Google Chrome analysis

Google Chrome is a web browser, and is the default browser on many devices. Chrome data on the device is somewhat unique in that it contains data not just from the device, but from all devices on which the user has logged into Chrome. This means that it is entirely possible (even very likely) that data from the user browsing on their desktop computer will be found in the databases on their phone. However, this also leads to huge amounts of data for an examiner to sort through, but that's a good problem to have.

Package name: com.android.chrome

Files of interest:

  • /app_chrome/Default/:
    • Sync Data/SyncData.sqlite3
    • Bookmarks
    • Cookies
    • Google Profile Picture.png
    • History
    • Login Data
    • Preferences
    • Top Sites
    • Web Data
  • /app_ChromeDocumentActivity/ ...

Get Learning Android Forensics - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.