Analyzing Browser Forensics With Hindsight

mukul975/Anthropic-Cybersecurity-Skills/skills/analyzing-browser-forensics-with-hindsight

作者 mukul97554a798831d2266a3ca61ce68a7acb80b81160d57Apache-2.0收录于 2026年10月9日更新于 2026年10月9日

Parse Chromium-based browser databases with Hindsight to extract and correlate browsing history, downloads, cookies, cached content, autofill data, saved passwords, and extensions from Chrome, Edge, Brave, Opera, and Vivaldi into a unified timeline (XLSX, JSON, or SQLite output). Use during incident response, insider-threat investigations, or criminal cases when you need to reconstruct a user's web activity from a browser profile.

包含脚本Security
AI 生成的概览

使用 Hindsight 解析基于 Chromium 的浏览器配置文件数据库,重建用于调查的网络活动时间线。

功能
使用 Hindsight 和 SQLite 查询从 Chrome、Edge、Brave、Opera 和 Vivaldi 配置文件中提取浏览历史、下载记录、Cookie、自动填充数据、已保存登录信息、书签和扩展程序。它将这些痕迹关联为按时间排序的时间线,并生成 XLSX、JSON 或 SQLite 格式的报告。该技能附带可读取配置文件数据库并写出 JSON 报告的 Python 脚本。
适用场景
适用于需要从浏览器配置文件重建用户网络活动的事件响应、内部威胁调查和刑事案件。也适合 SOC 分析师构建检测规则或验证相关技术的监控覆盖情况。
运行要求
Python 3.8+ 并安装 Hindsight(pip install pyhindsight),可访问取证镜像中的浏览器配置文件目录,且配置文件数据未受操作系统级加密保护。分析输出需要电子表格或时间线查看工具。附带可执行的 Python 脚本。

Analyzing Browser Forensics with Hindsight

Overview

Hindsight is an open-source browser forensics tool designed to parse artifacts from Google Chrome and other Chromium-based browsers (Microsoft Edge, Brave, Opera, Vivaldi). It extracts and correlates data from multiple browser database files to create a unified timeline of web activity. Hindsight can parse URLs, download history, cache records, bookmarks, autofill records, saved passwords, preferences, browser extensions, HTTP cookies, Local Storage (HTML5 cookies), login data, and session/tab information. The tool produces chronological timelines in multiple output formats (XLSX, JSON, SQLite) that enable investigators to reconstruct user web activity for incident response, insider threat investigations, and criminal cases.

When to Use

  • When investigating security incidents that require analyzing browser forensics with hindsight
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Python 3.8+ with Hindsight installed (pip install pyhindsight)
  • Access to browser profile directories from forensic image
  • Browser profile data (not encrypted with OS-level encryption)
  • Timeline Explorer or spreadsheet application for analysis

Browser Profile Locations

BrowserWindows Profile Path
Chrome%LOCALAPPDATA%\Google\Chrome\User Data\Default\
Edge%LOCALAPPDATA%\Microsoft\Edge\User Data\Default\
Brave%LOCALAPPDATA%\BraveSoftware\Brave-Browser\User Data\Default\
Opera%APPDATA%\Opera Software\Opera Stable\
Vivaldi%LOCALAPPDATA%\Vivaldi\User Data\Default\
Chrome (macOS)~/Library/Application Support/Google/Chrome/Default/
Chrome (Linux)~/.config/google-chrome/Default/

Key Artifact Files

FileContents
HistoryURL visits, downloads, keyword searches
CookiesHTTP cookies with domain, expiry, values
Web DataAutofill entries, saved credit cards
Login DataSaved usernames/passwords (encrypted)
BookmarksJSON bookmark tree
PreferencesBrowser configuration and extensions
Local Storage/HTML5 Local Storage per domain
Session Storage/Session-specific storage per domain
Network Action PredictorPreviously typed URLs
ShortcutsOmnibox shortcuts and predictions
Top SitesFrequently visited sites

Running Hindsight

Command Line

bash
# Basic analysis of a Chrome profilehindsight.exe -i "C:\Evidence\Users\suspect\AppData\Local\Google\Chrome\User Data\Default" -o C:\Output\chrome_analysis
# Specify browser typehindsight.exe -i "/path/to/profile" -o /output/analysis -b Chrome
# JSON output formathindsight.exe -i "C:\Evidence\Chrome\Default" -o C:\Output\chrome --format jsonl
# With cache parsing (slower but more complete)hindsight.exe -i "C:\Evidence\Chrome\Default" -o C:\Output\chrome --cache

Web UI

bash
# Start Hindsight web interfacehindsight_gui.exe# Navigate to http://localhost:8080# Upload or point to browser profile directory# Configure output format and analysis options# Generate and download report

Artifact Analysis Details

URL History and Visits

sql
-- Chrome History database schema (key tables)-- urls table: id, url, title, visit_count, typed_count, last_visit_time-- visits table: id, url, visit_time, from_visit, transition, segment_id
-- Timestamps are Chrome/WebKit format: microseconds since 1601-01-01-- Convert: datetime((visit_time/1000000)-11644473600, 'unixepoch')

Download History

sql
-- downloads table: id, current_path, target_path, start_time, end_time,--   received_bytes, total_bytes, state, danger_type, interrupt_reason,--   url, referrer, tab_url, mime_type, original_mime_type

Cookie Analysis

sql
-- cookies table: creation_utc, host_key, name, value, encrypted_value,--   path, expires_utc, is_secure, is_httponly, last_access_utc,--   has_expires, is_persistent, priority, samesite

