Before you begin
Atlas is intended for authorized forensic examination of devices, backups, and acquired evidence. Obtain the appropriate legal authority, consent, or organizational authorization before acquiring or examining data. Preserve original evidence and work from forensic copies whenever the case procedure requires it.
What’s New in This Revision
This revision brings the guide in line with the current Atlas build (application version 0.1.0). The table lists what is new or changed and where it is described. A case processed by an earlier build must be re-processed to populate the newer views (see section 8).
| Area | What changed (section) |
|---|---|
| Case time zone | A time zone is chosen when the case is created and applied to all analytics, reports and chat exports (4.1, 8.3). |
| OCR control | “Skip OCR” option on the Android and iOS setup pages; a startup warning when Tesseract is not found (6.3, 10.2). |
| Multi-DB and deleted chats | Older snapshots are processed as their own cases and whole deleted chats are recovered as HTML (6.4, 12.4, 12.6). |
| Incremental backups | msgstore-increment-N backups are decoded to show what was edited or deleted, and when (6.5, 9.11, 12.5). |
| Deleted Msg tab | Deleted chats, messages, revoked and modified messages, media and documents in one place (9.11). |
| Media view | Kind tabs, grid/list, preview, filters and “Open chat at this media” (9.4). |
| Media recovery by hash | Match missing media to extra evidence by SHA-256, thumbnail-only status and optional confirmed re-download (13). |
| Calls tab | Call log with KPIs, filters and CSV export (9.6). |
| Chat Details window | Split-screen chat view with message provenance and device timeline (9.2). |
| Activity, Identity, Fraud pack | New tabs for payments, channels, business and Meta AI messages, number/name/group changes and fraud indicators (9.12 to 9.14). |
| Locations & Timeline | Live-location paths and a combined case timeline in addition to shared-location maps (9.9). |
| Reports | HTML or PDF output, a report options dialog with company logo, and new report sections (11). |
| Network use | A summary of what Atlas contacts online, and when (15.5). |
| Corrections | Numbered procedures now restart at 1. The Multi-DB, Signals and Locations descriptions were updated to match the application (the group-call roster now lives in Calls). |
1. Product Overview
Atlas is a case-oriented WhatsApp forensic analysis application. It creates or opens a case workspace, acquires or imports WhatsApp data, normalizes platform-specific databases into an analysis model, calculates forensic analytics, performs integrity checks, and presents the results through an interactive analytics interface.
Core capabilities
| Capability | Description |
|---|---|
| Case management | Create a case folder, case name, and case number/ID. |
| Android acquisition | Pull WhatsApp data from a connected Android device through ADB over USB or Wi-Fi, or import an existing acquisition folder/ZIP. |
| Android decryption | Process WhatsApp encrypted databases using a compatible key file or 64-character hexadecimal key; supports crypt12, crypt14 and crypt15 inputs where supported by the acquisition. |
| iOS acquisition | Take a full device backup from a connected iPhone/iPad through the bundled iOS acquisition workflow, or use an existing iOS backup folder. |
| WhatsApp parsing | Normalize WhatsApp databases into a common analysis dataset. |
| Multi-DB comparison | Compare Android msgstore snapshots and incremental backups to surface messages, media and whole chats that are absent from the newest snapshot, and recover deleted chats as HTML. |
| Incremental backups | Decode WhatsApp incremental backups to show which messages were edited or deleted, and when; recover the text from older snapshots where available. |
| Media recovery by hash | Match media whose file is missing to files in extra evidence sources by SHA-256; thumbnail-only status and an optional, confirmed re-download. |
| Message provenance | Android: sending device, device/server/received times, receipts, edit and revoke events and media hashes for each message. |
| Case time zone | All times are shown in one time zone chosen when the case is created; stored evidence stays in UTC. |
| Analytics | KPIs, chats, content, media, groups, calls, signals, links/mentions, locations and live-location paths, combined case timeline, search, contacts and correlation, deleted messages, activity (payments, channels, business and Meta AI), identity changes, fraud indicators and integrity findings. |
| Reporting | Generate HTML or PDF case reports (with an optional company logo) and JSON case reports; export chat, media and document bundles and the call log (CSV). |
| Evidence integrity | SHA-256 input hashing, integrity findings, media completeness checks, and deletion/anti-forensic indicators. |
| Case protection | Case analysis data is encrypted at rest and tied to the application's licensing/case-key workflow. |
Typical workflow
Case → Platform → Acquire/Import → Review detected inputs → Parse → Analyze → Investigate → Export/Report → Preserve case.
2. Installation and First Launch
2.1 Installer requirements
| Requirement | Guidance |
|---|---|
| Operating system | Windows 10 or later; the supplied installer is configured for x64-compatible Windows. |
| Privileges | Installation requires administrator privileges because Atlas is installed under Program Files. |
| Disk space | Keep sufficient free space for the source acquisition plus a full working copy/analysis database and reports. iOS live extraction creates a full device backup, so its temporary/storage requirement can be substantially larger than WhatsApp data alone. |
| Network | Internet access is required for license activation and license/case-key verification. Case opening can require a reachable licensing service. The Locations map and place-name lookups, and the optional media re-download, also use the Internet (see 15.5). |
| USB | Required for live Android USB acquisition and live iOS acquisition. |
| Android tools | The compiled release bundles platform-tools/ADB; a separate ADB installation is normally not required for the shipped application. |
2.2 Installing Atlas
Run AtlasSetup-<version>.exe.
Accept the installer prompts and allow the requested Windows administrator elevation.
Choose the optional desktop shortcut if desired. The shortcut is not selected by default in the installer configuration.
Complete installation. Atlas is installed under Program Files.
Optionally enable “Launch Atlas now” on the final installer screen.
2.3 First launch
On first launch, Atlas checks its license state. If no usable license is present, the activation dialog requests a license key in the ATLAS-XXXX-XXXX-XXXX-XXXX format.
2.4 Installation/upgrade behavior
The installer can replace an existing Atlas installation. Close Atlas before upgrading. The installer removes the previous installed application tree before copying the new release so stale binaries do not remain.
