Series
Messaging forensics guides
7 posts in this series. Read them in order or jump to any one.
- What Is Messaging Forensics? A Practitioner's Primer
Messaging forensics explained: acquisition options, a normalized message model, the timestamp zoo, evidence hashing and the pitfalls that break timelines.
- Email Header Forensics: Received, SPF, DKIM and MIME
Read Received chains bottom-up, compare Return-Path, From and Reply-To, interpret SPF/DKIM/DMARC results and decode MIME across EML, MBOX, MSG and PST.
- Microsoft Teams Forensics: Purview, Graph and Cache
Acquire Teams chats via Purview eDiscovery, the Microsoft Graph chatMessage API or a Teams (free) export, and know which fields, edits and deletions matter.
- Slack Export Forensics: ZIP Layout, ts and Tombstones
What a Slack workspace export contains, how to read ts, thread_ts, edits, tombstones and message markup, what exports leave out, and how to verify integrity.
- WhatsApp forensics: chat exports, msgstore.db, ChatStorage
Where WhatsApp evidence lives on Android and iOS, how chat exports, msgstore.db and ChatStorage.sqlite differ, and how to read their timestamps correctly.
- Discord forensics: data packages and snowflake IDs
What the Discord data package contains, why it only holds the owner's messages, how to decode snowflake IDs, and when to use DiscordChatExporter output.
- iMessage forensics: chat.db, sms.db and Cocoa time
How to acquire macOS chat.db and iOS sms.db, read the message tables, convert Cocoa timestamps, and recover text, edits, unsends and tapbacks.