Kalpana Kalpana (Editor)

Glossary of digital forensics terms

Updated on
Edit
Like
Comment
Share on FacebookTweet on TwitterShare on LinkedInShare on Reddit

Digital forensics is a branch of the forensic sciences related to the investigation of digital devices and media. Within the field a number of "normal" forensics words are re-purposed, and new specialist terms have evolved.

acquisition
The process of creating a duplicate copy of digital media for the purposes of examining it
computational forensics
Computational forensics are digital forensics with the use of artificial intelligence.
digital media
Used within the fields to refer to the physical medium (such as a hard drive) or data storage device
e-discovery or eDiscovery
A common acronym for electronic discovery
exhibit
Digital media seized for investigation is usually referred to as an "exhibit"
hashing
Within the field "hashing" refers to the use of hash functions (e.g. CRC, SHA1 or MD5) to verify that an "image" is identical to the source media
image
A duplicate copy of some digital media created as part of the forensic process
imaging
Synonym of "acquisition"
live analysis
Analysis of a piece of digital media from within itself; often used to acquire data from RAM where this would be lost upon shutting down the device
slack space
The unused space at the end of a file in a file system that uses fixed size clusters (so if the file is smaller than the fixed block size then the unused space is simply left). Often contains deleted information from previous uses of the block
steganography
The word steganography comes from the Greek name “steganos” (hidden or secret) and “graphy” (writing or drawing) and literally means hidden writing. Steganography uses techniques to communicate information in a way that is hidden.
unallocated space
Clusters of a media partition not in use for storing any active files. They may contain pieces of files that were deleted from the file partition but not removed from the physical disk
verification
A term used to refer to the hashing of both source media and acquired image to verify the accuracy of the copy
write blocker
The common name used for a forensic disk controller, hardware used to access digital media in a read only fashion

References

Glossary of digital forensics terms Wikipedia