Agent skill

Extracting Browser History Artifacts

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Extracts and analyzes browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge using sqlite3, DB Browser for SQLite, Hindsight, and NirSoft tools…

Apache-2.0Auto-check: warningsSecurity

Install Extracting Browser History Artifacts

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill extracting-browser-history-artifacts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills extracting-browser-history-artifacts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/extracting-browser-history-artifacts .claude/skills/extracting-browser-history-artifacts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
extracting-browser-history-artifacts
GitHub stars
34k
Token cost
~2.9k tokens
SKILL.md length
449 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Extracts and analyzes browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge using sqlite3, DB Browser for SQLite, Hindsight, and NirSoft tools…

  • Works in 5 steps: Locate Browser Artifact Files → Extract Chrome Browsing History and… → Extract Firefox Browsing History → …
  • Performing digital forensics
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls sqlite3 and pip

What it does

Extracting Browser History Artifacts is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Extracts and analyzes browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge using sqlite3, DB Browser for SQLite, Hindsight, and NirSoft tools (BrowsingHistoryView, ChromeCacheView, MZCacheView). Use when performing digital forensics or incident response on a disk image or live system and you need timeline evidence of a user's web activity.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Digital forensics and Incident response. It works with SQLite. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Performing digital forensics
  • Incident response on a disk image
  • Live system and you need timeline evidence of a users web activity

Example prompts

  • “Use the extracting-browser-history-artifacts skill to extract and analyzes browser history, cookies, cache, downloads, and bookmarks from Chrome…”
  • “/extracting-browser-history-artifacts”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Locate Browser Artifact Files
  2. Extract Chrome Browsing History and Downloads
  3. Extract Firefox Browsing History
  4. Extract Cookies and Stored Credentials
  5. Use Hindsight for Comprehensive Chrome Analysis

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • sqlite3
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Extracting Browser History Artifacts loads about 2.9k tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 449 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:60
    # Key files: History, Cookies, Login Data, Web Data, Bookmarks, Preferences,
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:65
    # Key files: places.sqlite, cookies.sqlite, formhistory.sqlite, logins.json,
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:73
    cp -r "$CHROME_WIN"/{History,Cookies,Downloads,"Login Data","Web Data",Bookmarks} \
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:75
    cp -r $FIREFOX_WIN/{places.sqlite,cookies.sqlite,formhistory.sqlite,logins.json} \
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:77
    cp -r "$EDGE_WIN"/{History,Cookies,Downloads} \
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:198
    # Extract Chrome cookies
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:199
    sqlite3 /cases/case-2024-001/browser/chrome/Cookies << 'SQL'
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:202
    .output /cases/case-2024-001/analysis/chrome_cookies.csv
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:218
    # Extract Firefox cookies
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:219
    sqlite3 /cases/case-2024-001/browser/firefox/cookies.sqlite << 'SQL'

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 449 words, ~2,930 tokens.

Download SKILL.mdSave it as .claude/skills/extracting-browser-history-artifacts/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
extracting-browser-history-artifacts
description
Extracts and analyzes browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge using sqlite3, DB Browser for SQLite, Hindsight, and NirSoft tools (BrowsingHistoryView, ChromeCacheView, MZCacheView). Use when performing digital forensics or incident response on a disk image or live system and you need timeline evidence of a user's web activity.
domain
cybersecurity
subdomain
digital-forensics
tags
forensics, browser-forensics, chrome, firefox, edge, web-history, artifact-extraction
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
RS.AN-03, DE.AE-02, RS.MA-01
mitre_attack
T1005, T1074, T1119, T1070, T1059

Extracting Browser History Artifacts

When to Use

  • When investigating user web activity as part of a forensic examination
  • During insider threat investigations to establish patterns of data exfiltration
  • When tracing user visits to malicious or policy-violating websites
  • For correlating browser activity with other forensic artifacts and timelines
  • When investigating phishing attacks to identify which links were clicked

