Knowledge Base

Digital Forensics Resources

A practical guide to digital evidence and digital forensics, a glossary of the terms we use in our reports, and links to our methodology, chain-of-custody procedure and frequently asked questions — built to be genuinely useful, not just search-optimised filler.

17+

Guide Chapters

17+

Glossary Terms

8

FAQ Categories

Find What You Need

Six places to start, depending on what you’re trying to understand.

Digital Forensics Guide

A 17-chapter practical guide to digital evidence, from what it is to how it’s presented in court.

Learn More

Forensic Glossary

Plain-language definitions for the technical terms used throughout our reports and site.

Learn More

Our Methodology

The eight stages every examination follows, from identification through to presentation.

Learn More

Chain of Custody

How evidence is logged, transferred, stored and access-controlled from intake to return.

Learn More

Case Studies

Anonymised summaries of matters we’ve worked on, shared where confidentiality permits.

Learn More

Frequently Asked Questions

40 questions answered across 8 topic areas — general, legal and service-specific.

Learn More

Glossary

Forensic Terms, Plainly Explained

The terms you’ll come across most often in a forensic report or discussion.

1

Chain of Custody

A documented, chronological record of who has handled evidence, when, and what was done to it, from collection through to presentation in court.

2

Digital Evidence

Any data stored or transmitted in digital form that may be relied upon in an investigation or legal proceeding.

3

Forensic Image

An exact, bit-for-bit copy of digital storage media, created using write-blocking technology and verified against a hash value.

4

Hash Value

A fixed-length digital fingerprint generated by a cryptographic algorithm, used to verify that data has not changed.

5

Metadata

Data that describes other data — such as when a file was created, modified or accessed, or where a photo was taken.

6

EXIF

Exchangeable Image File Format — metadata embedded in photographs, often including camera model, capture date and GPS coordinates.

7

File System

The structure an operating system uses to organise and retrieve files on a storage device (e.g. NTFS, APFS, ext4).

8

Deleted Data

Data marked for removal by the operating system that may remain physically present on the storage medium until overwritten.

9

Mobile Extraction

The general process of retrieving data from a mobile device for forensic examination.

10

Logical Extraction

A mobile extraction method that retrieves accessible data such as contacts and messages, without reading the underlying file system.

11

Physical Extraction

A mobile extraction method that captures a complete bit-for-bit copy of a device’s storage, including deleted data where accessible.

12

Timeline Analysis

Reconstructing a chronological sequence of digital activity from file-system metadata, logs and other artefacts.

13

Write Blocker

Hardware or software that prevents any data being written to a storage device during forensic acquisition.

14

Artefact

Any trace or byproduct left behind by system or user activity that can be examined as evidence — a log entry, registry key or cache file.

15

CCTV

Closed-circuit television — a video surveillance system whose footage is a common subject of video forensic examination.

16

Video Authentication

Assessing whether video footage is consistent with continuous, unaltered recording from the claimed source.

17

Expert Witness

An individual permitted to give opinion evidence to a court on technical matters within their expertise, owing a duty to the court.

The Guide

Digital Evidence & Digital Forensics

A practical, plain-language guide — the full table of contents below.

01

What is digital evidence?

Defining digital evidence and why it’s treated differently from physical evidence.

02

Types of digital evidence

Files, communications, metadata, logs, images, video and more.

03

Evidence preservation

Why devices shouldn’t be used, backed up or returned before examination.

04

Chain of custody

How a documented record of handling supports admissibility.

05

Forensic acquisition

Creating and verifying a forensic image before examination begins.

06

Computer forensics

What’s involved in examining laptops, desktops and servers.

07

Mobile forensics

Extraction methods and what they can and can’t recover.

08

Video evidence

Enhancement, authentication and the limits of both.

09

Image evidence

Metadata, manipulation detection and provenance.

10

Metadata

Why the data about the data often matters as much as the content.

11

Deleted data

What “deleted” actually means on different storage media.

12

Authentication

Assessing whether evidence is what it appears to be.

13

Examination and analysis

The difference between finding data and interpreting it.

14

Expert reports

What a properly prepared forensic report should contain.

15

Digital evidence in court

How findings are presented, tested and cross-examined.

16

Limitations and uncertainty

Why honest reporting includes what couldn’t be determined.

17

Engaging a digital forensic expert

When and how to bring an expert into a matter. We’re publishing this guide chapter by chapter. In the meantime, each topic above is already covered in summary on the relevant service page — start with the services overview or get in touch if you’d like something explained directly.

In Progress

Guides We’re Currently Writing

Longer-form pieces going deeper than the FAQ — not yet published.

How forensic examination differs from ordinary data recovery

Why the original digital evidence matters

Understanding hash values in digital forensic examinations

What happens when CCTV footage is exported from a DVR

Why screenshots aren’t always equivalent to original digital evidence

Limitations of deleted-data recovery

How mobile-device evidence can change through normal use

How to preserve a computer or phone before forensic examination

Can’t find what you’re looking for?

Get in touch and we’ll either point you to the right resource or answer the question directly — no obligation.