Richu Ann Thomas
Abstract: An Instant messenger application can serve as a very useful yet very dangerous platform for the victim and the suspect to communicate WhatsApp is one of the worlds most popular instant messengers. There by, the artifacts left by them have become very relevant evidences these days in crime investigation. In Android phones Information is stored in different formats at varied locations on the phone. In this paper we discuss about the Android live memory acquisition & an in-depth Android Memory Analysis to retrieve the chat logs, deleted and encrypted messages, VOIP & Cloud Backup features provided by WhatsApp as well as its SQLite databases & structure.
Keywords: Android forensics, Instant Messenger Applications, WhatsApp, Memory Analysis, Live Memory Forensics, Cloud Backup