SubscribeGo ProYour plan Settings

A

AES-256-GCM
AES encryption with a 256-bit key, in Galois/Counter Mode, which both encrypts and authenticates: a file that has been altered, or a wrong key, fails to decrypt rather than producing rubbish. It is what browsers provide through the Web Crypto API, and what the tools here use when they encrypt a file or a message with a passphrase, after turning the passphrase into a key.
Shown by CAPSULE, CIPHER, JOURNAL. Guide: Sending a file without it sitting on a server.
age
A small, modern file encryption format and tool, designed by Filippo Valsorda as a simpler replacement for encrypting files with PGP. A key pair is two short strings, the public one beginning age1; a file can be encrypted to several recipients, or to a passphrase. It has no signatures, no web of trust and no configuration.
Shown by KEYRING.
Authenticode
Microsoft's way of signing Windows programs and drivers: a certificate and a signature over the file's hash, stored inside the Portable Executable itself. Windows shows the publisher from it. A valid signature says who signed the file and that it has not changed since; it says nothing about whether the program is safe.
Shown by VOUCH.

B

Base rate (base rate fallacy)
How common something is before any test is applied. An alert that is 99 per cent accurate, on an event that happens once in ten thousand cases, is wrong about a hundred times for every time it is right. Ignoring the base rate, the base rate fallacy, is why most alerts from a good detector can still be false.
Shown by BASERATE.
Bates numbering
Numbering every page of a set of documents in one run, with a prefix, such as ABC000001 to ABC000450, so any page can be cited exactly and a missing one is noticed. It is the standard way documents are produced in disclosure and litigation. The number is stamped on the page itself, usually at the foot.
Shown by EXHIBIT, BUNDLE, STAPLE. Guide: Bates numbering a bundle.
Beaconing
Malware checking in with its controller at regular intervals, to ask for instructions. On a network it shows as one machine contacting the same address again and again at a steady rhythm, often in small requests of the same size, day and night. Finding that rhythm in a connection log is one of the more reliable signs of an infected machine.
Shown by BEACON, WIRE. Guide: Spotting malware beaconing in a connection log.
Benford's law
The observation that in many sets of naturally occurring numbers, such as invoice amounts or populations, the first digit is 1 about 30 per cent of the time and 9 less than 5 per cent. Made-up numbers tend to spread more evenly. It only holds for data spanning several orders of magnitude without caps or assigned values, so a failed test is a reason to look, not proof.
Shown by DIGITS. Guide: Testing a column for invented numbers.
Browser fingerprint
What a website can learn about your browser without cookies: screen size, time zone, language, fonts, graphics card, and how the browser draws a hidden image. Together these are often close to unique, so a site can recognise a returning visitor who has cleared their cookies or is in a private window.
Shown by FINGERPRINT, COOKIEAUDIT. Guide: What a website learns before you click.

C

Certificate chain
The sequence of certificates from a website's or signer's own certificate up to a root the computer already trusts: each is signed by the next one up. A chain that is incomplete, expired at any link, or ends in a root the computer does not hold is why a certificate that looks valid is still refused.
Shown by CERTLENS.
Chain of custody
The written record of who held a piece of evidence, when, and what they did with it, from the moment it was collected. For digital evidence it usually records a hash of each file when it was taken, so that anyone can later show the file is the one collected and has not changed.
Shown by CHAIN, PROOF, ATTEST. Guide: Checking a file has not been changed.
Contemporaneous note
A note made at the time of an event, or as soon after as practicable, while memory is fresh. Courts and tribunals give such notes more weight than an account written later, and a witness may be allowed to refresh their memory from one. Its value depends on showing when it was written and that it has not been altered since.
Shown by THREAD, LOGBOOK. Guide: Keeping a record of a dispute.
Content-Security-Policy (CSP)
A header a website sends telling the browser where the page may load scripts, styles, pictures and connections from. A strict one stops injected code from running and stops a page from sending data anywhere unlisted. It is also one way to check a site's claim that nothing is sent elsewhere: the policy is visible in the browser.
Shown by RAMPART.
Critical path
The longest chain of tasks in a project that depend on one another. Its length is the shortest time the project can take, and any delay to a task on it delays the finish. Tasks off the critical path have slack, called float, and can slip by that much without moving the end date.
Shown by PLAN. Guide: An alternative to Microsoft Project.

D

DGA (domain generation algorithm)
A domain generation algorithm: code in malware that makes up new domain names each day from a date or a seed, so its controllers only need to register one of them. In a DNS log the names look random, like xkqjvbtr.info, and most of them fail to resolve.
Shown by DGA. Guide: Finding generated domains in a DNS log.
Digital signature
A value made from a document's hash with a private key, which anyone with the matching public key can check. If the document changes by one byte, or the key is different, the check fails. A drawn or typed signature on a PDF is only a picture; a digital signature is what shows the file has not changed since it was signed.
Shown by PACT, SIGIL, PDFSIG. Guide: Signing a PDF.
DKIM
DomainKeys Identified Mail: the sending mail server signs chosen headers and the body of each message, and publishes its public key in DNS. A receiving server checks the signature, which shows the message came through a server for that domain and was not changed on the way. It does not by itself check the From address a person sees.
Shown by DMARC, HEADERPROOF, MAILBOX. Guide: Telling whether an email is genuine.
DMARC
A DNS record in which a domain says what receivers should do with mail claiming to come from it that fails SPF or DKIM, or passes them only for some other domain: nothing, send it to spam, or reject it. It is what ties SPF and DKIM to the From address a reader sees, and it asks for reports on failures.
Shown by DMARC, HEADERPROOF. Guide: Telling whether an email is genuine.

E

Ed25519
A public-key signature scheme on the curve Edwards25519, specified in RFC 8032. Keys are 32 bytes and signatures 64, it is fast, and it avoids several ways older schemes could be misused. SSH, minisign, signify, age's key format and modern OpenPGP keys use it, and OBSCURA Pro keys are signed with it.
Shown by KEYPRINT, SIGIL. Guide: SSH key fingerprints.
Entropy
In a file, a measure of how unpredictable its bytes are, from 0 to 8 bits per byte. Text and code sit around 4 to 5; compressed or encrypted data is close to 8. A section of a file with high entropy where none is expected, inside a document or a program, often means something packed or encrypted is hidden there.
Shown by ENTROPY, SPECIMEN.
Error level analysis (ELA)
Saving a JPEG again at a known quality and comparing it with the original. Areas that were pasted in or edited after the last save often recompress differently from the rest and stand out. It suggests where to look; lighting, sharpening and plain surfaces also stand out, so it proves nothing alone.
Shown by TAMPER. Guide: Telling whether a photo was edited.
EXIF (Exchangeable image file format)
The block of data a camera or phone writes into a photo: the make and model, the settings, the time, often the GPS position, and a small thumbnail. It survives most copying and many uploads. It is read and written as tags, defined by the camera industry's CIPA DC-008 standard, and removing it is the usual first step before sharing a photo.
Shown by EXIF, CLOAK. Guide: The three metadata standards.

H

HAR (HTTP Archive)
An HTTP Archive: a JSON file, saved from a browser's developer tools, recording every request a page made with its headers, cookies, timings and often the responses. Support desks ask for them. One saved while signed in carries the session cookies, which can let someone else use the account.
Shown by INTERCEPT.
Hash (digest, checksum)
A fixed-length fingerprint of a file, worked out from every byte of it. The same file always gives the same hash; any change gives a different one, and it is not practical to make two different files with the same SHA-256 hash. Publishing a hash lets anyone check a copy is exactly the original.
Shown by CHECKSUM, PROOF. Guide: Checking a file has not been changed.
Hash set (NSRL)
A list of the hashes of known files, used to sort a large collection quickly: files matching a set of known operating system files can be set aside unread, and files matching a set of known illegal or malicious material are flagged. The best known is the US NIST's National Software Reference Library.
Shown by SIEVE. Guide: Sorting files by hash.
HEIC (HEIF)
The picture format iPhones use by default: images compressed with HEVC inside a HEIF container. It is usually much smaller than a JPEG of the same quality and carries the same EXIF data, but Windows and most browsers other than Safari do not open it without extra software.
Shown by PHOTO, SHRINK. Guide: Opening a HEIC file.
Homoglyph (lookalike character)
A character that looks like another: Cyrillic а and Latin a, or the digit 0 and the letter O. Swapping them into a domain name gives an address that reads as a familiar one and belongs to someone else. Browsers show some such names in their punycode form, beginning xn--, but not all.
Shown by HOMOGLYPH, UNSEEN.

