analyzing-outlook-pst-for-email-forensics

Extract emails, headers, and attachments from Outlook PST/OST files.

Updated Apr 23, 2026
One-click install
npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill analyzing-outlook-pst-for-email-forensics
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: analyzing-outlook-pst-for-email-forensics
Source: https://github.com/YukiIto1999/ctf-sleuth/tree/main/.claude/skills/analyzing-outlook-pst-for-email-forensics
Command: npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill analyzing-outlook-pst-for-email-forensics

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires pypff, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill enables investigators to perform structured forensic analysis of Outlook PST/OST files, extracting emails, headers, attachments, and metadata while preserving evidence for legal and incident-response workflows.

Core Features & Use Cases

  • PST/OST parsing across folders, including deleted items and recoverable data.
  • Metadata and header extraction (From, To, Date, Message-ID, Received, X-Originating-IP) and attachment inventory for correlation.
  • Evidence reconstruction and timeline generation to support incident response and legal investigations.

Quick Start

Run the PST forensic agent on a mailbox file to produce a JSON report and human-readable writeup that summarizes messages, headers, attachments, and suspicious items.

Frequently Asked Questions about analyzing-outlook-pst-for-email-forensics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I extract email headers and attachments from a PST file for forensic analysis?

Yes, forensic PST analysis includes parsing deleted items and recoverable data within Outlook OST and PST files. It extracts metadata and messages from these hidden folders to support incident response and legal-compliance workflows.

Can I recover deleted items and emails from an Outlook OST file?

Yes, forensic PST analysis includes parsing deleted items and recoverable data within Outlook OST and PST files. It extracts metadata and messages from these hidden folders to support incident response and legal-compliance workflows.

Does pypff support parsing Outlook PST and OST files?

PST forensic analysis generates a structured JSON report and a human-readable writeup. These outputs summarize extracted messages, headers, attachment inventories, and suspicious items to support legal investigations and incident response.

What is the best way to generate an email timeline from an OST file for incident response?

PST forensic analysis is designed for incident response, digital forensics, and legal-compliance workflows. It preserves mailbox metadata, applies hashing to extracted evidence, and maintains structured reporting for legal investigations.

How do I preserve email metadata and generate a structured forensic report?

PST forensic analysis is designed for incident response, digital forensics, and legal-compliance workflows. It preserves mailbox metadata, applies hashing to extracted evidence, and maintains structured reporting for legal investigations.