proves nothing about authenticity.

WHY IT MATTERSA challenge to a photograph or recording is usually won on where the file has been, not on what a detector says about its pixels.

R

Ransomware

CLOUD AND NETWORK

ALSO: encryption attack · extortion malware

Malicious software that encrypts data and demands payment, now commonly paired with prior theft of the data and a threat to publish it.

The litigation questions that follow are usually about the theft rather than the encryption: what was taken, whose it was, and when. Answering that is hard precisely because the encryption event destroys or obscures the local evidence, so the analysis often depends on network egress records, backups, and telemetry that survived off the affected machines. The scope of exposure and the scope of the encryption are different findings.

WHY IT MATTERSNotification obligations and damages arguments turn on what left the environment, which is a separate question from what stopped working.

RDP

CLOUD AND NETWORK

ALSO: Remote Desktop Protocol · remote desktop

The Windows protocol for interactive remote sessions, which leaves records on both the connecting and the receiving machine.

RDP sessions generate event log entries identifying the account, the source address and the session times, and leave client-side artifacts on the originating machine including connection histories and cached elements. Because the session is interactive, activity within it appears on the target as ordinary user activity — so an examination that only looks at the target may attribute work to a machine rather than to the remote operator who was driving it.

WHY IT MATTERSWhere remote access is in play, both ends of the connection are evidence, and preserving only one of them loses half the record.

Redaction

ROLES AND PROCEDURE

ALSO: redacted production · masking

Removing privileged or protected content from a document before production, which must remove the underlying data rather than merely obscuring it visually.

Failed redactions are a recurring and entirely technical failure: a black box drawn over text in a PDF that leaves the text layer intact and extractable, an image cropped in a way the file still records, or a spreadsheet with hidden rows and columns rather than deleted ones. Native files are hard to redact for exactly this reason, which is why redacted material is usually produced as images.

WHY IT MATTERSA redaction that can be undone by copying and pasting has disclosed the material and created a waiver argument at the same time.

Registry hive

ARTIFACTS AND FILE SYSTEMS

ALSO: Windows registry · SYSTEM hive · NTUSER.DAT · USRCLASS.DAT

A file holding part of the Windows registry — SYSTEM, SOFTWARE, SAM, NTUSER.DAT and USRCLASS.DAT — storing configuration and per-user activity records.

Most of the Windows artifacts a litigator hears named live inside a hive: USB device history in SYSTEM, shellbags in USRCLASS.DAT, UserAssist and typed paths in NTUSER.DAT, AmCache in its own hive file. Registry keys carry a last-written time for the key, not for each value in it, which is a limit examiners have to respect. A key that holds three timestamps per device holds three, however many times the device was actually connected.

WHY IT MATTERSBuilding a frequency argument on a registry key that keeps a fixed number of values is claiming a history the artifact never retained.

Rule 26(a)(2)(B)

LEGAL STANDARDS

ALSO: FRCP 26(a)(2)(B) · expert disclosure · Rule 26 report

The federal rule prescribing the written report a retained testifying expert must disclose, and what that report is required to contain.

The rule is specific: a complete statement of all opinions and the basis and reasons for them, the facts or data considered, any exhibits used to summarise or support them, the witness's qualifications including publications from the previous ten years, a list of other cases in which the witness testified as an expert at trial or by deposition in the previous four years, and a statement of the compensation. Omissions are a disclosure problem before they are ever a reliability problem.

WHY IT MATTERSExperts are excluded for defective disclosure without any court ever reaching the merits of the opinion.

S

SANS / GIAC

CREDENTIALS AND STANDARDS BODIES

ALSO: SANS Institute · GIAC · Global Information Assurance Certification

SANS is an information security training organisation; GIAC is the associated certification body that issues credentials including GCFA and GREM.

The distinction matters in a CV: SANS courses are training, GIAC certifications are examinations, and listing attendance as though it were certification is the kind of imprecision that gets found on cross-examination. Neither is an accreditation of a laboratory, which is a different thing again.

WHY IT MATTERSEvery line of an expert's CV is fair game at deposition, and an overstated credential damages the opinion far more than the missing credential would have.