3. Licensing and Activation
Atlas uses a license-based activation system. A license is associated with the machine and the license service. The application performs license checks at important checkpoints, including device extraction and case access.
Activate a license
Start Atlas.
When the Activate Atlas dialog appears, enter the license key provided by your organization/vendor.
Select the activation action and wait for confirmation.
If activation succeeds, continue to the Case Wizard.
If activation is rejected, verify that the key is correct and that it has not already been activated on another machine.
Common license messages
| Message type | Meaning / action |
|---|---|
| License required / not activated | Enter a valid license key. |
| Already activated elsewhere | The license seat is associated with another machine; contact the license administrator/support or use an available key. |
| License revoked | The server has explicitly revoked the license; contact the license administrator/support. |
| Subscription expired | The license subscription period has ended; obtain/renew the appropriate license. |
| License check failed | The locally stored license could not be verified. Confirm network connectivity and retry activation if requested. |
| Cannot reach license server | Check network/firewall/proxy/DNS and retry. |
| Case quota exceeded | The license's case quota for the current period has been reached. |
| Maximum cases open | Close another Atlas analytics case if the license limits concurrent open cases. |
4. Case Creation
The Case Wizard is the starting point for examination. The case folder becomes the working location for the case's analytics and outputs.
4.1 Create a case
On the Case Wizard page, select Browse… beside Case folder.
Select an existing folder or create/select a dedicated case folder.
Enter Case name. Example: “John Doe WhatsApp”.
Enter Case number / ID. Example: “CASE-2026-001”.
Choose the Time zone for this case. The default is India (IST).
Select Continue.
4.2 Case folder recommendations
Use one dedicated folder per forensic case.
Do not use the Windows Program Files installation folder as a case folder.
Use a storage location with adequate capacity and controlled access.
Keep original evidence in a separate evidence repository; use acquired/working copies for processing.
Do not manually rename or remove Atlas-generated case files while the case is open.
4.3 Platform selection
The platform page presents Android and iOS cards. Select the platform matching the source evidence. Atlas then asks whether you want to extract from a connected device or proceed with an existing acquisition/backup.
5. Choosing Android or iOS
| If you have… | Use… |
|---|---|
| Authorized Android device connected to the workstation | Android → Yes, extract from connected device. |
| Android acquisition folder from a forensic tool/manual pull | Android → No → Browse Folder…. |
| ZIP containing com.whatsapp/ and/or WhatsApp/ | Android → No → Select Zip…. |
| Android encrypted msgstore database + key | Android → No → enter/select backup and key directly. |
| Authorized iPhone/iPad connected by USB | iOS → Yes, extract from connected device. |
| Existing iOS/iTunes/3uTools/forensic backup folder | iOS → No → Browse… for the backup folder. |
6. Android Workflow
6.1 Live Android extraction
When Android is selected, Atlas can pull WhatsApp data from a connected Android device using ADB. USB and Wi-Fi devices are treated as ADB devices once connected.
Connect the Android device and enable the required USB/Wireless Debugging functions according to your examination procedure.
Select Android and answer Yes to “Extract from device?”.
Atlas checks for ADB and lists detected devices.
If multiple devices are present, select the correct device and choose Use selected device.
For an unauthorized device, unlock it and accept the “Allow USB debugging?” prompt, then Retry.
Leave “Attempt root/run-as internal-data recovery (decryption key, contacts)” enabled when your authorized workflow permits it.
Wait for extraction to complete. Review warnings in the extraction dialog.
Choose Continue. Atlas uses the extracted data to pre-fill the Android case fields.
6.2 Android Wi-Fi acquisition
The Android extraction dialog provides three network options:
Switch selected USB device to Wi-Fi — changes an already connected USB device into an ADB-over-network connection.
Connect — connect to an Android device whose wireless debugging endpoint is already available. Enter the device IP and port.
Pair — for Android 11+ wireless debugging, enter the pairing IP, pairing port, and six-digit pairing code shown by the device.
6.3 Manual Android acquisition
The Android case setup supports an acquisition folder or ZIP. If selected, Atlas searches the tree for relevant WhatsApp structures and automatically fills detected fields.
| Field | Purpose |
|---|---|
| Person name | Optional label associated with the case/subject. |
| Acquisition folder or ZIP | Convenience input containing com.whatsapp/ and/or WhatsApp/. |
| Multi-DB mode | Optional checkbox. Finds every msgstore snapshot in the acquisition folder and compares them for deleted messages and media (see 6.4). |
| Skip OCR | Optional checkbox. Faster processing; scanned or photographed PDFs will not be searchable. Text-based PDFs are still indexed. |
| Encrypted backup file | msgstore.db.crypt12, .crypt14 or .crypt15 file when available. |
| Key file / 64-char hex key | WhatsApp decryption key source. |
| Contact backup | Optional encrypted crypt15 wa.db backup for contact information. |
| Case folder | Read-only display of the selected case workspace. |
| Output folder | Automatically set to <case folder>\chats. |
| Template file | Optional custom HTML template. |
6.4 Multi-DB mode
Enable “Multi-DB mode” when the acquisition folder contains multiple msgstore snapshots and you want Atlas to compare them. Atlas searches for the live database and every historical encrypted snapshot, such as msgstore-YYYY-MM-DD.N.db.crypt1x. If only one database is found, Atlas behaves like a normal single-database run.
The newest snapshot becomes the main analysis case. It receives the normal analytics, case report and HTML chat export.
Each older snapshot is processed as its own independent case under multi_db\<label>\, so it can also be reviewed on its own.
Older snapshots are compared against the newest snapshot. Chats, messages, edited or revoked messages, media and document references present in an older snapshot but absent from the newest are surfaced as deletion-related evidence.
Whole deleted chats are recovered as HTML, using the same exporter as a normal run, under multi_db\deleted_chats\index.html (see 12.6).
Incremental backups found in the acquisition folder are decoded and used to confirm and date deletions (see 6.5).