Python Analysis Script

python
import sqlite3import osimport jsonimport sysfrom datetime import datetime, timedelta
CHROME_EPOCH = datetime(1601, 1, 1)
def chrome_time_to_datetime(chrome_ts: int):    """Convert Chrome timestamp to datetime."""    if chrome_ts == 0:        return None    try:        return CHROME_EPOCH + timedelta(microseconds=chrome_ts)    except (OverflowError, OSError):        return None
def analyze_chrome_history(profile_path: str, output_dir: str) -> dict:    """Analyze Chrome History database for forensic evidence."""    history_db = os.path.join(profile_path, "History")    if not os.path.exists(history_db):        return {"error": "History database not found"}
    os.makedirs(output_dir, exist_ok=True)    conn = sqlite3.connect(f"file:{history_db}?mode=ro", uri=True)
    # URL visits with timestamps    cursor = conn.cursor()    cursor.execute("""        SELECT u.url, u.title, v.visit_time, u.visit_count,               v.transition & 0xFF as transition_type        FROM visits v JOIN urls u ON v.url = u.id        ORDER BY v.visit_time DESC LIMIT 5000    """)    visits = [{        "url": r[0], "title": r[1],        "visit_time": str(chrome_time_to_datetime(r[2])),        "total_visits": r[3], "transition": r[4]    } for r in cursor.fetchall()]
    # Downloads    cursor.execute("""        SELECT target_path, tab_url, start_time, end_time,               received_bytes, total_bytes, mime_type, state        FROM downloads ORDER BY start_time DESC LIMIT 1000    """)    downloads = [{        "path": r[0], "source_url": r[1],        "start_time": str(chrome_time_to_datetime(r[2])),        "end_time": str(chrome_time_to_datetime(r[3])),        "received_bytes": r[4], "total_bytes": r[5],        "mime_type": r[6], "state": r[7]    } for r in cursor.fetchall()]
    # Keyword searches    cursor.execute("""        SELECT k.term, u.url, k.url_id        FROM keyword_search_terms k JOIN urls u ON k.url_id = u.id        ORDER BY u.last_visit_time DESC LIMIT 1000    """)    searches = [{"term": r[0], "url": r[1]} for r in cursor.fetchall()]
    conn.close()
    report = {        "analysis_timestamp": datetime.now().isoformat(),        "profile_path": profile_path,        "total_visits": len(visits),        "total_downloads": len(downloads),        "total_searches": len(searches),        "visits": visits,        "downloads": downloads,        "searches": searches    }
    report_path = os.path.join(output_dir, "browser_forensics.json")    with open(report_path, "w") as f:        json.dump(report, f, indent=2)
    return report
def main():    if len(sys.argv) < 3:        print("Usage: python process.py <chrome_profile_path> <output_dir>")        sys.exit(1)    analyze_chrome_history(sys.argv[1], sys.argv[2])
if __name__ == "__main__":    main()

References

Example Output

text
$ python hindsight.py -i /evidence/chrome-profile -o /analysis/hindsight_output
Hindsight v2024.01 - Chrome/Chromium Browser Forensic Analysis================================================================
Profile: /evidence/chrome-profile (Chrome 120.0.6099.130)OS: Windows 10
[+] Parsing History database...    URL records:          12,456    Download records:     234    Search terms:         567
[+] Parsing Cookies database...    Cookie records:       8,923    Encrypted cookies:    6,712
[+] Parsing Web Data (Autofill)...    Autofill entries:     1,234    Credit card entries:  2 (encrypted)
[+] Parsing Login Data...    Saved credentials:    45 (encrypted)
[+] Parsing Bookmarks...    Bookmark entries:     189
--- Browsing History (Last 10 Entries) ---Timestamp (UTC)          | URL                                          | Title                        | Visit Count2024-01-15 14:32:05.123  | https://mail.corporate.com/inbox             | Corporate Mail                | 452024-01-15 14:33:12.456  | https://drive.google.com/file/d/1aBcDe...    | Q4_Financial_Report.xlsx     | 12024-01-15 14:35:44.789  | https://mega.nz/folder/xYz123               | MEGA - Secure Cloud          | 32024-01-15 14:36:01.234  | https://mega.nz/folder/xYz123#upload        | MEGA - Upload                | 82024-01-15 14:42:15.567  | https://pastebin.com/raw/kL9mN2pQ           | Pastebin (raw)               | 12024-01-15 15:01:33.890  | https://192.168.1.50:8443/admin              | Admin Panel                  | 122024-01-15 15:15:22.111  | https://transfer.sh/upload                  | transfer.sh                  | 22024-01-15 15:30:45.222  | https://vpn-gateway.corporate.com            | VPN Login                    | 52024-01-15 16:00:00.333  | https://whatismyipaddress.com                 | What Is My IP                | 12024-01-15 16:05:12.444  | https://protonmail.com/inbox                 | ProtonMail                   | 3
--- Downloads (Suspicious) ---Timestamp (UTC)          | Filename                    | URL Source                               | Size2024-01-15 14:33:15.000  | Q4_Financial_Report.xlsm   | https://phish-domain.com/docs/report     | 245 KB2024-01-15 14:34:02.000  | update_client.exe          | https://cdn.evil-updates.com/client.exe  | 1.2 MB
--- Cookies (Session Tokens) ---Domain                   | Name              | Expires            | Secure | HttpOnly.corporate.com           | SESSION_ID        | 2024-01-16 14:32   | Yes    | Yes.mega.nz                 | session           | Session            | Yes    | Yes.protonmail.com          | AUTH-TOKEN        | 2024-02-15 00:00   | Yes    | Yes
Report saved to: /analysis/hindsight_output/Hindsight_Report.xlsx

来源与署名

来源:mukul975/Anthropic-Cybersecurity-Skills位于skills/analyzing-browser-forensics-with-hindsight提交54a7988

许可证: Apache-2.0

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架