Blog >> Skype

Investigating Skype for Desktop and Windows Application

15/06/2021 Tuesday

Skype is a software that allows users to communicate with one another and is used by millions of individuals and companies to make free video and voice one-to-one and group calls, send instant messages, and exchange files with others. Skype can be used in laptops, mobile devices, or tablets and available for Microsoft Windows, Apple macOS, and Linux computers, and mobile apps for iOS, Android, and Windows Phone smartphones and tablets.


Digital Forensics Value of Skype Artifacts


In Skype, the artifacts hold information about users' accounts, all of their activities, and also contains information about the stored and shared files. From a forensic perspective, it can provide us with a lot of resources that can be used as critical evidence. Suspects, on the other hand, can delete information by wiping conversation archives or physically destroying Skype logs. Tracking such information is critical during the digital forensic analysis process.


Location of Skype Artifacts


In Windows 7 Skype artifacts are located at:

C:\Users\%username%\AppData\Roaming\Skype\SkypeUserName\main.db

In Windows 10 Skype artifacts are located at:

C:\Users\%username%\AppData\Local\packages\Skype\LocalState\SkypeUserName\main.db

Whereas Skype Windows Application artifacts are located at:

C:\Users\%username%\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c/LocalState/live#3akabiletester/main.db
C:\Users\%username%\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c/LocalState


Structure of Skype Artifacts


Skype for desktop and Skype Windows application have identical structure that consist of databases that include information about user accounts, contacts, chats, voice calls initiated and received, and other information. All information is stored in main.db file and these files are SQLite database files.


Analyzing Skype Artifacts with ArtiFast Windows


This section will discuss how to use ArtiFast Windows to analyze Skype artifacts from Windows machines and what kind of digital forensics insights we can gain from the artifacts.

After you have created your case and added evidence for investigation, at the Artifacts Parser Selection Phase, you can select Skype artifacts:




ArtiFast can analyze Accounts, Calls, Contact Messages, Contacts, File Transfer, Gif Messages, Groups, Location Messages, Other Events, Photo Messages, Text Messages, Video Messages, and Voice Messages for Skype desktop. ArtiFast can also analyze Accounts, Alerts, Audio Messages, Calls, Contact Messages, Contacts, Conversations, Emotions, File Messages, File Transfer, Gif Message, Location Messages, Other Events, Other Messages, Photo Messages, Profile Cache, Scheduled Calls, Text Messages, Video Messages, and Audio Messages for different Skype Windows application versions.



Once ArtiFast parser plugins complete processing artifacts for analysis, it can be reviewed via “Artifact View” or “Timeline View,” with indexing, filtering, and searching capabilities. Below is a detailed description of Skype artifacts in ArtiFast software.


For Skype desktop and newer Windows application versions:


Skype Accounts Artifact


Skype Calls Artifact


Skype Contacts Artifact


Skype File Transfer Artifact


Skype Gif Messages Artifact


Skype Groups Artifact


Skype Location Messages Artifact


Skype Other Events Artifact


Skype Photo Messages Artifact


Skype Contact Messages Artifact


Skype Text Messages Artifact


Skype Video Messages Artifact


Skype Voice Messages Artifact



For Skype Windows application older versions:


Skype (Win Apps) Alerts Artifact


Skype (Win Apps) Audio Messages Artifact


Skype (Win Apps) Calls Artifact


Skype (Win Apps) Contact Messages Artifact


Skype (Win Apps) Conversations Artifact


Skype (Win Apps) Emotions Artifact


Skype (Win Apps) File Message Artifact


Skype (Win Apps) Location Messages Artifact


Skype (Win Apps) Other Messages Artifact


Skype (Win Apps) Photo Messages Artifact


Skype (Win Apps) Profile Cache Artifact


Skype (Win Apps) Scheduled Calls Artifact


Skype (Win Apps) Text Messages Artifact


Skype (Win Apps) Video Messages Artifact