Findings are added to the Integrity view and the case report. A standalone deletion report is written under reports\multi_db_deletion_report.json.
6.5 Incremental backups
WhatsApp on Android also writes small daily incremental backups, named like msgstore-increment-N-YYYY-MM-DD.S.db.crypt14. An incremental backup is not a database. Once decrypted it is an archive of changes: it records that a message was removed or edited, and when, but not what the message said. Atlas decodes these backups and, where possible, recovers the text from an older full snapshot or an earlier increment.
Place the increment files in the acquisition folder, or next to the encrypted backup. Already-decrypted increment ZIP archives are also accepted.
Provide the key as usual. The same key file or 64-character hexadecimal key is used to decrypt the increments.
Run the Android parse, with or without Multi-DB mode. Increments are recognised by file name and kept out of the main/older snapshot ranking.
Open the Deleted Msg tab and review the Incremental backups panel (see 9.11).
6.6 Run Android Parse
Review the auto-filled backup/key/media fields.
Select Multi-DB mode if historical snapshot comparison is required.
Select Skip OCR only if scanned or photographed PDFs do not need to be searchable.
Optionally provide a custom HTML template.
Select Run Android Parse.
Monitor the progress bar and Run log.
Wait for completion before opening the analytics workspace.
7. iOS Workflow
7.1 Live iOS extraction
The live iOS workflow takes a full device backup through the iOS acquisition component and then extracts the WhatsApp data needed for analysis. It is not a WhatsApp-only device backup operation.
Connect the iPhone/iPad by USB and unlock it.
Select iOS and answer Yes to “Extract from device?”.
If the device asks “Trust This Computer?”, tap Trust and enter the device passcode.
If multiple devices are detected, select the correct UDID and choose Use selected device.
Optionally enable WhatsApp Business if the target data is from WhatsApp Business.
If the backup is encrypted, enter the backup password in the password field.
Allow the full backup to complete. Keep the device connected and unlocked as required.
Select Continue after a successful backup.
7.2 Manual iOS backup
| Field | Purpose |
|---|---|
| Person name | Optional subject/person label. |
| Skip OCR | Optional checkbox. Faster processing; scanned or photographed PDFs will not be searchable. Text-based PDFs are still indexed. |
| Backup password | Password for an encrypted iOS backup, when required. |
| iOS backup folder | Existing iOS backup/acquisition directory. |
| Case folder | Selected case workspace. |
| Output folder | Automatically set to <case folder>\chats. |
| Template file | Optional custom HTML template. |
7.3 Run iOS Parse
Select the backup folder or use the folder populated by live extraction.
Enter the backup password if the backup is encrypted.
Optionally provide a person name and custom HTML template.
Select Skip OCR only if scanned or photographed PDFs do not need to be searchable.
Select Run iOS Parse.
Monitor the progress and Run log.
After completion, open the analytics workspace to review the case.
7.4 iOS call-history caveat
On iOS, Atlas can enrich the Calls view from Apple's system CallHistory.storedata. This is system-level call activity associated with CallKit-capable apps, not a WhatsApp-only call database. Where WhatsApp contact resolution is unavailable, the UI may fall back to a raw phone number/handle.
8. Analytics Workspace
After successful parsing, Atlas opens a case analytics workspace. The navigation is organized around investigation tasks. Most views can be scoped to a focused chat and/or date range where supported. Some tabs are populated only when the source data supports them; each says so when it is empty.
| View | Primary purpose |
|---|---|
| Overview | Case-level KPIs, case timeline, date range, report generation, top contacts and integrity findings. |
| Chats | List and inspect conversations; open the Chat Details window (details, message provenance, device timeline) and export a chat. |
| Content | Message types, reactions, forwarded messages and polls. |
| Media | Browse, filter, preview and trace attachments to the exact message; media recovery status and recovery sources. |
| Groups | Group roster churn and a per-group join/leave timeline. |
| Calls | Call KPIs, busiest days, one-to-one and group calls, a filterable call log and CSV export. |
| Signals | Chats with disappearing messages enabled, and view-once media. |
| Links & Mentions | Shared links and domains, and mention leaderboards. |
| Locations & Timeline | Shared-location map, frequent places, live-location paths and the combined case timeline. |
| Search | Keyword search across messages, and document search with OCR. |
| Contacts & Map | Contact list, correlation map and block/unblock timeline. |
| Deleted Msg | Deleted chats, messages, media and documents from Multi-DB comparison, and what incremental backups recorded. |
| Activity | Communication classes (people, groups, channels, Meta AI and bots), business and Meta AI messages, payments and channels. |
| Identity | Number changes, name and username history, group name and icon changes, admin roster and role changes. |
| Fraud pack | Payments, suspicious-flagged media, heavily forwarded content, business/template messages and foreign-number indicators. |
| Integrity | Media completeness, integrity findings and deleted-chat/anti-forensic indicators. |
8.1 Date-range filtering
Several views respond to the case timeline/date-range selection. Use a narrow date range when examining a specific incident, then return to the full case range for context. Views such as Groups, Contacts and Integrity may include case-wide information that is not constrained in the same way as message-centric views.
8.2 Focused chat
Selecting a chat can focus Content, Locations, Links & Mentions, Media, Calls and Signals on that conversation. Use “All chats” where available to return to a case-wide view.
8.3 Case time zone
All dates and times in analytics, reports and chat exports are displayed in the time zone selected when the case was created. The zone is fixed for the life of the case. Stored evidence timestamps remain in UTC, so a different examiner can still reconstruct the original values. State the case time zone whenever you quote a time from Atlas.
9. Investigative Views
9.1 Overview
Use Overview as the initial orientation screen. Review the case metadata, message and chat volume, the activity timeline, media present/missing counts, top contacts and integrity findings before drilling into individual chats. Overview also holds the date-range selector and the Generate report control (see section 11).
9.2 Chats and the Chat Details window
Use Chats to locate conversations by name or JID. Each row shows message and media counts, first and last activity and a status. Select a row to see that chat’s activity ribbon. Open chat opens the Chat Details window; Export… saves the chat’s HTML and media to a folder.
