Computer Forensics is the application of investigation and analysis techniques to gather and preserve evidence from a particular computing device in a way that is suitable for presentation in a court of law.
What are the different areas of Computer Forensics?
To become a Computer Forensics expert, you must know about these six areas:
- The Legal and Ethical Principles of Computer Forensics
- Computer Forensics Investigations
- Computer Forensics as Forensic Science
- Digital Forensics
- Application Forensics
- Hybrid and Emerging Technologies
Areas of Digital Forensics
- Media and File System Forensics
- Operating System Forensics
- Network Forensics (Specially Browser)
- Mobile Device Forensics
- Virtual System Forensics
Areas of Application Forensics
- Software Forensics
- Web and Email Forensics
- Database and Malware Forensics
Areas of Hybrid and Emerging Technologies Forensics
- Cloud Forensics
- Social Network Forensics
- The Big Data Paradigm
Web Browser Forensic
Web Browser Forensics means to trace and collect data (i.e. browser history, cookies etc.) what maybe cause for the incident.
In forensics analysis, browsers are a gold mine with the amount of information they contain. Often the source of incidents and malware can be traced down using the artifacts found inside of browsers. From the navigation history to downloaded files, browsers are a critical piece in any forensics analysis.
What are the Most Popular Web Browsers
Different types of Web Browsers based on user popularity (all desktop, tablet and mobile users):
- Google Chrome
- Safari
- Mozilla Firefox
- Samsung Internet
- Microsoft Edge
- Opera
- UC Browser
Comparing Web Browsers Based on User Popularity
Browser | StatCounter (August 2020) | NetMarketShare (August 2020) | Wikimedia (November 2019) |
Chrome | 65.99% | 65.86% | 48.7% |
Safari | 16.82% | 18.50% | 22.0% |
Firefox | 4.09% | 3.00% | 4.9% |
Samsung Internet | 3.47% | 3.01% | 2.7% |
Edge | 2.98% | 3.29% | 1.9% |
Opera | 2.09% | 0.83% | 1.1% |
UC | 1.35% | 0.47% | 0.3% |
Comparing Web Browsers Based on Security
Criteria | Mozilla | Opera | Safari | Edge | Chrome |
Private Browsing mode | √ | √ | √ | √ | √ |
Blocks third-party tracking cookies | √ | √ | √ | √ | √ |
Blocks cryptomining scripts | √ | √ | – | √ | – |
Blocks social trackers/td> | √ | √ | √ | – | – |
What are the different web browser artifacts?
- Navigation History
- Autocomplete Data
- Bookmarks
- Extensions and Addons
- Logins
- Browser Sessions
- Downloads
- Form Data
- Thumbnails
Web Browser Artifacts Location in Mozilla Firefox
Artifacts Data | Path |
Profile Path | C:UsersXXXAppDataRoamingMozillaFirefoxProfiles[profileID].default
C:UsersXXXAppDataLocalMozillaFirefoxProfiles[profileID].default |
Navigation History | C:UsersXXXAppDataRoamingMozillaFirefoxProfiles[profileID].defaultplaces.sqlite |
Bookmarks | C:UsersXXXAppDataRoamingMozillaFirefoxProfiles[profileID].defaultplaces.sqlite |
Bookmarks Backups | C:UsersXXXAppDataRoamingMozillaFirefoxProfiles[profileID].defaultbookmarkbackups |
Cookies | C:UsersXXXAppDataRoamingMozillaFirefoxProfiles[profileID].defaultcookies.sqlite |
Cache |
C:UsersXXXAppDataLocalMozillaFirefoxProfiles[profileID].defaultcache2entries C:UsersXXXAppDataLocalMozillaFirefoxProfiles[profileID].defaultstartupCache |
Form History | C:UsersXXXAppDataRoamingMozillaFirefoxProfiles[profileID].defaultformhistory.sqlite |
Addons | C:UsersXXXAppDataRoamingMozillaFirefoxProfiles[profileID].defaultaddons.sqlite |
Extensions | C:UsersXXXAppDataRoamingMozillaFirefoxProfiles[profileID].defaultextensions.sqlite |
Favicons | C:UsersXXXAppDataRoamingMozillaFirefoxProfiles[profileID].defaultfavicons.sqlite |
Settings And Preferences | C:UsersXXXAppDataRoamingMozillaFirefoxProfiles[profileID].defaultprefs.js |
Logins | C:UsersXXXAppDataRoamingMozillaFirefoxProfiles[profileID].defaultlogins.json |
Passwords | C:UsersXXXAppDataRoamingMozillaFirefoxProfiles[profileID].defaultkey4.db |
Sessions Data |
C:UsersXXXAppDataRoamingMozillaFirefoxProfiles[profileID].defaultsessionstore.jsonlz4 C:UsersXXXAppDataRoamingMozillaFirefoxProfiles[profileID].defaultsessionstore-backups |
Downloads | C:UsersXXXAppDataRoamingMozillaFirefoxProfiles[profileID].defaultdownloads.sqlite |
