Articles August 17, 2021 Trusted Timestamping (RFC 3161) in Digital Forensics Trusted timestamping as defined in RFC 3161 makes its way into my digital forensics workflow… Arman Gungor
Articles April 1, 2021 Investigating Message Read Status in Gmail & Google Workspace The need to determine whether a specific message was read by an end-user comes up… Arman Gungor
Articles July 20, 2020 Dates in Hiding Part 3 — Gmail Message ID and Thread ID Timestamps After my Gmail History Records post earlier this month, there was a great discussion in… Arman Gungor
Articles July 7, 2020 Gmail History Records in Forensic Email Investigations One of the common issues when examining Google email data, especially from free Gmail accounts,… Arman Gungor
Articles March 23, 2020 Dates in Hiding Part 2 — Gmail MIME Boundary Timestamps This post on Gmail MIME boundary timestamps is an update to my previous Dates in… Arman Gungor
Articles December 12, 2019 Google Takeout and Vault in Email Forensics Introduction Google Takeout and Google Vault are commonly used to export email evidence for digital… Arman Gungor
Articles September 17, 2019 Dates in Hiding—Uncovering Timestamps in Forensic Email Examination One of my favorite data points when forensically examining emails is hidden timestamps. These timestamps… Arman Gungor
Software August 26, 2019 Free Mailbox Sanitization Software—Obliterator What is Obliterator? I have been tasked with mailbox sanitization numerous times, and I know… Arman Gungor
Articles May 16, 2019 Leveraging DKIM in Email Forensics My last article was about using the Content-Length header field in email forensics. While the… Arman Gungor
Articles March 26, 2019 Using the Content-Length Header Field in Email Forensics As forensic examiners, we often have to analyze emails in isolation without the benefit of… Arman Gungor