Chat Details window. Details are on the left and the chat’s exported HTML is on the right, in the same window. The left side has three tabs: Overview, Message provenance and Device timeline.
Message provenance (Android). Search and filter the chat’s messages. Selecting a message shows the sending device (number, primary or linked, identity); the device, server and received times with a neutral verdict; delivered, read and played status for each recipient; per-device delivery acknowledgements; edit and revoke events; and the media hashes (as sent, original and encrypted) with an on-demand “Verify against file on disk”. Show in chat scrolls to and highlights the message in the right-hand pane.
Device timeline. Shows the first and last message seen from each device number for each person, compared with the cached device list, as a lifeline chart. When the list carries no refresh date, Atlas infers the windows in which it can have been refreshed from the devices seen.
9.3 Content
Content provides the message-type breakdown, reaction emoji frequency, reactions given and received by contact, forwarded messages ranked by forward score, and polls. Use the chat selector to scope the view to one conversation.
9.4 Media
Media lists every image, video, audio or voice note, document, sticker and GIF in the case. Narrow the list with the kind tabs (which show counts), the chat selector, the sent/received filter, the filename/caption search, the sort order and the Grid/List toggle. Load more pages through large cases, and the left and right arrow keys step through items.
The All / Missing only / Deleted (Multi-DB) toggle shows every item, only items whose file is missing from the case, or, when a Multi-DB comparison exists, media referenced only by older snapshots.
The recovery status filter and the Recovery sources panel match missing media to extra evidence (see section 13).
Selecting an item shows a preview and its details, including how the file was located on this machine and a flag if the recorded size differs from the file on disk. A ×N badge marks a file attached to several messages, with Open there links for the other chats.
Open chat at this media opens the chat’s exported HTML in an in-app window, scrolled to and highlighting the exact message. In browser opens the same page in the default browser, which may ignore the message anchor and cannot highlight it.
Open file works only for a list of safe types (images, audio, video, PDF and common Office and text files). Other types can only be shown in their folder. Opening a PDF or Office file hands the evidence to the operating system’s default application.
Video and audio preview depends on the codecs available. If a file will not play, use Open file or Show in folder.
9.5 Groups
Groups ranks every group by roster churn (joins plus leaves and removals). Select a group to see its roster timeline, including past participants who left.
9.6 Calls
Calls is built from the Android call log. It shows KPIs (including missed calls), the busiest days, a leaderboard of one-to-one calls by contact, every group call with its own participant roster, and the complete call log. The log can be filtered by All, Incoming, Outgoing, Missed and Video. Export CSV writes every call in the case, regardless of the on-screen filter.
Outgoing is any call placed from the device, whether or not it connected.
Missed is an incoming call that never connected.
Connected or Not connected is decided from the call duration (a duration above zero means connected). WhatsApp’s own call_result code is shown alongside it but is not interpreted, because there is no documented mapping of its values.
The by-contact leaderboard covers one-to-one calls only. Group calls are listed separately, each with its participants.
9.7 Signals
Signals lists the chats where disappearing messages are currently enabled and the view-once media found in the case.
9.8 Links & Mentions
Review the domains shared, recent links and the mention leaderboard, then pivot back to the relevant chat and message. On iOS, mention rows come from shared contact-card matches rather than live @-mentions in message text.
9.9 Locations & Timeline
Use the chat selector and date range to constrain the view. Three sub-tabs are available.
Shared locations. A map of location-share messages (amber for sent by me, blue for received). Hover a point for the chat, time, coordinates and place name; click it to open the chat. Below the map, Frequent places groups repeated shares within roughly 100–150 m, and All shares lists the most recent shares (up to 500).
Live-location paths. Joins live-location shares into paths on a map, with one-shot pins shown separately. A table lists each path and notes explain how it was built. The view follows the focused chat and date range.
Combined case timeline. Merges calls, deletions and edits, confirmed system events and locations into a single list, with “notable windows” highlighted. Filter by event kind, optionally include routine security notices or unnamed system codes, choose the sort order, and use Show more to page through the list.
9.10 Contacts & Map
Contacts lists every contact by message volume; selecting one focuses the dashboard on that chat. The correlation map shows shared group membership and correlated activity patterns, with line thickness showing strength. Search for a person, drag nodes, click a node to pin it and trace its connections, and scroll to zoom; Reset layout restores the default. The Block / unblock timeline lists block events. Correlation edges are analytical relationships, not proof of identity or intent.
9.11 Deleted Msg
Deleted Msg gathers deletion evidence recovered by Multi-DB comparison and by incremental backups. If the case holds no such findings, the tab says so and explains how to produce them: run Multi-DB mode on the acquisition folder and include the incremental backups.
The main list has tabs for All, Deleted chats, Deleted messages, Revoked (recovered), Modified, Media and Documents. Search by name, number, chat id or message text; tick Resolved identities only or Confirmed by incremental backup to narrow the list; sort newest or oldest first; Load more pages through long lists. A Deletion windows panel shows the time windows derived from the snapshots and backups.
The Incremental backups panel lists deletions recorded day by day. Below it, “What the backups recorded, message by message” has four tabs: Edits & deletions, Added / updated messages, Group leaves and Calls. The panel appears even when Multi-DB mode was not used.
9.12 Activity
Activity looks beyond one-to-one chats. Communication classes separates people, groups, channels, Meta AI and bots, status/broadcast and other traffic. Business & Meta AI messages lists messages tagged as business templates, business notices or Meta AI. Payments and Channels list that content where present.
Payments keep WhatsApp’s raw status and type codes and are not interpreted. Credential ids, payment methods, bank transaction ids and free-form payment metadata are never imported.
Existing statistics are not changed. Overview and KPI figures still count every chat; channels and bots are separated only in this view and in the report.
9.13 Identity
Identity assembles a change timeline for the people and groups in the case: phone-number changes and histories (including numbers that changed back), links between @lid identifiers and phone numbers, masked-number names, push and saved names, usernames, old group names, group icon changes (with the old and new thumbnails), the admin roster and role-change events. Search by name, number, group or username, filter by event kind and choose the sort order.
