Windows Instant Messaging App Forensics: Facebook and Skype as Case Studies
Teing Yee Yang, Ali Dehghantanha, Kim-Kwang Raymond Choo, Zaiton Muda

TL;DR
This paper investigates the forensic artifacts left by Facebook and Skype instant messaging apps on Windows 8.1, revealing data remnants that can aid digital investigations of modern Windows platforms.
Contribution
It provides an in-depth analysis of residual data artifacts from Facebook and Skype on Windows 8.1, a relatively unexplored area in digital forensics.
Findings
Detected installation and uninstallation artifacts
Identified login/logout and contact list remnants
Found conversation and file transfer data
Abstract
Instant messaging (IM) has changed the way people communicate with each other. However, the interactive and instant nature of these applications (apps) made them an attractive choice for malicious cyber activities such as phishing. The forensic examination of IM apps for modern Windows 8.1 (or later) has been largely unexplored, as the platform is relatively new. In this paper, we seek to determine the data remnants from the use of two popular Windows Store application software for instant messaging, namely Facebook and Skype on a Windows 8.1 client machine. This research contributes to an in-depth understanding of the types of terrestrial artefacts that are likely to remain after the use of instant messaging services and application software on a contemporary Windows operating system. Potential artefacts detected during the research include data relating to the installation or…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
