Repository files navigation

Hindsight

Internet history forensics for Google Chrome/Chromium and Mozilla Firefox

Hindsight is a free tool for analyzing web artifacts. It started with the browsing history of the Google Chrome web browser, has expanded to support other Chromium-based applications, and now also parses Mozilla Firefox profiles. Hindsight can parse a number of different types of web artifacts, including URLs, download history, cache records, bookmarks, autofill records, saved passwords, preferences, browser extensions, HTTP cookies, and Local Storage records (HTML5 cookies). Once the data is extracted from each file, it is correlated with data from other history files and placed in a timeline.

For Firefox profiles, Hindsight parses places.sqlite (history visits, bookmarks, and downloads), cookies.sqlite, and formhistory.sqlite. Select "Firefox" in the GUI or pass -b Firefox on the command line, pointing at a profile directory such as \[userdir]\AppData\Roaming\Mozilla\Firefox\Profiles\<profile>.

It has a simple web UI - to start it, run "hindsight_gui.py" (or on Windows, the packaged "hindsight_gui.exe") and visit http://localhost:8080 in a browser:

The only field you are required to complete is "Profile Path". This is the location of the Chrome profile you want to analyze (the default profile paths for different OSes is listed at the bottom of this page). Click "Run" and you'll be taken to the results page in where you can save the results to a spreadsheet (or other formats).

Manual Installation

To install Hindsight (both the command line tool and the web interface), do:

pip install pyhindsight
pip install git+https://github.com/cclgroupltd/ccl_chromium_reader.git

If you'd like to use the "View SQLite DB in Browser" feature in the Hindsight web interface, you'll need to run another install command:

curl -sSL https://raw.githubusercontent.com/RyanDFIR/hindsight/main/install-js.sh | sh

Command Line

There also is a command line version of Hindsight - hindsight.py or hindsight.exe. The user guide in the documentation folder covers many topics, but the info below should get you started with the command line version:

Example usage: > C:\hindsight.py -i "C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default" -o test_case

Command Line Options:

OptionDescription
-i or --inputPath to the Chrome(ium) "Default" directory
-o or --outputName of the output file (without extension)
-f or --formatOutput format (default is XLSX, other options are SQLite and JSONL)
-c or --cachePath to the cache directory; only needed if the directory is outside the given "input" directory. Mac systems are setup this way by default.
-b or --browser_typeThe type of browser the input files belong to. Supported options are Chrome (default) and Firefox.
-l or --logLocation Hindsight should log to (will append if exists)
-h or --helpShows these options and the default Chrome data locations
-t or --timezoneDisplay timezone for the timestamps in XLSX output
--only or --artifactsOnly parse these artifacts (comma-separated; repeatable)
--skip or --excludeParse everything except these artifacts (comma-separated; repeatable)
--list-artifactsPrint the artifact names accepted by --only and --skip, then exit

Selecting Which Artifacts to Parse

By default, Hindsight parses every artifact it finds. --only and --skip narrow that down, which is useful for quick triage and for skipping the cache when it is large and not relevant to the question at hand.

hindsight.py -i <profile> --only history,downloads
hindsight.py -i <profile> --skip cache
hindsight.py -i <profile> --only user-activity --skip sessions

Artifact names are browser-neutral: history selects Chrome's History URL records and Firefox's places.sqlite URL records, so the same command works on either. Names are case-insensitive, and spaces, underscores, and hyphens are interchangeable (local-storage, local_storage, and "Local Storage" are the same name).

Group names can be used anywhere an artifact name can, and select everything under them: user-activity, website-storage, browser-extensions, configuration, plus caches (every cache artifact) and all. --only and --skip can be combined, with --skip further narrowing --only.

Run hindsight.py --list-artifacts for the full list with descriptions and aliases.

An artifact excluded by a filter is reported as [ skipped ] during the run and noted in the log, so a report that omits an artifact stays distinguishable from a profile that never had it. An unrecognized name is an error rather than being ignored, so a typo can't quietly produce a report covering the wrong artifacts.

Note that version detection still reads the profile's database schemas, so filtering does not change the detected browser version.

Default Profile Paths

The Chrome default profile folder default locations are:

  • WinXP: [userdir]\Local Settings\Application Data\Google\Chrome\User Data\Default
  • Vista/7/8/10: [userdir]\AppData\Local\Google\Chrome\User Data\Default
  • Linux: [userdir]/.config/google-chrome/Default
  • OS X: [userdir]/Library/Application Support/Google/Chrome/Default
  • iOS: \Applications\com.google.chrome.ios\Library\Application Support\Google\Chrome\Default
  • Android: /userdata/data/com.android.chrome/app_chrome/Default
  • CrOS: \home\user\<GUID>

Feature Requests

Please file an issue if you have an idea for a new feature (or spotted something broken).

