{"id":83,"date":"2015-10-17T10:54:27","date_gmt":"2015-10-17T10:54:27","guid":{"rendered":"https:\/\/www.acquireforensics.com\/blog\/?p=83"},"modified":"2016-01-27T09:29:37","modified_gmt":"2016-01-27T09:29:37","slug":"google-chrome-browser-forensics","status":"publish","type":"post","link":"https:\/\/www.acquireforensics.com\/blog\/google-chrome-browser-forensics.html","title":{"rendered":"Google Chrome Forensic Analysis: An Ultimate Path For Evidence Collection"},"content":{"rendered":"<p>It is a common and well known fact that the number of web users has increased nowadays. People spends their whole day infront of the computer and this clearly marks that large about of information will be there in the files related to the browsing. As since now many of the criminal activities are done with the help of information available in web, searching the browser file has become the important part of investigation. Or in other words, it is said that illegal activities are carried out with the help of web. Because of these, Google Chrome forensic analysis to examine files related to web become important. There are different browsers available for the users to surf over the web such as, Firefox, Chrome, Yahoo etc. Here, in this page you will get to know about how to collect artifacts from Google Chrome. The discussion covers all the related topics from where one can get the details.<\/p>\n<p>Some of the areas in Google Chrome browser forensics that help investigators are as listed;<\/p>\n<ul>\n<li>History<\/li>\n<li>Cache<\/li>\n<li>Cookies<\/li>\n<li>Bookmarks<\/li>\n<li>Session restore file<\/li>\n<li>Current tabs<\/li>\n<li>Last session<\/li>\n<\/ul>\n<p>Let us start the evidence collection from \u2018History\u2019. But, where are the Chrome files located.<\/p>\n<p><strong>Location<\/strong><\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-84\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/1.png\" alt=\"1\" width=\"624\" height=\"32\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/21.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-87\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/21.png\" alt=\"2\" width=\"624\" height=\"51\" \/><\/a><\/p>\n<p><strong>History<\/strong><\/p>\n<p>During Google Chrome forensic analysis, in the \u2018History\u2019, you will get to see all the sites visited so far and all the files follows Sqlite database file format.<\/p>\n<p><em>Location of History:<\/em><\/p>\n<p>In <strong>Windows XP<\/strong><\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-89\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/3.png\" alt=\"3\" width=\"650\" height=\"51\" \/><\/a><\/p>\n<p>In <strong>Vista\/7\/8<\/strong> and above;<\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/4.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-91\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/4.png\" alt=\"4\" width=\"650\" height=\"32\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/history.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-93\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/history.png\" alt=\"Google Chrome Browser Forensics\" width=\"650\" height=\"400\" \/><\/a><\/p>\n<p>From the \u2018History\u2019 file, you can view the \u2018URLs\u2019, \u2018downloads\u2019 and \u2018visits\u2019. It reveals the URLs visited, downloads made and the table of \u2018visits lists the timestamps and type of visits thus, aids to the information collection easily.<\/p>\n<p><strong><u>Cache <\/u><\/strong><\/p>\n<p>In Google Chrome forensic analysis; Cache is the inevitable part since it contains the actual content of the message.<\/p>\n<p><em>Location:<\/em><\/p>\n<p>In <strong>Windows XP<\/strong><\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/5.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-96\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/5.png\" alt=\"5\" width=\"650\" height=\"51\" \/><\/a><\/p>\n<p>Vista and above;<\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/6.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-98\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/6.png\" alt=\"6\" width=\"624\" height=\"32\" \/><\/a><\/p>\n<p><strong><u>Cookies<\/u><\/strong><\/p>\n<p>Cookie stores the cookie information of the visited sites, includes site name, last time of the access of the cookie etc. Cookies are stored with \u2018Cookies\u2019 in Chrome and those cookies used with extension are stored in file called \u2018Extension Cookies\u2019.<\/p>\n<p>Location of Cookies in Google Chrome forensic analysis;<\/p>\n<p>Vista or Windows 7 or\/and above;<\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/7.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-99\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/7.png\" alt=\"7\" width=\"624\" height=\"32\" \/><\/a><\/p>\n<p>In Windows XP<\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/8.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-100\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/8.png\" alt=\"8\" width=\"650\" height=\"51\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/cookies1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-102\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/cookies1.png\" alt=\"Google Chrome Browser Forensics\" width=\"650\" height=\"221\" \/><\/a><\/p>\n<p><strong>Where Does The Password Get Stored?