I

Incremental update
The way a PDF is edited without rewriting it: the changes are added to the end of the file, and the old objects stay where they were. An edited or redacted PDF can therefore still hold the earlier text, deleted pages and removed pictures, recoverable by anyone who reads the file rather than looking at it.
Shown by STRATA, SEAL. Guide: What a PDF keeps after a page is deleted.
IOC (indicator of compromise)
An indicator of compromise: a detail that shows a system may have been attacked, such as a file hash, a domain, an IP address or a registry key used by known malware. IOCs are shared between organisations so each can search its own logs for them.
Shown by TRAWL, PARCEL, YARA.
IPTC
Fields for describing a photo for publication, set by the International Press Telecommunications Council: caption, credit, copyright, the photographer's name and contact details, and keywords. Newsrooms and photo agencies fill them in; they often carry a name and phone number that EXIF does not.
Shown by CLOAK, EXIF. Guide: The three metadata standards.

J

JWT (JSON Web Token)
A JSON Web Token: a small signed statement, in three base64 parts separated by dots, that websites use to show who is signed in. The middle part is only encoded, not encrypted, so anyone holding a token can read what it says; the signature only stops it being changed. A token pasted into a website can be used by that website.
Shown by JOT, JWKS.

K

k-anonymity
A test for a dataset about people: every combination of the details that could identify someone, such as postcode, age and sex, must be shared by at least k records. With k of 5, each person is indistinguishable from at least four others. It does not protect a sensitive value if all k people share it.
Shown by CROWD. Guide: Checking a dataset before release.
Key derivation (PBKDF2)
Turning a passphrase into an encryption key with a function, such as PBKDF2, scrypt or Argon2, designed to be slow. Each guess an attacker tries then costs the same work, so a long passphrase cannot be tried millions of times a second. A random salt stored with the file makes the same passphrase give a different key each time.
Shown by CIPHER, CAPSULE. Guide: Making a password you can remember.

L

LNK file (shortcut file)
A Windows shortcut. Besides the path of its target, it records the target's size and times, and often the volume's serial number and the name of the machine it was made on. Windows makes them for recently opened files, so they show that a file was opened even after the file is gone.
Shown by SHORTCUT.
LSB steganography (least significant bit)
Hiding data in the least significant bit of each colour value in an image. Changing that bit alters a pixel by one shade in 256, which no eye sees, and a picture of a few megapixels can hold hundreds of kilobytes. It survives only lossless formats: saving as JPEG destroys it.
Shown by STEGOSCAN, PALIMPSEST. Guide: A message that may be hidden in an image.

