// artifact family
china / apac messaging
27 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.
tools in this family
ordered as in the forensics catalog. every tool runs locally — no upload, no account.
- wechat android artifact forensic extractordrop wechat android EnMicroMsg.db + voice2 dir · parse contacts, chat messages, moments, payment records · reconstruct conversation timeline · surface contact graph + transaction history · runs locally
- wechat ios artifact forensic extractordrop wechat ios mm.sqlite from backup · parse messages, contacts, moments · surface deleted message remnants + group chat history · runs locally
- wechat desktop artifact forensic extractordrop wechat windows/mac client data dir · parse Msg/MSGd.db files · reconstruct desktop session chat history · runs locally
- wechat pay transaction forensic analyzerdrop wechat pay transaction export · parse send/receive/red-envelope/merchant records · surface counterparties + amounts · runs locally
- wechat moments timeline reconstructordrop sns_db / moments cache · reconstruct posts, comments, likes timeline · surface social graph activity · runs locally
- qq android artifact forensic extractordrop tencent qq android dataDir · parse Slowtable_*.db msg databases · reconstruct chat + group history · runs locally
- qq desktop artifact forensic extractordrop qq for windows %APPDATA%TencentQQUsers\<uin> · parse msg2.0 / Msg3.0.db · reconstruct desktop chat sessions · runs locally
- weibo artifact forensic extractordrop sina weibo android/ios data export · parse posts, reposts, comments · surface social graph + posting timeline · runs locally
- line android artifact forensic extractordrop line android dataDir naver_line/databases · parse naver_line.db chat/contact tables · runs locally
- line ios artifact forensic extractordrop line ios talk.sqlite + line.sqlite · parse messages, stickers, contacts · runs locally
- line desktop artifact forensic extractordrop line for windows/mac Cache + AppData · parse desktop client artifacts · runs locally
- line pay transaction forensic analyzerdrop line pay receipts / export · surface counterparties + amounts + timeline · runs locally
- kakaotalk android artifact forensic extractordrop kakaotalk android KakaoTalk.db (encrypted) + chatLogs · parse chat sessions · runs locally
- kakaotalk ios artifact forensic extractordrop kakaotalk ios SQLites from backup · parse messages, contacts, chat rooms · runs locally
- kakaotalk desktop artifact forensic extractordrop kakaotalk pc client data dir · parse desktop chat history · runs locally
- dingtalk android artifact forensic extractordrop alibaba dingtalk android dataDir · parse work chat, calls, calendar, attachments · runs locally
- dingtalk ios artifact forensic extractordrop dingtalk ios backup · parse messages, meetings, contacts · runs locally
- dingtalk desktop artifact forensic extractordrop dingtalk pc client data · parse desktop chat + screen-share history · runs locally
- alipay transaction forensic analyzerdrop alipay account billing export · parse send/receive/merchant/red-envelope · surface flow of funds · runs locally
- xiaohongshu rednote artifact forensic extractordrop xiaohongshu app data · parse posts, comments, follows · surface social activity · runs locally
- douyin tiktok china artifact forensic extractordrop douyin (china tiktok) android data · parse local videos, viewing history, drafts · runs locally
- bilibili artifact forensic extractordrop bilibili android/ios data · parse watch history, uploads, comments · runs locally
- viber android artifact forensic extractordrop viber android dataDir · parse messages.db calls + chats · runs locally
- viber ios artifact forensic extractordrop viber ios contacts/messages.data · runs locally
- viber desktop artifact forensic extractordrop viber desktop client data dir · runs locally
- skype legacy artifact forensic analyzerdrop skype legacy main.db / chatsync · parse messages, calls, file transfers from pre-Teams era · runs locally
- skype modern artifact forensic analyzerdrop skype electron client data dir · parse modern skype messaging + call records · runs locally