the not so brief history of Chrome

In digital forensics, often investigations occur after the fact. Investigating volitile artifacts can sometimes be difficult however not all. Web traffic is one of the artifacts that can disappear for good if there are no proper controls in place.

Investigating Web Traffic on an endpoint when all you have to work off is an image of the system can be as easy as running a one-liner with the right tool.

Hindsight can parse the history file from Chrome and output an .xlsx with extremely verbose information such as history, files opened using chome (eg. PDFs), installed extensions, preferences, and many more.

https://github.com/obsidianforensics/hindsight/tree/master/dist