Mikhail Ashshidiqie Rachman
Informatics Master's Program, Faculty of Industrial Technology, Universitas Islam Indonesia, Indonesia

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Comparative Analysis of Discord Artifact Recovery from Browser Cache Using Improved Generic Computer Forensic Investigation Model (GCFIM) Mikhail Ashshidiqie Rachman; Yudi Prayudi
Jurnal Teknik Informatika (Jutif) Vol. 7 No. 4 (2026): JUTIF Volume 7, Number 4, August 2026
Publisher : Informatika, Universitas Jenderal Soedirman

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.52436/1.jutif.2026.7.4.5377

Abstract

The rapid growth of Discord as a web-based communication platform has increased its relevance in cybercrime investigations, particularly in cases involving deleted digital evidence. Recovering residual artifacts from browser cache is therefore essential to support digital forensic analysis. This study aims to compare the effectiveness of forensic tools in recovering Discord artifacts from browser cache across Google Chrome, Mozilla Firefox, and Microsoft Edge. A live forensic approach was applied using the Improved Generic Computer Forensic Investigation Model (Improved GCFIM) to ensure a systematic and reproducible investigation process. Experiments were conducted by simulating identical Discord user interactions on each browser, including text messaging, emoji and sticker usage, and media file transfers, followed by artifact extraction using Autopsy, ChromeCacheView, and MZCacheView.The experimental results show that Mozilla Firefox produced the highest volume of recoverable data, with 484 cache files identified, allowing successful artifact extraction using both Autopsy and MZCacheView. Google Chrome and Microsoft Edge yielded 146 and 275 cache files respectively, where artifact recovery was only effective using ChromeCacheView due to their Chromium-based cache structure. Across all browsers, recovered artifacts included user identities, channel identifiers, timestamps, text messages (plain, edited, pinned, spoiler, and reply), emojis, stickers, images, videos, and documents, enabling accurate reconstruction of communication timelines. These findings demonstrate that browser architecture and tool compatibility significantly influence cache-based evidence recovery and highlight the necessity of a multi-tool, browser-aware forensic approach. This research contributes to digital forensics and computer science by strengthening cache-based evidence recovery and providing practical insights into browser-specific forensic analysis of web-based communication platforms.