Forensic analysis of Telegram Messenger for Windows Phone

This article presents a forensic analysis methodology for obtaining the digital evidence generated by one of today's many instant messaging applications, namely Telegram Messenger for Windows Phone, paying particular attention to the digital forensic artifacts produced. The paper provides an overview of this forensic analysis, while focusing particularly on how the information is structured and the user, chat and conversation data generated by the application are organised, with the goal of extracting related data from the information. The application has several other features (e.g. games, bots, stickers) besides those of an instant messaging application (e.g. messages, images, videos, files). It is therefore necessary to decode and interpret the information, which may relate to criminal offences, and establish the relation of different types of user, chat and conversation.

[1]  Cosimo Anglano,et al.  Forensic analysis of WhatsApp Messenger on Android smartphones , 2014, Digit. Investig..

[2]  Mohammad Iftekhar Husain,et al.  iForensics: Forensic Analysis of Instant Messaging on Smart Phones , 2009, ICDF2C.

[3]  Soo Young Shin,et al.  Android forensics analysis: Private chat on social messenger , 2016, 2016 Eighth International Conference on Ubiquitous and Future Networks (ICUFN).