Client-side browser forensics

Browser forensics, in your browser.

Inspect history, cookies, bookmarks, downloads and autofill from Chrome, Firefox and Safari — entirely client-side.

100% private: files are parsed in a Web Worker on your machine and never leave your browser.

Parse a browser artifact

Drop a file here or click to select

Supported: SQLite databases, Chrome Bookmarks & Local State JSON, Firefox .jsonlz4 sessions, Safari .plist & .binarycookies. Drop multiple files or a whole profile folder.

Loads a synthetic Chrome + Firefox profile from a fictional intrusion — no real data. Tip: click any timestamp to see ±5 min around it.

Tip: in the file dialog hold ⌘ (or Shift) to select several files at once. You can also drag a whole profile folder onto this area — that pairs -wal/-journal sidecars and groups LevelDB stores.

How to get your data

  1. Collect the profile folders
  2. Drop the folder (or ZIP) here
  3. Parsed in your browser — nothing is uploaded

Copy the browser profile folders, then drop the whole folder here. Pick the easiest method that fits your situation.

PowerShell, no admin needed. Quit Chrome, Edge and Firefox first — including the tray icon (Edge startup boost and Chrome background apps keep them running). Copies this user's Chrome, Edge and Firefox profiles, plus the DPAPI keys, to C:\triage.

PowerShell
$x = "Code Cache","GPUCache","GrShaderCache","ShaderCache","DawnGraphiteCache","DawnWebGPUCache","OptGuideOnDeviceModel","optimization_guide_model_store","screen_ai","component_crx_cache","Safe Browsing","safebrowsing","startupCache","Crashpad"
$b = "AppData\Local\Google\Chrome\User Data","AppData\Local\Microsoft\Edge\User Data","AppData\Roaming\Mozilla\Firefox","AppData\Local\Mozilla\Firefox\Profiles","AppData\Roaming\Microsoft\Protect"
foreach ($p in $b) {
  if (Test-Path "$env:USERPROFILE\$p") { robocopy "$env:USERPROFILE\$p" "C:\triage\Users\$env:USERNAME\$p" /E /R:0 /W:0 /NFL /NDL /NP /XD $x }
}
attrib -h -s "C:\triage\*" /s /d
explorer C:\triage

Then drag the triage folder onto the drop zone — or anywhere on the results workspace. Browsers that aren't installed are skipped; bulky GPU, code and model caches are left out.

Can't close the browser, or need every user?

Run PowerShell as administrator. Takes a Volume Shadow Copy of C:, copies every user's profiles from it (consistent even while the browsers run), then deletes the shadow copy.

PowerShell · Administrator
$x = "Code Cache","GPUCache","GrShaderCache","ShaderCache","DawnGraphiteCache","DawnWebGPUCache","OptGuideOnDeviceModel","optimization_guide_model_store","screen_ai","component_crx_cache","Safe Browsing","safebrowsing","startupCache","Crashpad"
$b = "AppData\Local\Google\Chrome\User Data","AppData\Local\Microsoft\Edge\User Data","AppData\Roaming\Mozilla\Firefox","AppData\Local\Mozilla\Firefox\Profiles","AppData\Roaming\Microsoft\Protect"
$s = Invoke-CimMethod -ClassName Win32_ShadowCopy -MethodName Create -Arguments @{ Volume = "C:\" }
$v = Get-CimInstance Win32_ShadowCopy | Where-Object ID -eq $s.ShadowID
cmd /c mklink /d C:\vss "$($v.DeviceObject)\"
foreach ($u in Get-ChildItem C:\vss\Users -Directory) {
  foreach ($p in $b) {
    if (Test-Path "$($u.FullName)\$p") { robocopy "$($u.FullName)\$p" "C:\triage\Users\$($u.Name)\$p" /B /E /R:0 /W:0 /NFL /NDL /NP /XD $x }
  }
}
cmd /c rmdir C:\vss
$v | Remove-CimInstance
attrib -h -s "C:\triage\*" /s /d
explorer C:\triage

Gotchas

  • A running browser locks its databases and keeps recent writes in -wal / -journal files: close it (check the tray) or use the shadow-copy command, and always copy the sidecars with their database. Never open a database with sqlite3 before copying.
  • Chrome 127+ on Windows encrypts new cookies with app-bound (v20) keys that the user's DPAPI alone can't open; history, downloads and bookmarks are unaffected.
  • Prefer dropping the folder: ZIP64 archives (over 4 GB or 65,535 files) and password-protected ZIPs can't be read. All times are shown in UTC.

Where to find the files

Per-user profile folders by browser and OS. Default may also be Profile 1, Profile 2… — check every profile. Drop the whole folder to parse everything at once.

