# Trouble Chrome History & Recent Activity

**URL:** <https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100>\
**Category:** Autopsy Feature Requests\
**Created:** [February 23, 2022, 2:21am UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100 "2022-02-23T02:21:04Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![nika](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/nika/32/1574_2.png) [@nika](https://sleuthkit.discourse.group/u/nika)\
**Post date:** [February 23, 2022, 2:21am UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/1 "2022-02-23T02:21:04Z")

</div>

I posted on Autopsy Help but so far no answer. I thought maybe that was the wrong category. I am posting here in case this will get some traction. Thank you all in advance.

> I recently started having trouble ingesting Chrome history files. These used to get pulled in by the Recent Activity module and would show up under Web History.
> 
> The files themselves can be read by Autopsy, but do not ingest. I can browse to them and view them using the built-in viewer.
> 
> I’m running Windows 10 and using Autopsy version 4.19.3 (the latest as of this writing).
> 
> Not sure what I’m doing wrong or if this is something that needs to be fixed in Autopsy.

---

<div class="post-metadata">

**Author:** ![apriestman](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/apriestman/32/24_2.png) [@apriestman](https://sleuthkit.discourse.group/u/apriestman)\
**Post date:** [February 23, 2022, 1:35pm UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/2 "2022-02-23T13:35:42Z")

</div>

Are your history files in the “Chrome/User Data/Default” folder?

---

<div class="post-metadata">

**Author:** ![nika](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/nika/32/1574_2.png) [@nika](https://sleuthkit.discourse.group/u/nika)\
**Post date:** [February 23, 2022, 5:24pm UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/3 "2022-02-23T17:24:54Z")

</div>

Hello @apriestman yes, that’s correct.

---

<div class="post-metadata">

**Author:** ![Mark\_McKinnon](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/mark_mckinnon/32/42_2.png) [@Mark\_McKinnon](https://sleuthkit.discourse.group/u/Mark_McKinnon)\
**Post date:** [February 23, 2022, 6:05pm UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/4 "2022-02-23T18:05:20Z")

</div>

If you go to the following location **C:\Users\<username\>\AppData\Local\Google\Chrome\User Data\Default and look at the file named history you can see if there is data in the file. I do not remember if application viewer will pop up for this or not for sqlite. Look to see if there is data in the table.**

---

<div class="post-metadata">

**Author:** ![nika](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/nika/32/1574_2.png) [@nika](https://sleuthkit.discourse.group/u/nika)\
**Post date:** [February 23, 2022, 8:25pm UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/5 "2022-02-23T20:25:54Z")

</div>

Thank you and I appreciate the response.

The table does contain data and Autopsy can parse/read it. And, from Autopsy, it can be extracted and imported into an sqlite browser and queried/read or each table can be exported from Autopsy as CSV.

However, the data used to get pulled in by the Recents module and put into “Web History” in Autopsy. This no longer occurs.

---

<div class="post-metadata">

**Author:** ![Mark\_McKinnon](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/mark_mckinnon/32/42_2.png) [@Mark\_McKinnon](https://sleuthkit.discourse.group/u/Mark_McKinnon)\
**Post date:** [February 24, 2022, 1:17pm UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/6 "2022-02-24T13:17:21Z")

</div>

I guess the next step would be to include the Autopsy.log file for the recent activity ingest run.

---

<div class="post-metadata">

**Author:** ![apriestman](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/apriestman/32/24_2.png) [@apriestman](https://sleuthkit.discourse.group/u/apriestman)\
**Post date:** [February 24, 2022, 3:53pm UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/7 "2022-02-24T15:53:33Z")

</div>

I just ran an image with Chrome history on Autopsy 4.19.2 and 4.19.3 and got the same Web History results each time, so I don’t believe the feature is broken.

