MSAB Digital Forensics Glossary
Key Terms and Definitions
Welcome to Our Digital Forensics Glossary — A resource for clear, concise definitions of key terms used in digital forensic investigations. This glossary includes terminology used in the field of smartphone investigations, mobile data extraction, and the analysis of digital evidence from mobile devices.
As mobile phones become central to cybercrime and digital investigations, it’s essential to understand critical concepts such as IMEI, mobile data acquisition, app artifacts, and SIM card analysis. You’ll also find definitions of broader digital forensics terms like hash values, metadata, and chain of custody — all explained in a straightforward, accessible format. Whether you’re a mobile forensics specialist, law enforcement officer, cybersecurity professional, or student, this glossary offers up-to-date explanations to help you navigate the rapidly evolving field of mobile forensics.
MAC Address
A unique Media Access Control address assigned to a network interface, traced in forensics to identify devices involved in network activity or incidents.
Read full termMalware
Malicious software (e.g., viruses, ransomware), analyzed in forensics to understand its behavior, origin, and impact on compromised systems.
Read full termMalware Forensics
The investigation of malicious software to identify its source, functionality, and effects, often involving reverse engineering and dynamic analysis.
Read full termMap Analytics
The use of geographic data visualization in forensics to plot location-based evidence (e.g., GPS, cell tower data), aiding in suspect tracking or event reconstruction.
Read full termMDN, Mobile Directory Number – Mobile Device Forensics
A 10-digit phone number assigned to a mobile device, extracted in forensics to link a device to a user or communication records.
Read full termMedia Analytics – Investigative Analytics
A feature in tools like MSAB XAMN Pro that identifies and categorizes media files (e.g., images, videos) containing specific attributes, enhancing investigative insights.
Read full termMEID – Mobile Device Forensics
Mobile Equipment Identifier, a unique CDMA identifier for mobile devices, analogous to IMEI, extracted to track hardware in forensic investigations.
Read full termMemory Dump
A snapshot of a device’s volatile memory (RAM), captured in forensics to recover active processes, encryption keys, or ephemeral data. Acquired using a tool such as MSAB XRY Pro.
Read full termMemory Forensics
The analysis of a system’s RAM to extract volatile evidence (e.g., running programs, passwords), critical when data isn’t stored on persistent media. XRY RAMAlyzer allows analysis from mobile RAM.
Read full termMerchant Services – Crypto Forensics
Authorized financial services enabling businesses to accept cryptocurrency payments, investigated in forensics to trace transactions or uncover illicit commerce.
Read full termMetadata
Data about data (e.g., file creation dates, GPS tags), extracted in forensics to establish timelines, ownership, or authenticity of digital evidence.
Read full termMIN – Mobile Device Forensics
Mobile Identification Number, a CDMA identifier often compared to IMSI, analyzed in forensics to associate a device with network activity or a subscriber.
Read full termMining – Crypto Forensics
The process of validating cryptocurrency transactions and earning rewards, examined in forensics to trace blockchain activity or link miners to illicit operations.
Read full termMining Pool – Crypto Forensics
A service where cryptocurrency miners combine resources to increase efficiency, analyzed in forensics to trace pooled transactions or identify participants.
Read full termMixing – Crypto Forensics
Websites or software that obscure cryptocurrency transaction trails (e.g., tumblers), investigated in forensics to uncover money laundering or hidden fund flows.
Read full termMobile Forensics
The process of accessing, recovering, and analyzing digital evidence from mobile devices (e.g., smartphones, tablets) to support investigations.
Read full termMobile Forensics Software
Specialized software (e.g., MSAB XRY, and open source tools such as UFADE) used to access, recover, and analyze digital evidence from mobile devices in a forensically sound manner.
Read full termMobile Forensics Tools
Hardware and software solutions designed for accessing, recovering, and analyzing digital evidence from mobile devices, widely used in forensic investigations. Mobile forensic tools are specialized software and hardware solutions designed to assist forensic examiners in acquiring, analyzing, and reporting data from mobile devices. These tools play a crucial role in mobile forensic investigations, enabling examiners […]
Read full termModel – Mobile Device Forensics
An option in tools like Physical Analyzer allowing examiners to select color-coded models or configurations for analyzing mobile device data, enhancing visual interpretation.
Read full termMounting
The process of making a forensic image or partition accessible as a virtual drive, allowing examiners to browse and analyze its contents without altering the original.
Read full termMSISDN – Mobile Device Forensics
Mobile Station International Subscriber Directory Number, a GSM identifier (phone number) tied to a SIM, extracted to link devices to users or communication records.
Read full termMSISDN Forensics
The forensic analysis of the Mobile Station International Subscriber Directory Number to trace calls, messages, or subscriber details in mobile investigations.
Read full termMultiSIM Card Reader – Mobile SIM Adapter from MSAB
A device from MSAB that reads multiple SIM card types, used in forensics to extract data (e.g., contacts, messages) from SIMs.
Read full termMutex (Mutual Exclusion)
A synchronization object in software, analyzed in forensics to detect malware behavior or identify processes running concurrently on a system.
Read full term