THE KEY POINTS
What to take with you.
- Specify WhatsApp and the Android phone in the collection request.
- A phone acquisition, a cloud backup, and a native chat export are different evidence sources.
- Analyzer supports Android WhatsApp decryption workflows and processing of native WhatsApp ZIP/TXT chat exports.
WhatsApp evidence starts with the source.
When a matter involves WhatsApp on Android, identify the phone and the evidence the team needs before deciding how to collect it. A conversation visible in the app, a device acquisition, a cloud backup, and a text export are related to the same account, but they are different sources for review.
MARA collects WhatsApp evidence from both iPhone and Android phones. Its Android WhatsApp workflows connect phone collection to downstream processing in Analyzer. The receiving team can work with the collected evidence rather than asking the custodian to turn every relevant chat into a separate email.
WhatsApp data is familiar to many reviewers through iPhone backup workflows. Android should still be named explicitly in the request: the phone’s platform, the app data, and the collection approach need to be considered together. Avoid assuming that a procedure used for an iPhone describes the Android acquisition.
The source of the evidence
Collect supported data
Receive the collection
Review and export
Phone collection, backup, or chat export?
A useful intake question is: “What do we actually have?” The answer determines the next processing step.
| Source | Starting point | Review question |
|---|---|---|
| Phone collection | The custodian’s device and its acquired supported data. | What WhatsApp evidence was obtained, and how will the team review it? |
| WhatsApp backup | An existing app recovery source. | When was it made, what does it contain, and what is needed to process it? |
| Native chat export | A chat exported from WhatsApp as text, with optional media. | Which chat and available attachments are represented in the supplied files? |
WhatsApp’s export documentation describes a per-chat text export with optional recent media. It also distinguishes an export from a backup that can be restored into WhatsApp. For evidence processing, that makes the exported files a source in their own right rather than a replacement for every artifact available through a phone acquisition.
Keep the backup’s context with the files.
WhatsApp supports Android backups to a Google Account and optional end-to-end encrypted backups. Backup timing and settings matter when considering what that source represents.
A backup can be useful, but “we have the backup” is not yet a complete processing instruction. Establish the source, when it was created or last updated, and whether the team has what is needed to handle it. Keep original supplied files together with that context; do not overwrite them with a converted output.
For a new MARA collection, the custodian follows the assigned phone workflow. Your team does not need to translate app-specific processing into improvised instructions for the custodian. For an existing source supplied to Analyzer, identify the format and the processing task before treating the result as ready for review.
Two useful WhatsApp workflows in Analyzer.
MARA Analyzer supports Android WhatsApp decryption workflows as part of processing supported source data. It also supports a different starting point: native WhatsApp chat exports supplied as ZIP or TXT files, with available associated media, for ingestion and downstream processing.
These options let a forensic team work with the source it actually has. A phone acquisition can lead into artifact review. An existing native export can be processed for downstream review without pretending that the export is a new phone acquisition.
Processing can organize supplied evidence; it cannot make a limited source contain history or attachments that were never supplied. Preserve the distinction between the original input and the resulting review output. When describing the result to the receiving team, identify whether it came from a phone collection or a native chat export.
For Enterprise teams, Analyzer access is included with the collection packs. That connects collection and processing within the MARA offering, including the Android WhatsApp and native export workflows. The Enterprise workspace is the place to explore that operating model.
For a new collection, keep the handoff simple.
The law firm requests the collection through its MARA portal and identifies the relevant phone and apps. MARA coordinates the custodian, who opens the invitation link and follows the collection page. Android collections use the guided path, with the phone connected to a supported computer.
After successful collection, the app starts the secure upload automatically. The firm can track the collection, then download the verified deliverables from the same portal. The result can move into Analyzer for review and export.
The firm's request should state the evidence need and receiving workflow. It does not need to contain a custom technical recipe. Read the remote collection preparation guide for the practical setup a custodian should have ready.
Define what the receiving team needs.
Before collecting or importing, agree what “ready for review” means for the matter: the relevant message evidence, available associated media, collection documentation, and the receiving team’s export requirements.
A good request might be: “We need WhatsApp evidence from this Android phone for our review team.” If the source is already an export, say that instead: “We have a native WhatsApp ZIP/TXT export and need it processed.” These are both useful requests. Keeping their starting points explicit helps everyone understand the result.