Blog >> Android Facebook Messenger

Investigating Android Facebook Messenger

29/09/2023 Friday

Facebook Messenger is a cross platform instant messaging application from Meta. Facebook Messenger is the main instant messaging application for Facebook, and Instagram. The application provides users with the ability to exchange messages, media, files, and supports voice and video, These features available in private chats as well as group chats.

Digital Forensics Value of Android Facebook Messenger


Android Facebook Messenger is a treasure trove for forensic analysts, brimming with valuable artifacts like accounts, activities, shared files, calls, messages, and media. This wealth of information can make play an important role in digital forensics investigations; where it can help identifying people, location and more.


Location of Android Facebook Messenger Artifacts


Android Facebook Messenger artifacts can be found at the following location:
data/user/0/com.facebook.orca/databases/threads_db2


Analyzing Android Facebook Messenger Artifacts with ArtiFast


This section will discuss how to use ArtiFast to extract Facebook Messenger from Android device and what kind of digital forensics insight we can gain from the artifacts.

After you have created your case and added evidence for the investigation, at the Artifact Selection phase, you can select Android Facebook Messenger artifacts:






Once ArtiFast parser plugins complete processing the artifact for analysis, it can be reviewed via “Artifact View” or “Timeline View,” with indexing, filtering, and searching capabilities. Below is a detailed description of Android Facebook Messenger artifacts in ArtiFast.


Android Facebook Messenger Messages Artifact

Android Facebook Messenger Contacts Artifact

Android Facebook Messenger Calls Artifact

Android Facebook Messenger Rooms Artifact

Android Facebook Messenger Attachments Artifact

Android Facebook Messenger Threads Artifact



For more information or suggestions please contact: [email protected]