About

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Topics

Resources

Security policy

Stars

1.5k stars

Watchers

65 watching

Forks

Releases

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

Hindsight

Internet history forensics for Google Chrome/Chromium and Mozilla Firefox

Hindsight is a free tool for analyzing web artifacts. It started with the browsing history of the Google Chrome web browser, has expanded to support other Chromium-based applications, and now also parses Mozilla Firefox profiles. Hindsight can parse a number of different types of web artifacts, including URLs, download history, cache records, bookmarks, autofill records, saved passwords, preferences, browser extensions, HTTP cookies, and Local Storage records (HTML5 cookies). Once the data is extracted from each file, it is correlated with data from other history files and placed in a timeline.

For Firefox profiles, Hindsight parses places.sqlite (history visits, bookmarks, and downloads), cookies.sqlite, and formhistory.sqlite. Select "Firefox" in the GUI or pass -b Firefox on the command line, pointing at a profile directory such as \[userdir]\AppData\Roaming\Mozilla\Firefox\Profiles\<profile>.

It has a simple web UI - to start it, run "hindsight_gui.py" (or on Windows, the packaged "hindsight_gui.exe") and visit http://localhost:8080 in a browser:

The only field you are required to complete is "Profile Path". This is the location of the Chrome profile you want to analyze (the default profile paths for different OSes is listed at the bottom of this page). Click "Run" and you'll be taken to the results page in where you can save the results to a spreadsheet (or other formats).

Manual Installation

To install Hindsight (both the command line tool and the web interface), do:

pip install pyhindsight
pip install git+https://github.com/cclgroupltd/ccl_chromium_reader.git

If you'd like to use the "View SQLite DB in Browser" feature in the Hindsight web interface, you'll need to run another install command:

curl -sSL https://raw.githubusercontent.com/RyanDFIR/hindsight/main/install-js.sh | sh

Command Line

There also is a command line version of Hindsight - hindsight.py or hindsight.exe. The user guide in the documentation folder covers many topics, but the info below should get you started with the command line version:

Example usage: > C:\hindsight.py -i "C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default" -o test_case

Command Line Options:

OptionDescription
-i or --inputPath to the Chrome(ium) "Default" directory
-o or --outputName of the output file (without extension)
-f or --formatOutput format (default is XLSX, other options are SQLite and JSONL)
-c or --cachePath to the cache directory; only needed if the directory is outside the given "input" directory. Mac systems are setup this way by default.
-b or --browser_typeThe type of browser the input files belong to. Supported options are Chrome (default) and Firefox.
-l or --logLocation Hindsight should log to (will append if exists)
-h or --helpShows these options and the default Chrome data locations
-t or --timezoneDisplay timezone for the timestamps in XLSX output
--only or --artifactsOnly parse these artifacts (comma-separated; repeatable)
--skip or --excludeParse everything except these artifacts (comma-separated; repeatable)
--list-artifactsPrint the artifact names accepted by --only and --skip, then exit

Selecting Which Artifacts to Parse

By default, Hindsight parses every artifact it finds. --only and --skip narrow that down, which is useful for quick triage and for skipping the cache when it is large and not relevant to the question at hand.

hindsight.py -i <profile> --only history,downloads
hindsight.py -i <profile> --skip cache
hindsight.py -i <profile> --only user-activity --skip sessions

Artifact names are browser-neutral: history selects Chrome's History URL records and Firefox's places.sqlite URL records, so the same command works on either. Names are case-insensitive, and spaces, underscores, and hyphens are interchangeable (local-storage, local_storage, and "Local Storage" are the same name).

Group names can be used anywhere an artifact name can, and select everything under them: user-activity, website-storage, browser-extensions, configuration, plus caches (every cache artifact) and all. --only and --skip can be combined, with --skip further narrowing --only.

Run hindsight.py --list-artifacts for the full list with descriptions and aliases.

An artifact excluded by a filter is reported as [ skipped ] during the run and noted in the log, so a report that omits an artifact stays distinguishable from a profile that never had it. An unrecognized name is an error rather than being ignored, so a typo can't quietly produce a report covering the wrong artifacts.

Note that version detection still reads the profile's database schemas, so filtering does not change the detected browser version.

Default Profile Paths

The Chrome default profile folder default locations are:

  • WinXP: [userdir]\Local Settings\Application Data\Google\Chrome\User Data\Default
  • Vista/7/8/10: [userdir]\AppData\Local\Google\Chrome\User Data\Default
  • Linux: [userdir]/.config/google-chrome/Default
  • OS X: [userdir]/Library/Application Support/Google/Chrome/Default
  • iOS: \Applications\com.google.chrome.ios\Library\Application Support\Google\Chrome\Default
  • Android: /userdata/data/com.android.chrome/app_chrome/Default
  • CrOS: \home\user\<GUID>

Feature Requests

Please file an issue if you have an idea for a new feature (or spotted something broken).

