This scenario simulates a live digital forensics examination focusing on host-based artifact analysis. You will learn to identify the correct directory structure containing Microsoft Teams local cache and database files during an insider threat investigation.

CHFI (312-49) Digital Forensics Simulation

Investigation Scenario

A corporate investigation is underway at a Seattle-based firm regarding suspected intellectual property theft. The suspect allegedly used the Microsoft Teams desktop client to communicate with an external competitor and exfiltrate sensitive schematics.

The incident response team has acquired a full physical image of the suspect's Windows 10 workstation. As the lead forensic examiner, your objective is to parse the user's profile to extract the local Teams database (specifically leveldb and IndexedDB artifacts) to recover deleted chat messages and file transfer histories.

Evidence Collected

Question

In a corporate investigation in Seattle, a forensic examiner is analyzing the Microsoft Teams artifacts on a suspect's workstation. Which directory on a Windows system typically stores the local cache and databases for the Microsoft Teams desktop application?
Investigator Hint: Think about where Windows applications traditionally store user-specific configuration files and roaming database caches that follow a user across a domain environment.

Expert Analysis

1. What the evidence shows:
The physical disk image (EVID-001) contains the NTFS file system. The examiner must target the `JSmith` user profile (EVID-002) to locate the application's persistent databases, such as LevelDB and IndexedDB, which hold the chat contents and cache (EVID-003).

2. Forensic Stage:
Examination and Analysis. The digital image has been preserved and verified via hashing. The investigator is now navigating the file system structure to collect specific application artifacts.

3. Why correct answer is correct (A):
The classic Microsoft Teams desktop application (built on Electron) stores its user-specific local cache, `IndexedDB`, `leveldb` files, and configuration data inside the Roaming AppData directory. The path natively translates to `C:\Users\\AppData\Roaming\Microsoft\Teams`. This is the primary location forensic examiners target to recover Teams chat logs.

4. Why others are wrong:
- B (%ProgramFiles%): This directory stores the application's global executable binaries (`.exe`, `.dll`), not user-specific chat histories or cached databases.
- C (%Temp%): This directory handles ephemeral temporary files during application operation or updates. It does not store persistent database files like LevelDB.
- D (%LocalAppData%): While some modern Windows Store apps (and the "New Teams" client) utilize LocalAppData packages, the standard classical Teams client targeted in foundational CHFI investigations stores its primary forensic artifacts in the Roaming `%AppData%` folder.

5. Real-world forensic action:
The investigator will mount the `E01` image, navigate to `C:\Users\JSmith\AppData\Roaming\Microsoft\Teams\`, and export the `IndexedDB` folder. Because Teams uses an unstructured LevelDB database, the investigator will then use a specialized parsing tool (such as TeamsParser or an equivalent Python script) to reconstruct the fragmented JSON artifacts into a readable chat timeline.

MINI LESSON: Artifact Interpretation
Microsoft Teams chat data is not stored in a plain text file or a clean SQLite database. It is heavily fragmented across a LevelDB key-value store. Proper extraction requires identifying the correct Roaming profile path, preserving the entire directory structure (as LevelDB relies on log and ldb files), and utilizing DB-specific parsing tools to avoid corrupting the sequence of evidentiary artifacts.

Ready for the next investigation?

Master your forensic process and evidence analysis skills.

Explore more CHFI simulations
ExamRange – CHFI 312-49 Simulation

Welcome to the digital forensics training environment. In this module, you will analyze network traffic artifacts to extract potential payload data. Enhance your forensic reasoning and prepare for the CHFI (312-49) examination.

CHFI (312-49) Digital Forensics Simulation

Investigation Scenario

Case Reference: #2026-NFW-088

Organization: FinTech Global Operations (Financial Services, NY)

Context: A perimeter firewall detected continuous outbound traffic originating from an executive's workstation. Forensic imaging has been authorized. Initial triage reveals a suspected hollowed process masquerading as legitimate traffic to bypass Data Loss Prevention (DLP) controls. You must analyze the packet capture to determine the exact contents of the exfiltrated data.

Evidence Source: Full Packet Capture (PCAP) from switch SPAN port and Endpoint logs.

