Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox
-
Updated
Sep 7, 2026 - Python
Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox
Point it at disk + memory evidence; get a correlated, ATT&CK-mapped attack timeline. Rust DFIR orchestrator: one command ingests E01/EWF/VMDK/raw + memory dumps, parses NTFS/registry/EVTX/prefetch/LNK/SRUM/browser/Amcache + memory (processes, netstat, injection), correlates into a DuckDB super-timeline, scans threat-intel, and reports.
Decrypt chrome profile data offline using the Chrome Safe Storage keyring secret.
Firefox profile decryption tool and master password cracker.
Chrome SNSS session parser + History forensic extractor for Windows
Complete notes, lab writeups, and challenge walkthroughs for the LetsDefend Incident Responder Path. This covers DFIR, memory forensics, Windows Event Log analysis, Active Directory attack hunting, malware triage and more!
⚡ Temporal Browser Intelligence & Agent-Owned Workflow Runtime with 350 Certified MCP Tools & Python SDK · Sub-Millisecond DOM Time-Travel, Target Memory & Deterministic Automation.
DFIR tool for offline browser artifacts analysis — Chrome & Firefox
Parse Chrome/Firefox/Safari and embedded-Chromium app artifacts — history, cookies, web storage, integrity/tampering, free-page carving, container discovery — into one JSON timeline. Single static Rust binary, no runtime deps.
A local forensic workstation for web browser artifact analysis
BrowserDig (Browser Digital Information Gatherer) is a fast, lightweight, cross-platform browser forensics tool for DFIR, threat hunting, and privacy audits. It extracts and analyze history, cookies, logins, downloads, bookmarks, and more from multiple browsers like Chrome, Edge, Firefox, Brave, Opera, Vivaldi, and Safari.
⚡ Browser Forensic Recorder, Live DOM Intelligence & Universal MCP Server for real-time AI Agent inspection and DOM time-travel.
Parse Chrome/Firefox history and cookies into searchable timelines — browser forensics for DFIR and insider investigations.
FAEP is an automated tool to extract and parse forensic artifacts from .E01 images automatically, with a clean GUI and minimal manual effort.
A write-up about the CyberDefenders Lab Phishy
Chronika is a forensic analysis tool for reading and visualizing different browser histories in a chronological timeline format. Supports Chrome, Firefox, Safari, Brave, Opera, Edge, Vivaldi, Tor Browser, Chromium, LibreWolf and all browsers on Linux and macOS.
Tools and documentation for examining what AI platforms do during your sessions using standard browser developer tools (F12/DevTools). Covers Claude, ChatGPT, Gemini, Grok, DeepSeek, and Perplexity.
Chromium/Brave/Edge SNSS session-file forensic decoder — panic-free, read-only; validates the SNSS command stream, decodes navigation base::Pickle payloads, replays per-window tab state. No runtime deps.
Cross-platform vibe-coded (probably badly made but w.e) endpoint forensics suite. Dual SHA-256+SHA3-256 hash-chained. ML-DSA-65-signed evidence.
Linux browser forensics — collects Chrome/Firefox/Edge history and builds HTML dashboards & JSON timelines. See what happened on your own devices. GTK GUI + PowerShell collector, fully offline.
To associate your repository with the browser-forensics topic, visit your repo's landing page and select "manage topics."