Skip to content

Series

Messaging forensics guides

7 posts in this series. Read them in order or jump to any one.

  1. What Is Messaging Forensics? A Practitioner's Primer

    Messaging forensics explained: acquisition options, a normalized message model, the timestamp zoo, evidence hashing and the pitfalls that break timelines.

  2. Email Header Forensics: Received, SPF, DKIM and MIME

    Read Received chains bottom-up, compare Return-Path, From and Reply-To, interpret SPF/DKIM/DMARC results and decode MIME across EML, MBOX, MSG and PST.

  3. Microsoft Teams Forensics: Purview, Graph and Cache

    Acquire Teams chats via Purview eDiscovery, the Microsoft Graph chatMessage API or a Teams (free) export, and know which fields, edits and deletions matter.

  4. Slack Export Forensics: ZIP Layout, ts and Tombstones

    What a Slack workspace export contains, how to read ts, thread_ts, edits, tombstones and message markup, what exports leave out, and how to verify integrity.

  5. WhatsApp forensics: chat exports, msgstore.db, ChatStorage

    Where WhatsApp evidence lives on Android and iOS, how chat exports, msgstore.db and ChatStorage.sqlite differ, and how to read their timestamps correctly.

  6. Discord forensics: data packages and snowflake IDs

    What the Discord data package contains, why it only holds the owner's messages, how to decode snowflake IDs, and when to use DiscordChatExporter output.

  7. iMessage forensics: chat.db, sms.db and Cocoa time

    How to acquire macOS chat.db and iOS sms.db, read the message tables, convert Cocoa timestamps, and recover text, edits, unsends and tapbacks.

All posts in this series

Messaging forensics explained: acquisition options, a normalized message model, the timestamp zoo, evidence hashing and the pitfalls that break timelines.
Read Received chains bottom-up, compare Return-Path, From and Reply-To, interpret SPF/DKIM/DMARC results and decode MIME across EML, MBOX, MSG and PST.
Acquire Teams chats via Purview eDiscovery, the Microsoft Graph chatMessage API or a Teams (free) export, and know which fields, edits and deletions matter.
What a Slack workspace export contains, how to read ts, thread_ts, edits, tombstones and message markup, what exports leave out, and how to verify integrity.
Where WhatsApp evidence lives on Android and iOS, how chat exports, msgstore.db and ChatStorage.sqlite differ, and how to read their timestamps correctly.
What the Discord data package contains, why it only holds the owner's messages, how to decode snowflake IDs, and when to use DiscordChatExporter output.
How to acquire macOS chat.db and iOS sms.db, read the message tables, convert Cocoa timestamps, and recover text, edits, unsends and tapbacks.