M

Macro (VBA)
A program inside an Office document, written in VBA, that can run when the document opens or a button is pressed. Macros can read and write files and download others, which is why documents with them are a common way malware arrives, and why Office blocks macros in files from the internet by default.
Shown by MACROLENS, DISARM.
Magic number (file signature)
The first few bytes of a file, which identify its real type whatever the extension says: %PDF for a PDF, PK for a zip (and so for .docx and .xlsx), FF D8 FF for a JPEG, MZ for a Windows program. A file whose magic number does not match its extension deserves a second look.
Shown by MAGIC, HEX, X-RAY. Guide: A .docx that opens as XML.
MBOX
A mailbox format that keeps many emails in one text file, each beginning on a line that starts with From and a space. Gmail's Takeout exports mail as MBOX, and Thunderbird and Apple Mail can import it. Any text editor can open one, though a large mailbox is hard to read that way.
Shown by POSTBAG, POST. Guide: What a Google Takeout export contains.
MD5
A hash function from 1991 that gives a 128-bit digest. It is broken for security: two different files with the same MD5 can be made deliberately. It is still used to sort and deduplicate files, where nobody is attacking the list, and many older hash sets exist only as MD5.
Shown by SIEVE, CHECKSUM. Guide: Sorting files by hash.
Metadata
Data about a file rather than its content: who made it, when, with what, and where. Photos carry the camera and the place, Word documents the author and editing time, PDFs the software that made them. It travels with the file and is rarely shown, which is how it gives away more than the sender meant.
Shown by X-RAY, CLEANROOM, SCRUB. Guide: What is hidden in a Word document.
$MFT
The Master File Table of an NTFS volume: one record, usually 1,024 bytes, for every file and folder, holding its name, size, where its data is, and two sets of timestamps. Deleted files keep their record until it is reused, so the $MFT often still lists files that are gone. Reading it is how an examiner finds files whose dates were changed, because the two sets of timestamps are set by different parts of Windows.
Shown by MFT, TIMESTOMP.
MITRE ATT&CK
A public catalogue, kept by the MITRE Corporation, of the techniques attackers use, from getting in to moving around and taking data out, each with an identifier such as T1059. Security teams map what they have seen onto it so that reports from different sources describe the same behaviour the same way.
Shown by MITRE.
MPF (Multi-Picture Format)
The Multi-Picture Format, a CIPA standard for storing more than one image in a JPEG. Phones and cameras use it to keep a large preview, a depth map or a second exposure after the main picture, indexed in a block marked MPF. Cropping or editing the main picture often leaves those extra images untouched.
Shown by STEGOSCAN, CLOAK. Guide: The thumbnail hidden inside a photo.

O

OCR (optical character recognition)
Optical character recognition: reading the letters in a picture of text, such as a scan or a photo of a page, and turning them into text that can be searched and copied. It gets clean print nearly right and handwriting and poor scans much less so, so the result needs checking.
Shown by OPTIC, RECEIPTS. Guide: Reading text out of a picture.
OpenPGP (PGP, GPG)
The standard behind PGP and GnuPG for signing and encrypting files and email, now RFC 9580. Each person has a key pair; others check signatures with the public key and encrypt to it. Software projects publish a .asc or .sig file beside each download so it can be checked against the developers' key.
Shown by SIGIL. Guide: Checking a file has not been changed.

P

PACE detention clock
In England and Wales, the time limits on keeping someone in police detention without charge, set by the Police and Criminal Evidence Act 1984. The clock usually starts on arrival at the station, with reviews due at set points and a normal limit of 24 hours, extendable in defined circumstances.
Shown by CUSTODY. Guide: The PACE detention clock.
pcap (packet capture)
The file format tcpdump and Wireshark save network traffic in: a short header, then each packet as it was seen on the wire with the time it was captured. Its successor, pcapng, can also record several interfaces and comments. Reading one shows every address a device spoke to and, for unencrypted traffic, what was said.
Shown by WIRE. Guide: Reading a packet capture.
Prefetch (.pf file)
Files Windows writes to C:\Windows\Prefetch to start programs faster. Each records a program's name, how many times it has run, when it last ran (the last eight times, since Windows 8), and the files it loaded in its first seconds. They survive the program being deleted, so they are a standard record of what has run on a machine.
Shown by PREFETCH.
Pseudonymisation
Replacing names and other direct identifiers with codes, such as P-0042, while keeping the same code for the same person throughout, so that the data can still be analysed. Under the UK and EU GDPR pseudonymised data is still personal data, because whoever holds the key, or enough other details, can put the names back.
Shown by ANON, ALIAS. Guide: Anonymising a spreadsheet.

