Digital Forensic Investigation of the ChatGPT Windows Application

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Kankanamge, Malithi Wanniarachchi, McKenna, Nick, Carmona, Santiago, Hasan, Syed Mhamudul, Shahid, Abdur R., Imteaj, Ahmed
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918038947758080
author Kankanamge, Malithi Wanniarachchi
McKenna, Nick
Carmona, Santiago
Hasan, Syed Mhamudul
Shahid, Abdur R.
Imteaj, Ahmed
author_facet Kankanamge, Malithi Wanniarachchi
McKenna, Nick
Carmona, Santiago
Hasan, Syed Mhamudul
Shahid, Abdur R.
Imteaj, Ahmed
contents The ChatGPT Windows application offers better user interaction in the Windows operating system (OS) by enhancing productivity and streamlining the workflow of ChatGPT's utilization. However, there are potential misuses associated with this application that require rigorous forensic analysis. This study presents a holistic forensic analysis of the ChatGPT Windows application, focusing on identifying and recovering digital artifacts for investigative purposes. With the use of widely popular and openly available digital forensics tools such as Autopsy, FTK Imager, Magnet RAM Capture, Wireshark, and Hex Workshop, this research explores different methods to extract and analyze cache, chat logs, metadata, and network traffic from the application. Our key findings also demonstrate the history of the application's chat, user interactions, and system-level traces that can be recovered even after deletion, providing critical insights into the crime investigation and, thus, documenting and outlining a potential misuse report for digital forensics.
format Preprint
id arxiv_https___arxiv_org_abs_2505_23938
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Digital Forensic Investigation of the ChatGPT Windows Application
Kankanamge, Malithi Wanniarachchi
McKenna, Nick
Carmona, Santiago
Hasan, Syed Mhamudul
Shahid, Abdur R.
Imteaj, Ahmed
Cryptography and Security
The ChatGPT Windows application offers better user interaction in the Windows operating system (OS) by enhancing productivity and streamlining the workflow of ChatGPT's utilization. However, there are potential misuses associated with this application that require rigorous forensic analysis. This study presents a holistic forensic analysis of the ChatGPT Windows application, focusing on identifying and recovering digital artifacts for investigative purposes. With the use of widely popular and openly available digital forensics tools such as Autopsy, FTK Imager, Magnet RAM Capture, Wireshark, and Hex Workshop, this research explores different methods to extract and analyze cache, chat logs, metadata, and network traffic from the application. Our key findings also demonstrate the history of the application's chat, user interactions, and system-level traces that can be recovered even after deletion, providing critical insights into the crime investigation and, thus, documenting and outlining a potential misuse report for digital forensics.
title Digital Forensic Investigation of the ChatGPT Windows Application
topic Cryptography and Security
url https://arxiv.org/abs/2505.23938