Prerequisites

  • Forensic image or access to user profile directories
  • SQLite3 for querying browser databases
  • Hindsight, BrowsingHistoryView, or DB Browser for SQLite
  • Knowledge of browser artifact file locations per OS
  • Python 3 with sqlite3 module for automated extraction
  • Understanding of Chrome, Firefox, and Edge storage formats

Workflow

Step 1: Locate Browser Artifact Files
bash
# Mount forensic image
mount -o ro,loop,offset=$((2048*512)) /cases/case-2024-001/images/evidence.dd /mnt/evidence

# Chrome artifact locations (Windows)
CHROME_WIN="/mnt/evidence/Users/suspect/AppData/Local/Google/Chrome/User Data/Default"
# Key files: History, Cookies, Login Data, Web Data, Bookmarks, Preferences,
#            Cache/, GPUCache/, Local Storage/, Session Storage/, IndexedDB/

# Firefox artifact locations (Windows)
FIREFOX_WIN="/mnt/evidence/Users/suspect/AppData/Roaming/Mozilla/Firefox/Profiles/*.default-release"
# Key files: places.sqlite, cookies.sqlite, formhistory.sqlite, logins.json,
#            key4.db, sessionstore.jsonlz4, webappsstore.sqlite

# Edge (Chromium) artifact locations (Windows)
EDGE_WIN="/mnt/evidence/Users/suspect/AppData/Local/Microsoft/Edge/User Data/Default"

# Copy artifacts to working directory
mkdir -p /cases/case-2024-001/browser/{chrome,firefox,edge}
cp -r "$CHROME_WIN"/{History,Cookies,Downloads,"Login Data","Web Data",Bookmarks} \
   /cases/case-2024-001/browser/chrome/ 2>/dev/null
cp -r $FIREFOX_WIN/{places.sqlite,cookies.sqlite,formhistory.sqlite,logins.json} \
   /cases/case-2024-001/browser/firefox/ 2>/dev/null
cp -r "$EDGE_WIN"/{History,Cookies,Downloads} \
   /cases/case-2024-001/browser/edge/ 2>/dev/null

# Hash artifacts for integrity
find /cases/case-2024-001/browser/ -type f -exec sha256sum {} \; \
   > /cases/case-2024-001/browser/artifact_hashes.txt
Step 2: Extract Chrome Browsing History and Downloads
bash
# Query Chrome History database
sqlite3 /cases/case-2024-001/browser/chrome/History << 'SQL'
.headers on
.mode csv
.output /cases/case-2024-001/analysis/chrome_history.csv

SELECT
    urls.url,
    urls.title,
    datetime(urls.last_visit_time/1000000-11644473600, 'unixepoch') AS last_visit,
    urls.visit_count,
    urls.typed_count,
    visits.transition & 0xFF AS transition_type
FROM urls
LEFT JOIN visits ON urls.id = visits.url
ORDER BY urls.last_visit_time DESC;
SQL

# Extract Chrome downloads
sqlite3 /cases/case-2024-001/browser/chrome/History << 'SQL'
.headers on
.mode csv
.output /cases/case-2024-001/analysis/chrome_downloads.csv

SELECT
    current_path,
    tab_url AS source_url,
    total_bytes,
    datetime(start_time/1000000-11644473600, 'unixepoch') AS start_time,
    datetime(end_time/1000000-11644473600, 'unixepoch') AS end_time,
    state,
    danger_type,
    mime_type
FROM downloads
ORDER BY start_time DESC;
SQL

# Extract Chrome search terms
sqlite3 /cases/case-2024-001/browser/chrome/History << 'SQL'
.headers on
.mode csv
.output /cases/case-2024-001/analysis/chrome_searches.csv

SELECT
    term,
    urls.url,
    datetime(urls.last_visit_time/1000000-11644473600, 'unixepoch') AS search_time
FROM keyword_search_terms
JOIN urls ON keyword_search_terms.url_id = urls.id
ORDER BY urls.last_visit_time DESC;
SQL
Step 3: Extract Firefox Browsing History
bash
# Query Firefox places.sqlite for history
sqlite3 /cases/case-2024-001/browser/firefox/places.sqlite << 'SQL'
.headers on
.mode csv
.output /cases/case-2024-001/analysis/firefox_history.csv

