Notifications
Clear all

Facebook chats

21 Posts
11 Users
0 Reactions
4,109 Views
(@jaappie)
Active Member
Joined: 14 years ago
Posts: 11
Topic starter   [#9842]

Hello everyone,

Does anyone know if it's still possible to recover facebook chat artifacts through EnCase?
I've been testing with a VM and chatting around, doing keyword searches. But nothing comes up. Am I missing something, or did Facebook changed their way of storing information on the system?



   
Quote
ForensicRanger
(@forensicranger)
Estimable Member
Joined: 17 years ago
Posts: 122
 

What search string are you using?



   
ReplyQuote
chrisdavies
(@chrisdavies)
Trusted Member
Joined: 17 years ago
Posts: 55
 

i saw an EnScript somewhere once that did search and find i will try and dig it out



   
ReplyQuote
(@jaappie)
Active Member
Joined: 14 years ago
Posts: 11
Topic starter  

The search strings I used were the words that were sent/received throughout the conversation.



   
ReplyQuote
(@robert-maierhofer)
New Member
Joined: 14 years ago
Posts: 1
 

You can find an Encase Script here - I didn't try it yet with Encase 7 - so I don't know if it will work with it.

In case you want to find the strings on your own try [{„msg“{text“ because every chat starts with it. As far as I found out yet chats are only stored in the temporary internet files or their remainings.

Regards and let me know if it worked for you )



   
ReplyQuote
(@jaappie)
Active Member
Joined: 14 years ago
Posts: 11
Topic starter  

The EnScript isn't producing any results, just empty CSV files. I think it might be outdated. Facebook probably changed their structure, as the script is already 1 year old.

I'm only finding some messages in the System Volume Information, any thoughts?

Not finding anything in the temporary internet files.



   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 22 years ago
Posts: 3568
 

I know that EnCase is capable of recovering FB chat fragments; I assisted an LE who had done exactly that, and asked for my help in reassembling the conversation. They provided me with some samples and I wrote a script that ran through several hundred extracted JSON segments and reassembled the conversation, in order.



   
ReplyQuote
(@int-genericusername)
New Member
Joined: 15 years ago
Posts: 1
 

It's not encase but i found the best way to get back facebook chats and IE carved data is http//www.magnetforensics.com/products/internet-evidence-finder/ , Im not trying to sell it to you but it loads E01 images direct and i have always found more from this than with encase, might be worth a look at.



   
ReplyQuote
Belkasoft
(@belkasoft)
Joined: 17 years ago
Posts: 169
 

You can extract Facebook chats with the help of Belkasoft Evidence Center tool and then import them back to EnCase v.7 using a free EnScript provided here http//forensic.belkasoft.com/en/bec/en/Encase_Integration.asp.



   
ReplyQuote
(@jaappie)
Active Member
Joined: 14 years ago
Posts: 11
Topic starter  

As I'm a student, I can't buy expensive software.
The main goal of the project is to extract chat conversations through EnCase.

Are the messages encrypted or something? Because I only find some messages in the System Volume Information and the $LogFile.

@keydet89, would you mind sharing your script?



   
ReplyQuote
Page 1 / 3
Share: