Digital Forensics Resources
A practical guide to digital evidence and digital forensics, a glossary of the terms we use in our reports, and links to our methodology, chain-of-custody procedure and frequently asked questions — built to be genuinely useful, not just search-optimised filler.
17+
Guide Chapters
17+
Glossary Terms
8
FAQ Categories
Find What You Need
Six places to start, depending on what you’re trying to understand.
Digital Forensics Guide
A 17-chapter practical guide to digital evidence, from what it is to how it’s presented in court.
Forensic Glossary
Plain-language definitions for the technical terms used throughout our reports and site.
Our Methodology
The eight stages every examination follows, from identification through to presentation.
Chain of Custody
How evidence is logged, transferred, stored and access-controlled from intake to return.
Case Studies
Anonymised summaries of matters we’ve worked on, shared where confidentiality permits.
Frequently Asked Questions
40 questions answered across 8 topic areas — general, legal and service-specific.
Forensic Terms, Plainly Explained
The terms you’ll come across most often in a forensic report or discussion.
1
Chain of Custody
A documented, chronological record of who has handled evidence, when, and what was done to it, from collection through to presentation in court.
2
Digital Evidence
Any data stored or transmitted in digital form that may be relied upon in an investigation or legal proceeding.
3
Forensic Image
An exact, bit-for-bit copy of digital storage media, created using write-blocking technology and verified against a hash value.
4
Hash Value
A fixed-length digital fingerprint generated by a cryptographic algorithm, used to verify that data has not changed.
5
Metadata
Data that describes other data — such as when a file was created, modified or accessed, or where a photo was taken.
6
EXIF
Exchangeable Image File Format — metadata embedded in photographs, often including camera model, capture date and GPS coordinates.
7
File System
The structure an operating system uses to organise and retrieve files on a storage device (e.g. NTFS, APFS, ext4).
8
Deleted Data
Data marked for removal by the operating system that may remain physically present on the storage medium until overwritten.
9
Mobile Extraction
The general process of retrieving data from a mobile device for forensic examination.
10
Logical Extraction
A mobile extraction method that retrieves accessible data such as contacts and messages, without reading the underlying file system.
11
Physical Extraction
A mobile extraction method that captures a complete bit-for-bit copy of a device’s storage, including deleted data where accessible.
12
Timeline Analysis
Reconstructing a chronological sequence of digital activity from file-system metadata, logs and other artefacts.
13
Write Blocker
Hardware or software that prevents any data being written to a storage device during forensic acquisition.
14
Artefact
Any trace or byproduct left behind by system or user activity that can be examined as evidence — a log entry, registry key or cache file.
15
CCTV
Closed-circuit television — a video surveillance system whose footage is a common subject of video forensic examination.
16
Video Authentication
Assessing whether video footage is consistent with continuous, unaltered recording from the claimed source.
17
Expert Witness
An individual permitted to give opinion evidence to a court on technical matters within their expertise, owing a duty to the court.
Digital Evidence & Digital Forensics
A practical, plain-language guide — the full table of contents below.
What is digital evidence?
Defining digital evidence and why it’s treated differently from physical evidence.
Types of digital evidence
Files, communications, metadata, logs, images, video and more.
Evidence preservation
Why devices shouldn’t be used, backed up or returned before examination.
Chain of custody
How a documented record of handling supports admissibility.
Forensic acquisition
Creating and verifying a forensic image before examination begins.
Computer forensics
What’s involved in examining laptops, desktops and servers.
Mobile forensics
Extraction methods and what they can and can’t recover.
Video evidence
Enhancement, authentication and the limits of both.
Image evidence
Metadata, manipulation detection and provenance.
Metadata
Why the data about the data often matters as much as the content.
Deleted data
What “deleted” actually means on different storage media.
Authentication
Assessing whether evidence is what it appears to be.
Examination and analysis
The difference between finding data and interpreting it.
Expert reports
What a properly prepared forensic report should contain.
Digital evidence in court
How findings are presented, tested and cross-examined.
Limitations and uncertainty
Why honest reporting includes what couldn’t be determined.
Engaging a digital forensic expert
When and how to bring an expert into a matter. We’re publishing this guide chapter by chapter. In the meantime, each topic above is already covered in summary on the relevant service page — start with the services overview or get in touch if you’d like something explained directly.
Guides We’re Currently Writing
Longer-form pieces going deeper than the FAQ — not yet published.
