Analyzing Browser Forensics With Hindsight

mukul975/Anthropic-Cybersecurity-Skills/skills/analyzing-browser-forensics-with-hindsight

作者 mukul97554a798831d2266a3ca61ce68a7acb80b81160d57Apache-2.0收錄於 2026年10月9日更新於 2026年10月9日

Parse Chromium-based browser databases with Hindsight to extract and correlate browsing history, downloads, cookies, cached content, autofill data, saved passwords, and extensions from Chrome, Edge, Brave, Opera, and Vivaldi into a unified timeline (XLSX, JSON, or SQLite output). Use during incident response, insider-threat investigations, or criminal cases when you need to reconstruct a user's web activity from a browser profile.

包含腳本Security
AI 產生的概覽

使用 Hindsight 解析以 Chromium 為基礎的瀏覽器設定檔資料庫,重建供調查使用的網路活動時間軸。

功能
使用 Hindsight 與 SQLite 查詢,從 Chrome、Edge、Brave、Opera 與 Vivaldi 設定檔中擷取瀏覽紀錄、下載項目、Cookie、自動填入資料、已儲存的登入資訊、書籤與擴充功能。它會將這些痕跡關聯成依時間排序的時間軸,並產出 XLSX、JSON 或 SQLite 格式的報告。此技能附有可讀取設定檔資料庫並寫出 JSON 報告的 Python 指令碼。
適用情境
適用於需要從瀏覽器設定檔重建使用者網路活動的事件應變、內部威脅調查與刑事案件。也適合 SOC 分析師建立偵測規則或驗證相關技術的監控涵蓋範圍。
執行需求
Python 3.8+ 並安裝 Hindsight(pip install pyhindsight),可存取取證映像中的瀏覽器設定檔目錄,且設定檔資料未受作業系統層級加密保護。分析輸出需要試算表或時間軸檢視工具。附有可執行的 Python 指令碼。

Analyzing Browser Forensics with Hindsight

Overview

Hindsight is an open-source browser forensics tool designed to parse artifacts from Google Chrome and other Chromium-based browsers (Microsoft Edge, Brave, Opera, Vivaldi). It extracts and correlates data from multiple browser database files to create a unified timeline of web activity. Hindsight can parse URLs, download history, cache records, bookmarks, autofill records, saved passwords, preferences, browser extensions, HTTP cookies, Local Storage (HTML5 cookies), login data, and session/tab information. The tool produces chronological timelines in multiple output formats (XLSX, JSON, SQLite) that enable investigators to reconstruct user web activity for incident response, insider threat investigations, and criminal cases.

When to Use

  • When investigating security incidents that require analyzing browser forensics with hindsight
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Python 3.8+ with Hindsight installed (pip install pyhindsight)
  • Access to browser profile directories from forensic image
  • Browser profile data (not encrypted with OS-level encryption)
  • Timeline Explorer or spreadsheet application for analysis

Browser Profile Locations

BrowserWindows Profile Path
Chrome%LOCALAPPDATA%\Google\Chrome\User Data\Default\
Edge%LOCALAPPDATA%\Microsoft\Edge\User Data\Default\
Brave%LOCALAPPDATA%\BraveSoftware\Brave-Browser\User Data\Default\
Opera%APPDATA%\Opera Software\Opera Stable\
Vivaldi%LOCALAPPDATA%\Vivaldi\User Data\Default\
Chrome (macOS)~/Library/Application Support/Google/Chrome/Default/
Chrome (Linux)~/.config/google-chrome/Default/

Key Artifact Files

FileContents
HistoryURL visits, downloads, keyword searches
CookiesHTTP cookies with domain, expiry, values
Web DataAutofill entries, saved credit cards
Login DataSaved usernames/passwords (encrypted)
BookmarksJSON bookmark tree
PreferencesBrowser configuration and extensions
Local Storage/HTML5 Local Storage per domain
Session Storage/Session-specific storage per domain
Network Action PredictorPreviously typed URLs
ShortcutsOmnibox shortcuts and predictions
Top SitesFrequently visited sites

