MSAB Digital Forensics Glossary
Key Terms and Definitions
Welcome to Our Digital Forensics Glossary — A resource for clear, concise definitions of key terms used in digital forensic investigations. This glossary includes terminology used in the field of smartphone investigations, mobile data extraction, and the analysis of digital evidence from mobile devices.
As mobile phones become central to cybercrime and digital investigations, it’s essential to understand critical concepts such as IMEI, mobile data acquisition, app artifacts, and SIM card analysis. You’ll also find definitions of broader digital forensics terms like hash values, metadata, and chain of custody — all explained in a straightforward, accessible format. Whether you’re a mobile forensics specialist, law enforcement officer, cybersecurity professional, or student, this glossary offers up-to-date explanations to help you navigate the rapidly evolving field of mobile forensics.
Access Service
MSAB digital forensic experts use advanced forensically sound techniques to recover and decrypt the data from […]
Read full termACPO (Association of Chief of Police)
ACPO Guidelines for computer-based evidence, these are a set of guidelines followed by forensic examiners acro […]
Read full termAcquisition
The process of collecting digital evidence from devices, often by creating a forensically sound copy or image.
Read full termActive Data
Information on a storage device that is readily accessible to the operating system (as opposed to deleted or h […]
Read full termADS (Alternate Data Streams)
ADS – A feature of the NTFS file system that allows a single file to contain multiple data streams. These seco […]
Read full termAdware
Malicious or unwanted software that automatically displays advertisements and is often bundled with free progr […]
Read full termAES (Advanced Encryption Standard)
A widely used symmetric encryption algorithm that encrypts data in fixed block sizes with a secret key.
Read full termAfter First Unlock (AFU)
AFU: after first unlock, means the device is locked, but it has been unlocked since it booted up at least once […]
Read full termAllocated Space
Allocated Space is the area on a device’s memory that stores data in an organized manner and contains its oper […]
Read full termAndroid Backup
An Android backup refers to the copy of data from a mobile Android device that investigators can use to analyz […]
Read full termAndroid Forensics
Android applications store data in various formats, such as SQLite databases, XML files, and SharedPreferences […]
Read full termAnti-Forensics
Techniques used by perpetrators to obstruct forensic analysis (e.g., data wiping, encryption, or altering meta […]
Read full termAPFS (Apple File System)
APFS, or Apple File System, is a proprietary file system developed by Apple Inc. for macOS, iOS, iPadOS, watch […]
Read full termAPI (Application Programming Interface)
In the context of mobile forensics, an API (Application Programming Interface) refers to a set of protocols, r […]
Read full termAPK (Android Package Kit)
The Android package with the file extension apk is the file format used by the Android Operating System and se […]
Read full termApple Account
User accounts are used to access all Apple services and devices, including the App Store, iCloud, iMessage, Fa […]
Read full termAPT (Advanced Persistent Threat)
A stealthy, sophisticated cyber-attack where an unauthorized user gains prolonged access to a network, often s […]
Read full termArtifact (Digital Artifact)
Any file, metadata, or residue that is evidence of digital activity (e.g., logs, registry keys, link files).
Read full termAsymmetric Encryption
An encryption method using a pair of keys – a public key for encryption and a private key for decryption (also […]
Read full termAttribution
In a forensic context, attribution is the process of linking digital evidence or actions to a specific individ […]
Read full termAudio File Forensics
Audio file forensics is a specialized branch of digital forensics that deals with the analysis, authentication […]
Read full termAudit Trail
A chronological record of system or user activities. Audit trails log events like logins, file access, changes […]
Read full termAutopsy
An open-source digital forensics platform (graphical interface for The Sleuth Kit) used to analyze disks, smar […]
Read full term