About

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Topics

Resources

Security policy

Stars

1.5k stars

Watchers

65 watching

Forks

Releases

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Hindsight

Internet history forensics for Google Chrome/Chromium and Mozilla Firefox

Hindsight is a free tool for analyzing web artifacts. It started with the browsing history of the Google Chrome web browser, has expanded to support other Chromium-based applications, and now also parses Mozilla Firefox profiles. Hindsight can parse a number of different types of web artifacts, including URLs, download history, cache records, bookmarks, autofill records, saved passwords, preferences, browser extensions, HTTP cookies, and Local Storage records (HTML5 cookies). Once the data is extracted from each file, it is correlated with data from other history files and placed in a timeline.

For Firefox profiles, Hindsight parses places.sqlite (history visits, bookmarks, and downloads), cookies.sqlite, and formhistory.sqlite. Select "Firefox" in the GUI or pass -b Firefox on the command line, pointing at a profile directory such as \[userdir]\AppData\Roaming\Mozilla\Firefox\Profiles\<profile>.

It has a simple web UI - to start it, run "hindsight_gui.py" (or on Windows, the packaged "hindsight_gui.exe") and visit http://localhost:8080 in a browser:

The only field you are required to complete is "Profile Path". This is the location of the Chrome profile you want to analyze (the default profile paths for different OSes is listed at the bottom of this page). Click "Run" and you'll be taken to the results page in where you can save the results to a spreadsheet (or other formats).

Manual Installation

To install Hindsight (both the command line tool and the web interface), do:

pip install pyhindsight
pip install git+https://github.com/cclgroupltd/ccl_chromium_reader.git

If you'd like to use the "View SQLite DB in Browser" feature in the Hindsight web interface, you'll need to run another install command:

curl -sSL https://raw.githubusercontent.com/RyanDFIR/hindsight/main/install-js.sh | sh

Command Line

There also is a command line version of Hindsight - hindsight.py or hindsight.exe. The user guide in the documentation folder covers many topics, but the info below should get you started with the command line version:

Example usage: > C:\hindsight.py -i "C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default" -o test_case

Command Line Options:

OptionDescription
-i or --inputPath to the Chrome(ium) "Default" directory
-o or --outputName of the output file (without extension)
-f or --formatOutput format (default is XLSX, other options are SQLite and JSONL)
-c or --cachePath to the cache directory; only needed if the directory is outside the given "input" directory. Mac systems are setup this way by default.
-b or --browser_typeThe type of browser the input files belong to. Supported options are Chrome (default) and Firefox.
-l or --logLocation Hindsight should log to (will append if exists)
-h or --helpShows these options and the default Chrome data locations
-t or --timezoneDisplay timezone for the timestamps in XLSX output
--only or --artifactsOnly parse these artifacts (comma-separated; repeatable)
--skip or --excludeParse everything except these artifacts (comma-separated; repeatable)
--list-artifactsPrint the artifact names accepted by --only and --skip, then exit

Selecting Which Artifacts to Parse

By default, Hindsight parses every artifact it finds. --only and --skip narrow that down, which is useful for quick triage and for skipping the cache when it is large and not relevant to the question at hand.

hindsight.py -i <profile> --only history,downloads
hindsight.py -i <profile> --skip cache
hindsight.py -i <profile> --only user-activity --skip sessions

Artifact names are browser-neutral: history selects Chrome's History URL records and Firefox's places.sqlite URL records, so the same command works on either. Names are case-insensitive, and spaces, underscores, and hyphens are interchangeable (local-storage, local_storage, and "Local Storage" are the same name).

Group names can be used anywhere an artifact name can, and select everything under them: user-activity, website-storage, browser-extensions, configuration, plus caches (every cache artifact) and all. --only and --skip can be combined, with --skip further narrowing --only.

Run hindsight.py --list-artifacts for the full list with descriptions and aliases.

An artifact excluded by a filter is reported as [ skipped ] during the run and noted in the log, so a report that omits an artifact stays distinguishable from a profile that never had it. An unrecognized name is an error rather than being ignored, so a typo can't quietly produce a report covering the wrong artifacts.

Note that version detection still reads the profile's database schemas, so filtering does not change the detected browser version.

Default Profile Paths

The Chrome default profile folder default locations are:

  • WinXP: [userdir]\Local Settings\Application Data\Google\Chrome\User Data\Default
  • Vista/7/8/10: [userdir]\AppData\Local\Google\Chrome\User Data\Default
  • Linux: [userdir]/.config/google-chrome/Default
  • OS X: [userdir]/Library/Application Support/Google/Chrome/Default
  • iOS: \Applications\com.google.chrome.ios\Library\Application Support\Google\Chrome\Default
  • Android: /userdata/data/com.android.chrome/app_chrome/Default
  • CrOS: \home\user\<GUID>

Feature Requests

Please file an issue if you have an idea for a new feature (or spotted something broken).

