File Download and Browser Activity Investigation Guide
asComplete DFIR Workflow & Cheatsheet
π Table of Contents
π― Investigation Framework
Artifact Priority Matrix
Investigation Goal
Primary Artifacts
Secondary Artifacts
Timeframe
π Quick Triage (First 15 Minutes)
Determine Investigation Scope
Quick Win Queries
π Browser History Analysis
Overview
Chrome/Edge (Chromium) Browser History
Table
Description
Key Columns
Firefox Browser History
Table
Description
Key Columns
Type
Description
Investigation Workflows - Browser History
π₯ Download History Analysis
Overview
Chrome/Edge Download History
Firefox Download History
Investigation Workflows - Downloads
π Internet Explorer/Edge File Access
WebCache Database
π§ Email Attachments Investigation
Overview
Microsoft Outlook
Format
Description
Use Case
Investigation Workflows - Email Attachments
OLK Temporary Attachments
π Cross-Browser Analysis
Multi-Browser Investigation
Unified Timeline Creation
π Investigation Playbooks
Playbook 1: Malware Download Investigation
Playbook 2: Phishing Investigation
Playbook 3: Data Exfiltration via Web
π οΈ Tool Reference
Browser Analysis Tools
Email Analysis Tools
Collection Tools
π Quick Reference Cards
Browser Database Comparison
Browser
Database
Format
History Table
Downloads Table
Location
Time Conversion Reference
Investigation Time Estimates
Task
Estimated Time
π Pro Tips
Cross-Artifact Correlation Strategy
Red Flag Summary
Common Pitfalls
Timeline Reconstruction Tips
PreviousFile and Folder Access Investigation GuideNextBrowser Forensics β DFIR Workflow & Cheatsheet
Last updated