Group-name changes store only the old name. The new name is derived (from the next change, or the current subject) and is marked as derived.
Admin promotion dates are not stored. Role changes are shown as a raw code with the target’s current role.
Only system codes confirmed against detail tables are named. Unnamed codes are hidden by default in the timeline views.
Real push names come from the contacts database (wa.db) when it is supplied; otherwise only masked numbers may be available.
9.14 Fraud pack
Fraud pack collects indicators that may help a reviewer: payments, suspicious-flagged media, heavily forwarded content (and the same content in several chats), business and template messages (one-time-passcode text is masked) and the foreign-number mix. Two controls adjust it: Heavily forwarded from score (default 4) and Home country prefix (automatic unless you enter one), then Apply.
9.15 Integrity
Integrity is the principal evidence-quality review area. Examine media completeness, integrity findings, deleted-chat/deletion-related signals and any warnings before drawing conclusions. When a Multi-DB comparison exists, a panel summarises deleted chats and messages across snapshots, with a button to open the Deleted Msg tab. The deleted-chat and anti-forensic section is Android-only bookkeeping that can survive a chat being deleted on the device; it is empty on iOS cases by design.
10. Search and Document Search
10.1 Message keyword search
Open Search.
Enter a keyword or phrase in Search message text.
Optionally select a chat.
Set From/To dates when a time window is required.
Run the search.
Review matching messages and use the available open/export actions to preserve relevant context.
10.2 Document search
Atlas can search text extracted from document attachments. PDFs with a text layer can be searched directly; where a PDF lacks a usable text layer, Atlas can OCR the document to make text searchable.
OCR uses Tesseract. If Tesseract is not found when Atlas starts, a warning explains how to install it and offers Locate tesseract.exe… for a non-standard location; OCR then applies to cases processed afterwards. Selecting Skip OCR on the setup page bypasses OCR entirely (text-based PDFs are still indexed). The Search page can show a banner describing the OCR status of the case.
Open Search → Document search.
Enter a document-text query.
Select Search.
Review matching documents and associated chat context.
Use Export documents + chats… when you need an examination bundle.
10.3 Export search results
Search results can be exported with Export all matching chats… (message search) or Export documents + chats… (document search). Exported bundles are intended to preserve useful context and associated media/documents rather than replacing the original forensic evidence.
11. Reports and Exports
11.1 Automatic case report
After a normal Android or iOS analysis run, Atlas can generate a latest.wareport.html and latest.wareport.json report in the case reports directory. The report contains case/environment information, evidence metadata, methodology/results, discrepancies/integrity findings and a conclusion section.
11.2 Interactive report generation
On the Overview tab, set an optional date range, choose HTML or PDF and select Generate report. A Report options dialog then lets you choose the summary level, which media to include and an optional company logo. The report follows the focused chat and date range.
| Option | Use |
|---|---|
| Full summary | Retain broader case-level analytical detail. |
| Short summary | Produce a more concise report for review/distribution. |
| All media | Include media across the report scope. |
| Only media in selected date range | Restrict included media when a date range is selected. |
| Company logo | Optional PNG, JPEG, SVG or WebP image shown in the report header and footer. |
| Media links | Always on: every media item included is copied to an attachments folder next to the report and linked to that copy. |
| HTML or PDF | Chosen on the Overview tab before generating. The PDF is rendered from the same report page. |
Newer builds add report sections for call activity, media recovery by hash, communication classes and payments, the identity and change timeline, the fraud pack, live-location paths (with a path map) and the combined case timeline. Short summaries include only the notable-window events of the timeline.
11.3 Chat export
Chat export can bundle a conversation's HTML representation with associated media. This is useful for sharing a self-contained review package while preserving the underlying case separately.
11.4 Calls CSV
The Calls view provides an Export CSV action that writes every call in the case, ignoring the on-screen filter. Preserve the exported CSV as a derived artifact and document its relationship to the source case.
11.5 Export discipline
Do not edit an exported report and represent it as an original Atlas-generated artifact.
Record the export date/time and examiner in your case notes.
Retain the original case workspace separately from distributed report copies.
When a report is provided to a third party, include the relevant attachments/media bundle where required.
State the case time zone whenever you quote times from an export.
12. Integrity and Deletion Analysis
12.1 Input hashing
Atlas calculates SHA-256 hashes for important normalized input database artifacts and records them in the case manifest. These hashes help detect changes to processed inputs between runs.
12.2 Integrity findings
The Integrity view collects discrepancies and evidence-quality findings detected during normalization and analytics. Findings can relate to database/media inconsistencies, missing attachments and other conditions that affect interpretation.
12.3 Media completeness
Atlas compares message/media references with files that can be resolved in the case workspace. A high missing-media count does not automatically prove deletion; it can also result from an incomplete acquisition, unavailable external media, path differences or source-tool limitations. Where media is missing, section 13 describes how to attempt recovery by hash.
12.4 Android multi-DB deletion analysis
When multiple msgstore snapshots are available, Atlas can compare older snapshots with the newest snapshot. Records that existed in older snapshots but are not present in the newest snapshot are surfaced as deletion-related evidence.
| Finding | Interpretation |
|---|---|
| Older message absent from newest snapshot | Candidate historical/deletion evidence; investigate snapshot dates and database lifecycle. |
| Media reference present but file missing | Possible missing acquisition/media, path mismatch, or deletion; correlate with source layout and integrity findings. |
| Multiple snapshots show changing records | Expected in a rolling backup environment; interpret differences in chronological context. |
| Whole chat present only in an older snapshot | Deleted chat. Atlas also recovers it as HTML (see 12.6); the content reflects the snapshot it was read from. |
| Message edited or revoked between snapshots | Listed as modified or revoked (recovered). Compare the versions and their timestamps. |
12.5 Incremental backup findings
Incremental backups (see 6.5) record changes rather than content, so they are interpreted differently from full snapshots.
| Finding | Interpretation |
|---|---|
| Message id listed as deleted | The message row was removed from the database before that increment. The text is shown only if an older snapshot or an earlier increment holds it. |
| Edit event | The increment records the original message id and the new text. Compare it with the original in an older snapshot. |
| Group leave or call record | Group departures and call entries recorded by an increment are listed on the Deleted Msg tab for correlation with the main database. |
| Header count differs from decoded messages | Atlas records a note when an increment’s header count differs from what it could decode. The cause is not determined; mention the difference in your report. |
12.6 Recovered deleted chats
In Multi-DB mode Atlas renders each whole deleted chat as HTML, using the same exporter as a normal run and reading from the newest older snapshot that still contains the chat. The results are written under multi_db\deleted_chats\, with an index.html that lists every recovered chat. Only the attachments that the recovered chats reference are copied alongside them.
