Skip to content

Reference

Forensic technology glossary

Plain-language definitions of the digital forensics, eDiscovery and cybersecurity terms that decide cases — written by the examiners and testifying experts who work them.

38 terms, each reviewed by the practice that uses it.

Digital forensics

Anti-forensics
Anti-forensics is deliberate activity intended to destroy, hide or falsify digital evidence — secure wiping, timestamp manipulation, log deletion, or resetting a device before returning it. The activity almost always leaves its own traces, so the attempt is frequently more probative than what it destroyed.
Asset tracing
Asset tracing follows misappropriated funds or property through the transactions and entities used to move them, with the goal of finding assets a court can actually reach. Locating the money is rarely the hard part — the difficulty is finding it somewhere a judgment can be enforced before it moves again.
Blockchain analysis
Blockchain analysis traces the movement of cryptocurrency across a public ledger and attributes addresses to real-world entities. The ledger itself is permanent and complete, so the hard part is never finding the transactions — it is establishing who controlled the addresses at each end.
Chain of custody
Chain of custody is the documented record of who handled a piece of evidence, when, and what they did with it. In digital forensics it runs from seizure to the moment the evidence is offered in court, and an unexplained gap in that record is grounds to challenge admissibility.
Cloud forensics
Cloud forensics is the collection and analysis of evidence held by cloud and SaaS providers rather than on a device you can seize. There is nothing to image, so integrity rests on documented API or admin-console collection, provider audit logs, and hashing the exported output.
Deepfake
A deepfake is audio, image or video synthesised or altered by machine learning to depict something that did not occur. For litigation the significance is twofold: fabricated media offered as evidence, and the growing tendency of parties to dispute authentic recordings by claiming they are synthetic.
Forensic accounting
Forensic accounting applies accounting analysis to questions that will be tested in litigation or regulatory proceedings — whether funds were misappropriated, how a loss should be quantified, or whether records were manipulated. It differs from audit in purpose: an audit seeks reasonable assurance, an investigation seeks a defensible answer to a specific question.
Forensic image
A forensic image is a complete, bit-for-bit copy of a storage device, including the space the file system reports as empty. It is not a backup and not a file copy: it captures deleted data, slack space and unallocated areas, and it is verified with a cryptographic hash so the copy can be proven identical to the source.
Hash value
A hash value is a fixed-length string calculated from a file or drive's contents, functioning as a digital fingerprint. Change a single bit and the hash changes completely, which is what allows an examiner to prove that a forensic copy is identical to its source and that nothing was altered between acquisition and analysis.
Mobile device forensics
Mobile device forensics is the recovery and analysis of data from phones and tablets. Unlike computer forensics it cannot rely on removing storage and imaging it directly: what can be extracted depends on the device model, the operating system version, and the security state at the moment of acquisition.
Social media evidence
Social media evidence is content and activity records from platforms — posts, messages, reactions, and the account metadata behind them. Screenshots are the usual method of capture and the usual reason it fails: a screenshot carries no metadata, no provenance, and nothing distinguishing it from a fabrication.
Timeline analysis
Timeline analysis combines timestamps from across a system — file activity, logs, registry, browser and application artifacts — into one chronological sequence. It is how an examiner establishes what happened in what order, which is usually the question in dispute rather than what any single file contains.
Write blocker
A write blocker is hardware or software that sits between an examiner's machine and a piece of evidence, permitting reads and refusing every write. It exists because connecting a drive to a running computer causes that computer to modify it automatically, which would alter the evidence before anyone deliberately did anything to it.

eDiscovery

Custodian
A custodian is a person who holds or controls data potentially relevant to a matter — typically an employee whose email, files, messages and devices fall within scope. Custodian selection is the single decision that most determines the cost and the completeness of a discovery effort.
Electronically stored information (ESI)
Electronically stored information is the category the Federal Rules use for any information created or stored in digital form that is discoverable in litigation. It is deliberately broad — email, chat, documents, databases, cloud records, phone data and system logs all qualify, whatever the format or medium.
Ephemeral messaging
Ephemeral messaging is communication designed to auto-delete after a set period — Signal's disappearing messages, similar features in Slack, Teams and WhatsApp. The technology is lawful; using it for business communications after a duty to preserve attaches is what courts have treated as evidence of intent to deprive.
ESI protocol
An ESI protocol is the agreement — usually entered as a court order — setting out how electronically stored information will be preserved, collected, searched, and produced in a case. It fixes formats, metadata fields, search methodology and privilege handling before production, rather than litigating each afterwards.
Metadata
Metadata is the data a file carries about itself — who created it, when it was last modified, what device made it, and how it travelled. In litigation it is frequently more probative than the document's contents, because it records what happened rather than what someone wrote.
Predictive coding
Predictive coding is the use of machine learning to prioritise or classify documents for review: attorneys code a sample, the system learns from those decisions, and it ranks the remaining population by likely relevance. Courts have accepted it for well over a decade where the methodology is disclosed and validated.

