Digital Forensic Recovery and Analysis of WhatsApp Artifacts on Android Using the NIST Framework
DOI:
https://doi.org/10.53363/ijbtob.v6i3.412Keywords:
Digital Forensics, WhatsApp Messenger,, NIST Framework, Logical AcquisitionAbstract
The rapid development of communication technology has made instant messenger applications like WhatsApp frequently misused in cybercrimes, requiring proper digital forensics handling. However, the security architecture in modern operating systems such as Android 14 poses a major challenge for investigators due to strict restrictions on internal access and rooting. This study aims to conduct a digital forensic investigation to recover WhatsApp Messenger data artifacts on an unrooted Android 14 device by implementing the National Institute of Standards and Technology (NIST) SP 800-86 framework. The method utilized is logical acquisition based on Android Debug Bridge (ADB) pull commands for data collection, combined with Autopsy and DB Browser for SQLite software for the examination and analysis phases. The experimental results indicate that this methodology was 100% successful in meeting NIST compliance standards and successfully recovered thousands of multimedia assets with a total data volume of approximately 10.7 GB. The recovered data details include 6,664 images, 1,042 videos, 1,092 audios, 25 archive files, and 3 supporting documents. Nevertheless, the testing recorded a total failure in recovering deleted text messages due to the Android 14 sandbox protection, which isolates the main database files within an encrypted internal directory that strictly requires root access. In conclusion, this combination of ADB and Autopsy methods is highly recommended for rapid digital triage processes because it is safe, non-destructive, and capable of maintaining the integrity of the chain of custody without altering the target device's original system. .
Downloads
References
Aljumaiah, O., Jiang, W., Reddy Addula, S., & Amin Almaiah, M. (2025). Analyzing Cybersecurity Risks and Threats in IT Infrastructure based on NIST Framework. Journal of Cyber Security and Risk Auditing , 2025 (2). https://doi.org/10.63180/jcsra.thestap.2025.2.2
Anglano, C. (2014). Forensic analysis of whats app messenger on Android smartphones. Digital Investigation , 11 (3). https://doi.org/10.1016/j.diin.2014.04.003
Audita, D., Lestari, P., & Fattah, F. (2025). Digital Forensic Analysis of Data Recovery in File Deletion Cases Using the National Institute of Standards and Technology (NIST) Method. Journal Homepage: AKIRATECH : Journal of Computer and Electrical Engineering , 2 (1).
Bernardo, L., Malta, S., & Magalhães, J. (2025). An Evaluation Framework for Cybersecurity Maturity Aligned with the NIST CSF. Electronics (Switzerland) , 14 (7). https://doi.org/10.3390/electronics14071364
Cohen, F. (2012). The Science of Digital Forensics: Recovery of Data from Overwritten Areas of Magnetic Media. Journal of Digital Forensics, Security and Law . https://doi.org/10.15394/jdfsl.2012.1131
Cruz, C. (2024). Innovative Learning in a Digital Forensics Laboratory: Tools and Techniques for Data Recovery. Applied Sciences (Switzerland) , 14 (23). https://doi.org/10.3390/app142311095
Dimakopoulou, A., & Rantos, K. (2024). Comprehensive Analysis of Maritime Cybersecurity Landscape Based on the NIST CSF v2.0. Journal of Marine Science and Engineering , 12 (6). https://doi.org/10.3390/jmse12060919
Fitriana, M., AR, KA, & Marsya, JM (2020). APPLICATION OF THE NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY (NIST) METHOD IN DIGITAL FORENSIC ANALYSIS FOR HANDLING CYBER CRIME. Cyberspace: Journal of Information Technology Education , 4 (1). https://doi.org/10.22373/cj.v4i1.7241
