Accessing a suspect's communications via email and instant messengers will help you to solve lots of cases; and you will be asked to find and extract such artifacts very often. It doesn't matter if the case is a phishing attack, intellectual property theft, or a terrorist act - a computer forensic examiner must be able to locate, parse, and analyze a suspect's digital communications.
In this chapter, we will show you how to parse and analyze artifacts from the most common Windows email clients - Microsoft Outlook, Mozilla Thunderbird, and Skype instant messenger.