Analyzing Browser Forensics With Hindsight

mukul975/Anthropic-Cybersecurity-Skills/skills/analyzing-browser-forensics-with-hindsight

by mukul97554a798831d2266a3ca61ce68a7acb80b81160d57Apache-2.0Listed Oct 9, 2026Updated Oct 9, 2026

Parse Chromium-based browser databases with Hindsight to extract and correlate browsing history, downloads, cookies, cached content, autofill data, saved passwords, and extensions from Chrome, Edge, Brave, Opera, and Vivaldi into a unified timeline (XLSX, JSON, or SQLite output). Use during incident response, insider-threat investigations, or criminal cases when you need to reconstruct a user's web activity from a browser profile.

Includes scriptsSecurity
AI-generated overview

Parses Chromium-based browser profile databases with Hindsight to reconstruct web activity timelines for investigations.

What it does
Uses Hindsight and SQLite queries to extract browsing history, downloads, cookies, autofill data, saved logins, bookmarks and extensions from Chrome, Edge, Brave, Opera and Vivaldi profiles. It correlates these artifacts into a chronological timeline and produces reports in XLSX, JSON or SQLite formats. It ships Python scripts that read profile databases and write a JSON report.
When to use it
Intended for incident response, insider-threat investigations and criminal cases where a user's web activity must be reconstructed from a browser profile. Also suited to SOC analysts building detection rules or validating monitoring coverage for related techniques.
Requirements
Python 3.8+ with Hindsight installed (pip install pyhindsight), access to browser profile directories from a forensic image, and profile data not protected by OS-level encryption. Output analysis needs a spreadsheet or timeline viewer. Ships executable Python scripts.

Analyzing Browser Forensics with Hindsight

Overview

Hindsight is an open-source browser forensics tool designed to parse artifacts from Google Chrome and other Chromium-based browsers (Microsoft Edge, Brave, Opera, Vivaldi). It extracts and correlates data from multiple browser database files to create a unified timeline of web activity. Hindsight can parse URLs, download history, cache records, bookmarks, autofill records, saved passwords, preferences, browser extensions, HTTP cookies, Local Storage (HTML5 cookies), login data, and session/tab information. The tool produces chronological timelines in multiple output formats (XLSX, JSON, SQLite) that enable investigators to reconstruct user web activity for incident response, insider threat investigations, and criminal cases.

When to Use

  • When investigating security incidents that require analyzing browser forensics with hindsight
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Python 3.8+ with Hindsight installed (pip install pyhindsight)
  • Access to browser profile directories from forensic image
  • Browser profile data (not encrypted with OS-level encryption)
  • Timeline Explorer or spreadsheet application for analysis

Browser Profile Locations

BrowserWindows Profile Path
Chrome%LOCALAPPDATA%\Google\Chrome\User Data\Default\
Edge%LOCALAPPDATA%\Microsoft\Edge\User Data\Default\
Brave%LOCALAPPDATA%\BraveSoftware\Brave-Browser\User Data\Default\
Opera%APPDATA%\Opera Software\Opera Stable\
Vivaldi%LOCALAPPDATA%\Vivaldi\User Data\Default\
Chrome (macOS)~/Library/Application Support/Google/Chrome/Default/
Chrome (Linux)~/.config/google-chrome/Default/

Key Artifact Files

FileContents
HistoryURL visits, downloads, keyword searches
CookiesHTTP cookies with domain, expiry, values
Web DataAutofill entries, saved credit cards
Login DataSaved usernames/passwords (encrypted)
BookmarksJSON bookmark tree
PreferencesBrowser configuration and extensions
Local Storage/HTML5 Local Storage per domain
Session Storage/Session-specific storage per domain
Network Action PredictorPreviously typed URLs
ShortcutsOmnibox shortcuts and predictions
Top SitesFrequently visited sites

Running Hindsight

Command Line

bash
# Basic analysis of a Chrome profilehindsight.exe -i "C:\Evidence\Users\suspect\AppData\Local\Google\Chrome\User Data\Default" -o C:\Output\chrome_analysis
# Specify browser typehindsight.exe -i "/path/to/profile" -o /output/analysis -b Chrome
# JSON output formathindsight.exe -i "C:\Evidence\Chrome\Default" -o C:\Output\chrome --format jsonl
# With cache parsing (slower but more complete)hindsight.exe -i "C:\Evidence\Chrome\Default" -o C:\Output\chrome --cache