Secure wipe

EVIDENCE HANDLING

ALSO: data wiping · disk wiping · shredding · sanitization

Overwriting storage so the previous content cannot be recovered, as distinct from deletion, which normally only unlinks the file and leaves the data in place.

Wiping generally works on content. What it does not remove is the evidence that it happened: installer and registry records for the wiping tool, prefetch entries showing execution, a change journal full of deletions clustered at one moment, and a conspicuously clean region on a machine whose neighbours are full of recoverable fragments. Those traces are frequently more probative than the wiped files would have been. They also do not, on their own, establish what was destroyed or why.

WHY IT MATTERSUnder Rule 37(e) the court is asked about loss, reasonable steps, and intent — and wiping-tool traces speak to the last of those in a way that ordinary deletion does not.

SHA-256

EVIDENCE HANDLING

ALSO: SHA-2 · SHA256

A 256-bit hash algorithm from the SHA-2 family, with no known practical collision attack, now the default for forensic verification and productions.

SHA-256 is what an examiner reaches for when the hash has to survive an argument rather than merely catch a read error. It is slower than MD5 and the difference is irrelevant at the scale of a single drive image. Most acquisition tools compute both in one pass, and an ESI protocol that specifies a hash field should say which algorithm, because two productions hashed differently cannot be de-duplicated against each other.

WHY IT MATTERSAgreeing the hash algorithm in the ESI protocol costs one clause. Discovering after production that two parties hashed with different algorithms costs a re-production.

Shellbag

ARTIFACTS AND FILE SYSTEMS

ALSO: shellbags · BagMRU · shell bags

Registry entries recording folders a user browsed in Windows Explorer, including the view settings, and persisting after the folder or its media is gone.

Shellbags survive the disappearance of what they describe, so they can show that a user browsed a folder tree on a device that was never produced and no longer exists. What they record is browsing through the shell — not opening a file, not copying anything. They also carry no volume serial number, so a shellbag alone cannot tie a folder tree to one specific physical drive; that link needs an LNK file or a device history record to close it.

WHY IT MATTERSShellbags are routinely offered as proof that a user copied files from a USB drive. They show the user looked at folders, which is a different finding and one an opposing expert will insist on.

ShimCache

ARTIFACTS AND FILE SYSTEMS

ALSO: AppCompatCache · application compatibility cache

A Windows registry cache of executable paths and file metadata that the system queried for compatibility purposes, holding a bounded number of entries.

ShimCache records that the operating system looked at a binary's metadata, which usually means the file was present and was at least examined. Entries are written to the registry when the system shuts down, so a machine that has not been rebooted may not have the entries an examiner expects. Like AmCache it is evidence of presence, and it is repeatedly and wrongly cited as evidence of execution.

WHY IT MATTERSAn opposing report that treats a ShimCache entry as an execution record has made a technical error that is straightforward to demonstrate and hard for the author to walk back.

SIEM

CLOUD AND NETWORK

ALSO: security information and event management · log aggregation

A platform that collects logs from across an environment into one searchable store, used for security monitoring, alerting and investigation.

Its value in litigation is that it may hold a copy of log data from a source whose own retention has already expired, and it holds it with times normalised across systems. Two cautions follow. A SIEM stores what it was configured to ingest, so a source nobody onboarded is not there; and the stored record is a parsed representation, so where precision matters the original log remains the better evidence.

WHY IT MATTERSThe SIEM is often the only surviving copy of a log the originating system discarded weeks ago.

Source code review

ROLES AND PROCEDURE

ALSO: code review · software forensic examination · code comparison

Examination of software source code as evidence, typically to assess copying, trade-secret use, independent development, or whether code performs as alleged.

The examination runs inside the protective order's review environment and against an agreed scope, and it draws on more than the code: version-control history, build records, third-party component inventories, and comments and artefacts that survived from an earlier codebase. Similarity alone establishes little, because common libraries, generated code and standard idioms produce it — the question is whether the similarity is of a kind that independent development explains.

WHY IT MATTERSIn a departing-employee matter the device examination establishes the route and the code review establishes what was actually taken; neither answers the other's question.

Source code tier

LEGAL STANDARDS

ALSO: source code designation · highly confidential source code

The most restrictive protective-order designation, reserved for source code and typically requiring review on a standalone machine in a controlled room.

