Instant messaging (IM) has changed the way people communicate with each other. However, the interactive and instant nature of these applications (apps) made them an attractive choice for malicious cyber activities such as phishing. The forensic examination of IM apps for modern Windows 8.1 (or later) has been largely unexplored, as the platform is relatively new. In this paper, we seek to determine the data remnants from the use of two popular Windows Store application software for instant messaging, namely Facebook and Skype on a Windows 8.1 client machine. This research contributes to an in-depth understanding of the types of terrestrial artefacts that are likely to remain after the use of instant messaging services and application software on a contemporary Windows operating system. Potential artefacts detected during the research include data relating to the installation or uninstallation of the instant messaging application software, log-in and log-off information, contact lists, conversations, and transferred files.
翻译:即时信息传递(IM)改变了人们的交流方式,然而,这些应用程序(应用程序)的交互性和即时性使他们成为像网钓等恶意网络活动的吸引选择。现代Windows 8.1(或以后)的IM应用程序的法证检查基本上尚未探索,因为平台相对较新。在本文件中,我们力求确定使用两个流行的Windows Store应用软件即时信息传递(即Windows 8.1客户机上的Facebook和Skype)应用软件(即脸书和Skype)的剩余数据。这一研究有助于深入了解在使用即时信息服务以及现代Windows操作系统应用软件后可能留下的陆生手工艺品类型。研究期间发现的潜在手工艺品包括与安装或未安装即时信息应用软件、登录和登录信息、联系名单、交谈和转移文件有关的数据。