Digital Forensic Recovery and Analysis of WhatsApp Artifacts on Android Using the NIST Framework

Authors

  • Fathurrahman Walidain Al Azhar Islamic University
  • Firmansyah Firmansyah Al Azhar Islamic University

DOI:

https://doi.org/10.53363/ijbtob.v6i3.412

Keywords:

Digital Forensics, WhatsApp Messenger,, NIST Framework, Logical Acquisition

Abstract

The rapid development of communication technology has made instant messenger applications like WhatsApp frequently misused in cybercrimes, requiring proper digital forensics handling. However, the security architecture in modern operating systems such as Android 14 poses a major challenge for investigators due to strict restrictions on internal access and rooting. This study aims to conduct a digital forensic investigation to recover WhatsApp Messenger data artifacts on an unrooted Android 14 device by implementing the National Institute of Standards and Technology (NIST) SP 800-86 framework. The method utilized is logical acquisition based on Android Debug Bridge (ADB) pull commands for data collection, combined with Autopsy and DB Browser for SQLite software for the examination and analysis phases. The experimental results indicate that this methodology was 100% successful in meeting NIST compliance standards and successfully recovered thousands of multimedia assets with a total data volume of approximately 10.7 GB. The recovered data details include 6,664 images, 1,042 videos, 1,092 audios, 25 archive files, and 3 supporting documents. Nevertheless, the testing recorded a total failure in recovering deleted text messages due to the Android 14 sandbox protection, which isolates the main database files within an encrypted internal directory that strictly requires root access. In conclusion, this combination of ADB and Autopsy methods is highly recommended for rapid digital triage processes because it is safe, non-destructive, and capable of maintaining the integrity of the chain of custody without altering the target device's original system. .

Downloads

Download data is not yet available.

References

Aljumaiah, O., Jiang, W., Reddy Addula, S., & Amin Almaiah, M. (2025). Analyzing Cybersecurity Risks and Threats in IT Infrastructure based on NIST Framework. Journal of Cyber Security and Risk Auditing , 2025 (2). https://doi.org/10.63180/jcsra.thestap.2025.2.2

Anglano, C. (2014). Forensic analysis of whats app messenger on Android smartphones. Digital Investigation , 11 (3). https://doi.org/10.1016/j.diin.2014.04.003

Audita, D., Lestari, P., & Fattah, F. (2025). Digital Forensic Analysis of Data Recovery in File Deletion Cases Using the National Institute of Standards and Technology (NIST) Method. Journal Homepage: AKIRATECH : Journal of Computer and Electrical Engineering , 2 (1).

Bernardo, L., Malta, S., & Magalhães, J. (2025). An Evaluation Framework for Cybersecurity Maturity Aligned with the NIST CSF. Electronics (Switzerland) , 14 (7). https://doi.org/10.3390/electronics14071364

Cohen, F. (2012). The Science of Digital Forensics: Recovery of Data from Overwritten Areas of Magnetic Media. Journal of Digital Forensics, Security and Law . https://doi.org/10.15394/jdfsl.2012.1131

Cruz, C. (2024). Innovative Learning in a Digital Forensics Laboratory: Tools and Techniques for Data Recovery. Applied Sciences (Switzerland) , 14 (23). https://doi.org/10.3390/app142311095

Dimakopoulou, A., & Rantos, K. (2024). Comprehensive Analysis of Maritime Cybersecurity Landscape Based on the NIST CSF v2.0. Journal of Marine Science and Engineering , 12 (6). https://doi.org/10.3390/jmse12060919

Fitriana, M., AR, KA, & Marsya, JM (2020). APPLICATION OF THE NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY (NIST) METHOD IN DIGITAL FORENSIC ANALYSIS FOR HANDLING CYBER CRIME. Cyberspace: Journal of Information Technology Education , 4 (1). https://doi.org/10.22373/cj.v4i1.7241

Gordon, L. A., Loeb, M. P., & Zhou, L. (2020). Integrating cost-benefit analysis into the NIST cybersecurity framework via the Gordon-Loeb model. Journal of Cybersecurity , 6 (1). https://doi.org/10.1093/CYBSEC/TYAA005