Terms commonly include a non-networked review computer, no removable media, a log of everyone who enters, limits on how many pages may be printed and on printing contiguous blocks, and a bar on taking notes containing code out of the room. Each restriction is a real constraint on how the examination proceeds. Printing caps in particular decide whether the analysis can be documented at all, and they are negotiated before anyone knows how large the codebase is.

WHY IT MATTERSA per-page or per-block printing cap agreed without reference to the size of the codebase can make it impossible to attach the exhibits the opinion depends on.

Special master

ROLES AND PROCEDURE

ALSO: FRE 706 expert · court-appointed expert · Rule 53 master

A person appointed by the court to handle defined matters, whether as a master under Rule 53 or as a court-appointed expert witness under FRE 706.

The two routes are distinct. Rule 53 appoints a master to perform duties the court assigns — often supervising a technical discovery dispute or a device examination protocol — while FRE 706 allows the court to appoint an expert witness who may be deposed and called by any party. In digital evidence disputes the appointment usually follows a breakdown in trust over access to devices or source code.

WHY IT MATTERSOnce a court appoints its own technical help, the parties' own experts are arguing to someone who can evaluate the method rather than only the conclusion.

Spoliation

LEGAL STANDARDS

ALSO: evidence destruction · spoliation of evidence

The loss, destruction, or material alteration of evidence a party had a duty to preserve, whether by deliberate act or by failure to suspend routine deletion.

Most spoliation is not dramatic. It is an auto-delete policy nobody paused, a laptop reimaged and reissued, a mailbox purged when an employee left, or a device replaced under a normal refresh cycle. Forensic examination can often establish what was lost, when, and by what mechanism, and can sometimes recover part of it. What it cannot supply is the state of mind, which is the element the severe sanctions turn on.

WHY IT MATTERSThe routine-operation cases are the common ones, and they are usually lost at the moment nobody suspended a retention schedule rather than at the moment someone deleted something.

SRUM

ARTIFACTS AND FILE SYSTEMS

ALSO: System Resource Usage Monitor · SRUDB.dat

A Windows database recording per-application, per-user resource use in time buckets, including bytes sent and received over each network interface.

SRUM is often the only record on a workstation bearing on how much data left it, which is why it appears in exfiltration analysis. The counters are aggregate: they attribute a volume of traffic to an application and a user account over an interval, and they carry no filenames, no destinations, and no content. Retention is limited — the database is trimmed on a rolling basis — so it supports a picture of recent weeks rather than a year.

WHY IT MATTERSSRUM can show that a browser or sync client moved gigabytes on the evening before a resignation. It cannot show what was in them, and a report that implies otherwise is asking a counter to be a manifest.

SWGDE

CREDENTIALS AND STANDARDS BODIES

ALSO: Scientific Working Group on Digital Evidence

The Scientific Working Group on Digital Evidence, which publishes best-practice documents and guidelines for the handling and examination of digital evidence.

Its documents cover acquisition, examination, reporting and quality practices, and they are widely cited as a statement of what the discipline expects. They are guidance, not binding rules, so departing from them is not automatically improper — but a departure that was never documented or explained is a straightforward line of cross-examination.

WHY IT MATTERSPublished best practice supplies the benchmark a challenge measures an examination against, whether or not the examiner ever consulted it.

System metadata

ARTIFACTS AND FILE SYSTEMS

ALSO: filesystem metadata · file system metadata

Metadata the operating system keeps about a file — name, path, size, and the created, modified and accessed times — stored outside the file itself.

Because it lives in the filesystem rather than the document, system metadata is rewritten by ordinary handling: copying a file to a new volume sets a new creation time, and dragging a folder to a share updates access times across everything in it. That is why self-collection by a custodian damages the evidence about the evidence even when every document survives intact. It is also why system metadata alone rarely dates a document; it dates this copy of it.

WHY IT MATTERSA creation date that post-dates the events in a document usually means the file was copied, not that the document is fake — and an examiner who cannot tell those apart will say the wrong one under oath.

T

Testifying expert

ROLES AND PROCEDURE

ALSO: retained expert · disclosed expert

An expert retained to give opinion testimony, whose identity, opinions, and the facts and data considered must be disclosed to the other side.