Web UI

bash
# Start Hindsight web interfacehindsight_gui.exe# Navigate to http://localhost:8080# Upload or point to browser profile directory# Configure output format and analysis options# Generate and download report

Artifact Analysis Details

URL History and Visits

sql
-- Chrome History database schema (key tables)-- urls table: id, url, title, visit_count, typed_count, last_visit_time-- visits table: id, url, visit_time, from_visit, transition, segment_id
-- Timestamps are Chrome/WebKit format: microseconds since 1601-01-01-- Convert: datetime((visit_time/1000000)-11644473600, 'unixepoch')

Download History

sql
-- downloads table: id, current_path, target_path, start_time, end_time,--   received_bytes, total_bytes, state, danger_type, interrupt_reason,--   url, referrer, tab_url, mime_type, original_mime_type

Cookie Analysis

sql
-- cookies table: creation_utc, host_key, name, value, encrypted_value,--   path, expires_utc, is_secure, is_httponly, last_access_utc,--   has_expires, is_persistent, priority, samesite

Python Analysis Script

python
import sqlite3import osimport jsonimport sysfrom datetime import datetime, timedelta
CHROME_EPOCH = datetime(1601, 1, 1)
def chrome_time_to_datetime(chrome_ts: int):    """Convert Chrome timestamp to datetime."""    if chrome_ts == 0:        return None    try:        return CHROME_EPOCH + timedelta(microseconds=chrome_ts)    except (OverflowError, OSError):        return None
def analyze_chrome_history(profile_path: str, output_dir: str) -> dict:    """Analyze Chrome History database for forensic evidence."""    history_db = os.path.join(profile_path, "History")    if not os.path.exists(history_db):        return {"error": "History database not found"}
    os.makedirs(output_dir, exist_ok=True)    conn = sqlite3.connect(f"file:{history_db}?mode=ro", uri=True)
    # URL visits with timestamps    cursor = conn.cursor()    cursor.execute("""        SELECT u.url, u.title, v.visit_time, u.visit_count,               v.transition & 0xFF as transition_type        FROM visits v JOIN urls u ON v.url = u.id        ORDER BY v.visit_time DESC LIMIT 5000    """)    visits = [{        "url": r[0], "title": r[1],        "visit_time": str(chrome_time_to_datetime(r[2])),        "total_visits": r[3], "transition": r[4]    } for r in cursor.fetchall()]
    # Downloads    cursor.execute("""        SELECT target_path, tab_url, start_time, end_time,               received_bytes, total_bytes, mime_type, state        FROM downloads ORDER BY start_time DESC LIMIT 1000    """)    downloads = [{        "path": r[0], "source_url": r[1],        "start_time": str(chrome_time_to_datetime(r[2])),        "end_time": str(chrome_time_to_datetime(r[3])),        "received_bytes": r[4], "total_bytes": r[5],        "mime_type": r[6], "state": r[7]    } for r in cursor.fetchall()]
    # Keyword searches    cursor.execute("""        SELECT k.term, u.url, k.url_id        FROM keyword_search_terms k JOIN urls u ON k.url_id = u.id        ORDER BY u.last_visit_time DESC LIMIT 1000    """)    searches = [{"term": r[0], "url": r[1]} for r in cursor.fetchall()]
    conn.close()
    report = {        "analysis_timestamp": datetime.now().isoformat(),        "profile_path": profile_path,        "total_visits": len(visits),        "total_downloads": len(downloads),        "total_searches": len(searches),        "visits": visits,        "downloads": downloads,        "searches": searches    }
    report_path = os.path.join(output_dir, "browser_forensics.json")    with open(report_path, "w") as f:        json.dump(report, f, indent=2)
    return report
def main():    if len(sys.argv) < 3:        print("Usage: python process.py <chrome_profile_path> <output_dir>")        sys.exit(1)    analyze_chrome_history(sys.argv[1], sys.argv[2])
if __name__ == "__main__":    main()

