Glossary
AppleDouble (._ files)
The ._name companion files macOS writes on volumes without extended attributes, such as exFAT, FAT or SMB, to keep a file's xattrs.
When macOS copies a file to a file system without extended attributes, such as exFAT, FAT or an SMB share, it writes the attributes into an AppleDouble companion file named ._name next to the original. ZIPs made with Finder's "Compress" carry the same data as __MACOSX/._name entries; Velociraptor's MacOS.Forensics.AppleDoubleZip reads those.
This matters for provenance because the quarantine attribute and kMDItemWhereFroms travel into the ._ file. A document copied to an exFAT USB stick can still show where it was downloaded from and which event UUID it belongs to, even though the copy itself leaves no trace in quarantine data. See a macOS download investigation walkthrough.