The role determines discoverability, not merely who speaks at trial. The facts and data a testifying expert considered are disclosable, and drafts and most attorney-expert communications receive protection under Rule 26(b)(4) — but material the expert relied on is fair game. Converting a consulting expert into a testifying expert exposes work performed while the protection applied, which is why the decision is made at retention.

WHY IT MATTERSChoosing the role after the expert has already reviewed the evidence is how privileged working material becomes discoverable.

TIFF production

TOOLS AND FORMATS

ALSO: image production · TIFF/PDF production · petrified production

Production of documents as page images with extracted text and a metadata load file, rather than as the original application files.

It is the traditional review-friendly form: every page carries a Bates number and a confidentiality designation, and redaction is straightforward. It is also lossy in exactly the places forensic questions live — formulas, revision history, embedded objects, and internal timestamps are gone from the image, surviving only as whatever fields the load file was configured to carry. Requesting natives for a defined subset is the usual accommodation.

WHY IT MATTERSOnce a document is produced only as an image, the questions that needed the native file cannot be answered without going back for a re-production.

Time zone offset

ARTIFACTS AND FILE SYSTEMS

ALSO: UTC offset · local time versus UTC · time zone

The difference between a recorded local time and UTC, which must be established for every source before times from different sources can be compared.

Some artifacts store UTC, some store local time, and forensic tools display whatever time zone the examiner configured — so the same event can appear at three different times in three exhibits without anything being wrong. Daylight saving adds a further shift that changes during the period under examination. The convention should be stated on the face of the report, because a reader cannot infer it.

WHY IT MATTERSA one-hour discrepancy across a daylight-saving boundary has ended more timeline arguments than any sophisticated attack, and it is entirely avoidable.

Timestamp

ARTIFACTS AND FILE SYSTEMS

ALSO: date stamp · time stamp

A recorded time value, which reflects what one source wrote according to one clock in one time zone, not necessarily when an act occurred.

Every timeline rests on timestamps and almost every serious attack on a timeline lands on them. A time value can be wrong because the clock was wrong, because it was recorded in local time and read as UTC, because the application and the filesystem disagree about what the event was, or because someone changed it. Corroboration across independent sources is what turns a timestamp into a time.

WHY IT MATTERSA timeline built from one source, without an anchor event to test it against, is an assertion. One tested against records the other side controls is an argument.

Timestomping

ARTIFACTS AND FILE SYSTEMS

ALSO: timestamp manipulation · time stomping · backdating a file

Deliberately altering a file's timestamps to misrepresent when it was created, modified or accessed, usually with a utility written for the purpose.

The technique defeats a naive reading of file properties and usually leaves a signature, because the common tools rewrite the $STANDARD_INFORMATION timestamps and not the $FILE_NAME copies held in the same $MFT record. Other tells include timestamps with implausible sub-second precision and values inconsistent with the change journal. None of these prove who did it, and a mismatch can also arise from ordinary file movement, so the finding is stated as a discrepancy with its candidate explanations, not as an accusation.

WHY IT MATTERSTimestomping evidence is what converts a document-dating dispute into a spoliation argument, so the technical statement of it has to be exact.

U

Unallocated space

ARTIFACTS AND FILE SYSTEMS

ALSO: free space · unallocated clusters

Areas of a drive not currently assigned to any live file, which routinely still contain the content of deleted files until the space is reused.

This is where deleted material lives until it is overwritten, and it is the reason a physical image is worth taking. How long content survives there depends on how heavily the machine is used and on the storage technology: solid-state drives with active garbage collection can discard the content of deleted files without any user action, so absence of a recoverable file on an SSD is weak evidence that it was never there. Preservation of unallocated space is a term parties fight over in ESI protocols precisely because conceding it forecloses this whole class of question.

WHY IT MATTERSOnce a custodian's machine is reimaged or redeployed, the unallocated space is gone, and no order can put it back.

Unified Audit Log (UAL)

CLOUD AND NETWORK

ALSO: UAL · Microsoft 365 audit log · unified audit logging

The Microsoft 365 tenant-wide log of user and administrator activity across services, recording actions such as sign-in, file access, sharing, and mailbox operations.