Running Hindsight

Command Line

bash
# Basic analysis of a Chrome profilehindsight.exe -i "C:\Evidence\Users\suspect\AppData\Local\Google\Chrome\User Data\Default" -o C:\Output\chrome_analysis
# Specify browser typehindsight.exe -i "/path/to/profile" -o /output/analysis -b Chrome
# JSON output formathindsight.exe -i "C:\Evidence\Chrome\Default" -o C:\Output\chrome --format jsonl
# With cache parsing (slower but more complete)hindsight.exe -i "C:\Evidence\Chrome\Default" -o C:\Output\chrome --cache

Web UI

bash
# Start Hindsight web interfacehindsight_gui.exe# Navigate to http://localhost:8080# Upload or point to browser profile directory# Configure output format and analysis options# Generate and download report

Artifact Analysis Details

URL History and Visits

sql
-- Chrome History database schema (key tables)-- urls table: id, url, title, visit_count, typed_count, last_visit_time-- visits table: id, url, visit_time, from_visit, transition, segment_id
-- Timestamps are Chrome/WebKit format: microseconds since 1601-01-01-- Convert: datetime((visit_time/1000000)-11644473600, 'unixepoch')

Download History

sql
-- downloads table: id, current_path, target_path, start_time, end_time,--   received_bytes, total_bytes, state, danger_type, interrupt_reason,--   url, referrer, tab_url, mime_type, original_mime_type

Cookie Analysis

sql
-- cookies table: creation_utc, host_key, name, value, encrypted_value,--   path, expires_utc, is_secure, is_httponly, last_access_utc,--   has_expires, is_persistent, priority, samesite

Python Analysis Script

python
import sqlite3import osimport jsonimport sysfrom datetime import datetime, timedelta
CHROME_EPOCH = datetime(1601, 1, 1)
def chrome_time_to_datetime(chrome_ts: int):    """Convert Chrome timestamp to datetime."""    if chrome_ts == 0:        return None    try:        return CHROME_EPOCH + timedelta(microseconds=chrome_ts)    except (OverflowError, OSError):        return None
def analyze_chrome_history(profile_path: str, output_dir: str) -> dict:    """Analyze Chrome History database for forensic evidence."""    history_db = os.path.join(profile_path, "History")    if not os.path.exists(history_db):        return {"error": "History database not found"}
    os.makedirs(output_dir, exist_ok=True)    conn = sqlite3.connect(f"file:{history_db}?mode=ro", uri=True)
    # URL visits with timestamps    cursor = conn.cursor()    cursor.execute("""        SELECT u.url, u.title, v.visit_time, u.visit_count,               v.transition & 0xFF as transition_type        FROM visits v JOIN urls u ON v.url = u.id        ORDER BY v.visit_time DESC LIMIT 5000    """)    visits = [{        "url": r[0], "title": r[1],        "visit_time": str(chrome_time_to_datetime(r[2])),        "total_visits": r[3], "transition": r[4]    } for r in cursor.fetchall()]
    # Downloads    cursor.execute("""        SELECT target_path, tab_url, start_time, end_time,               received_bytes, total_bytes, mime_type, state        FROM downloads ORDER BY start_time DESC LIMIT 1000    """)    downloads = [{        "path": r[0], "source_url": r[1],        "start_time": str(chrome_time_to_datetime(r[2])),        "end_time": str(chrome_time_to_datetime(r[3])),        "received_bytes": r[4], "total_bytes": r[5],        "mime_type": r[6], "state": r[7]    } for r in cursor.fetchall()]
    # Keyword searches    cursor.execute("""        SELECT k.term, u.url, k.url_id        FROM keyword_search_terms k JOIN urls u ON k.url_id = u.id        ORDER BY u.last_visit_time DESC LIMIT 1000    """)    searches = [{"term": r[0], "url": r[1]} for r in cursor.fetchall()]
    conn.close()
    report = {        "analysis_timestamp": datetime.now().isoformat(),        "profile_path": profile_path,        "total_visits": len(visits),        "total_downloads": len(downloads),        "total_searches": len(searches),        "visits": visits,        "downloads": downloads,        "searches": searches    }
    report_path = os.path.join(output_dir, "browser_forensics.json")    with open(report_path, "w") as f:        json.dump(report, f, indent=2)
    return report
def main():    if len(sys.argv) < 3:        print("Usage: python process.py <chrome_profile_path> <output_dir>")        sys.exit(1)    analyze_chrome_history(sys.argv[1], sys.argv[2])
if __name__ == "__main__":    main()