About

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Topics

Resources

Security policy

Stars

1.5k stars

Watchers

65 watching

Forks

Releases

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Hindsight

Internet history forensics for Google Chrome/Chromium and Mozilla Firefox

Hindsight is a free tool for analyzing web artifacts. It started with the browsing history of the Google Chrome web browser, has expanded to support other Chromium-based applications, and now also parses Mozilla Firefox profiles. Hindsight can parse a number of different types of web artifacts, including URLs, download history, cache records, bookmarks, autofill records, saved passwords, preferences, browser extensions, HTTP cookies, and Local Storage records (HTML5 cookies). Once the data is extracted from each file, it is correlated with data from other history files and placed in a timeline.

For Firefox profiles, Hindsight parses places.sqlite (history visits, bookmarks, and downloads), cookies.sqlite, and formhistory.sqlite. Select "Firefox" in the GUI or pass -b Firefox on the command line, pointing at a profile directory such as \[userdir]\AppData\Roaming\Mozilla\Firefox\Profiles\<profile>.

It has a simple web UI - to start it, run "hindsight_gui.py" (or on Windows, the packaged "hindsight_gui.exe") and visit http://localhost:8080 in a browser:

The only field you are required to complete is "Profile Path". This is the location of the Chrome profile you want to analyze (the default profile paths for different OSes is listed at the bottom of this page). Click "Run" and you'll be taken to the results page in where you can save the results to a spreadsheet (or other formats).

Manual Installation

To install Hindsight (both the command line tool and the web interface), do:

pip install pyhindsight
pip install git+https://github.com/cclgroupltd/ccl_chromium_reader.git

If you'd like to use the "View SQLite DB in Browser" feature in the Hindsight web interface, you'll need to run another install command:

curl -sSL https://raw.githubusercontent.com/RyanDFIR/hindsight/main/install-js.sh | sh

Command Line

There also is a command line version of Hindsight - hindsight.py or hindsight.exe. The user guide in the documentation folder covers many topics, but the info below should get you started with the command line version:

Example usage: > C:\hindsight.py -i "C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default" -o test_case

Command Line Options:

OptionDescription
-i or --inputPath to the Chrome(ium) "Default" directory
-o or --outputName of the output file (without extension)
-f or --formatOutput format (default is XLSX, other options are SQLite and JSONL)
-c or --cachePath to the cache directory; only needed if the directory is outside the given "input" directory. Mac systems are setup this way by default.
-b or --browser_typeThe type of browser the input files belong to. Supported options are Chrome (default) and Firefox.
-l or --logLocation Hindsight should log to (will append if exists)
-h or --helpShows these options and the default Chrome data locations
-t or --timezoneDisplay timezone for the timestamps in XLSX output
--only or --artifactsOnly parse these artifacts (comma-separated; repeatable)
--skip or --excludeParse everything except these artifacts (comma-separated; repeatable)
--list-artifactsPrint the artifact names accepted by --only and --skip, then exit

Selecting Which Artifacts to Parse

By default, Hindsight parses every artifact it finds. --only and --skip narrow that down, which is useful for quick triage and for skipping the cache when it is large and not relevant to the question at hand.

hindsight.py -i <profile> --only history,downloads
hindsight.py -i <profile> --skip cache
hindsight.py -i <profile> --only user-activity --skip sessions

Artifact names are browser-neutral: history selects Chrome's History URL records and Firefox's places.sqlite URL records, so the same command works on either. Names are case-insensitive, and spaces, underscores, and hyphens are interchangeable (local-storage, local_storage, and "Local Storage" are the same name).

Group names can be used anywhere an artifact name can, and select everything under them: user-activity, website-storage, browser-extensions, configuration, plus caches (every cache artifact) and all. --only and --skip can be combined, with --skip further narrowing --only.

Run hindsight.py --list-artifacts for the full list with descriptions and aliases.

An artifact excluded by a filter is reported as [ skipped ] during the run and noted in the log, so a report that omits an artifact stays distinguishable from a profile that never had it. An unrecognized name is an error rather than being ignored, so a typo can't quietly produce a report covering the wrong artifacts.

Note that version detection still reads the profile's database schemas, so filtering does not change the detected browser version.

Default Profile Paths

The Chrome default profile folder default locations are:

  • WinXP: [userdir]\Local Settings\Application Data\Google\Chrome\User Data\Default
  • Vista/7/8/10: [userdir]\AppData\Local\Google\Chrome\User Data\Default
  • Linux: [userdir]/.config/google-chrome/Default
  • OS X: [userdir]/Library/Application Support/Google/Chrome/Default
  • iOS: \Applications\com.google.chrome.ios\Library\Application Support\Google\Chrome\Default
  • Android: /userdata/data/com.android.chrome/app_chrome/Default
  • CrOS: \home\user\<GUID>

Feature Requests

Please file an issue if you have an idea for a new feature (or spotted something broken).

