MSAB Digital Forensics Glossary

Key Terms and Definitions

 

Welcome to Our Digital Forensics GlossaryA resource for clear, concise definitions of key terms used in digital forensic investigations. This glossary includes terminology used in the field of smartphone investigations, mobile data extraction, and the analysis of digital evidence from mobile devices.

As mobile phones become central to cybercrime and digital investigations, it’s essential to understand critical concepts such as IMEI, mobile data acquisition, app artifacts, and SIM card analysis. You’ll also find definitions of broader digital forensics terms like hash values, metadata, and chain of custody — all explained in a straightforward, accessible format. Whether you’re a mobile forensics specialist, law enforcement officer, cybersecurity professional, or student, this glossary offers up-to-date explanations to help you navigate the rapidly evolving field of mobile forensics.

Access Service

MSAB digital forensic experts use advanced forensically sound techniques to recover and decrypt the data from […]

Read full term

ACPO (Association of Chief of Police)

ACPO Guidelines for computer-based evidence, these are a set of guidelines followed by forensic examiners acro […]

Read full term

Acquisition

The process of collecting digital evidence from devices, often by creating a forensically sound copy or image.

Read full term

Active Data

Information on a storage device that is readily accessible to the operating system (as opposed to deleted or h […]

Read full term

ADS (Alternate Data Streams)

ADS – A feature of the NTFS file system that allows a single file to contain multiple data streams. These seco […]

Read full term

Adware

Malicious or unwanted software that automatically displays advertisements and is often bundled with free progr […]

Read full term

AES (Advanced Encryption Standard)

A widely used symmetric encryption algorithm that encrypts data in fixed block sizes with a secret key.

Read full term

After First Unlock (AFU)

AFU: after first unlock, means the device is locked, but it has been unlocked since it booted up at least once […]

Read full term

Allocated Space

Allocated Space is the area on a device’s memory that stores data in an organized manner and contains its oper […]

Read full term

Android Backup

An Android backup refers to the copy of data from a mobile Android device that investigators can use to analyz […]

Read full term

Android Forensics

Android applications store data in various formats, such as SQLite databases, XML files, and SharedPreferences […]

Read full term

Anti-Forensics

Techniques used by perpetrators to obstruct forensic analysis (e.g., data wiping, encryption, or altering meta […]

Read full term

APFS (Apple File System)

APFS, or Apple File System, is a proprietary file system developed by Apple Inc. for macOS, iOS, iPadOS, watch […]

Read full term

API (Application Programming Interface)

In the context of mobile forensics, an API (Application Programming Interface) refers to a set of protocols, r […]

Read full term

APK (Android Package Kit)

The Android package with the file extension apk is the file format used by the Android Operating System and se […]

Read full term

Apple Account

User accounts are used to access all Apple services and devices, including the App Store, iCloud, iMessage, Fa […]

Read full term

APT (Advanced Persistent Threat)

A stealthy, sophisticated cyber-attack where an unauthorized user gains prolonged access to a network, often s […]

Read full term

Artifact (Digital Artifact)

Any file, metadata, or residue that is evidence of digital activity (e.g., logs, registry keys, link files).

Read full term

Asymmetric Encryption

An encryption method using a pair of keys – a public key for encryption and a private key for decryption (also […]

Read full term

Attribution

In a forensic context, attribution is the process of linking digital evidence or actions to a specific individ […]

Read full term

Audio File Forensics

Audio file forensics is a specialized branch of digital forensics that deals with the analysis, authentication […]

Read full term

Audit Trail

A chronological record of system or user activities. Audit trails log events like logins, file access, changes […]

Read full term

Autopsy

An open-source digital forensics platform (graphical interface for The Sleuth Kit) used to analyze disks, smar […]

Read full term