  • Windows%LOCALAPPDATA%\Google\Chrome\User Data\Default
  • macOS~/Library/Application Support/Google/Chrome/Default
  • Linux~/.config/google-chrome/Default
  • Chromium~/.config/chromium/Default
  • Local State%LOCALAPPDATA%\Google\Chrome\User Data\Local State
  • DPAPI key%APPDATA%\Microsoft\Protect\<SID>\

Files in the profile: History · Network/Cookies · Login Data · Web Data · Bookmarks · Preferences · Top Sites · Shortcuts · Favicons · Local Storage/leveldb/ · Session Storage/ · IndexedDB/ · Cache/Cache_Data/

Cookies are in Network/Cookies since Chrome 96 (older: Cookies at the profile root). Local State sits one level up, in User Data.

How to get them

  • Databases are locked while the browser runs: close it, or copy from a snapshot — esentutl /y <file> /vss /d <dest> (admin), KAPE (WebBrowsers target), FTK Imager, or a mounted E01 / VSS.
  • Always take the -wal / -shm (or -journal) sidecars with each SQLite file — the latest activity often lives only in the WAL.
  • AppData and ~/Library are hidden. On macOS the copying app needs Full Disk Access to read Safari's folders.
  • To decrypt: Chromium Local State + the DPAPI masterkey and user password (Windows) or the Safe Storage secret (macOS / Linux); Firefox key4.db next to logins.json.

Full guide →

artifact types
34
browsers
8
ready-made hunts
25
uploaded
0 B

Capabilities

Everything a browser remembers, on one timeline.

History, cookies, logins, autofill, downloads, sessions, extensions and caches — parsed, attributed to their user and profile, and searchable together.

Every major browser

Chromium-based browsers, Firefox and Safari, from Windows, macOS and Linux profiles — SQLite (with WAL replay), JSON, plist, binarycookies, LevelDB and cache stores.

Browsers
  • Chrome
  • Edge
  • Brave
  • Opera
  • Vivaldi
  • Chromium
  • Firefox
  • Safari
Artifacts
  • History · Visits
  • Cookies
  • Login Data · logins.json
  • Web Data · formhistory
  • Downloads
  • Bookmarks · Top Sites
  • Sessions · Tabs
  • Extensions · Permissions
  • Local / Session Storage
  • IndexedDB · Cache

Decrypt the secrets

Cookie values, saved passwords and cards: Chromium keys via DPAPI masterkey, macOS Safe Storage, Linux or app-bound blobs; Firefox logins via key4.db.

Every user, every profile

Files are attributed to their OS user, browser and profile, so a shared machine reads as separate people — and keys pair with the right profile.

Hunts and pivots

Search every artifact at once, stack values, pivot on a domain or a moment, and run 25 ready-made hunts for exfiltration, RMM tools and anti-forensics.

Triage collections, as-is

Drop a Disk Image Parser collection ZIP: its manifest restores original paths and each file's SHA-256 is checked against it.

Chain of custody

Every loaded file is hashed; export CSV, JSON and a self-contained HTML report, and save cases in this browser.

Workflow

From image to answers, in three steps.

  1. 01

    Collect

    Copy the profile folders, or run the Browser history preset of Disk Image Parser on the disk image.

  2. 02

    Drop

    Drop folders, files or the collection ZIP. Everything is parsed by a Web Worker on your machine.

  3. 03

    Investigate

    Read the unified timeline, run hunts, pivot, decrypt, then export the report.

Privacy

Your evidence never leaves this tab.

There is no server-side processing. Files are read with the File API and parsed in a Web Worker; results live in memory, or in this browser's storage if you save a case.

  • No upload — parsing runs locally
  • No account needed
  • Keys and passwords are never saved
  • Saved cases stay in this browser

FAQ

Questions, answered.

Are my files uploaded anywhere?

No. Files are read and parsed in a Web Worker inside your browser. Nothing is sent to a server — you can verify it in the network tab.

Which files do I need?

The browser profile folders (see “Where to find the files” above). Drop the whole folder, several users' folders, or a triage collection ZIP — sidecars and LevelDB stores are grouped automatically.

Can it decrypt Chrome cookies and passwords?

Yes. Load Local State, then paste the AES key or derive it from the user's DPAPI masterkey and password or NT hash; macOS Safe Storage and Linux keys are supported too. Firefox logins decrypt with key4.db.

Does it work with Disk Image Parser?

Yes. Run the Browser history preset, then drop the ZIP (or its extracted folder) here: manifest.csv restores each file's original path, so users and profiles are grouped, and every SHA-256 is verified.

Is it free?

Yes — free, with no account and no limits beyond your browser's memory.

Open a profile and follow the trace.

Drop a folder or a collection — results in seconds, and nothing leaves your machine.

Open the parser →