Certification & Online Trace Collection · service active
WACZ · ISO 28500/ eIDAS timestamping/ Client area
C.E.R.T.O.
Sign in Register free
IT EN
C.E.R.T.O. / Modules / Telegram
09 · CHAT

Telegram

Seal Telegram chats, groups and channels, preserving messages, media and metadata in a verifiable way.

The acquisition is performed from Telegram Web: on the left your linked account, on the right C.E.R.T.O. listing chats, groups and channels and letting you select them (here 157 chats, with channels and their counts). Flat rate: 5 slots (+2 with a qualified eIDAS InfoCert timestamp), independent of the volume.

C.E.R.T.O.'s Telegram module performs the forensic acquisition of Telegram chats, groups and channels operating from Telegram Web: once the account is linked, it captures the messages (with date, time and author), the media (photos, videos, audio, documents) and the session metadata, while recording a video of the whole session. It acquires private chats, groups, supergroups and channels. Everything is sealed as digital evidence with a per-element hash, a double RFC 3161 timestamp and an Ed25519 signature. On Telegram a message can be “deleted for everyone” at any time and a channel can vanish: it is the tool for court-appointed and party experts, lawyers and law enforcement who must freeze the content before it changes.

Key features

What this module does.

  • Acquisition of private chats, groups and channels (MTProto mirror).
  • Media and metadata with hash + session video recording.
  • Offline interactive HTML dashboard.
  • BagIt 1.0 bundle signed with Ed25519, double RFC 3161 timestamp and CASE/UCO.
Final forensic report: the interactive dashboard of the Telegram bundle — summary (chats, messages, media, duration, TSA stamp), operator and acquisition, account and session, system environment, chats and messages, media, session recording, chain of custody, hash inventory and integrity check.
The rationale

On Telegram, too, nothing is forever.

Telegram messages live in the service's cloud, but stay at the mercy of whoever wrote them: a message can be “deleted for everyone” at any time, a channel or group can vanish, and secret chats self-destruct. Acquiring them promptly fixes them while they exist.

“Deleted for everyone”, no time limit

Unlike other platforms, on Telegram a message can be deleted for all participants at any time, even years later. What has been acquired and sealed, however, stays in the bundle, with a certified date.

Channels & groups can be removed

A public channel or a group can be wiped, made private or deleted by its admins. Freezing its content beforehand is often the only way to preserve it as evidence.

Self-destructing secret chats

Secret chats are end-to-end encrypted, device-bound and have a self-destruct timer: content disappears on its own. If not acquired in time, the evidence vanishes.

Video of the whole session

The acquisition is recorded in full as a video: it transparently documents what the operator saw and did, from linking to chat capture, strengthening genuineness and repeatability.

Telegram Web

How the acquisition happens.

C.E.R.T.O. operates via Telegram Web: you link the account — just like for normal use on the computer — while the software extracts the messages, media and metadata of the selected chats and records the entire session.

The Telegram Web interface captured in the session recording: the list of the account's chats, groups and channels. The whole session is recorded as a video (.webm) and as frames, downloadable from the bundle. Click to enlarge.
01 · LINK

Account linking

You link your account to Telegram Web, exactly as in everyday use on the computer.

02 · REC

Session recording

From start to finish, the screen is recorded as a video: every operation performed during the acquisition is documented and repeatable.

03 · SELECT

Chat & channel selection

Private chats, groups, supergroups and channels of the account are listed and you choose those to acquire, with the option to download media.

04 · CAPTURE

Message & media capture

Extraction of messages (text, date, time, author) and download of media and attachments, before they can be removed.

Chat types

Chats, groups, supergroups and channels.

Telegram is not only private messaging: channels with thousands of subscribers and large groups can hold hundreds of media. C.E.R.T.O. acquires them all at a flat rate, whatever the volume.

The acquisition in progress in C.E.R.T.O. Desktop: the progress bar shows the chat being processed, with Pause and Cancel buttons. The banner reminds the flat rate: 5 slots, independent of the number of messages and media acquired. Click to enlarge.

Private chats

One-to-one conversations, with the messages, media and metadata of both parties, in their original order.

Groups & supergroups

Group discussions, with each message attributed to its author and all the shared media.

Channels

Broadcast channels, even with thousands of subscribers: the published posts, the media and the metadata, frozen before they change.

Flat rate

5 slots (+2 with a qualified eIDAS InfoCert timestamp), independent of the number of messages and media: a channel with thousands of items costs the same as a short chat.

Review

Messages and media, browsable offline.

The bundle includes an interactive dashboard: the conversation is faithfully reconstructed (bubbles, dates, authors) and all the captured media are gathered in a gallery, each with its own hashes and clickable for preview.

Faithful messages

Text, date, time and author of every message, in the original order of the conversation, for private chats, groups and channels.

Media gallery

Downloaded images, videos, audio and documents, gathered in a filterable gallery openable from the dashboard, each with its own hashes.

Account & session

The account identifiers, the platform and the technical context of the web client at acquisition time.

Transparent log

Every step of the acquisition is recorded with a timestamp: a complete, verifiable trace of how it was carried out.

Forensic pipeline

How the module operates.