Thumbnails | C:UsersXXXAppDataLocalMozillaFirefoxProfiles[profileID].defaultthumbnails |
Web Browser Artifacts Location in Google Chrome
Artifacts Data | Path |
Profile Path |
C:UsersXXXAppDataLocalGoogleChromeUser DataDefault C:UsersXXXAppDataLocalGoogleChromeUser DataChromeDefaultData |
Navigation History, Search History, Download |
C:UsersXXXAppDataLocalGoogleChromeUser DataDefaultHistory C:UsersXXXAppDataLocalGoogleChromeUser DataChromeDefaultDataHistory |
Bookmarks |
C:UsersXXXAppDataLocalGoogleChromeUser DataDefaultBookmarks C:UsersXXXAppDataLocalGoogleChromeUser DataChromeDefaultDataBookmarks |
Cookies | C:UsersXXXAppDataLocalGoogleChromeUser DataDefaultCookies C:UsersXXXAppDataLocalGoogleChromeUser DataChromeDefaultDataCookies |
Cache |
C:UsersXXXAppDataLocalGoogleChromeUser DataDefaultCache C:UsersXXXAppDataLocalGoogleChromeUser DataChromeDefaultDataCache |
Form History | C:UsersXXXAppDataLocalGoogleChromeUser DataDefaultWeb Data C:UsersXXXAppDataLocalGoogleChromeUser DataChromeDefaultDataWeb Data |
Addons and Extensions | C:UsersXXXAppDataLocalGoogleChromeUser DataDefaultExtensions C:UsersXXXAppDataLocalGoogleChromeUser DataChromeDefaultDataExtensions |
Favicons | C:UsersXXXAppDataLocalGoogleChromeUser DataDefaultFavicons C:UsersXXXAppDataLocalGoogleChromeUser DataChromeDefaultDataFavicons |
Logins | C:UsersXXXAppDataLocalGoogleChromeUser DataChromeDefaultDataLogin Data |
Thumbnails | C:UsersXXXAppDataLocalGoogleChromeUser DataDefaultTop Sites C:UsersXXXAppDataLocalGoogleChromeUser DataDefaultThumbnails (Older versions) |
Current Sessions Data | C:UsersXXXAppDataLocalGoogleChromeUser DataDefaultCurrent Session C:UsersXXXAppDataLocalGoogleChromeUser DataChromeDefaultDataCurrent Session |
Current Tabs Data | C:UsersXXXAppDataLocalGoogleChromeUser DataDefaultCurrent Tabs C:UsersXXXAppDataLocalGoogleChromeUser DataChromeDefaultDataCurrent Tabs |
Previous Sessions Data | C:UsersXXXAppDataLocalGoogleChromeUser DataDefaultLast Session C:UsersXXXAppDataLocalGoogleChromeUser DataChromeDefaultDataLast Session |
Previous Tabs Data | C:UsersXXXAppDataLocalGoogleChromeUser DataDefaultLast Tabs C:UsersXXXAppDataLocalGoogleChromeUser DataChromeDefaultDataLast Tabs |
Web Browser Artifacts Location in Microsoft Edge
Artifacts Data | Path |
Profile Path | C:UsersXXAppDataLocalPackagesMicrosoft.MicrosoftEdge_XXXAC |
Navigation History | C:UsersXXAppDataLocalMicrosoftWindowsWebCacheWebCacheV01.dat |
Cookies | C:UsersXXAppDataLocalMicrosoftWindowsWebCacheWebCacheV01.dat |
Cache | C:UsersXXXAppDataLocalPackagesMicrosoft.MicrosoftEdge_XXXAC#!XXXMicrosoftEdgeCache |
Settings And Bookmarks | C:UsersXXAppDataLocalPackagesMicrosoft.MicrosoftEdge_XXXACMicrosoftEdgeUserDefaultDataStoreDatanouser1XXXDBStorespartan.edb |
Last Session | C:UsersXXAppDataLocalPackagesMicrosoft.MicrosoftEdge_XXXACMicrosoftEdgeUserDefaultRecoveryActive |
Web Browser Artifacts Location in Opera Mini
Artifacts Data | Path |
Cache | C:Users%userprofile%AppDataRoamingOpera SoftwareOpera StableShaderCacheGPUCachedata_3 |
Current Sessions Data | C:Users%userprofile%AppDataRoamingOpera SoftwareOpera StableCurrent Session |
Current Tabs Data | C:Users%userprofile%AppDataRoamingOpera SoftwareOpera StableCurrent Tabs |
Previous Sessions Data | C:Users%userprofile%AppDataRoamingOpera SoftwareOpera StableLast Session |
Last Tabs Data | C:Users%userprofile%AppDataRoamingOpera SoftwareOpera StableLast Tabs |
Web Browser Artifacts Location in Safari
Artifacts Data | Path |
Navigation History | C:Users%userprofile%LibrarySafariHistory.db |
Bookmarks | C:Users%userprofile%LibrarySafariBookmarks.plist |
Top Visited Sites | C:Users%userprofile%LibrarySafariTopSites.plist |
Cache | C:Users%userprofile%LibraryCachescom.apple.SafariCache.db |
Sessions Data | C:Users%userprofile%LibrarySafariLastSession.plist |
Top Web Browser Forensic Tools
Free
- Browser History Capturer
- Browser History Viewer
- SQLite Examiner
- Pasco
- Web Historian
- Nirsoft
- Total Recall (works for Internet Explorer versions prior to 10)
- Browser Forensic Tool
Paid
- Hindsight
- FTK
- Encase
- OSForensics
- Belkasoft Evidence Centre
- NetAnalysis
- Internet Examiner Toolkit
Hope your experience in our blog is not bad. Fell free to throw acomment.