Based in Sheffield, UK, Dr. Ali Dehghantanha is a researcher in cyber security and digital forensics with special focus on application of machine learning and data analytic techniques in cyber threat hunting and intelligence. 

Windows Instant Messaging App Forensics: Facebook and Skype as Case Studies

Hi All,


Another research result of our cyber forensics research team titled "Windows Instant Messaging App Forensics: Facebook and Skype as Case Studies" is published at PLOSONE journal. Here is the link to final version of the paper and following is the paper abstract: 

Instant messaging (IM) has changed the way people communicate with each other. However, the interactive and instant nature of these applications (apps) made them an attractive choice for malicious cyber activities such as phishing. The forensic examination of IM apps for modern Windows 8.1 (or later) has been largely unexplored, as the platform is relatively new. In this paper, we seek to determine the data remnants from the use of two popular Windows Store application software for instant messaging, namely Facebook and Skype on a Windows 8.1 client machine. This research contributes to an in-depth understanding of the types of terrestrial artefacts that are likely to remain after the use of instant messaging services and application software on a contemporary Windows operating system. Potential artefacts detected during the research include data relating to the installation or uninstallation of the instant messaging application software, log-in and log-off information, contact lists, conversations, and transferred files.


Please cite the paper as: 

  • Teing Yee Yang, Ali Dehghantanha, Kim-Kwang Raymond Choo, Zaiton Muda, "Windows Instant Messaging App Forensics: Facebook and Skype as Case Studies", PLOSONE, Vol.11 Issue 3,  (JCR IF 2014: 3.234), DOI: 10.1371/journal.pone.0150300

SugarSync forensic analysis

Forensic Investigation of OneDrive, Box, GoogleDrive and Dropbox Applications on Android and iOS Devices