SELECT
    moz_places.url,
    moz_places.title,
    datetime(moz_historyvisits.visit_date/1000000, 'unixepoch') AS visit_date,
    moz_places.visit_count,
    moz_historyvisits.visit_type
FROM moz_places
JOIN moz_historyvisits ON moz_places.id = moz_historyvisits.place_id
ORDER BY moz_historyvisits.visit_date DESC;
SQL

# Extract Firefox bookmarks
sqlite3 /cases/case-2024-001/browser/firefox/places.sqlite << 'SQL'
.headers on
.mode csv
.output /cases/case-2024-001/analysis/firefox_bookmarks.csv

SELECT
    moz_bookmarks.title,
    moz_places.url,
    datetime(moz_bookmarks.dateAdded/1000000, 'unixepoch') AS date_added,
    datetime(moz_bookmarks.lastModified/1000000, 'unixepoch') AS last_modified
FROM moz_bookmarks
JOIN moz_places ON moz_bookmarks.fk = moz_places.id
WHERE moz_bookmarks.type = 1
ORDER BY moz_bookmarks.dateAdded DESC;
SQL

# Extract Firefox form history (search terms, form fills)
sqlite3 /cases/case-2024-001/browser/firefox/formhistory.sqlite << 'SQL'
.headers on
.mode csv
.output /cases/case-2024-001/analysis/firefox_forms.csv

SELECT
    fieldname,
    value,
    timesUsed,
    datetime(firstUsed/1000000, 'unixepoch') AS first_used,
    datetime(lastUsed/1000000, 'unixepoch') AS last_used
FROM moz_formhistory
ORDER BY lastUsed DESC;
SQL
Step 4: Extract Cookies and Stored Credentials
bash
# Extract Chrome cookies
sqlite3 /cases/case-2024-001/browser/chrome/Cookies << 'SQL'
.headers on
.mode csv
.output /cases/case-2024-001/analysis/chrome_cookies.csv

SELECT
    host_key,
    name,
    path,
    datetime(creation_utc/1000000-11644473600, 'unixepoch') AS created,
    datetime(expires_utc/1000000-11644473600, 'unixepoch') AS expires,
    datetime(last_access_utc/1000000-11644473600, 'unixepoch') AS last_access,
    is_secure,
    is_httponly,
    is_persistent
FROM cookies
ORDER BY last_access_utc DESC;
SQL

# Extract Firefox cookies
sqlite3 /cases/case-2024-001/browser/firefox/cookies.sqlite << 'SQL'
.headers on
.mode csv
.output /cases/case-2024-001/analysis/firefox_cookies.csv

SELECT
    host,
    name,
    path,
    datetime(creationTime/1000000, 'unixepoch') AS created,
    datetime(expiry, 'unixepoch') AS expires,
    datetime(lastAccessed/1000000, 'unixepoch') AS last_access,
    isSecure,
    isHttpOnly
FROM moz_cookies
ORDER BY lastAccessed DESC;
SQL

# Note: Chrome Login Data is encrypted with DPAPI (Windows) or keychain (Mac)
# Extract stored login URLs (passwords are encrypted)
sqlite3 /cases/case-2024-001/browser/chrome/"Login Data" << 'SQL'
.headers on
.mode csv
.output /cases/case-2024-001/analysis/chrome_logins.csv

SELECT
    origin_url,
    action_url,
    username_value,
    datetime(date_created/1000000-11644473600, 'unixepoch') AS date_created,
    datetime(date_last_used/1000000-11644473600, 'unixepoch') AS date_last_used,
    times_used
FROM logins
ORDER BY date_last_used DESC;
SQL
Step 5: Use Hindsight for Comprehensive Chrome Analysis
bash
# Install Hindsight
pip install pyhindsight

# Run Hindsight against Chrome profile
hindsight -i "/cases/case-2024-001/browser/chrome/" \
   -o /cases/case-2024-001/analysis/hindsight_report \
   -f xlsx