It is often the only record of what happened inside a cloud tenant, which makes its two configuration-dependent properties decisive: what is captured depends on the licensing and audit settings in force at the time, and how far back it reaches depends on the retention tier. Neither can be changed retroactively. Where mailbox auditing of specific actions was not enabled, those actions simply were not recorded.

WHY IT MATTERSThe window in which a tenant's audit log can still answer the question is measured in months, and often less — which puts the preservation request at the very start of the matter.

Unix epoch time

ARTIFACTS AND FILE SYSTEMS

ALSO: epoch time · POSIX time · Unix timestamp

A time format counting seconds since 1 January 1970 UTC, used across Linux, macOS, mobile platforms, and application databases.

It appears in artifacts as a bare integer, and the same field may be seconds, milliseconds, microseconds or nanoseconds depending on the application. Misreading the unit produces a date that is obviously wrong, which is the harmless failure, or one that is plausibly wrong, which is not. The value is UTC by definition, so a local time shown next to it came from the tool's configuration.

WHY IT MATTERSWhen a produced spreadsheet of log entries carries raw epoch values, the conversion is a step someone has to have done correctly, and it is a fair thing to ask about.

USB device history

ARTIFACTS AND FILE SYSTEMS

ALSO: USBSTOR · MountedDevices · removable device history

Windows registry records of removable storage devices connected to a machine, holding vendor, product and serial identifiers and a limited set of timestamps.

These records place a specific device on a specific machine, and where the device carries a unique serial they identify it precisely enough to match a produced exhibit. What they record is attachment. They do not record what was read from or written to the device, so no USB artifact shows a file transfer. The timestamps kept per device are few, so a record of connection is not a count of connections.

WHY IT MATTERSDevice connection plus browsing plus a shortcut with a matching volume serial number is a strong circumstantial case. Any one of them offered as proof of copying is an overreach the other side will name.

UserAssist

ARTIFACTS AND FILE SYSTEMS

ALSO: UserAssist keys

Registry values, kept per user, recording programs launched through the Windows shell along with a run count and a last-execution time.

Because it is per user, UserAssist speaks to which account did something rather than only that the machine did it. It covers launches through the graphical shell, so programs started by a script, a service, or the command line may not appear at all. The values are also obfuscated in the registry and must be decoded, which means the finding depends on the tool doing it correctly — a point worth stating in a report rather than leaving for cross-examination.

WHY IT MATTERSAn account is not a person. UserAssist narrows a launch to a user profile, and connecting that profile to a human being requires something outside the machine.

USN change journal ($UsnJrnl)

ARTIFACTS AND FILE SYSTEMS

ALSO: $UsnJrnl · UsnJrnl · change journal · USN journal

An NTFS log of file-level changes — creation, rename, data change, deletion — recorded as a rolling record that overwrites its oldest entries.

It is one of the few sources that shows deletions as events rather than as absences, which makes it central to spoliation work: a burst of deletion entries at a particular hour is a finding, where an empty folder is not. The critical limit is retention. The journal is capped and rolls over, so on a busy machine it may cover days or weeks rather than months, and nothing in it proves an event did not happen — only that no surviving entry records it.

WHY IT MATTERSThe rollover is why preservation timing decides these matters. A device imaged three months after the conduct may simply no longer hold the journal entries that would have shown it.

V

Voir dire

ROLES AND PROCEDURE

ALSO: expert voir dire · qualification examination

Preliminary questioning of a witness, used with an expert to examine qualifications before the court rules on whether they may give opinion testimony.

It is brief, aimed at the CV rather than the analysis, and it is where an overstated credential does its damage: a certification described as something it is not, training listed as though it were certification, or a claimed specialism the witness has not practised. The reliability of the opinion is a separate fight, usually already framed by motion.

WHY IT MATTERSA CV that overstates anything gives the opponent a credibility argument that costs nothing and colours everything the expert says afterwards.

Volume serial number

ARTIFACTS AND FILE SYSTEMS

ALSO: VSN · volume ID

An identifier assigned to a formatted volume, recorded inside LNK files and elsewhere, which links an artifact to one specific piece of media.