13. Media Recovery by Hash
A chat can reference an attachment whose file is not in the case. Media recovery matches such items to files in extra, read-only evidence sources by the SHA-256 value WhatsApp stored for the attachment. It is optional, and it applies to Android cases (the iOS media table carries no hash columns).
13.1 Add recovery sources and match
Open the Media tab and select Recovery sources.
Select Add folder… or Add zip… for each extra evidence source, for example a second acquisition or a media folder produced by another tool. ZIP files are never extracted.
Select Index & match. Atlas hashes the files in the sources and compares them with the stored hash of every missing item.
Review the summary and the coverage table, then use the recovery status filter on the Media tab to inspect the results.
Sources are read-only. A matched file is referenced in place and is not copied into the case.
Files are hashed as a stream, with a size pre-filter. Cancel keeps a valid partial index, and re-running reuses files that have not changed.
A match means an identical SHA-256. Several files can match one item, and one file can match several items; both are recorded.
Identical file in this case needs no extra source: a missing item is matched to another message’s file with the same stored hash, but only after that file’s actual bytes are hashed and equal the stored value. It ranks below a match from an external source.
13.2 Recovery statuses
| Status | Meaning |
|---|---|
| Missing | The chat references a file that is not on disk and no recovery has been found. |
| Recovered – matched file | A file in a recovery source has the same SHA-256 as the stored hash. |
| Recovered – identical file in this case | Another message in the case carries a file whose bytes match the stored hash. |
| Thumbnail only | Only WhatsApp’s stored thumbnail (or a quoted-message preview matched by hash) is available. It is a preview, never the original file. |
| Recovered – re-downloaded | The file was downloaded after you confirmed a re-download and passed every hash check. |
13.3 Optional re-download from WhatsApp
For an item that carries the data a download needs, the item details offer Try re-download from WhatsApp…. Atlas asks for confirmation first (the default answer is No), because this contacts a WhatsApp server. Nothing is contacted unless you ask for it.
Atlas checks the downloaded data against the stored encrypted-file hash and its message authentication code, then checks the decrypted file against the stored file hash. Only a file that passes every check is saved, under recovered_media\cdn_download\ in the case folder.
Server refusals (403, 404, 410) and network failures are normal results, because WhatsApp removes media after a time. They are reported, not treated as errors.
Every attempt is recorded in an audit table. The media key is held separately from the media table and is never written to logs, reports or the interface.
If an item cannot be re-downloaded the details say why.
13.4 Coverage and reporting
The Recovery sources panel includes a coverage table: missing media per month (in the case time zone) and per file type, split into recovered, thumbnail only and missing, with a count of unrecovered items that could be re-downloaded. The case report gains a “Media recovery by hash” section giving the number checked, matched, unmatched and thumbnail only, with the sources used and their file counts.
14. Case Files and Output Structure
A typical case workspace contains Atlas-managed metadata, analysis data, reports and chat/export material. Exact contents vary by platform, acquisition type and release.
| Path / pattern | Purpose |
|---|---|
| <case>\case.wacase.json | Case metadata/manifest used by the application. |
| <case>\analysis.wacase | Protected analysis database/case analysis data. |
| <case>\chats\ | Working area and chat HTML/export material. |
| <case>\export_ledger.sqlite | Index of exported chats and their HTML files; used to open chats from Media and Chat Details. |
| <case>\media_recovery.sqlite | Media recovery work tables (sources, matches, downloads, audit), kept beside the case database. |
| <case>\recovered_media\cdn_download\ | Files recovered by a confirmed re-download. |
| <case>\multi_db\plan.json | Which msgstore snapshots were found and how they were ranked (Multi-DB mode). |
| <case>\multi_db\<label>\ | An independent case for each older snapshot (Multi-DB mode). |
| <case>\multi_db\deleted_chats\index.html | Overview of deleted chats recovered as HTML, with the recovered chats beside it. |
| <case>\reports\latest.wareport.html | Human-readable generated forensic report. |
| <case>\reports\latest.wareport.json | Structured report representation. |
| <case>\reports\multi_db_deletion_report.json | Android multi-DB comparison report when multi-DB mode is used. |
| <case>\_zip_extract\ | Extraction area created for relevant content imported from Android ZIP archives. |
| Attachments/export folders | Derived media/document copies associated with reports or exports. |
Do not manually delete protected case files
Atlas uses an encrypted analysis database and licensing/case-key workflow. Do not copy only individual internal case database files and expect them to open independently. Preserve the case folder as a unit.
15. Evidence, Security and Privacy
15.1 Case data protection
Atlas protects the analysis database at rest using a server-issued case key. The application keeps the active case key in memory during a case session rather than treating a local plaintext key file as the authoritative long-term storage mechanism.
15.2 Licensing data
The application's per-user license data is stored outside the Program Files installation directory. The installer does not remove this license data during ordinary uninstall, allowing a later reinstall to reuse the activation state where the license remains valid.
15.3 Sensitive evidence
Treat WhatsApp content, attachments, locations, contacts and call information as sensitive personal data.
Restrict case-folder permissions to authorized examiners.
Avoid placing case data in consumer-synced folders unless permitted by your evidence-handling policy.
Do not include passwords, decryption keys or device passcodes in general-purpose report distributions.