<\/strong><\/p>\n<p>Apart from the history, cache, cookies etc., Chrome stores the login details in \u2018Web Data\u2019 file which is now replaced by \u2018Login Data\u2019 file. Moreover, the file stores IE7 Logins, auto complete entries, search keywords etc. Except the password, all the others are stored in text and passwords are encrypted by Triple DES algorithm.<\/p>\n<p>In Vista and above Windows version, the location of \u2018Login Data\u2019 is;<\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/9.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-103\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/9.png\" alt=\"9\" width=\"624\" height=\"32\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/login-data.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-105\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/login-data.png\" alt=\"Google Chrome Forensic Analysis\" width=\"650\" height=\"364\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong><u>Database<\/u><\/strong><\/p>\n<p>The location of database files is;<\/p>\n<p>Windows XP<\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/10.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-106\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/10.png\" alt=\"10\" width=\"650\" height=\"51\" \/><\/a><\/p>\n<p>Vista and later<\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/11.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-107\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/11.png\" alt=\"11\" width=\"624\" height=\"32\" \/><\/a><\/p>\n<p><strong>What More Can Be Seen?<\/strong><\/p>\n<p>While conducting Google Chrome browser forensics; for more probe, you can visit the sessions such as, Current Sessions, Current Tabs, Last Session and Last Tabs.<\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/current-session.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-108\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/current-session.png\" alt=\"Google Chrome Browser Forensics\" width=\"650\" height=\"327\" \/><\/a><\/p>\n<p>From the name of the files itself users will get to know about the use of the file. The last session file helps the users or the investigators to restore the last browsed session when the browser is opened up. While carrying out Google Chrome forensic analysis, these files are the way to collect the information regarding the opened tabs, about the sites exhibited etc.<\/p>\n<p><strong><u>Bookmarks<\/u><\/strong><\/p>\n<p>The bookmark specified by the users, if any will be stored in the \u2018bookmarks\u2019 and the file is located in;<\/p>\n<p><strong>Windows XP<\/strong><\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/12.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-109\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/12.png\" alt=\"12\" width=\"650\" height=\"51\" \/><\/a><\/p>\n<p><strong>Vista\/7\/8<\/strong><\/p>\n<p><a href=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/13.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-110\" src=\"https:\/\/www.acquireforensics.com\/blog\/wp-content\/uploads\/2015\/10\/13.png\" alt=\"13\" width=\"624\" height=\"64\" \/><\/a><\/p>\n<p>With a thorough search over the Chrome files, an investigator can get the evidence for closing the case, if any. For a trained agent, finding the artifacts will be easier and now there are even tools available in the market to help in finding the evidence from these files. During Google Chrome browser forensics; if the locations are clear, one can find information easier. Hope this page has added some valuable information.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It is a common and well known fact that the number of web users has increased nowadays. People spends their whole day infront of the computer and this clearly marks that large about of information will be there in the files related to the browsing. As since now many of the criminal activities are done [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":111,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":["post-83","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-web-browser"],"_links":{"self":[{"href":"https:\/\/www.acquireforensics.com\/blog\/wp-json\/wp\/v2\/posts\/83","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.acquireforensics.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.acquireforensics.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.acquireforensics.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.acquireforensics.com\/blog\/wp-json\/wp\/v2\/comments?post=83"}],"version-history":[{"count":1,"href":"https:\/\/www.acquireforensics.com\/blog\/wp-json\/wp\/v2\/posts\/83\/revisions"}],"predecessor-version":[{"id":166,"href":"https:\/\/www.acquireforensics.com\/blog\/wp-json\/wp\/v2\/posts\/83\/revisions\/166"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.acquireforensics.com\/blog\/wp-json\/wp\/v2\/media\/111"}],"wp:attachment":[{"href":"https:\/\/www.acquireforensics.com\/blog\/wp-json\/wp\/v2\/media?parent=83"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.acquireforensics.com\/blog\/wp-json\/wp\/v2\/categories?post=83"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.acquireforensics.com\/blog\/wp-json\/wp\/v2\/tags?post=83"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}