πŸ‘₯ Communication

πŸ’¬ Slack

These are primarily my course notes from Slacking on insider threat by Magnet Forensics. Thank you, guys, for sharing! I will put a quote paragraph with a πŸ’‘at the beginning whenever I have some ideas or thoughts along the way.

Instant messaging with channels and file sharing. Also, provides logs and eDiscovery.

Cloud-based, collection is not enough (non reviewable format), your plan matters, tons of functionality.

  • Workspaces
  • Channels
  • DMs

With certain settings users of workspace can override retention settings. It’s recommended to turn this feature off, so that all logs are preserved.

πŸ“¬ Mail

General Reference

πŸ’¬ Messaging Data

Electron is a framework that is available for building applications, cross-platform. You’re creating a web-application that can be used as a desktop one (implementing both back- and frontend). Backend - node.js, and frontend - Chrome. So, a lot of artifacts can be shared with Chrome and buddies. It’s in wide use. For example, ⚠️ WhatsApp and Skype use it.

Skype

Tools πŸ› : Belkasoft EC, SkypeLogView (NirSoft)

C:\Users\%Username%\AppData\Roaming\Skype.

Skype: Path: C:| Users\ \*\AppData\ Local\ Packages\Microsoft.SkypeApp\_\*\ Localstate\\*\main. db
Skype: Path: C:\Documents and Settings\\*\Application Data\Skype\\*\main.db

Xbox

Windows: C:\Users\%Username%\AppData\Local\LocalState\ModelManager\Messaging.

WhatsApp

*This article is a summary of all possible location of WhatsApp app on mobile and desktop and the recommendations on acquisition and analysis. *