Slack is a cross-platform communication and productivity application
used by both individuals and organizations. It allows users to exchange
messages, files, and images within “Channels,” which are organized under
a Slack “Workspace.” Organizations can create multiple workspaces to
manage and monitor different teams. Within these, teams can set up
project-specific channels to collaborate and track progress. Slack
supports integration with a wide range of tools and services, including
Google Drive and Microsoft Teams. Its broad integration support,
flexible configuration, and centralized management distinguish it from
other collaboration platforms.
Slack is currently used by a wide variety of organizations around the
world. The platform is utilized by more than 750,000 businesses. With
its widespread adoption among both individuals and organizations, Slack
becomes a very important tool that should not be missed in digital
forensics investigations. Whether it's an organization's internal or
criminal case investigation, Slack artifacts can be a valuable source of
information. Artifacts such as user messages, channels, and attachments
can be a very rich source of information.
Information related to the user’s Slack can be found in the following
locations:
/private/var/mobile/Containers/Shared/AppGroup/<APP_GUID>/$random-UID_random-GID/ModelDatabase/db.sqlite
This section will discuss how to use ArtiFast to extract iOS Slack
artifacts from iOS and what digital forensic insights we can gain from
them.
After you have created your case and added evidence for the
investigation, at the Artifact Selection phase, you can select the iOS
Slack artifact.
Once ArtiFast parser plugins complete processing the artifact for analysis, it can be reviewed via “Artifact View” or “Timeline View,” with indexing, filtering, and searching capabilities. Below is a detailed description of iOS Slack artifact in ArtiFast.
iOS Slack Messages
iOS Slack Channels
iOS Slack Attachments
iOS Slack User Information
For more information or suggestions please contact: ekrma.elnour@forensafe.com