About

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Topics

Resources

Security policy

Stars

1.5k stars

Watchers

65 watching

Forks

Releases

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

Hindsight

Internet history forensics for Google Chrome/Chromium and Mozilla Firefox

Hindsight is a free tool for analyzing web artifacts. It started with the browsing history of the Google Chrome web browser, has expanded to support other Chromium-based applications, and now also parses Mozilla Firefox profiles. Hindsight can parse a number of different types of web artifacts, including URLs, download history, cache records, bookmarks, autofill records, saved passwords, preferences, browser extensions, HTTP cookies, and Local Storage records (HTML5 cookies). Once the data is extracted from each file, it is correlated with data from other history files and placed in a timeline.

For Firefox profiles, Hindsight parses places.sqlite (history visits, bookmarks, and downloads), cookies.sqlite, and formhistory.sqlite. Select "Firefox" in the GUI or pass -b Firefox on the command line, pointing at a profile directory such as \[userdir]\AppData\Roaming\Mozilla\Firefox\Profiles\<profile>.

It has a simple web UI - to start it, run "hindsight_gui.py" (or on Windows, the packaged "hindsight_gui.exe") and visit http://localhost:8080 in a browser:

The only field you are required to complete is "Profile Path". This is the location of the Chrome profile you want to analyze (the default profile paths for different OSes is listed at the bottom of this page). Click "Run" and you'll be taken to the results page in where you can save the results to a spreadsheet (or other formats).

Manual Installation

To install Hindsight (both the command line tool and the web interface), do:

pip install pyhindsight
pip install git+https://github.com/cclgroupltd/ccl_chromium_reader.git

If you'd like to use the "View SQLite DB in Browser" feature in the Hindsight web interface, you'll need to run another install command:

curl -sSL https://raw.githubusercontent.com/RyanDFIR/hindsight/main/install-js.sh | sh

Command Line

There also is a command line version of Hindsight - hindsight.py or hindsight.exe. The user guide in the documentation folder covers many topics, but the info below should get you started with the command line version:

Example usage: > C:\hindsight.py -i "C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default" -o test_case

Command Line Options:

OptionDescription
-i or --inputPath to the Chrome(ium) "Default" directory
-o or --outputName of the output file (without extension)
-f or --formatOutput format (default is XLSX, other options are SQLite and JSONL)
-c or --cachePath to the cache directory; only needed if the directory is outside the given "input" directory. Mac systems are setup this way by default.
-b or --browser_typeThe type of browser the input files belong to. Supported options are Chrome (default) and Firefox.
-l or --logLocation Hindsight should log to (will append if exists)
-h or --helpShows these options and the default Chrome data locations
-t or --timezoneDisplay timezone for the timestamps in XLSX output
--only or --artifactsOnly parse these artifacts (comma-separated; repeatable)
--skip or --excludeParse everything except these artifacts (comma-separated; repeatable)
--list-artifactsPrint the artifact names accepted by --only and --skip, then exit

Selecting Which Artifacts to Parse

By default, Hindsight parses every artifact it finds. --only and --skip narrow that down, which is useful for quick triage and for skipping the cache when it is large and not relevant to the question at hand.

hindsight.py -i <profile> --only history,downloads
hindsight.py -i <profile> --skip cache
hindsight.py -i <profile> --only user-activity --skip sessions

Artifact names are browser-neutral: history selects Chrome's History URL records and Firefox's places.sqlite URL records, so the same command works on either. Names are case-insensitive, and spaces, underscores, and hyphens are interchangeable (local-storage, local_storage, and "Local Storage" are the same name).

Group names can be used anywhere an artifact name can, and select everything under them: user-activity, website-storage, browser-extensions, configuration, plus caches (every cache artifact) and all. --only and --skip can be combined, with --skip further narrowing --only.

Run hindsight.py --list-artifacts for the full list with descriptions and aliases.

An artifact excluded by a filter is reported as [ skipped ] during the run and noted in the log, so a report that omits an artifact stays distinguishable from a profile that never had it. An unrecognized name is an error rather than being ignored, so a typo can't quietly produce a report covering the wrong artifacts.

Note that version detection still reads the profile's database schemas, so filtering does not change the detected browser version.

Default Profile Paths

The Chrome default profile folder default locations are:

  • WinXP: [userdir]\Local Settings\Application Data\Google\Chrome\User Data\Default
  • Vista/7/8/10: [userdir]\AppData\Local\Google\Chrome\User Data\Default
  • Linux: [userdir]/.config/google-chrome/Default
  • OS X: [userdir]/Library/Application Support/Google/Chrome/Default
  • iOS: \Applications\com.google.chrome.ios\Library\Application Support\Google\Chrome\Default
  • Android: /userdata/data/com.android.chrome/app_chrome/Default
  • CrOS: \home\user\<GUID>

Feature Requests

Please file an issue if you have an idea for a new feature (or spotted something broken).

