The rapid development of communication technology has made instant messenger applications like WhatsApp frequently misused in cybercrimes, requiring proper digital forensics handling. However, the security architecture in modern operating systems such as Android 14 poses a major challenge for investigators due to strict restrictions on internal access and rooting. This study aims to conduct a digital forensic investigation to recover WhatsApp Messenger data artifacts on an unrooted Android 14 device by implementing the National Institute of Standards and Technology (NIST) SP 800-86 framework. The method utilized is logical acquisition based on Android Debug Bridge (ADB) pull commands for data collection, combined with Autopsy and DB Browser for SQLite software for the examination and analysis phases. The experimental results indicate that this methodology was 100% successful in meeting NIST compliance standards and successfully recovered thousands of multimedia assets with a total data volume of approximately 10.7 GB. The recovered data details include 6,664 images, 1,042 videos, 1,092 audios, 25 archive files, and 3 supporting documents. Nevertheless, the testing recorded a total failure in recovering deleted text messages due to the Android 14 sandbox protection, which isolates the main database files within an encrypted internal directory that strictly requires root access. In conclusion, this combination of ADB and Autopsy methods is highly recommended for rapid digital triage processes because it is safe, non-destructive, and capable of maintaining the integrity of the chain of custody without altering the target device's original system. .
Copyrights © 2026