DFIR For Beginners
search
Ctrlk
DFIR For Beginners
  • OS Basics
    • Windows Internals
    • Analyzing Windows Processes
    • Windows Living off the Land
  • Logs
    • Sysmon
  • Forensics
    • Digital Forensics for Beginners
    • Windows Forensics
    • Linux Forensics
    • Web Server
    • Email Forensics
    • Browser Artifacts
    • iOS Forensics
    • Memory Forensics
    • ADS
    • Forensics Images & Labs
    • Forensics Notes
    • Essential Tools
  • Malware Analysis
    • Malware Analysis Basics
    • Malware Sandbox
    • Static Analysis
    • Dynamic Analysis
    • Heap Analysis
    • Portable Executable
    • HTA Files
    • PDF Files
    • Disassembly
    • IDA
    • Traffic Analysis
    • Malware Tips
    • Bypass EDR
    • Detection
    • Malware Samples Repos
    • Malware Analysis Resources
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Forensics

Browser Artifacts

LogoChrome Password Dumper: Guide to Browser Password Recovery | Red Team Leadersdocs.redteamleaders.comchevron-right
LogoGitHub - CyberSecurityUP/ChromePasswordDumper: Chrome Dump PasswordGitHubchevron-right
LogoGitHub - AlessandroZ/LaZagne: Credentials recovery projectGitHubchevron-right
LogoGitHub - The-Viper-One/Invoke-PowerChrome: Decrypt Chromium based browser passwords with PowerShell.GitHubchevron-right
LogoGitHub - gustavoparedes/Browser-Reviewer: Browser Reviewer is a portable forensic tool for analyzing user activity in Firefox and Chrome-based browsers. It extracts and displays browsing history, downloads, bookmarks, and autofill data. The tool allows analysts to tag, comment, and export reports in PDF.GitHubchevron-right

hashtag
Mimikatz

Mimikatz is the premier credential extraction tool for Windows environments, with specific capabilities for Chrome password recovery:

Extract DPAPI master keys

Dump process memory for analysis

Extract credentials from live processes

hashtag
Logs Locations

  • Apache: /var/www/html/ Default on most Linux distros

  • Nginx: /usr/share/nginx/html/ Default on many Linux setups

PreviousEmail Forensicschevron-leftNextiOS Forensicschevron-right

Last updated 3 days ago

  • Mimikatz
  • Logs Locations
mimikatz # dpapi::chrome
mimikatz # sekurlsa::minidump chrome.dmp
mimikatz # sekurlsa::logonpasswords