A repeatable, documented procedure: from synchronised time to the cryptographic seal, every message and every media item leaves a verifiable trace inside the bundle.

01 · NTP

Synchronised time

Multi-source NTP sync with documented offset: the acquisition window is anchored.

02 · LINK

Telegram Web

Linking the account to Telegram Web and starting the video recording of the whole session.

03 · SESSION

Session collection

Capture of account and session metadata and of the web client state (cookies, storage) at acquisition time.

04 · CHATS

Chat capture

Extraction of the messages of the selected chats, groups and channels, with date, time, author and original order.

05 · MEDIA

Media download

Download of the media and attachments and computation of MD5/SHA-1/SHA-256 for each item.

06 · SEAL

Signature & double timestamp

manifest.json signed with Ed25519 + double RFC 3161 timestamp, packaging into a BagIt 1.0 bundle with a CASE/UCO description and verify.sh / verify.bat verifiers.

Bundle contents

Everything that gets generated.

Each acquisition produces a coordinated set of artefacts, each with a precise forensic role, organised into clearly-named folders inside data/.

Chats & messages

The acquired chats, groups and channels in browsable HTML and structured JSON: text, date, time, author and media references, in their original order.

evidence/chats/

Media & attachments

Photos, videos, audio and documents downloaded from the chats, preserved in their original format: the authoritative media of the bundle.

evidence/media/

Session recording

The video of the entire acquisition session (.webm) and the extracted frames: the transparent proof of how the operation was carried out.

evidence/session/recording.webm

Account & session

The account and session metadata and the web client state: cookies and storage at acquisition time, with the list of available chats.

evidence/session/ · network/

Hash inventory

The hashes (MD5/SHA-1/SHA-256) of every media item and every artefact of the bundle: the fingerprint that proves their integrity.

hashes/media-hashes.json

Report & log

The forensic report (PDF/TXT) with its own RFC 3161 timestamp and the detailed acquisition log, event by event, with timestamps.

reports/report.pdf · acquisition-log.txt

Self-validation

A bundle that proves itself.

The bundle does not need C.E.R.T.O. to be validated: anyone, even years from now, can verify its authenticity with standard tools. The BagIt 1.0 structure and the interactive dashboard make it self-explanatory.

  • interactive.html — the navigable offline dashboard: summary, chats and messages, media, session recording, account and session, hash inventory, log and client-side integrity check.
  • manifest.json signed with Ed25519 (RFC 8032), bound to the identity of the device registered at first launch.
  • Double RFC 3161 timestamp: inner anchor on data/tsa.tsr and outer seal on tagmanifest-sha256.txt.tsr. Free cascade Sectigo→DigiCert→GlobalSign; optional qualified eIDAS InfoCert.
  • manifest-sha256.txt and tagmanifest-sha256.txt (RFC 8493): fixity of the payload and of the control files; no media or message can be added or altered without the check failing.
  • metadata/evidence.case.jsonldCASE 1.3 / UCO 1.4 description of the evidence, and tsa-ca.pem for verifying the timestamp even offline.
  • verify.sh / verify.bat — standalone verifiers: they recompute the hashes, check the double timestamp and the signature, and declare “VALID BUNDLE”.
FAQ

Frequently asked questions

Telegram acquisition from Telegram Web, channels and groups, message deletion, cost and bundle verification: the most common questions.

How is Telegram acquired?
The acquisition is performed via <b>Telegram Web</b>: you link your account as for normal use on the computer and C.E.R.T.O. extracts the messages, media and metadata of the selected chats, while simultaneously recording a video of the whole session. You can acquire private chats, groups, supergroups and channels.
Can channels and groups be acquired, not just private chats?
Yes. C.E.R.T.O. acquires <b>private chats, groups, supergroups and channels</b>: for each it extracts the messages (with date, time and author), the media and the metadata. It is particularly useful to freeze the content of a public channel or a group before it is modified or removed.
Can messages and media on Telegram disappear?
Yes. On Telegram a message can be <b>“deleted for everyone” at any time</b>, with no time limit; a channel or a group can be removed and <b>secret chats</b> are end-to-end encrypted and self-destructing. Acquiring promptly fixes content and media while they are present.
What exactly is acquired?
The selected chats (messages with date, time and author), all media and attachments (images, videos, audio, documents), the account and session metadata, the session video and the detailed acquisition log. A hash MD5/SHA-1/SHA-256 is computed for every media item.
How much does it cost? Does it depend on the number of messages or media?
The rate is <b>flat</b>: 5 slots (+ 2 with a qualified eIDAS InfoCert timestamp), <b>independent of the number of messages and media</b> acquired. Whether you acquire a chat with ten messages or a channel with thousands of media, the cost does not change.
Is the acquisition valid as evidence in court?
The bundle follows recognised standards (ISO/IEC 27037, BagIt RFC 8493, RFC 3161, CASE/UCO) with an Ed25519 signature and a double timestamp; the authenticity and integrity of messages and media can be verified by anyone, even offline. The session video and per-element hashing strengthen the evidentiary value; the final assessment rests with the adjudicating authority.

Collect evidence with the Telegram module.

Register for free and download C.E.R.T.O. Desktop for Windows and macOS from your client area.