Webmail analysis with Magnet AXIOM
As you may know, some people (including the authors) use only webmail and no mail clients. Is it possible to recover such forensic artifacts from a drive image? The answer is - yes! And in this recipe, we will show you how to recover webmail activity with Oleg's favorite digital forensic tool - Magnet AXIOM.
Getting ready
We are sure that you already have AXIOM installed on your workstation. So run the tool and create a new case. Now, the most interesting thing is the evidence source. If you have already walked through the recipe Extracting Web Browser Data from Pagefile.sys in Chapter 8, Web Browser Forensics, you may guess what we are going to do next. Yes, webmail artifacts can be extracted from pagefile.sys
, swapfile.sys
and hiberfil.sys
. So you can use one of these files as the data source, or the whole forensic image - AXIOM will find and parse data from these files automatically.
How to do it...
We can start the process by following the given steps:
- Process...