R

Received header
A line each mail server adds to the top of a message as it passes through, saying which server it came from, which received it, and when. Read from the bottom up, they trace the message's route. Only the ones added by servers you trust can be believed, since a sender can write false ones below them.
Shown by MAILBOX, HEADERPROOF. Guide: Telling whether an email is genuine.
Record of processing activities (ROPA, Article 30 record)
The record Article 30 of the UK and EU GDPR asks most organisations to keep: what personal data they process, why, about whom, who it is shared with, where it goes abroad, how long it is kept, and how it is protected. A regulator can ask to see it.
Shown by ROPA.
Redaction
Removing information from a document so that it cannot be recovered, not just hidden. In a PDF, a black box drawn over text leaves the text underneath, where it can be copied or extracted; a true redaction removes the text and any image data under the box, and the document's history, before it is sent.
Shown by SEAL, REDACTLOG, SCREENSHIELD. Guide: Recovering text from under a redaction.
RFC 3161 timestamp (trusted timestamp)
A signed statement from a timestamping authority that a given hash existed at a given time, defined in RFC 3161. It proves a file was in its present form no later than that moment, without the authority seeing the file. It comes as a .tsr response, checked against the file's hash and the authority's certificate.
Shown by STAMP.
rsid (revision save ID)
The revision save ID Word gives each editing session: a random eight-digit number stamped on every paragraph and run of text typed in that session, and listed in the document's settings. Comparing them shows which parts of a document were written together, and which were pasted in or added later.
Shown by LINEAGE, DOCSCRUB. Guide: What is hidden in a Word document.

S

S/MIME
A standard for signing and encrypting email with X.509 certificates, widely used in companies and governments. A signed message carries an attachment called smime.p7s holding the sender's certificate and the signature. A mail program that does not understand S/MIME shows that attachment instead of a signed-message badge.
Shown by SIGNET, CERTLENS. Guide: The smime.p7s attachment.
SAML
Security Assertion Markup Language: the XML that a company's sign-in service sends to an application to say who someone is, used for single sign-on. The response is signed; an application that checks the signature carelessly can be fooled by an altered response, which is why they are examined when sign-in goes wrong.
Shown by ASSERT.
setupapi.dev.log
A Windows log, in C:\Windows\INF, that records each time a device driver is installed, including the first time each USB storage device is plugged in, with its serial number and the date and time. It is one of the main records used to show that a particular drive was connected to a PC.
Shown by PLUGGED. Guide: Telling whether a USB drive was plugged in.
SHA-256
A hash function from the SHA-2 family, specified by NIST in FIPS 180-4, that gives a 256-bit digest written as 64 hexadecimal characters. No two different files with the same SHA-256 have ever been found. It is what download pages publish to check files against, and what evidence logs record.
Shown by CHECKSUM, PROOF, SIEVE. Guide: Checking a file has not been changed.
Shamir's secret sharing (Shamir sharing)
A way of splitting a secret into n pieces so that any k of them together recover it and fewer than k reveal nothing at all, devised by Adi Shamir in 1979. A backup split three ways with any two needed survives the loss of one piece and the theft of another.
Shown by SHARD.
Spaced repetition
Reviewing a card just before you would forget it: a card you know comes back after longer and longer gaps, one you miss comes back soon. It is the method behind Anki and most flashcard apps, and it takes far fewer reviews to remember something than going over everything equally.
Shown by Cards. Guide: Flashcards without an account.
SPF (Sender Policy Framework)
Sender Policy Framework: a DNS record in which a domain lists the servers allowed to send its mail. A receiving server checks whether the server that delivered a message is on the list for the domain in the envelope sender, which is not necessarily the From address the reader sees.
Shown by DMARC, HEADERPROOF. Guide: Telling whether an email is genuine.
SSH key fingerprint
A short hash of an SSH public key, shown as SHA256: followed by 43 characters, or in older tools as MD5 pairs of hex digits. Comparing the fingerprint a server shows on first connection with one obtained another way is how you know you are talking to the right server.
Shown by KEYPRINT. Guide: SSH key fingerprints.
Steganography
Hiding a message inside something that looks ordinary, such as a picture, a sound or a text, so that nobody suspects there is a message at all. Encryption hides what a message says; steganography hides that there is one. The two are often combined.
Shown by STEGOSCAN, PALIMPSEST, GLYPH. Guide: A message that may be hidden in an image.
Subject access request (SAR, DSAR)
A request by a person to an organisation for a copy of the personal data it holds about them, a right under Article 15 of the UK and EU GDPR. The organisation must normally answer within one month of receiving it, which can be extended by two further months for complex or numerous requests.
Shown by DSAR, REQUEST.