Evidence Collected

You have loaded workstation_triage.pcap into your protocol analyzer. Correlating with the endpoint's Sysmon logs, you observe the following:

SYSMON EVENT ID 3 (Network Connection): ProcessId: 4592 Image: C:\Windows\System32\svchost.exe DestinationIp: 104.21.x.x DestinationPort: 443 Protocol: tcp WIRESHARK FILTER: ip.addr == 192.168.10.45 && tcp.port == 443 No. Time Source Destination Proto Length Info 124 0.000000 192.168.10.45 104.21.x.x TLSv1.2 517 Client Hello 128 0.045123 104.21.x.x 192.168.10.45 TLSv1.2 1460 Server Hello, Certificate 135 0.089234 192.168.10.45 104.21.x.x TLSv1.2 342 Client Key Exchange, Change Cipher Spec 140 0.123456 104.21.x.x 192.168.10.45 TLSv1.2 1185 Application Data

The forensic tool reveals the payloads under "Application Data" are currently unreadable and scrambled.

Question

During a network-forensics investigation, an analyst identifies a suspicious process on a workstation that is making frequent connections to an external IP address on port 443 (HTTPS). To inspect the content of this encrypted traffic, what technique must the analyst use?
Investigator's Hint: You already have the packets (sniffing/mirroring has been done), but the Application Data is scrambled due to HTTPS (Transport Layer Security). What process must be applied to convert ciphertext back into plaintext for analysis?

Expert Analysis

1. What the Evidence Shows

The PCAP and Sysmon logs confirm that the workstation is transmitting data over port 443 utilizing the TLSv1.2 protocol. The packet capture successfully records the handshake ("Client Hello", "Server Hello") but the actual payload is encapsulated as encrypted "Application Data".

2. Forensic Stage

Examination and Analysis. The analyst has successfully acquired the network data (collection) but must now process it to extract readable artifacts for reporting.

3. Why the Correct Answer is Correct

A. SSL/TLS Decryption (using a proxy or shared keys) is correct. Encrypted traffic (HTTPS/port 443) converts plaintext into ciphertext using symmetric session keys. To read the payload contents (e.g., to see if credit card numbers or source code were exfiltrated), an investigator must decrypt the traffic. This requires extracting the shared session keys (often logged locally as `SSLKEYLOGFILE`) or obtaining the server's private RSA key (if Perfect Forward Secrecy is not used), and applying them within the protocol analyzer.

4. Why the Others are Wrong

  • B. Packet sniffing with Wireshark: This only captures the encrypted packets. It does not natively decrypt them without being supplied the correct cryptographic keys.
  • C. Port mirroring: This is a collection technique (SPAN port) used to copy traffic to a sensor. It does not alter or decrypt the payload.
  • D. NetFlow analysis: NetFlow only records metadata and telemetry (IP addresses, ports, byte counts, and timestamps). It does not capture the payload contents at all.

5. Real-World Forensic Action

In a real incident, investigators often retrieve the endpoint's RAM image (memory dump) or check for an environment variable pointing to a master secret log file. They then feed these keys into Wireshark's SSL/TLS protocol preferences to decrypt the "Application Data" layers into readable HTTP streams. Alternatively, enterprise environments often utilize SSL Inspection proxies (Man-In-The-Middle) that decrypt, inspect, and re-encrypt the traffic at the perimeter.

MINI LESSON: The `SSLKEYLOGFILE` Artifact

Modern browsers (Chrome, Firefox, Edge) support an environment variable called SSLKEYLOGFILE. When enabled, the browser writes the symmetric master secrets of every TLS session to a specified text file.

  • Path: Configured by the user/admin (e.g., C:\Temp\sslkeys.log)
  • Forensic Value: If an investigator can secure this file during endpoint triage, they can load it directly into Wireshark (Edit > Preferences > Protocols > TLS > (Pre)-Master-Secret log filename).
  • Limitation: Malware/Custom processes (like our malicious svchost.exe) may not respect this environment variable, requiring more advanced memory forensics to extract the session keys directly from the process memory space.

Ready for the next investigation?

Master digital forensics processes, artifact analysis, and incident investigation.

Explore more CHFI simulations