Hamid, N., Kuswanto, J., Nurani, D., Dwi Putra, A., Mahananing Puri, F., & Tri Atmaja Ramadhani, S. (2024). Forensic Recovery Techniques on Android Devices with the National Institute of Standards and Technology (NIST) Approach. JTECS: Journal of Electronic Telecommunication Systems, Control Systems, Power Systems and Computers , 4 (1). https://doi.org/10.32503/jtecs.v4i1.4676

Hapsari, NP, & Parga Zen, B. (2024). Application of the NIST 800-86 Framework to Forensic Digital Evidence for Signal and Litmatch. Journal of Innovation Information Technology and Application (JINITA) , 6 (1). https://doi.org/10.35970/jinita.v6i1.2025

Heath, H., MacDermott, Á., & Akinbi, A. (2023). Forensic analysis of ephemeral messaging applications: Disappearing messages or evidential data? Forensic Science International: Digital Investigation , 46 . https://doi.org/10.1016/j.fsidi.2023.301585

Iqbal, M., & Riadi, I. (2019). Forensic WhatsApp based on Android using National Institute of Standard Technology (NIST) Method. International Journal of Computer Applications , 177 (8). https://doi.org/10.5120/ijca2019919443

Jafri, MS, Raharjo, S., & Arief, MR (2022). Implementation of ACPO Framework for Digital Evidence Acquisition in Smartphones. CCIT Journal , 15 (1). https://doi.org/10.33050/ccit.v15i1.1586

Karnewar, R., & Chahankar, A. (2024). Data Recovery In Digital Forensics. International Journal of Innovations in Engineering and Science , 9 (8).

Martini, B., & Choo, K. K. R. (2012). An integrated conceptual digital forensic framework for cloud computing. In Digital Investigation (Vol. 9, Number 2). https://doi.org/10.1016/j.diin.2012.07.001

Oh, J., Lee, S., & Hwang, H. (2022). Forensic Recovery of File System Metadata for Digital Forensic Investigation. IEEE Access , 10 . https://doi.org/10.1109/ACCESS.2022.3213030

Ramadhan, RA, Rachmat Setiawan, P., & Hariyadi, D. (2022). Digital Forensic Investigation for Non-Volatile Memory Architecture by Hybrid Evaluation Based on ISO/IEC 27037:2012 and NIST SP800-86 Framework. IT Journal Research and Development . https://doi.org/10.25299/itjrd.2022.8968

Santoso, BS, & Sulaksono, PM (2022). Static Forensics on USB Mass Storage Using Forensics Toolkit Imager. Applied Computer Journal , 8 (1). https://doi.org/10.35143/jkt.v8i1.5334

Shandilya, S. K., Singh, Y., Izonin, I., & Hentosh, L. (2024). Metaverse forensics framework: A NIST based investigation framework for the metaverse. In Science and Justice (Vol. 64, Number 6). https://doi.org/10.1016/j.scijus.2024.10.005

Sudiana, D., Nuruddin, CH, Rizkinia, M., & Husna, D. (2024). Forensic Analysis of WhatsApp Disappearing Message on Unrooted Android Using Mobile Device Forensics Methodology NIST SP 800-101r1. Evergreen , 11 (1). https://doi.org/10.5109/7172316

Syaiful Huda Mubarok, M., Ardiansyah, A., Novrianda Dasmen, R., Pranata, V., & Januarta, MA (2024). Digital Analysis of Forensic Data Recovery on Flash Drive Using National Institute of Justice (NIJ) Method. Jurnal Ilmiah Informatika , 12 (01).

Syukri, M., Riadi, I., & Sutikno, T. (2025). Validation and Evaluation of Browser Forensics Using Digital Forensic Approach Based on the National Institute of Standards and Technology (NIST) Framework. Journal of Informatics Engineering (Jutif) , 6 (4). https://doi.org/10.52436/1.jutif.2025.6.4.4977

Downloads

Submitted

25-06-2026

Accepted

27-07-2026

Published

30-06-2026

How to Cite

Walidain, F., & Firmansyah, F. (2026). Digital Forensic Recovery and Analysis of WhatsApp Artifacts on Android Using the NIST Framework. International Journal of Business, Technology and Organizational Behavior (IJBTOB), 6(3), 241–252. https://doi.org/10.53363/ijbtob.v6i3.412

Similar Articles

1 2 3 > >> 

You may also start an advanced similarity search for this article.