Gordon, L. A., Loeb, M. P., & Zhou, L. (2020). Integrating cost-benefit analysis into the NIST cybersecurity framework via the Gordon-Loeb model. Journal of Cybersecurity , 6 (1). https://doi.org/10.1093/CYBSEC/TYAA005
Hamid, N., Kuswanto, J., Nurani, D., Dwi Putra, A., Mahananing Puri, F., & Tri Atmaja Ramadhani, S. (2024). Forensic Recovery Techniques on Android Devices with the National Institute of Standards and Technology (NIST) Approach. JTECS: Journal of Electronic Telecommunication Systems, Control Systems, Power Systems and Computers , 4 (1). https://doi.org/10.32503/jtecs.v4i1.4676
Hapsari, NP, & Parga Zen, B. (2024). Application of the NIST 800-86 Framework to Forensic Digital Evidence for Signal and Litmatch. Journal of Innovation Information Technology and Application (JINITA) , 6 (1). https://doi.org/10.35970/jinita.v6i1.2025
Heath, H., MacDermott, Á., & Akinbi, A. (2023). Forensic analysis of ephemeral messaging applications: Disappearing messages or evidential data? Forensic Science International: Digital Investigation , 46 . https://doi.org/10.1016/j.fsidi.2023.301585
Iqbal, M., & Riadi, I. (2019). Forensic WhatsApp based on Android using National Institute of Standard Technology (NIST) Method. International Journal of Computer Applications , 177 (8). https://doi.org/10.5120/ijca2019919443
Jafri, MS, Raharjo, S., & Arief, MR (2022). Implementation of ACPO Framework for Digital Evidence Acquisition in Smartphones. CCIT Journal , 15 (1). https://doi.org/10.33050/ccit.v15i1.1586
Karnewar, R., & Chahankar, A. (2024). Data Recovery In Digital Forensics. International Journal of Innovations in Engineering and Science , 9 (8).
Martini, B., & Choo, K. K. R. (2012). An integrated conceptual digital forensic framework for cloud computing. In Digital Investigation (Vol. 9, Number 2). https://doi.org/10.1016/j.diin.2012.07.001
Oh, J., Lee, S., & Hwang, H. (2022). Forensic Recovery of File System Metadata for Digital Forensic Investigation. IEEE Access , 10 . https://doi.org/10.1109/ACCESS.2022.3213030
Ramadhan, RA, Rachmat Setiawan, P., & Hariyadi, D. (2022). Digital Forensic Investigation for Non-Volatile Memory Architecture by Hybrid Evaluation Based on ISO/IEC 27037:2012 and NIST SP800-86 Framework. IT Journal Research and Development . https://doi.org/10.25299/itjrd.2022.8968
Santoso, BS, & Sulaksono, PM (2022). Static Forensics on USB Mass Storage Using Forensics Toolkit Imager. Applied Computer Journal , 8 (1). https://doi.org/10.35143/jkt.v8i1.5334
Shandilya, S. K., Singh, Y., Izonin, I., & Hentosh, L. (2024). Metaverse forensics framework: A NIST based investigation framework for the metaverse. In Science and Justice (Vol. 64, Number 6). https://doi.org/10.1016/j.scijus.2024.10.005
Sudiana, D., Nuruddin, CH, Rizkinia, M., & Husna, D. (2024). Forensic Analysis of WhatsApp Disappearing Message on Unrooted Android Using Mobile Device Forensics Methodology NIST SP 800-101r1. Evergreen , 11 (1). https://doi.org/10.5109/7172316
Syaiful Huda Mubarok, M., Ardiansyah, A., Novrianda Dasmen, R., Pranata, V., & Januarta, MA (2024). Digital Analysis of Forensic Data Recovery on Flash Drive Using National Institute of Justice (NIJ) Method. Jurnal Ilmiah Informatika , 12 (01).
Syukri, M., Riadi, I., & Sutikno, T. (2025). Validation and Evaluation of Browser Forensics Using Digital Forensic Approach Based on the National Institute of Standards and Technology (NIST) Framework. Journal of Informatics Engineering (Jutif) , 6 (4). https://doi.org/10.52436/1.jutif.2025.6.4.4977
Downloads
Submitted
Accepted
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Fathurrahman Walidain, Firmansyah Firmansyah

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.























This is an open access article under