Keep a record of who accessed/exported the case.
15.4 Originals and working copies
Atlas should normally operate on an acquired copy. If your laboratory procedure requires a pristine original image, mount or copy it according to the laboratory's validated workflow rather than allowing Atlas to modify the original.
15.5 Network activity
Atlas processes evidence locally. It uses the network only in these cases:
License activation and license/case-key verification.
The Locations & Timeline maps load the Leaflet map library and OpenStreetMap tiles online, and place names are looked up with the Nominatim geocoding service, which means coordinates from the case are sent to that service.
Media re-download contacts a WhatsApp server, and only after you confirm it (see 13.3).
16. Troubleshooting
| Problem | Recommended action |
|---|---|
| Atlas will not activate | Confirm Internet connectivity, system date/time, license key and whether the key is already assigned to another machine. |
| License server unreachable | Check firewall/proxy/DNS and network access. Retry when the service is reachable. |
| Case will not open | Confirm the license is active and Internet access is available; case keys may need to be re-issued by the license service. |
| Android device shows unauthorized | Unlock the device, accept the USB debugging authorization prompt, then Retry. |
| Android device offline | Reconnect the cable/network connection or restart the ADB server and Retry. |
| No Android device detected | Check cable, USB debugging, device drivers/permissions and that the device is awake/unlocked. |
| Wi-Fi ADB fails | Confirm the IP/port, wireless debugging state, pairing status and that the workstation and device can communicate. |
| Android key not found | Use the acquisition-folder discovery, select the key manually, or provide a valid 64-character hexadecimal key if your authorized evidence workflow supplies one. |
| Android backup decrypts but media is missing | Ensure the external WhatsApp/Media directory was included in the acquisition and select the acquisition folder/ZIP rather than only the encrypted database. |
| iOS device not detected | Connect via USB, unlock the device and accept Trust This Computer. Retry. |
| iOS trust/pairing error | Reconnect the device, unlock it, accept the trust prompt and retry. |
| iOS backup password error | Confirm the backup password. Do not confuse the device passcode with the encrypted backup password. |
| iOS extraction runs out of disk space | Free sufficient local storage; live iOS extraction takes a full device backup. |
| Parse fails with a missing/invalid input | Review the Run log. Confirm that the selected backup/database belongs to the selected platform and is readable. |
| Media count is lower than expected | Review Integrity → Media completeness and verify that the external media directory was acquired. For items that remain missing, try Media → Recovery sources (section 13). |
| Search returns no results | Check spelling, date range, focused-chat filter and whether the source actually contains the searchable text. |
| Document search has poor OCR | Open the original document and validate the OCR-derived text manually. |
| Installer upgrade fails or Atlas is running | Close Atlas and run the installer again with administrator rights. |
| Atlas starts but immediately closes | This is typically a release/build or integrity issue. Reinstall the same signed release or contact the distributor/support with the installer version and any visible error details. |
| Locations map is blank or place names are missing | The map and place names need Internet access. Check the network or proxy; the coordinates and tables still display. |
| A tab (Calls, Identity, Fraud pack, Activity, provenance) is empty | The case may have been processed by an older build, or the source may not hold the data (iOS has no WhatsApp call log and no provenance). Re-run the parse on the original source. |
| Startup warning that Tesseract OCR was not found | Install Tesseract, or choose Locate tesseract.exe… in the warning. OCR then applies to cases processed afterwards. Alternatively select Skip OCR. |
| Open chat at this media opens at the top with a warning | The message is not in the exported HTML. If the chat has no export the button is disabled. |
| Open file is unavailable for a media item | Only safe file types can be opened; other types can only be shown in their folder. The file may also be missing (see section 13). |
| Re-download is unavailable or fails | The item may lack the stored hashes, path or key, or WhatsApp no longer holds the file (403, 404 or 410), or the network failed. These are normal outcomes. |
| Incremental backups show deletions but no message text | Increments record that a message was removed, not what it said. Text appears only if an older snapshot or an earlier increment holds it. |
| Video or audio preview does not play | Preview depends on the available codecs. Use Open file or Show in folder. |
16.1 Capture useful troubleshooting information
Atlas version/installer version
Windows version
Android/iOS device model and OS version, where relevant
Case ID
Exact operation being performed
The visible Run log/error message
Whether the problem occurs with another known-good acquisition
Case time zone and whether the case was processed by an earlier build
17. Recommended Examination Procedure
Minimum examination notes
| Record | Example |
|---|---|
| Case ID | CASE-2026-001 |
| Subject/person | John Doe |
| Source | Android acquisition / iOS backup |
| Acquisition date/time | 2026-09-29 18:30 IST |
| Atlas version | 0.1.0 |
| Case time zone | Asia/Kolkata (IST) |
| Recovery sources | Folders/ZIPs added for media recovery; any re-download performed |
| Examiner | <name> |
| Input hash(es) | SHA-256 values from case manifest |
| Special conditions | Encrypted backup; password supplied by authorized source |
| Limitations | Missing media; partial backup; unavailable call history; etc. |
18. Limitations and Platform Notes
Android
Successful WhatsApp decryption depends on obtaining the correct backup/key material and on the source acquisition containing the relevant files.
ADB access does not automatically guarantee access to protected application data. The live extractor attempts supported recovery paths and reports what it can obtain.
Media analysis depends on the external WhatsApp/Media content being acquired.
Multi-DB comparisons depend on having multiple usable snapshots.
Incremental backups record that a message was removed or edited, not its original text. Text is recoverable only from older snapshots or earlier increments.
Message provenance, the device timeline, payments and most deletion indicators come from Android-only tables.
Media recovery by hash depends on the stored hash values and on the extra evidence you supply.
iOS
Live acquisition creates a full device backup rather than a WhatsApp-only backup.
Encrypted iOS backups require the correct backup password.
iOS call records come from the system CallHistory.storedata and should not automatically be treated as WhatsApp-only calls.
Some contact/call resolution is best-effort and can fall back to raw phone numbers/handles.
iOS stores no sending device and keeps receipts in a format Atlas does not decode, so there is no message provenance.