T

Timestomping
Changing a file's timestamps to hide when it was really created or modified. On NTFS, tools that do this usually change the times in the file's $STANDARD_INFORMATION attribute but not the ones in $FILE_NAME, which Windows sets itself, so a mismatch between the two, or times with the fractions of a second all zero, gives it away.
Shown by TIMESTOMP, MFT.
TNEF (winmail.dat)
Transport Neutral Encapsulation Format: Outlook's way of packing a message's rich formatting and attachments into one attachment, winmail.dat. Mail programs other than Outlook see only that file and not the attachments inside it, which is why a message from an Outlook user sometimes arrives with nothing but winmail.dat.
Shown by SATCHEL. Guide: Opening winmail.dat.
TOTP (two-step code)
A time-based one-time password, the six-digit code an authenticator app shows for two-step sign-in, defined in RFC 6238. The app and the website share a secret when you set it up, and each works out the same code from the secret and the current 30-second period, with no network needed.
Shown by TOKEN.
Tracked changes
Word's record of every insertion and deletion made while tracking was on, with who made it and when, kept in the document until each change is accepted or rejected. Turning off the display of markup hides them without removing them, so a document sent as final can still carry every earlier draft's wording.
Shown by DOCSCRUB, REDLINE, SCRUB. Guide: What is hidden in a Word document.
Tracking pixel (web beacon, spy pixel)
A picture one pixel square, usually invisible, placed in an email or a page so that loading it tells the sender's server when it was opened, from what address and in which program. Mail programs that load pictures automatically report every opening this way.
Shown by UNBEACON.

U

UTM parameters
The utm_source, utm_medium and utm_campaign parts added to the end of a link so the website it points to can count where its visitors came from. They are harmless to remove and the link still works. Other added parameters, such as fbclid and gclid, identify a particular click.
Shown by SANILINK. Guide: The tracking on a link.

X

X.509 certificate (certificate)
The standard form of certificate, defined in RFC 5280, that binds a public key to a name and is signed by a certificate authority. Websites, signed email, signed PDFs and signed Windows programs all use them. It states who it was issued to, by whom, what it may be used for, and when it expires.
Shown by CERTLENS.
XMP
Adobe's Extensible Metadata Platform: metadata written as XML inside a file, used by Photoshop, Lightroom and many other programs. Besides captions and ratings it can carry the full history of edits made in Adobe software and the names of files that were placed into the picture.
Shown by CLOAK, EXIF. Guide: The three metadata standards.

Y

YARA
A language for writing rules that match files, mostly used to recognise malware families: a rule lists strings or byte patterns and a condition, such as two of these strings and a file under 1 MB. Security teams share rules so each can search its own files.
Shown by YARA.

Z

Zero-width character
A character that takes up no space and cannot be seen, such as the zero-width space or joiner. Pasted into text it can split a word so a filter misses it, carry a hidden watermark that identifies who received a copy, or hide instructions for a machine to read.
Shown by UNSEEN, GLYPH, LANTERN. Guide: What you hand over when you paste into an AI.
ZipCrypto (traditional PKWARE encryption)
The original password protection in the zip format, from the early 1990s. It is weak: given one file known to be in the archive, the password can be broken. Zips can use AES instead, which is strong, but Windows' built-in zip support opens only ZipCrypto. In both, the file names inside stay readable.
Shown by STRONGBOX, PACK. Guide: A zip Windows will not open.