Star 历史趋势
数据来源: GitHub API · 生成自 Stargazers.cn
README.md

Hindsight

Internet history forensics for Google Chrome/Chromium and Mozilla Firefox

Hindsight is a free tool for analyzing web artifacts. It started with the browsing history of the Google Chrome web browser, has expanded to support other Chromium-based applications, and now also parses Mozilla Firefox profiles. Hindsight can parse a number of different types of web artifacts, including URLs, download history, cache records, bookmarks, autofill records, saved passwords, preferences, browser extensions, HTTP cookies, and Local Storage records (HTML5 cookies). Once the data is extracted from each file, it is correlated with data from other history files and placed in a timeline.

For Firefox profiles, Hindsight parses places.sqlite (history visits, bookmarks, and downloads), cookies.sqlite, and formhistory.sqlite. Select "Firefox" in the GUI or pass -b Firefox on the command line, pointing at a profile directory such as \[userdir]\AppData\Roaming\Mozilla\Firefox\Profiles\<profile>.

It has a simple web UI - to start it, run "hindsight_gui.py" (or on Windows, the packaged "hindsight_gui.exe") and visit http://localhost:8080 in a browser:

The only field you are required to complete is "Profile Path". This is the location of the Chrome profile you want to analyze (the default profile paths for different OSes is listed at the bottom of this page). Click "Run" and you'll be taken to the results page in where you can save the results to a spreadsheet (or other formats).

Manual Installation

To install Hindsight (both the command line tool and the web interface), do:

pip install pyhindsight pip install git+https://github.com/cclgroupltd/ccl_chromium_reader.git

If you'd like to use the "View SQLite DB in Browser" feature in the Hindsight web interface, you'll need to run another install command:

curl -sSL https://raw.githubusercontent.com/obsidianforensics/hindsight/master/install-js.sh | sh

Command Line

There also is a command line version of Hindsight - hindsight.py or hindsight.exe. The user guide in the documentation folder covers many topics, but the info below should get you started with the command line version:

Example usage: > C:\hindsight.py -i "C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default" -o test_case

Command Line Options:

OptionDescription
-i or --inputPath to the Chrome(ium) "Default" directory
-o or --outputName of the output file (without extension)
-f or --formatOutput format (default is XLSX, other options are SQLite and JSONL)
-c or --cachePath to the cache directory; only needed if the directory is outside the given "input" directory. Mac systems are setup this way by default.
-b or --browser_typeThe type of browser the input files belong to. Supported options are Chrome (default) and Firefox.
-l or --logLocation Hindsight should log to (will append if exists)
-h or --helpShows these options and the default Chrome data locations
-t or --timezoneDisplay timezone for the timestamps in XLSX output

Default Profile Paths

The Chrome default profile folder default locations are:

  • WinXP: [userdir]\Local Settings\Application Data\Google\Chrome\User Data\Default
  • Vista/7/8/10: [userdir]\AppData\Local\Google\Chrome\User Data\Default
  • Linux: [userdir]/.config/google-chrome/Default
  • OS X: [userdir]/Library/Application Support/Google/Chrome/Default
  • iOS: \Applications\com.google.chrome.ios\Library\Application Support\Google\Chrome\Default
  • Android: /userdata/data/com.android.chrome/app_chrome/Default
  • CrOS: \home\user\<GUID>

Feature Requests

Please file an issue if you have an idea for a new feature (or spotted something broken).

关于 About

Browser forensics tool for Google Chrome (and other Chromium-based browsers)
browser-forensicschromedfirforensicsgoogle-chromehindsight

语言 Languages

Python95.7%
Go Template2.7%
CSS0.7%
Smarty0.7%
Shell0.3%

提交活跃度 Commit Activity

代码提交热力图
过去 52 周的开发活跃度
150
Total Commits
峰值: 17次/周
Less
More

核心贡献者 Contributors