Blog >> Microsoft Messaging

Investigating Microsoft Messaging

05/01/2021 Tuesday

Microsoft Messaging is an instant messaging platform in Windows 8, Windows 10, and Windows 10 mobile environments. It provides messaging and voice/video calling services. SMS, MMS, and RCS messaging are all supported on the web edition. SMS messages sent via Skype and billing SMS messages from an LTE operator are the only features available on the desktop version.

Digital Forensics Value of Microsoft Messaging Artifacts

In Microsoft Messaging artifacts provide data about calls, messages, contacts, media, and the information exchange between Windows and linked devices. Tracking such information is critical during the digital forensic analysis process and helps us understand the types of artifacts that are likely to remain for digital forensics investigators.

Location of Microsoft Messaging Artifacts

Windows 10: %AppData%\Local\Packages\Microsoft.Messaging_xxxxxxxxxxxxx\LocalState\<user id>\main.db

Structure of Microsoft Messaging Artifacts

The structure of Microsoft Messaging artifacts is an SQLite Database that contains multiple tables each with information regarding the users’ actions on the software.

Analyzing Microsoft Messaging Artifacts with ArtiFast Windows

This section will discuss how to use ArtiFast Windows to analyze Microsoft Messaging artifacts from Windows machines and what kind of digital forensics insights we can gain from the artifacts.

After you have created your case and added evidence for investigation, at the Artifacts Parser Selection Phase, you can select Microsoft Messaging artifacts:

Once ArtiFast parser plugins complete processing artifacts for analysis, it can be reviewed via “Artifact View” or “Timeline View,” with indexing, filtering, and searching capabilities. Below is a detailed description of Microsoft Messaging artifacts in ArtiFast software.

Microsoft Messaging Calls Artifact

Microsoft Messaging Chats Artifact

Microsoft Messaging Contacts Artifact

Microsoft Messaging Messages Artifact

Microsoft Messaging SMSes Artifact

Microsoft Messaging Transfers Artifact

Microsoft Messaging Video Messages Artifact

Microsoft Messaging Videos Artifact