1/32
Vocabulary flashcards covering core concepts, legal standards, processes, and tools in digital forensics and investigations.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Digital Forensics
The application of computer science and investigative procedures for a legal purpose involving the analysis of digital evidence after proper search authority, chain of custody, validation with mathematics, use of validated tools, repeatability, reporting, and possible expert presentation.
Internet of Things (IoT)
Devices and objects connected to the Internet via sensors, software, and embedded chips, which may or may not be able to store data.
Inculpatory Evidence
Evidence that indicates guilt or incriminates a suspect in a criminal case.
Exculpatory Evidence
Evidence that tends to clear or exonerate a suspect.
Network Forensics
The discipline focused on determining how attackers gained access to a network, tracking user log-ons, URLs accessed, intrusion methods, and changes made to victim systems using log files.
Data Recovery
The retrieval of information that was deleted by mistake or lost during system failures, where the target data is typically known beforehand.
Investigations Triad
The three computing security functions comprising vulnerability/threat assessment and risk management, network intrusion detection and incident response, and digital investigations.

Vulnerability/Threat Assessment and Risk Management
A component of the computing security triad responsible for testing and verifying the physical and software integrity of stand-alone workstations and network servers.
Network Intrusion Detection and Incident Response
A component of the computing security triad that uses automated tools and firewall logs to detect external intruder attacks, track intrusion methods, deny network access, and collect evidence.
Digital Investigations
A component of the computing security triad that manages investigations and conducts forensic disk imaging and analysis on systems suspected of containing evidence.
Insider Threat
A person working for a company as an employee or contractor who has access to the corporate network and steals or destroys corporate data or distributes malware.
Digital Evidence First Responder (DEFR)
A person with the skill and training to arrive on an incident scene, assess the situation, and take precautions to acquire and preserve digital evidence, as defined by ISO 27037.
Digital Evidence Specialist (DES)
A person qualified to analyze digital data and determine when another specialist should be called in to assist with analysis, as defined by ISO 27037.
Five Steps of a Case
The sequential workflow for case management consisting of: Assess; Determine needed resources and specialists; Gather resources and specialists; Delegate, collect, and process evidence; and Present collected evidence in the form of a report.

Affidavit
A sworn statement of support of facts about or evidence of a crime submitted to a judge with a request for a search warrant.
Warning Banner
A banner displayed on computer screens upon startup or network logon that informs end users that the organization reserves the right to inspect computer systems and network traffic at will, establishing a waiver of expectation of privacy.
Authorized Requester
A designated executive or corporate entity with the defined power to initiate internal computer investigations and forensic analysis.
Industrial Espionage
The act of stealing sensitive or confidential company information and selling or transferring it to a competitor.
Chain of Custody
The documented route and record tracking digital evidence from the time it is collected until the case is closed or presented in court.
Bit-Stream Copy
A bit-by-bit forensic duplicate of an original drive or storage medium, copying every user-addressable sector including deleted files and unallocated space.
Bit-Stream Image
The file containing the bit-stream copy of all data on a disk or disk partition.
Interview
A conversation conducted to collect information from a witness or suspect about specific facts related to an investigation.
Interrogation
The process of questioning a suspect with the goal of obtaining a confession regarding a specific incident or crime.
Attorney-Client Privilege (ACP)
A legal privilege requiring all digital forensics findings, communications, and work conducted for an attorney to remain strictly confidential.
Hash Algorithm
A mathematical formula used in digital forensics to generate a unique hexadecimal value for data or files, allowing examiners to verify that digital evidence remains unaltered.
Message Digest 5 (MD5)
A common cryptographic hash algorithm used in digital forensics to generate a unique value for verifying file and drive integrity.
Secure Hash Algorithm 1 (SHA1)
A widely used cryptographic hash algorithm that produces a unique mathematical signature for validating digital evidence.
Federal Rules of Civil Procedure (FRCP)
The set of rules governing civil court proceedings in U.S. federal courts, updated in 2006 to incorporate rules regarding electronically stored information and discovery.
Curriculum Vitae (CV)
A document detailing an expert witness's education, training, publication history, and professional experience, used to qualify their testimony.
Deposition
A formal pre-trial examination under oath where a witness is questioned by opposing parties with a court reporter present.
Spoliation
The destruction, alteration, or concealment of evidence, which can subject a party to legal sanctions.
Examination Plan
A document created to guide direct examination testimony in court, detailing expected questions, key technical terms, and core forensic findings.
Abstract
A concise 150- to 200-word summary at the beginning of a forensic report that condenses the essential points, purpose, and findings of the investigation.