1/29
Comprehensive vocabulary flashcards covering digital forensics concepts including data acquisition, disk partitioning (MBR/GPT), SSD architecture, RAID levels, and forensic analysis tools.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Filesystem layer
The data abstraction layer directly responsible for organizing block storage into files, directories, and associated metadata such as timestamps and permissions.
conv=noerror
An option for the dd utility that instructs it to continue copying after a read error occurs rather than aborting the process.
SHA-256
The cryptographic hash algorithm currently recommended as the minimum standard for new forensic acquisitions.
dc3dd
A forensic acquisition tool that provides integrated hashing (MD5, SHA-1, SHA-256, SHA-512), detailed activity logging, on-the-fly hash verification, and the ability to split output files.
Expert Witness Format (E01)
A forensic container format that supports built-in compression, embedded case metadata, per-chunk CRC32 checksums, and automatic file splitting.
GNU ddrescue
A utility used for acquiring data from physically failing drives with bad sectors, utilizing a mapfile to track progress and retry failed sectors.
Wear-leveling
A proprietary algorithm used by SSD controllers to distribute write operations evenly across flash cells, which results in logical block addresses being decoupled from physical locations.
Pseudo-physical acquisition
A term for block-level imaging noting that not all physical media areas—such as reallocated sectors and Host Protected Areas—are accessible through the standard HBA interface.
4Kn
A native 4K drive configuration under the Advanced Format standard featuring 4096ext−byte logical sectors and 4096ext−byte physical sectors.
TRIM
A SATA SSD command that flags specified logical blocks as no longer in use, allowing the controller to proactively erase them.
RAID 1
A RAID level that provides fault tolerance exclusively through mirroring, where each member disk holds a complete copy of the array's data.
Flash Translation Layer (FTL)
The component in an SSD responsible for wear leveling, garbage collection, bad block management, and over-provisioning.
Shannon entropy
A measure of randomness where a value of 7.9+ indicates significant randomness consistent with encryption, compression, or deliberate random fill.
RAID 5
A RAID configuration that uses distributed parity and can tolerate the loss of exactly one member disk, allowing reconstruction from the remaining n−1 disks.
Over-provisioned area
An SSD area inaccessible through standard host commands used by the FTL for background operations; it may retain remnants of deleted data not yet erased by TRIM.
SMART logs
Logs containing hardware health data including cumulative power-on hours, power cycle counts, sector reallocation counts, and historical error rates.
mdadm
The Linux tool used to reassemble a software RAID array from imaged member disks by reading metadata stored in superblocks.
Master Boot Record (MBR) Partition Table
A 64ext−byte section within the first 512ext−byte sector of a disk that defines up to four primary partitions.
0x83
The one-byte MBR type code used to identify a Linux native filesystem such as ext2, ext3, or ext4.
/dev/sdb5
The device node corresponding to the first logical partition on the second disk (/dev/sdb) in a Linux system.
GUID Partition Table (GPT)
A partitioning scheme that removes the 2extTiB per-disk capacity ceiling and provides redundant backup tables and CRC32 checksums for integrity.
LBA 1
The location in the GPT disk layout where the primary GPT header is stored.
mmls
A tool from The Sleuth Kit that displays unallocated inter-partition gaps and alignment regions missing from standard fdisk−l output.
LVM Abstraction Layers
The sequence of layers in Logical Volume Management: Physical Volume −> Volume Group −> Logical Volume.
bulk_extractor
A forensic tool that scans a disk image as a flat byte stream, ignoring filesystem structures to extract features like email addresses and URLs.
Forensic path
A string (e.g., 2097152-ZIP-4096-BASE64-128) that identifies an artifact's location, including its raw byte offset and any decompression/decoding steps taken to find it.
Stop list
A technique used to reduce analyst workload by supplying a list of known artifacts (like OS background noise) to be excluded from results.
sdhash
An approximate matching tool that produces a similarity score on a continuous scale rather than a binary match result to compare two artifacts.
Bloom filter
A data structure used in sdhash where the bitwise overlap between two filters is proportional to the number of shared byte-level features.
sdhash digest
An ordered sequence of 256ext−byte Bloom filters, typically one per 8ext−10extKB segment, totaling approximately 500extKB for a 1extGB input.