# Hindsight automatically extracts:
# - Browsing history with timestamps
# - Downloads with source URLs
# - Cookies with decryption (where possible)
# - Cache records
# - Local Storage entries
# - Autofill data
# - Saved passwords (encrypted)
# - Preferences and extensions
# - Session/tab recovery data

# For JSONL output (easier to parse)
hindsight -i "/cases/case-2024-001/browser/chrome/" \
   -o /cases/case-2024-001/analysis/hindsight_report \
   -f jsonl

Key Concepts

ConceptDescription
Chrome timestampMicroseconds since January 1, 1601 (WebKit/Chrome epoch)
Firefox timestampMicroseconds since January 1, 1970 (Unix epoch in microseconds)
Transition typesHow a URL was accessed: typed (1), link (0), bookmark (1), redirect (5/6)
DPAPI encryptionWindows Data Protection API encrypting stored passwords and cookies
places.sqliteFirefox combined history and bookmark database
SQLite WALWrite-Ahead Log that may contain recently deleted browser records
Session restoreBrowser data preserving open tabs across restarts
IndexedDBBrowser-based database that may contain web application data

Tools & Systems

ToolPurpose
HindsightComprehensive Chrome/Chromium forensic analysis tool
sqlite3Command-line SQLite database query tool
DB Browser for SQLiteGUI tool for browsing SQLite databases
BrowsingHistoryViewNirSoft tool for viewing browser history across all browsers
ChromeCacheViewNirSoft tool for examining Chrome cache contents
MZCacheViewNirSoft tool for Firefox cache analysis
KAPEAutomated artifact collection including browser data
AutopsyFull forensic platform with browser artifact ingest modules
Show full SKILL.md (158 more words)Show less

Common Scenarios

Scenario 1: Phishing Investigation Extract browser history around the reported phishing timeframe, identify the phishing URL that was visited, check downloads for malicious attachments, examine cookies for session tokens that may have been stolen, correlate with email header analysis.

Scenario 2: Data Exfiltration via Cloud Services Search history for cloud storage URLs (Dropbox, Google Drive, OneDrive, Mega), examine downloads and uploads, check form history for file names entered, review cookies for active cloud service sessions during the investigation period.

Scenario 3: Policy Violation Investigation Extract complete browsing history for the investigation period, categorize sites visited, identify access to prohibited content categories, document timestamps and visit duration, correlate with network proxy logs for verification.

Scenario 4: Malware Delivery Vector Analysis Trace the chain of redirects leading to a drive-by download, examine the downloads database for the malware payload, check cache for exploit kit landing pages, identify the initial referrer URL that started the infection chain.

Output Format

Browser Forensics Summary:
  User Profile: suspect (Windows 10)
  Browsers Found: Chrome 120, Firefox 121, Edge 120

  Chrome Analysis:
    History Entries:    12,456
    Downloads:          234
    Saved Passwords:    67 sites (encrypted)
    Cookies:            3,456
    Bookmarks:          89

  Firefox Analysis:
    History Entries:    5,678
    Form Entries:       234
    Bookmarks:          45
    Cookies:            1,234

  Suspicious Findings:
    - Visited known phishing URL at 2024-01-15 14:32 UTC
    - Downloaded "invoice_update.exe" from suspicious domain
    - Cloud storage (mega.nz) accessed 15 times in 2-hour window
    - Search queries: "how to encrypt files", "secure file transfer"

  Reports:
    Chrome History:   /analysis/chrome_history.csv
    Firefox History:  /analysis/firefox_history.csv
    Full Report:      /analysis/hindsight_report.xlsx

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/extracting-browser-history-artifacts of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Extracting Browser History Artifacts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Extracting Browser History Artifacts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Extracting Browser History Artifacts this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: WarnApache-2.0
Forensics OsqueryAgentSecOps/SecOpsAgentKit2201 repos~4.9kAutomated safety check: NotesCustom licence
Incident Response NetworkLeoYeAI/openclaw-master-skills2.2k—~5kAutomated safety check: PassApache-2.0
Incident Responsehypnguyen1209/offensive-claude388—~2.5kAutomated safety check: PassMIT
Ir VelociraptorAgentSecOps/SecOpsAgentKit2201 repos~3.1kAutomated safety check: PassCustom licence
DB Ops SopOpenDCAI/DataMind451—~388Automated safety check: PassApache-2.0

Similar skills

  • Forensics Osquery

    AgentSecOps/SecOpsAgentKit

    SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.