The WhatsApp iOS database holds no call history and no media hashes for recovery; iOS revoked-message and system-event tables are not modelled, so iOS deletions and system events are absent from the timeline.
Analytics
Correlation graphs represent analytical relationships such as shared groups or temporal activity; they are not identity attribution.
Location maps represent location records present in the acquired dataset; absence of a location is not evidence that the device was never at a location.
OCR text is derived data and should be validated against the source document.
Missing media can have several causes and must be interpreted in context.
A live-location path is a set of straight lines between recorded positions, not a recorded route.
Fraud pack and Activity figures are indicators for a human reviewer. Undocumented codes are shown raw and are not interpreted.
A thumbnail-only item is a preview, not the original file. A hash match proves identical content, not where the file was held.
Reports
Generated reports are derived analytical artifacts. They should be retained alongside the underlying case and source evidence, not used as a substitute for the source acquisition.
19. Quick Reference
| Task | Path |
|---|---|
| Create a case | Launch → Case folder → Case name → Case ID → Continue |
| Choose the case time zone | Case Wizard → Time zone for this case (before Continue) |
| Android live extraction | Android → Yes → select device → extract → Continue |
| Android acquisition folder | Android → No → Browse Folder… |
| Android ZIP | Android → No → Select Zip… |
| Android multi-DB | Android → enable Multi-DB mode → Run Android Parse |
| Skip OCR | Android or iOS setup → Skip OCR checkbox |
| Review incremental backups | Deleted Msg → Incremental backups |
| Recover a deleted chat as HTML | Android multi-DB run → multi_db\deleted_chats\index.html |
| iOS live extraction | iOS → Yes → unlock/trust → backup → Continue |
| Existing iOS backup | iOS → No → Browse… → Run iOS Parse |
| Review case | Analytics → Overview |
| Find a conversation | Analytics → Chats |
| Find a keyword | Analytics → Search |
| Find a document phrase | Analytics → Search → Document search |
| Review missing media | Analytics → Integrity; Media → Missing only |
| Review deletion signals | Analytics → Deleted Msg and Integrity; Android multi-DB report when applicable |
| Export a chat | Chats → Export… |
| Export calls | Calls → Export CSV |
| Generate report | Overview → Generate report (HTML or PDF) → Report options |
| Match missing media | Media → Recovery sources → Add folder… / Add zip… → Index & match |
| Re-download missing media | Media → select item → Try re-download from WhatsApp… (confirm) |
| Open a chat at a media item | Media → select item → Open chat at this media |
| Message provenance | Chats → Open chat → Message provenance |
| Device timeline | Chats → Open chat → Device timeline |
| Live-location paths | Locations & Timeline → Live-location paths |
| Combined case timeline | Locations & Timeline → Combined case timeline |
| Payments, channels, business messages | Activity |
| Number, name and group changes | Identity |
| Fraud indicators | Fraud pack |
Recommended first five checks after parsing
Confirm case name/ID and platform.
Confirm message/chat counts look plausible.
Check media completeness.
Check Integrity findings, the Deleted Msg tab and deletion-related indicators.
Run targeted searches for known dates, contacts, terms and documents.
Appendix A — Glossary
| Term | Meaning |
|---|---|
| ADB | Android Debug Bridge; used by Atlas for authorized Android device communication. |
| Case folder | User-selected workspace containing Atlas case data and derived outputs. |
| crypt12/crypt14/crypt15 | WhatsApp encrypted database backup formats supported by the Android workflow where compatible key material is available. |
| msgstore | WhatsApp Android message database/snapshot. |
| ChatStorage | A principal iOS WhatsApp chat database used by the iOS parser. |
| Manifest.db | Database used by many iOS backup formats to map backup file identifiers to logical paths. |
| SHA-256 | Cryptographic hash function used by Atlas for input integrity records. |
| Multi-DB | Android workflow that discovers and compares multiple msgstore snapshots. |
| Integrity finding | A condition identified during analysis that may affect evidence completeness or interpretation. |
| Incremental backup | A WhatsApp Android backup (msgstore-increment-N) that records changes since an earlier backup, such as removed or edited messages, rather than a full database. |
| Provenance | Per-message technical origin: sending device, device/server/received times, receipts, edits and media hashes. |
| Recovery source | A read-only folder or ZIP of extra evidence that Atlas searches by hash for missing media. |
| Thumbnail only | A media recovery status: only WhatsApp’s stored preview is available, not the original file. |
| LID (@lid) | WhatsApp’s alternative account identifier, used instead of a phone number in some chats. Atlas links LIDs to phone numbers where the evidence supports it. |
| Case time zone | The time zone chosen at case creation and used to display all times; stored evidence stays in UTC. |
| Derived artifact | An output created by analysis from source evidence, such as an HTML report, CSV or OCR text. |
| Case key | Encryption key used to protect the Atlas analysis database for a case. |
| Focused chat | A selected conversation used to scope supported analytics views. |
Appendix B — Examiner Checklist
☐ Authorization/legal basis confirmed
☐ Case ID assigned
☐ Evidence source documented
☐ Original/acquisition copy preserved
☐ Source hashes recorded where required
☐ Atlas license verified
☐ Case folder created
☐ Case time zone confirmed
☐ Correct platform selected
☐ Acquisition/backup source validated
☐ Android key/password or iOS backup password handled securely
☐ Parse completed successfully
☐ Run log reviewed
☐ Media completeness reviewed
☐ Missing-media recovery attempted; sources and any re-download documented
☐ Integrity findings reviewed
☐ Multi-DB comparison performed if historical snapshots exist
☐ Incremental backups included where available; Deleted Msg tab reviewed
☐ Targeted message/document searches completed
☐ Relevant chats/media/documents exported
☐ Calls/locations/links reviewed where relevant
☐ Provenance, Identity, Fraud pack and Timeline reviewed where relevant
☐ Online lookups (maps, place names, re-download) avoided or documented per procedure
☐ Report generated and reviewed
☐ Limitations documented
☐ Final case workspace preserved