About

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Topics

Resources

Security policy

Stars

1.5k stars

Watchers

65 watching

Forks

Releases

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Hindsight

Internet history forensics for Google Chrome/Chromium and Mozilla Firefox

Hindsight is a free tool for analyzing web artifacts. It started with the browsing history of the Google Chrome web browser, has expanded to support other Chromium-based applications, and now also parses Mozilla Firefox profiles. Hindsight can parse a number of different types of web artifacts, including URLs, download history, cache records, bookmarks, autofill records, saved passwords, preferences, browser extensions, HTTP cookies, and Local Storage records (HTML5 cookies). Once the data is extracted from each file, it is correlated with data from other history files and placed in a timeline.

For Firefox profiles, Hindsight parses places.sqlite (history visits, bookmarks, and downloads), cookies.sqlite, and formhistory.sqlite. Select "Firefox" in the GUI or pass -b Firefox on the command line, pointing at a profile directory such as \[userdir]\AppData\Roaming\Mozilla\Firefox\Profiles\<profile>.

It has a simple web UI - to start it, run "hindsight_gui.py" (or on Windows, the packaged "hindsight_gui.exe") and visit http://localhost:8080 in a browser:

The only field you are required to complete is "Profile Path". This is the location of the Chrome profile you want to analyze (the default profile paths for different OSes is listed at the bottom of this page). Click "Run" and you'll be taken to the results page in where you can save the results to a spreadsheet (or other formats).

Manual Installation

To install Hindsight (both the command line tool and the web interface), do:

pip install pyhindsight
pip install git+https://github.com/cclgroupltd/ccl_chromium_reader.git

If you'd like to use the "View SQLite DB in Browser" feature in the Hindsight web interface, you'll need to run another install command:

curl -sSL https://raw.githubusercontent.com/RyanDFIR/hindsight/main/install-js.sh | sh

Command Line

There also is a command line version of Hindsight - hindsight.py or hindsight.exe. The user guide in the documentation folder covers many topics, but the info below should get you started with the command line version:

Example usage: > C:\hindsight.py -i "C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default" -o test_case

Command Line Options:

OptionDescription
-i or --inputPath to the Chrome(ium) "Default" directory
-o or --outputName of the output file (without extension)
-f or --formatOutput format (default is XLSX, other options are SQLite and JSONL)
-c or --cachePath to the cache directory; only needed if the directory is outside the given "input" directory. Mac systems are setup this way by default.
-b or --browser_typeThe type of browser the input files belong to. Supported options are Chrome (default) and Firefox.
-l or --logLocation Hindsight should log to (will append if exists)
-h or --helpShows these options and the default Chrome data locations
-t or --timezoneDisplay timezone for the timestamps in XLSX output
--only or --artifactsOnly parse these artifacts (comma-separated; repeatable)
--skip or --excludeParse everything except these artifacts (comma-separated; repeatable)
--list-artifactsPrint the artifact names accepted by --only and --skip, then exit

Selecting Which Artifacts to Parse

By default, Hindsight parses every artifact it finds. --only and --skip narrow that down, which is useful for quick triage and for skipping the cache when it is large and not relevant to the question at hand.

hindsight.py -i <profile> --only history,downloads
hindsight.py -i <profile> --skip cache
hindsight.py -i <profile> --only user-activity --skip sessions

Artifact names are browser-neutral: history selects Chrome's History URL records and Firefox's places.sqlite URL records, so the same command works on either. Names are case-insensitive, and spaces, underscores, and hyphens are interchangeable (local-storage, local_storage, and "Local Storage" are the same name).

Group names can be used anywhere an artifact name can, and select everything under them: user-activity, website-storage, browser-extensions, configuration, plus caches (every cache artifact) and all. --only and --skip can be combined, with --skip further narrowing --only.

Run hindsight.py --list-artifacts for the full list with descriptions and aliases.

An artifact excluded by a filter is reported as [ skipped ] during the run and noted in the log, so a report that omits an artifact stays distinguishable from a profile that never had it. An unrecognized name is an error rather than being ignored, so a typo can't quietly produce a report covering the wrong artifacts.

Note that version detection still reads the profile's database schemas, so filtering does not change the detected browser version.

Default Profile Paths

The Chrome default profile folder default locations are:

  • WinXP: [userdir]\Local Settings\Application Data\Google\Chrome\User Data\Default
  • Vista/7/8/10: [userdir]\AppData\Local\Google\Chrome\User Data\Default
  • Linux: [userdir]/.config/google-chrome/Default
  • OS X: [userdir]/Library/Application Support/Google/Chrome/Default
  • iOS: \Applications\com.google.chrome.ios\Library\Application Support\Google\Chrome\Default
  • Android: /userdata/data/com.android.chrome/app_chrome/Default
  • CrOS: \home\user\<GUID>

Feature Requests

Please file an issue if you have an idea for a new feature (or spotted something broken).

