Browser Artifact Analysis

GIAC Certified Forensic Examiner Objectives:

Microsoft Browser Forensics

  • The candidate will demonstrate an understanding of the artifacts created by Microsoft browsers during user activity.

Third-Party Browser Forensics and Browser Artifact Analysis

  • The candidate will demonstrate an understanding of the artifacts created by third-party browsers and when privacy settings are applied during user activity.

Windows Registry Artifact Analysis

  • The candidate will demonstrate an understanding of the registry artifacts created by the system and user activity.

Windows Registry Fundamentals

  • The candidate will demonstrate an understanding of the structure and purpose of the Windows registry and the types of tools used to analyze and parse the data.

Overview

This lab is part of a series of lab exercises designed through a grant initiative by the Center for Systems Security and Information Assurance (CSSIA) and the Network Development Group (NDG), funded by the National Science Foundation’s (NSF) Advanced Technological Education (ATE) program Department of Undergraduate Education (DUE) Award No. 0702872 and 1002746.

The World Wide Web (www), known as the Web, is a client/server application that hosts resources such as documents, multimedia, images, etc. These resources are identified by Uniform Resource Locators (URLs) and are transferred between a web client/browser and web server using a special protocol called hypertext transfer protocol (HTTP). Documents on the web are created using a markup language called hypertext markup language (HTML). These HTML documents contain hyperlinks that allow you to visit different URLs through these links. By the end of this lab, the student will analyze three major browsers: Internet Explorer, Google Chrome, and Mozilla Firefox.

OUTCOMES:

In this lab, you will learn to:

  1. Meet your browser
  2. Analyze Internet Explorer
  3. Analyze Google Chrome
  4. Analyze Mozilla Firefox

Key terms and descriptions

Index.dat Viewer
Reads the index.dat files associated with Internet Explorer
History Viewer
Displays the entire history stored by web browsers such as Internet Explorer, Mozilla Firefox, and Google Chrome