File Download and Browser Activity Investigation Guide
asComplete DFIR Workflow & Cheatsheet
๐ Table of Contents
๐ฏ Investigation Framework
Artifact Priority Matrix
Investigation Goal
Primary Artifacts
Secondary Artifacts
Timeframe
๐ Quick Triage (First 15 Minutes)
Determine Investigation Scope
Quick Win Queries
๐ Browser History Analysis
Overview
Chrome/Edge (Chromium) Browser History
Table
Description
Key Columns
Firefox Browser History
Table
Description
Key Columns
Type
Description
Investigation Workflows - Browser History
๐ฅ Download History Analysis
Overview
Chrome/Edge Download History
Firefox Download History
Investigation Workflows - Downloads
๐ Internet Explorer/Edge File Access
WebCache Database
๐ง Email Attachments Investigation
Overview
Microsoft Outlook
Format
Description
Use Case
Investigation Workflows - Email Attachments
OLK Temporary Attachments
๐ Cross-Browser Analysis
Multi-Browser Investigation
Unified Timeline Creation
๐ Investigation Playbooks
Playbook 1: Malware Download Investigation
Playbook 2: Phishing Investigation
Playbook 3: Data Exfiltration via Web
๐ ๏ธ Tool Reference
Browser Analysis Tools
Email Analysis Tools
Collection Tools
๐ Quick Reference Cards
Browser Database Comparison
Browser
Database
Format
History Table
Downloads Table
Location
Time Conversion Reference
Investigation Time Estimates
Task
Estimated Time
๐ Pro Tips
Cross-Artifact Correlation Strategy
Red Flag Summary
Common Pitfalls
Timeline Reconstruction Tips
PreviousFile and Folder Access Investigation GuideNextBrowser Forensics โ DFIR Workflow & Cheatsheet
Last updated