About

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Topics

Resources

Security policy

Stars

1.5k stars

Watchers

65 watching

Forks

Releases

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Hindsight

Internet history forensics for Google Chrome/Chromium and Mozilla Firefox

Hindsight is a free tool for analyzing web artifacts. It started with the browsing history of the Google Chrome web browser, has expanded to support other Chromium-based applications, and now also parses Mozilla Firefox profiles. Hindsight can parse a number of different types of web artifacts, including URLs, download history, cache records, bookmarks, autofill records, saved passwords, preferences, browser extensions, HTTP cookies, and Local Storage records (HTML5 cookies). Once the data is extracted from each file, it is correlated with data from other history files and placed in a timeline.

For Firefox profiles, Hindsight parses places.sqlite (history visits, bookmarks, and downloads), cookies.sqlite, and formhistory.sqlite. Select "Firefox" in the GUI or pass -b Firefox on the command line, pointing at a profile directory such as \[userdir]\AppData\Roaming\Mozilla\Firefox\Profiles\<profile>.

It has a simple web UI - to start it, run "hindsight_gui.py" (or on Windows, the packaged "hindsight_gui.exe") and visit http://localhost:8080 in a browser:

The only field you are required to complete is "Profile Path". This is the location of the Chrome profile you want to analyze (the default profile paths for different OSes is listed at the bottom of this page). Click "Run" and you'll be taken to the results page in where you can save the results to a spreadsheet (or other formats).

Manual Installation

To install Hindsight (both the command line tool and the web interface), do:

pip install pyhindsight
pip install git+https://github.com/cclgroupltd/ccl_chromium_reader.git

If you'd like to use the "View SQLite DB in Browser" feature in the Hindsight web interface, you'll need to run another install command:

curl -sSL https://raw.githubusercontent.com/RyanDFIR/hindsight/main/install-js.sh | sh

Command Line

There also is a command line version of Hindsight - hindsight.py or hindsight.exe. The user guide in the documentation folder covers many topics, but the info below should get you started with the command line version:

Example usage: > C:\hindsight.py -i "C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default" -o test_case

Command Line Options:

OptionDescription
-i or --inputPath to the Chrome(ium) "Default" directory
-o or --outputName of the output file (without extension)
-f or --formatOutput format (default is XLSX, other options are SQLite and JSONL)
-c or --cachePath to the cache directory; only needed if the directory is outside the given "input" directory. Mac systems are setup this way by default.
-b or --browser_typeThe type of browser the input files belong to. Supported options are Chrome (default) and Firefox.
-l or --logLocation Hindsight should log to (will append if exists)
-h or --helpShows these options and the default Chrome data locations
-t or --timezoneDisplay timezone for the timestamps in XLSX output
--only or --artifactsOnly parse these artifacts (comma-separated; repeatable)
--skip or --excludeParse everything except these artifacts (comma-separated; repeatable)
--list-artifactsPrint the artifact names accepted by --only and --skip, then exit

Selecting Which Artifacts to Parse

By default, Hindsight parses every artifact it finds. --only and --skip narrow that down, which is useful for quick triage and for skipping the cache when it is large and not relevant to the question at hand.

hindsight.py -i <profile> --only history,downloads
hindsight.py -i <profile> --skip cache
hindsight.py -i <profile> --only user-activity --skip sessions

Artifact names are browser-neutral: history selects Chrome's History URL records and Firefox's places.sqlite URL records, so the same command works on either. Names are case-insensitive, and spaces, underscores, and hyphens are interchangeable (local-storage, local_storage, and "Local Storage" are the same name).

Group names can be used anywhere an artifact name can, and select everything under them: user-activity, website-storage, browser-extensions, configuration, plus caches (every cache artifact) and all. --only and --skip can be combined, with --skip further narrowing --only.

Run hindsight.py --list-artifacts for the full list with descriptions and aliases.

An artifact excluded by a filter is reported as [ skipped ] during the run and noted in the log, so a report that omits an artifact stays distinguishable from a profile that never had it. An unrecognized name is an error rather than being ignored, so a typo can't quietly produce a report covering the wrong artifacts.

Note that version detection still reads the profile's database schemas, so filtering does not change the detected browser version.

Default Profile Paths

The Chrome default profile folder default locations are:

  • WinXP: [userdir]\Local Settings\Application Data\Google\Chrome\User Data\Default
  • Vista/7/8/10: [userdir]\AppData\Local\Google\Chrome\User Data\Default
  • Linux: [userdir]/.config/google-chrome/Default
  • OS X: [userdir]/Library/Application Support/Google/Chrome/Default
  • iOS: \Applications\com.google.chrome.ios\Library\Application Support\Google\Chrome\Default
  • Android: /userdata/data/com.android.chrome/app_chrome/Default
  • CrOS: \home\user\<GUID>

Feature Requests

Please file an issue if you have an idea for a new feature (or spotted something broken).

