Forensics Analysis of WhatsApp Using Virtual Machines
摘要
Using Instant Messaging (IM) such as Telegram, WhatsApp, etc. has become part of people’s daily activities. IM facilitates users’ communication with family, friends, social groups, and business-related activities. However, there are downsides associated with the use of this technology including online crime, fraud, malware, exploitation of minors, etc. In addition, many users may accidentally expose personal and intimate details about themselves, their friends, and their relationships online. This can be done by posting photos, participating in group activities, polling, and providing personally identifiable information such as their home addresses, phone numbers, etc. Forensic analysis of IMs can help investigators solve the crimes or misuse of IMs. This experimental research aims to investigate traces of WhatsApp user’s activities via computer forensics. The activities may include personal information or any type of exploitation information. Several open-source forensics tools will be used in the experiment. The platform for the experiment is Virtual Machines. This research demonstrates that memory forensics is more effective than regular forensics in retrieving IM-related artifacts.