Audit Trail

A chronological record of system or user activities. Audit trails log events like logins, file access, changes, or network operations. In forensics, audit logs are analyzed to reconstruct events, verify authorized vs. unauthorized actions, and maintain accountability by showing who did what and when on a computing system. Audit logs can also be kept by forensic examiners to document the processes carried out in acquiring and analyzing digital evidence so it can be repeated by an independent third-party.