acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Analyze Chromium-based browser artifacts using Hindsight to extract browsing history, downloads, cookies, cached
$ npx -y skills add Mikaru0Mystic/sectinel --skill analyzing-browser-forensics-with-hindsight --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/analyzing-browser-forensics-with-hindsightContext preview
The summary Claude sees to decide when to auto-load this skill.
Analyze Chromium-based browser artifacts using Hindsight to extract browsing history, downloads, cookies, cached
name: analyzing-browser-forensics-with-hindsight description: Analyze Chromium-based browser artifacts using Hindsight to extract browsing history, downloads, cookies, cached content, autofill data, saved passwords, and browser extensions from Chrome, Edge, Brave, and Opera for forensic investigation. domain: cybersecurity subdomain: digital-forensics tags: - browser-forensics - hindsight - chrome-forensics - chromium - edge - browsing-history - cookies - downloads - cache - web-artifacts version: '1.0' author: mahipal license: Apache-2.0 nist_csf: - RS.AN-01 - RS.AN-03 - DE.AE-02 - RS.MA-01
Hindsight is an open-source browser forensics tool designed to parse artifacts from Google Chrome and other Chromium-based browsers (Microsoft Edge, Brave, Opera, Vivaldi). It extracts and correlates data from multiple browser database files to create a unified timeline of web activity. Hindsight can parse URLs, download history, cache records, bookmarks, autofill records, saved passwords, preferences, browser extensions, HTTP cookies, Local Storage (HTML5 cookies), login data, and session/tab information. The tool produces chronological timelines in multiple output formats (XLSX, JSON, SQLite) that enable investigators to reconstruct user web activity for incident response, insider threat investigations, and criminal cases.
| Browser | Windows Profile Path | |---------|---------------------| | Chrome | %LOCALAPPDATA%\Google\Chrome\User Data\Default\ | | Edge | %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\ | | Brave | %LOCALAPPDATA%\BraveSoftware\Brave-Browser\User Data\Default\ | | Opera | %APPDATA%\Opera Software\Opera Stable\ | | Vivaldi | %LOCALAPPDATA%\Vivaldi\User Data\Default\ | | Chrome (macOS) | ~/Library/Application Support/Google/Chrome/Default/ | | Chrome (Linux) | ~/.config/google-chrome/Default/ |
| File | Contents | |------|----------| | History | URL visits, downloads, keyword searches | | Cookies | HTTP cookies with domain, expiry, values | | Web Data | Autofill entries, saved credit cards | | Login Data | Saved usernames/passwords (encrypted) | | Bookmarks | JSON bookmark tree | | Preferences | Browser configuration and extensions | | Local Storage/ | HTML5 Local Storage per domain | | Session Storage/ | Session-specific storage per domain | | Network Action Predictor | Previously typed URLs | | Shortcuts | Omnibox shortcuts and predictions | | Top Sites | Frequently visited sites |
# Basic analysis of a Chrome profile hindsight.exe -i "C:\Evidence\Users\suspect\AppData\Local\Google\Chrome\User Data\Default" -o C:\Output\chrome_analysis # Specify browser type hindsight.exe -i "/path/to/profile" -o /output/analysis -b Chrome # JSON output format hindsight.exe -i "C:\Evidence\Chrome\Default" -o C:\Output\chrome --format jsonl # With cache parsing (slower but more complete) hindsight.exe -i "C:\Evidence\Chrome\Default" -o C:\Output\chrome --cache
# Start Hindsight web interface hindsight_gui.exe # Navigate to http://localhost:8080 # Upload or point to browser profile directory # Configure output format and analysis options # Generate and download report
-- Chrome History database schema (key tables) -- urls table: id, url, title, visit_count, typed_count, last_visit_time -- visits table: id, url, visit_time, from_visit, transition, segment_id -- Timestamps are Chrome/WebKit format: microseconds since 1601-01-01 -- Convert: datetime((visit_time/1000000)-11644473600, 'unixepoch')
-- downloads table: id, current_path, target_path, start_time, end_time, -- received_bytes, total_bytes, state, danger_type, interrupt_reason, -- url, referrer, tab_url, mime_type, original_mime_type
-- cookies table: creation_utc, host_key, name, value, encrypted_value, -- path, expires_utc, is_secure, is_httponly, last_access_utc, -- has_expires, is_persistent, priority, samesite
import sqlite3
import os
import json
import sys
from datetime import datetime, timedelta
CHROME_EPOCH = datetime(1601, 1, 1)
def chrome_time_to_datetime(chrome_ts: int):
"""Convert Chrome timestamp to datetime."""
if chrome_ts == 0:
return None
try:
return CHROME_EPOCH + timedelta(microseconds=chrome_ts)
except (OverflowError, OSError):
return None
def analyze_chrome_history(profile_path: str, output_dir: str) -> dict:
"""Analyze Chrome History database for forensic evidence."""
history_db = os.path.join(profile_path, "History")
if not os.path.exists(history_db):
return {"error": "History database not found"}
os.makedirs(output_dir, exist_ok=True)
conn = sqlite3.connect(f"file:{history_db}?mode=ro", uri=True)
# URL visits with timestamps
cursor = conn.cursor()
cursor.execute("""
SELECT u.url, u.title, v.visit_time, u.visit_count,
v.transition & 0xFF as transition_type
FROM visits v JOIN urls u ON v.url = u.id
ORDER BY v.visit_time DESC LIMIT 5000
""")
visits = [{
"url": r[0], "title": r[1],
"visit_time": strOpen-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative