Events & Webinars

The Disappearing Evidence Trap: Forensically Capturing Teams, Slack, and Encrypted Apps in the Australian Enterprise

Join the April 28 forensic webinar on "The Disappearing Evidence Trap." Expert analysis on Slack, Teams, and Signal data acquisition for Australian enterprises.

Virtual

28/04/2026 ( 1PM AEST - 2PM AEST )

Can your current collection workflow reliably reconstruct a threaded conversation from a private Slack channel or an eighteen-month-old Teams chat? For many forensic practitioners in Australia, the answer is "no"—not because the data doesn't exist, but because native "legal hold" exports often fail to capture the full metadata chain or ephemeral artifacts.

The Disappearing Evidence Trap is a technical reality where edited messages, deleted snippets, and "off-platform" encrypted chats fall through the cracks of standard IT backups. This session breaks down the forensic roadmap for capturing modern, transient communication in a way that survives the scrutiny of the Federal Court.

Key Technical Takeaways:

  • The Persistence Gap: Analyzing the decay of forensic artifacts in Slack vs. Teams over an 18-month horizon.
  • Export vs. Acquisition: Why native vendor tools (e.g., M365 Purview) may be legally insufficient for high-stakes forensic validation.
  • The Encryption Wall: Forensic methodologies for handling "Shadow IT" apps (Signal/WhatsApp) within the Australian regulatory framework.