Email Forensics

Deals with recovery and analysis of emails, including deleted emails, calendars, and contacts.

Tool NameDescription
EnCase  A widely used digital forensics platform that supports email analysis, providing in-depth examination of email headers, attachments, and content.
MailXaminerEmail forensics software that offers comprehensive analysis of various email formats, including support for metadata extraction and keyword searching.
MBOX ViewerA tool specifically designed for MBOX file format, enabling investigators to view, search, and analyze emails stored in MBOX files.
Email ExaminerAn email forensics tool with advanced search capabilities, supporting multiple email formats, and providing detailed analysis of email artifacts and metadata.
Forensic ToolkitA powerful forensic tool that includes email analysis features, allowing investigators to recover, analyze, and present email evidence in legal cases.
PST ViewerSoftware to view and analyze Microsoft Outlook PST files, providing access to email messages, attachments, and other data stored in the PST file format.
WiresharkA network protocol analyzer that can be used for email forensics by capturing and analyzing network traffic, including email communications over the network.
OxygenForensic DetectiveA mobile forensics tool that supports email analysis on smartphones, extracting emails, attachments, and other related data from mobile devices.
MailMarshalAn email security tool that can be utilized for forensics purposes, helping investigators analyze email traffic, identify threats, and trace email sources.
NetworkMinerA network forensic analysis tool that can be used to parse and analyze emails transmitted over a network, extracting valuable information from captured network traffic.
Sintelix Adcomplain
XtraxtorAccessData’s FTK
Aid4Mail ForensicEnCase Forensic
MailXaminer Forensic Email Analysis Software FINALeMAIL
MailPro+Forensics Investigation Toolkit (FIT)
AutopsyMxToolBox Email Software
Advik Email Forensic WizardParaben Email Examiner
Stellar data recovery OSForensic Software
Advik MBOX to PDF ConverterKernel Outlook PST Viewer
FreeViewerR-Mail by R-tools-technology
eMailTrackerProEmailTracer

Email forensics is the investigation of email communications to detect fraud, phishing, data breaches, and cybercrimes. It helps uncover forged emails, track senders, and analyze malicious attachments or links.

Techniques & Tools:

Techniques:

  1. Preserve Email Evidence
    1. Securely collect email files (e.g., PST, OST, EML) or server backups without altering metadata.
    1. Tools: FTK Imager (Download).
  2. Analyze Email Headers
    1. Extract and decode email headers to trace sender IPs, mail servers, and authentication results (e.g., SPF, DKIM).
    1. Tools: MXToolbox Header Analyzer (Download), MIME-Tools (Download).
  3. Inspect Email Content and Metadata
    1. Review timestamps, email threads, and metadata for tampering or anomalies.
    1. Tools: MailXray (Download), Paraben Email Examiner (Download).
  4. Analyze Attachments and Links
    1. Scan attachments for malware and links for phishing.
    1. Tools: VirusTotal (Download), Cuckoo Sandbox (Download).
  5. Reconstruct Email Threads
    1. Organize email threads for context or detect missing communications.
    1. Tools: Belkasoft Evidence Center (Download)
  6. Report Findings Document the sender’s details, communication patterns, and flagged anomalies in a comprehensive report.

Open-Source Tools:

  1. MIME-Tools: Analyze email structures and metadata. Download
  2. Cuckoo Sandbox: Analyze email attachments and links for malware. Download
  3. MXToolbox Header Analyzer: Decode email headers. Download

Commercial Tools:

  1. Paraben Email Examiner: Advanced email forensics suite. Download
  2. MailXray: Header and metadata analysis. Download
  3. Belkasoft Evidence Center: Comprehensive forensic suite for email and attachments. Download
  4. AccessData FTK Imager: Email data extraction and metadata preservation. Download