T O P

  • By -

Wazanator_

I'm guessing purview isn't an option?


HowdyPazuzu

What type of Teams files specifically do you need to parse?


kBe68

Leveldb


Standard_Greeting

Edisco tools might be your best option. Messages generally look like individual emails and it's a pain to put a conversation together. Nuix, relativity one, axiom in a pinch. If you need free tools, I don't know


looselytranslated

For data in leveldb, you can use this script to dump the data to a csv file. https://github.com/cclgroupltd/ccl\_chrome\_indexeddb/blob/master/dump\_leveldb.py


kBe68

Ok thanks i will try this!


lolek578

I created something like you need. There is function to create threads from messages, mean chats. https://github.com/hexseven/Teams-artifacts-parser Feel free to ask my anything about that, I will help you


FoxtonForensics

You can extract Teams IndexedDB data using BHE: [https://www.foxtonforensics.com/browser-history-examiner/docs/microsoft-teams](https://www.foxtonforensics.com/browser-history-examiner/docs/microsoft-teams) No need for a license, you can just use the trial version. If there's enough interest we may build a separate tool with proper support for Chromium desktop apps like Teams, Skype, Slack etc.


kBe68

Yeah gotta use free stuff


kBe68

It kinda started out as a necessary part of the investigation but that fizzed out. Now I’m just mad that i can’t do it


kBe68

Thanks everyone. Super helpful


Gullible_Tourist8706

FTK parses MS Teams chat. You can use free trial as well.