įrom digital forensics point of view, the advancement of technology enables digital crimes to be committed by diverse means and methods, such as mobile devices. Therefore, WhatsApp is considered a gold mine for forensics evidences and artifacts due to the vast amount of data it stores. All these features can be utilized by variety of fields and users, for evil or for good purposes. WhatsApp is well-known for its diverse features, it enables text messaging, videos, images and voice notes transmission, video and audio calls. Additionally, several researchers’ requirements such as: creating projects, comprehensive analysis, applying filters and validating the extracted files, were not met in the studied tools. The results of the comparative study showed a shortage in the current WhatsApp forensics tools as they do not satisfy all NIST Test Assertions. The comparative study is based on two aspects National Institute of Standards and Technology (NIST) Mobile Device Tool Test Assertions and researchers’ requirements. This study analyzes and compares currently available forensics tools that are designed to extract WhatsApp data only. Both cases are effort and time consuming. Unfortunately, the resultant output does not facilitate investigating cases related to specific mobile application, since the tool might acquire more than what is needed which requires investigators to filter data manually, or acquire all the application’s data without sufficient analysis. The current mobile acquisition tools use these methods to produce an image of the entire mobile content, files of specific datatypes, or data of a certain application.
#Elcomsoft explorer for whatsapp erfahrungen manual
Before starting investigation, the investigator should choose one of the acquisition types physical acquisition, logical acquisition or manual acquisition. Hence, an urgent need for mobile forensics. With the increasing number of mobile phones and mobile applications, there is a noticeable rise in cybercrimes.