13
About Me

Whats app forensic

Embed Size (px)

Citation preview

Page 1: Whats app forensic

About Me

Page 2: Whats app forensic

I am Not A....● Teacher● Trainer● Hacker

● .........I am An IT Security Analyst ........

Page 3: Whats app forensic

Todays Entertainment

WhatsApp Forensic

Page 4: Whats app forensic

Introduction

Page 5: Whats app forensic

Steps to Perform Forensic

Page 6: Whats app forensic

Key Artifiacts of WhatsApp

● Main Evidence files-->>

● ->/data/data/com.whatsapp/databases/msgstore.db

● ->/data/data/com.whatsapp/databases/wa.db

● ->/sdcard/WhatsApp/Databases/msgstore.db.crypt8

Page 7: Whats app forensic

Directory Structure

● Main Evidence Directories-->>

● .Shared - Hidden

● .Trash - Hidden

● Databases

● Media

● Profile Pictures

Page 8: Whats app forensic

Ricovery Methods

● 1. Online Websites

● Example:- https://www.recovermessages.com/

2. Get back Deleted WhatsApp Messages Manually

● 3. Tools

● Example:- Oxygen Forensic Suite, Mobiledit Etc

Page 9: Whats app forensic

Comman Challenges

● 1. Encryption

● 2. Tools are Paid

● 3. Patience and Time Consuming

Page 10: Whats app forensic

Demo...

Page 11: Whats app forensic

References

->http://sch3m4.github.io/wforensic/

->http://www.magnetforensics.com/recovering-whatsapp-forensic-artifacts/

->http://blog.digital-forensics.it/2012/05/whatsapp-forensics.html

Page 12: Whats app forensic

Credits -->> Internet & Me

Page 13: Whats app forensic

Any Queries..??

----------->>Thank You<<-----------