References

Example Output

text
$ python hindsight.py -i /evidence/chrome-profile -o /analysis/hindsight_output
Hindsight v2024.01 - Chrome/Chromium Browser Forensic Analysis================================================================
Profile: /evidence/chrome-profile (Chrome 120.0.6099.130)OS: Windows 10
[+] Parsing History database...    URL records:          12,456    Download records:     234    Search terms:         567
[+] Parsing Cookies database...    Cookie records:       8,923    Encrypted cookies:    6,712
[+] Parsing Web Data (Autofill)...    Autofill entries:     1,234    Credit card entries:  2 (encrypted)
[+] Parsing Login Data...    Saved credentials:    45 (encrypted)
[+] Parsing Bookmarks...    Bookmark entries:     189
--- Browsing History (Last 10 Entries) ---Timestamp (UTC)          | URL                                          | Title                        | Visit Count2024-01-15 14:32:05.123  | https://mail.corporate.com/inbox             | Corporate Mail                | 452024-01-15 14:33:12.456  | https://drive.google.com/file/d/1aBcDe...    | Q4_Financial_Report.xlsx     | 12024-01-15 14:35:44.789  | https://mega.nz/folder/xYz123               | MEGA - Secure Cloud          | 32024-01-15 14:36:01.234  | https://mega.nz/folder/xYz123#upload        | MEGA - Upload                | 82024-01-15 14:42:15.567  | https://pastebin.com/raw/kL9mN2pQ           | Pastebin (raw)               | 12024-01-15 15:01:33.890  | https://192.168.1.50:8443/admin              | Admin Panel                  | 122024-01-15 15:15:22.111  | https://transfer.sh/upload                  | transfer.sh                  | 22024-01-15 15:30:45.222  | https://vpn-gateway.corporate.com            | VPN Login                    | 52024-01-15 16:00:00.333  | https://whatismyipaddress.com                 | What Is My IP                | 12024-01-15 16:05:12.444  | https://protonmail.com/inbox                 | ProtonMail                   | 3
--- Downloads (Suspicious) ---Timestamp (UTC)          | Filename                    | URL Source                               | Size2024-01-15 14:33:15.000  | Q4_Financial_Report.xlsm   | https://phish-domain.com/docs/report     | 245 KB2024-01-15 14:34:02.000  | update_client.exe          | https://cdn.evil-updates.com/client.exe  | 1.2 MB
--- Cookies (Session Tokens) ---Domain                   | Name              | Expires            | Secure | HttpOnly.corporate.com           | SESSION_ID        | 2024-01-16 14:32   | Yes    | Yes.mega.nz                 | session           | Session            | Yes    | Yes.protonmail.com          | AUTH-TOKEN        | 2024-02-15 00:00   | Yes    | Yes
Report saved to: /analysis/hindsight_output/Hindsight_Report.xlsx

Source and attribution

Source:mukul975/Anthropic-Cybersecurity-Skillsinskills/analyzing-browser-forensics-with-hindsightat commit54a7988

License: Apache-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from mukul975/Anthropic-Cybersecurity-Skills

Exploiting Sql Injection Vulnerabilities

mukul975

Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester detects injection points through error-based, union-based, blind boolean, and time-based blind techniques across all major database engines (MySQL, PostgreSQL, MSSQL, Oracle) to demonstrate data extraction, authentication bypass, and potential remote code execution. Activates for requests involving SQL injection testing, SQLi exploitation, database security assessment, or injection vulnerability verification.

Includes scripts
Awaiting classificationOct 9, 2026

Analyzing Network Traffic With Wireshark

mukul975

Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.

Includes scripts
Awaiting classificationOct 9, 2026

Analyzing Dns Logs For Exfiltration

mukul975

Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection in SIEM platforms. Use when SOC teams need to identify DNS-based threats that bypass traditional network security controls.

Includes scripts
Awaiting classificationOct 9, 2026

Analyzing Cloud Storage Access Patterns

mukul975

Detects abnormal cloud storage access in AWS S3, GCS and Azure Blob logs using statistical baselines and anomaly detection.

Includes scripts
SecurityOct 9, 2026

Analyzing Campaign Attribution Evidence

mukul975

Evaluates cyber-campaign evidence to attribute attacks to threat actors using the Diamond Model and competing-hypotheses analysis.

Includes scripts
SecurityOct 9, 2026

Analyzing Certificate Transparency For Phishing

mukul975

Monitors Certificate Transparency logs via crt.sh and Certstream to detect phishing domains and lookalike certificates.

Includes scripts
SecurityOct 9, 2026