References

Example Output

text
$ python hindsight.py -i /evidence/chrome-profile -o /analysis/hindsight_output
Hindsight v2024.01 - Chrome/Chromium Browser Forensic Analysis================================================================
Profile: /evidence/chrome-profile (Chrome 120.0.6099.130)OS: Windows 10
[+] Parsing History database...    URL records:          12,456    Download records:     234    Search terms:         567
[+] Parsing Cookies database...    Cookie records:       8,923    Encrypted cookies:    6,712
[+] Parsing Web Data (Autofill)...    Autofill entries:     1,234    Credit card entries:  2 (encrypted)
[+] Parsing Login Data...    Saved credentials:    45 (encrypted)
[+] Parsing Bookmarks...    Bookmark entries:     189
--- Browsing History (Last 10 Entries) ---Timestamp (UTC)          | URL                                          | Title                        | Visit Count2024-01-15 14:32:05.123  | https://mail.corporate.com/inbox             | Corporate Mail                | 452024-01-15 14:33:12.456  | https://drive.google.com/file/d/1aBcDe...    | Q4_Financial_Report.xlsx     | 12024-01-15 14:35:44.789  | https://mega.nz/folder/xYz123               | MEGA - Secure Cloud          | 32024-01-15 14:36:01.234  | https://mega.nz/folder/xYz123#upload        | MEGA - Upload                | 82024-01-15 14:42:15.567  | https://pastebin.com/raw/kL9mN2pQ           | Pastebin (raw)               | 12024-01-15 15:01:33.890  | https://192.168.1.50:8443/admin              | Admin Panel                  | 122024-01-15 15:15:22.111  | https://transfer.sh/upload                  | transfer.sh                  | 22024-01-15 15:30:45.222  | https://vpn-gateway.corporate.com            | VPN Login                    | 52024-01-15 16:00:00.333  | https://whatismyipaddress.com                 | What Is My IP                | 12024-01-15 16:05:12.444  | https://protonmail.com/inbox                 | ProtonMail                   | 3
--- Downloads (Suspicious) ---Timestamp (UTC)          | Filename                    | URL Source                               | Size2024-01-15 14:33:15.000  | Q4_Financial_Report.xlsm   | https://phish-domain.com/docs/report     | 245 KB2024-01-15 14:34:02.000  | update_client.exe          | https://cdn.evil-updates.com/client.exe  | 1.2 MB
--- Cookies (Session Tokens) ---Domain                   | Name              | Expires            | Secure | HttpOnly.corporate.com           | SESSION_ID        | 2024-01-16 14:32   | Yes    | Yes.mega.nz                 | session           | Session            | Yes    | Yes.protonmail.com          | AUTH-TOKEN        | 2024-02-15 00:00   | Yes    | Yes
Report saved to: /analysis/hindsight_output/Hindsight_Report.xlsx

來源與署名

來源:mukul975/Anthropic-Cybersecurity-Skills位於skills/analyzing-browser-forensics-with-hindsight提交54a7988

授權條款: Apache-2.0

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架