Cybersecurity

Audit log
An audit log is a system-generated record of who did what, when, and from where. In litigation it is unusually valuable because it is machine-generated rather than authored — which means it is generally not hearsay, and it records activity that no document describes.
Business email compromise
Business email compromise is fraud in which an attacker uses a genuine or convincingly spoofed email account to induce a payment to an account they control. It usually involves no malware at all — the attacker reads real correspondence and intervenes in a transaction that was already happening.
Cyber insurance
Cyber insurance covers losses from security incidents — response costs, business interruption, liability to third parties, and sometimes extortion payments. Coverage disputes rarely turn on whether an incident occurred; they turn on notice timing, panel-vendor requirements, and whether the insured's security representations at underwriting were accurate.
Incident response
Incident response is the structured process for detecting, containing, investigating and recovering from a security incident. The legally consequential part is not containment but scope: establishing what data was accessed or taken, because notification duties, regulatory deadlines and litigation exposure all follow from that finding.
Insider threat
An insider threat is risk originating from someone with authorised access — an employee, contractor or partner. It is difficult to detect precisely because the activity uses legitimate credentials and often looks like normal work, so the evidence is usually a deviation from a person's own baseline rather than an obvious intrusion.
Ransomware
Ransomware is malware that encrypts an organisation's data and demands payment for the key. Modern operations almost always steal the data first and threaten publication, so paying to decrypt does not resolve the exposure — the breach-notification and regulatory obligations arise from the theft, not from the encryption.

Litigation & procedure

Clawback agreement
A clawback agreement lets a party retrieve privileged material that was produced by mistake, without that production waiving privilege. Entered as a court order under Federal Rule of Evidence 502(d), it binds non-parties and other proceedings too — protection a private agreement between the parties cannot provide.
Daubert standard
The Daubert standard governs the admissibility of expert testimony in federal court, requiring a judge to assess whether an expert's methodology is reliable and whether it fits the facts of the case. It is a gatekeeping test about method, not a judgment on whether the expert's conclusion is correct.
Forensic neutral
A forensic neutral is an independent digital forensics examiner engaged by both parties or appointed by the court, rather than retained by one side. They examine devices and data under an agreed protocol and report findings to everyone at once, which resolves factual disputes that duelling party experts tend to entrench.
Legal hold
A legal hold is the process of suspending normal deletion and retention practices so that evidence relevant to anticipated or pending litigation is preserved. It is not a single email: it is a notice, a suspension of automated deletion, and an ongoing obligation to confirm that both are actually working.
Privilege log
A privilege log is the itemised list a producing party provides of documents withheld or redacted on privilege grounds, describing each well enough for the other side to assess the claim without revealing the protected content itself. Getting that balance wrong is what generates most privilege disputes.
Proportionality
Proportionality is the Rule 26(b)(1) limit on discovery: material must be relevant and proportional to the needs of the case, weighed against the amount in controversy, the parties' resources, the importance of the issues, and whether the likely benefit justifies the burden. Relevance alone no longer makes something discoverable.
Special master
A special master is a neutral appointed by a court under Rule 53 to handle matters the judge cannot practically manage directly — most often complex discovery, technical disputes, or claims administration. The appointment is judicial in character: a master decides or recommends, rather than advising one side.
Spoliation
Spoliation is the destruction, alteration or failure to preserve evidence that a party knew or should have known was relevant to litigation. It does not require bad intent — routine auto-deletion running after the duty to preserve attaches is the most common form, and the most commonly sanctioned.
Trade secret
A trade secret is information that derives economic value from not being generally known and that its owner takes reasonable measures to keep secret. Both elements are required, and the second is where most claims are won or lost — protection depends on what the company actually did, not on what it labelled confidential.

Privacy & regulation

CCPA
The California Consumer Privacy Act, as amended by the CPRA, gives California residents rights over personal information businesses hold about them. Its distinctive feature for litigators is a private right of action for breaches caused by a failure to maintain reasonable security, with statutory damages that do not require proving loss.
Data breach
A data breach is unauthorised access to, or acquisition of, protected information. Whether a given incident is legally a breach is a definitional question that varies by statute and by data type — and the same facts can be reportable under one regime, exempt under another, and subject to different deadlines under a third.
GDPR
The General Data Protection Regulation governs the processing of personal data relating to people in the EU and UK. For litigation its sharpest edges are the 72-hour breach notification clock, the need for a lawful basis before processing data for discovery, and the constraints on transferring personal data out of the EEA.
SEC cyber disclosure rules
SEC rules require public companies to disclose material cybersecurity incidents on Form 8-K, generally within four business days of determining materiality, and to describe their risk management, strategy and governance annually. The clock runs from the materiality determination, not from discovery — and unreasonable delay in reaching it is itself exposure.

Need one of these applied to your matter?

Definitions decide motions. Our examiners and testifying experts work these questions in live litigation.