    220 GitHub starsUsed in 1 repo~4.9k tokens
    SecurityAuto-check: notes
  • Incident Response Network

    LeoYeAI/openclaw-master-skills

    Network forensics evidence collection and analysis during security incidents.

    2.2k GitHub stars~5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Incident Response

    hypnguyen1209/offensive-claude

    A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining…

    388 GitHub stars~2.5k tokensUpdated 13 days ago
    SecurityAuto-check passed
  • Ir Velociraptor

    AgentSecOps/SecOpsAgentKit

    Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale.

    220 GitHub starsUsed in 1 repo~3.1k tokens
    SecurityAuto-check passed
  • DB Ops Sop

    OpenDCAI/DataMind

    Database operations runbook — backup, recovery, performance tuning, troubleshooting.

    451 GitHub stars~388 tokensUpdated 20 days ago
    DatabasesAuto-check passed
  • Digital Forensics

    sickn33/agentic-awesome-skills

    Authorized digital forensics: memory dumps, disk timelines, PCAP investigation, artifact triage, and incident-response evidence preservation.

    47k GitHub starsUsed in 1 repo~495 tokens
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Extracting Browser History Artifacts

What does Extracting Browser History Artifacts do?

Extracts and analyzes browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge using sqlite3, DB Browser for SQLite, Hindsight, and NirSoft tools…. Extracting Browser History Artifacts is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Extracts and analyzes browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge using sqlite3, DB Browser for SQLite, Hindsight, and NirSoft tools (BrowsingHistoryView, ChromeCacheView, MZCacheView).

When should I use Extracting Browser History Artifacts?

Extracting Browser History Artifacts fits situations like: performing digital forensics; incident response on a disk image; live system and you need timeline evidence of a users web activity.

How do I install Extracting Browser History Artifacts in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill extracting-browser-history-artifacts -a claude-code`. Or copy the skill folder (skills/extracting-browser-history-artifacts in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/extracting-browser-history-artifacts in your project. Claude Code loads it when a task matches its description.

How do I install Extracting Browser History Artifacts in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill extracting-browser-history-artifacts -a codex`. Or copy the skill folder (skills/extracting-browser-history-artifacts in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/extracting-browser-history-artifacts in your project. Codex loads it when a task matches its description.

Can I use Extracting Browser History Artifacts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill extracting-browser-history-artifacts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/extracting-browser-history-artifacts, .gemini/skills/extracting-browser-history-artifacts, .github/skills/extracting-browser-history-artifacts and .opencode/skills/extracting-browser-history-artifacts in your project.

What does Extracting Browser History Artifacts need to run?

Going by SKILL.md and its folder, Extracting Browser History Artifacts needs Python for the scripts in its folder and the command-line tools its instructions call (sqlite3 and pip). Our summary lists: Python 3.

Does Extracting Browser History Artifacts access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Extracting Browser History Artifacts safe to install?

Our automated static check of SKILL.md flagged 10 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Extracting Browser History Artifacts use?

Extracting Browser History Artifacts is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Extracting Browser History Artifacts use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 543 tokens, read only when the agent opens those files.

What are the alternatives to Extracting Browser History Artifacts?

Skills that share tags, products or a category with Extracting Browser History Artifacts: Forensics Osquery (AgentSecOps/SecOpsAgentKit, 220 stars), Incident Response Network (LeoYeAI/openclaw-master-skills, 2.2k stars), Incident Response (hypnguyen1209/offensive-claude, 388 stars) and Ir Velociraptor (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Extracting Browser History Artifacts?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.