The adoption of Network Attached Storage (NAS) based private communication platforms such as Synology Chat is increasing in organizations and may store valuable digital evidence. However, encryption and closed system architecture can limit evidence acquisition using conventional forensic approaches. This study applies network live forensics by proactively capturing network traffic and analyzing capture files to recover deleted chat messages and transferred files. The investigation follows the National Institute of Standards and Technology NIST framework consisting of collection, examination, analysis, and reporting using digital evidence including packet capture PCAP or packet capture next generation PCAPNG files, communication artifacts, and reconstructed file objects. An experimental method is conducted by comparing server-side capturing via Secure Shell SSH on the NAS server and external capturing from a device within the same Local Area Network LAN. Results show that server-side capturing is more effective for file reconstruction and message recovery under certain conditions, while external capturing provides limited artifacts and cannot reveal plain text messages.
Copyrights © 2026