About

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Topics

Resources

Security policy

Stars

1.5k stars

Watchers

65 watching

Forks

Releases

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

Hindsight

Internet history forensics for Google Chrome/Chromium and Mozilla Firefox

Hindsight is a free tool for analyzing web artifacts. It started with the browsing history of the Google Chrome web browser, has expanded to support other Chromium-based applications, and now also parses Mozilla Firefox profiles. Hindsight can parse a number of different types of web artifacts, including URLs, download history, cache records, bookmarks, autofill records, saved passwords, preferences, browser extensions, HTTP cookies, and Local Storage records (HTML5 cookies). Once the data is extracted from each file, it is correlated with data from other history files and placed in a timeline.

For Firefox profiles, Hindsight parses places.sqlite (history visits, bookmarks, and downloads), cookies.sqlite, and formhistory.sqlite. Select "Firefox" in the GUI or pass -b Firefox on the command line, pointing at a profile directory such as \[userdir]\AppData\Roaming\Mozilla\Firefox\Profiles\<profile>.

It has a simple web UI - to start it, run "hindsight_gui.py" (or on Windows, the packaged "hindsight_gui.exe") and visit http://localhost:8080 in a browser:

The only field you are required to complete is "Profile Path". This is the location of the Chrome profile you want to analyze (the default profile paths for different OSes is listed at the bottom of this page). Click "Run" and you'll be taken to the results page in where you can save the results to a spreadsheet (or other formats).

Manual Installation

To install Hindsight (both the command line tool and the web interface), do:

pip install pyhindsight
pip install git+https://github.com/cclgroupltd/ccl_chromium_reader.git

If you'd like to use the "View SQLite DB in Browser" feature in the Hindsight web interface, you'll need to run another install command:

curl -sSL https://raw.githubusercontent.com/RyanDFIR/hindsight/main/install-js.sh | sh

Command Line

There also is a command line version of Hindsight - hindsight.py or hindsight.exe. The user guide in the documentation folder covers many topics, but the info below should get you started with the command line version:

Example usage: > C:\hindsight.py -i "C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default" -o test_case

Command Line Options:

OptionDescription
-i or --inputPath to the Chrome(ium) "Default" directory
-o or --outputName of the output file (without extension)
-f or --formatOutput format (default is XLSX, other options are SQLite and JSONL)
-c or --cachePath to the cache directory; only needed if the directory is outside the given "input" directory. Mac systems are setup this way by default.
-b or --browser_typeThe type of browser the input files belong to. Supported options are Chrome (default) and Firefox.
-l or --logLocation Hindsight should log to (will append if exists)
-h or --helpShows these options and the default Chrome data locations
-t or --timezoneDisplay timezone for the timestamps in XLSX output
--only or --artifactsOnly parse these artifacts (comma-separated; repeatable)
--skip or --excludeParse everything except these artifacts (comma-separated; repeatable)
--list-artifactsPrint the artifact names accepted by --only and --skip, then exit

Selecting Which Artifacts to Parse

By default, Hindsight parses every artifact it finds. --only and --skip narrow that down, which is useful for quick triage and for skipping the cache when it is large and not relevant to the question at hand.

hindsight.py -i <profile> --only history,downloads
hindsight.py -i <profile> --skip cache
hindsight.py -i <profile> --only user-activity --skip sessions

Artifact names are browser-neutral: history selects Chrome's History URL records and Firefox's places.sqlite URL records, so the same command works on either. Names are case-insensitive, and spaces, underscores, and hyphens are interchangeable (local-storage, local_storage, and "Local Storage" are the same name).

Group names can be used anywhere an artifact name can, and select everything under them: user-activity, website-storage, browser-extensions, configuration, plus caches (every cache artifact) and all. --only and --skip can be combined, with --skip further narrowing --only.

Run hindsight.py --list-artifacts for the full list with descriptions and aliases.

An artifact excluded by a filter is reported as [ skipped ] during the run and noted in the log, so a report that omits an artifact stays distinguishable from a profile that never had it. An unrecognized name is an error rather than being ignored, so a typo can't quietly produce a report covering the wrong artifacts.

Note that version detection still reads the profile's database schemas, so filtering does not change the detected browser version.

Default Profile Paths

The Chrome default profile folder default locations are:

  • WinXP: [userdir]\Local Settings\Application Data\Google\Chrome\User Data\Default
  • Vista/7/8/10: [userdir]\AppData\Local\Google\Chrome\User Data\Default
  • Linux: [userdir]/.config/google-chrome/Default
  • OS X: [userdir]/Library/Application Support/Google/Chrome/Default
  • iOS: \Applications\com.google.chrome.ios\Library\Application Support\Google\Chrome\Default
  • Android: /userdata/data/com.android.chrome/app_chrome/Default
  • CrOS: \home\user\<GUID>

Feature Requests

Please file an issue if you have an idea for a new feature (or spotted something broken).

About

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Topics

Resources

Security policy

Stars

1.5k stars

Watchers

65 watching

Forks

Releases

Used by

Contributors

Languages