It is what allows an examiner to say a document was opened from that external drive rather than from some external drive. It identifies the volume, not the hardware: reformatting produces a new serial number, and a device with several partitions has several. Because it is a software value rather than a manufacturer's identifier, it is not by itself proof that a particular physical exhibit is the one in question — the device history records and the drive itself close that gap.

WHY IT MATTERSMatching a volume serial number in an LNK file to a produced thumb drive is often the strongest link in a data-theft matter, and it is the link a shellbag cannot supply.

Volume Shadow Copy

ARTIFACTS AND FILE SYSTEMS

ALSO: VSS · shadow copy · restore point

A point-in-time snapshot of a Windows volume, retained by the system, that can contain an earlier version of a file that has since been altered or deleted.

Shadow copies are the closest thing a workstation has to a backup nobody thought to tamper with, and they are how an earlier draft of a contested document is often recovered. They are created and discarded by the operating system on its own schedule and under space pressure, so the set available on any given machine is unpredictable and shrinking. Deleting them is trivially easy and leaves its own trace.

WHY IT MATTERSAn independent earlier copy of the document is what turns a backdating theory into a finding, and shadow copies are frequently the only place one exists.

VPN

CLOUD AND NETWORK

ALSO: virtual private network · remote access VPN

An encrypted tunnel carrying traffic between a device and a network, used for remote access to corporate systems and to obscure a user's apparent location.

Corporate VPN concentrator logs are valuable because they tie an account to a session with times and a source address — and they are often kept for a very short period. On the other side, a commercial VPN service breaks the link between an apparent address and a real location, so an address associated with a VPN provider identifies the provider and nothing more. Either way the log names an account, not a person.

WHY IT MATTERSVPN logs are among the first records to roll over, which makes them a priority in the preservation letter rather than a later discovery request.

W

Windows event log

ARTIFACTS AND FILE SYSTEMS

ALSO: event logs · EVTX · security log

Windows records of system, security and application events — logons, service installation, process creation where auditing is enabled, and log clearing.

How much is there depends entirely on configuration. Process-creation and command-line auditing are off by default and capture nothing retroactively, so the answer to what was run on a workstation often turns on a policy decision made years before the dispute. Logs are also fixed-size and roll over. The record that a log was cleared is itself logged, which is why clearing a log rarely helps the person who does it.

WHY IT MATTERSTwo failures decide these matters before anyone examines anything: auditing that was never enabled, and retention measured in days. Both are worth asking about at the first conference.

Write blocker

EVIDENCE HANDLING

ALSO: write block · hardware write blocker · forensic bridge

A hardware device or software driver that permits reads from an evidence drive while physically or logically preventing any write to it.

Attaching a drive to a running computer without one causes the operating system to write to it — mounting metadata, indexing, restore points — altering the evidence in the act of examining it. A hardware write blocker sits in the cable path and is preferred because it does not depend on the examiner's operating system behaving. Where the machine cannot be powered down, a live acquisition is taken instead, and it is documented as such: a live image cannot be hash-verified against an unchanged source, because the source did not stay unchanged.

WHY IT MATTERSAcquisition without write protection is the cleanest available attack on an examiner. It does not require the challenger to show anything was actually altered, only that nothing prevented it.

Where to take a term next

A definition settles what a word means. What it cannot settle is what a record will carry in your matter — that question belongs to the artifact itself. The artifact index answers it entry by entry, and Can This Artifact Prove That? answers it starting from the claim you need to support.

A TERM THAT DECIDES YOUR MATTER

If one of these terms is doing real work in an expert report, an ESI protocol, or a motion in your case, Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

  • The artifact index

    One page per forensic artifact: what it records, what it proves, what it cannot prove, and how long it survives.

  • Can This Artifact Prove That?

    Six claims litigators routinely need to support, the records that bear on each, and what no combination of them establishes.

  • Daubert and digital evidence

    How the reliability factors are actually applied to a forensic opinion, and the ways digital-evidence opinions fail.

  • Hiring a digital forensic expert witness

    What to ask, what the credentials in this glossary actually certify, and how a Rule 26(a)(2)(B) report is scoped.

↑ BACK TO THE TOP OF THE GLOSSARY

Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.