Browser Forensics – DFIR Workflow & Cheatsheet
Quick Reference: Investigation Priority Matrix
Priority
Artifact
Key Questions Answered
Volatility
Investigation Workflow
Phase 1: Initial Triage (High Priority)
Firefox Locations:
Chrome/Edge Locations:
1.2 Session Restore Files
Chrome/Edge Locations:
Phase 2: Content Analysis (Medium Priority)
Firefox Locations:
Chrome/Edge Locations:
2.2 Media History (Chromium Only)
Chrome/Edge Locations:
Phase 3: User Behaviour & Intent (Medium Priority)
3.1 Auto-Complete Data
Firefox Locations:
Chrome/Edge Locations - By Data Type:
3.2 Cookies
Chrome/Edge Locations:
Phase 4: Configuration & Credentials (Low-Medium Priority)
4.1 Stored Credentials
4.2 Browser Preferences
Phase 5: Supporting Artifacts (Low Priority)
5.1 Bookmarks
5.2 Extensions & Add-ons
Critical Investigation Tips
Multi-Profile Awareness
Timestamp Interpretation
Data Persistence Hierarchy
Anti-Forensics Detection
Live System vs. Dead Disk
Essential DFIR Tools
SQLite Browsers
Browser-Specific Tools
Comprehensive Suites
Manual Analysis
Quick Command Reference
Identify Browser Profiles
Collect All Browser Artifacts (PowerShell)
Hash Browser Databases (Before Analysis)
Investigation Checklist
Initial Response
Data Collection
Analysis
Reporting
File Path Environment Variables
Notes & Gotchas
PreviousFile Download and Browser Activity Investigation GuideNextDeleted Files & File Knowledge—DFIR Workflow & Cheatsheet
Last updated