---

<div class="post-metadata">

**Author:** ![nika](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/nika/32/1574_2.png) [@nika](https://sleuthkit.discourse.group/u/nika)\
**Post date:** [February 25, 2022, 5:06am UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/8 "2022-02-25T05:06:17Z")

</div>

Thank you all. I am sorry but it just came to me that this was run on an OSX (not Windows) image. I’m not sure if this changes anything or not. I’ll provide the logs in short order.

---

<div class="post-metadata">

**Author:** ![nika](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/nika/32/1574_2.png) [@nika](https://sleuthkit.discourse.group/u/nika)\
**Post date:** [February 25, 2022, 7:15am UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/10 "2022-02-25T07:15:13Z")

</div>

@apriestman @Mark_McKinnon Very sorry for the misleading statements earlier in the thread. Here is the [log file](https://pastebin.com/8VxJbZ6X) run on an OSX image using Autopsy version 4.19.3. (Recents module run only.) The Chrome history file is located in `/Users/User1/Library/Application Support/Google/Chrome/Default/` on this machine. The file contains history data, as explained earlier. The Recents module output Safari history only.

Thank you again.

---

<div class="post-metadata">

**Author:** ![apriestman](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/apriestman/32/24_2.png) [@apriestman](https://sleuthkit.discourse.group/u/apriestman)\
**Post date:** [February 25, 2022, 2:06pm UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/11 "2022-02-25T14:06:02Z")

</div>

Ok, so I think that explains it. We look for history files in the “Chrome/User Data/Default” folder which doesn’t appear to match the format on OSX. If you want to try to process the history file, this should work:

- Browse to it in Autopsy, right-click and select “Extract File(s)” to save it to disk. Copy any other associated database files as well (.wal, etc) since I think they also get read.
- Make a new folder somewhere on your system. Create a subfolder named “Chrome”, then “User Data”, then “Default” to simulate the expected hierarchy. Put your extracted History file(s) in the Default folder.  
 ![historyTestDir](https://global.discourse-cdn.com/free1/uploads/sleuthkit/original/2X/5/5780c0c204b94c6b55b11c46fab426c7d616fa7c.png)
- Add a new logical file data source to your case and add the new folder created in the last step (This would be “HistoryTest” in the screenshot). Run the Recent Activity module. It should try to process the History file.

---

<div class="post-metadata">

**Author:** ![nika](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/nika/32/1574_2.png) [@nika](https://sleuthkit.discourse.group/u/nika)\
**Post date:** [February 25, 2022, 8:32pm UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/12 "2022-02-25T20:32:03Z")

</div>

Well, that is a good work around and does the trick. Thank you very much!

Is adding functionality to read OSX Chrome files something that might be considered?

---

<div class="post-metadata">

**Author:** ![nika](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/nika/32/1574_2.png) [@nika](https://sleuthkit.discourse.group/u/nika)\
**Post date:** [May 18, 2022, 12:42am UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/13 "2022-05-18T00:42:42Z")

</div>

Hello @apriestman @Mark_McKinnon ,

Something new came upon this same topic (thanks again for the previous assistance provided).

It seems that sometimes “Chrome/User Data/Default” doesn’t contain all of the history, etc. data. For instance, I recently found there is a “Profile X” folder, in this case “Chrome/User Data/Profile 1” it contains all the same folders/files/artifacts that “Default” contains. This data did _not_ get picked up by the Recents ingest module.

I figure I could just rename “Profile 1” it to “Default.” But if there is data both in “Default” _and_ in “Profile 1,” it seems this could get messy (in this specific case, there is data in “Default” and in “Profile 1.”

Thanks for your time and assistance.

---

<div class="post-metadata">

**Author:** ![Mark\_McKinnon](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/mark_mckinnon/32/42_2.png) [@Mark\_McKinnon](https://sleuthkit.discourse.group/u/Mark_McKinnon)\
**Post date:** [May 18, 2022, 2:44pm UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/14 "2022-05-18T14:44:22Z")

</div>

Yes, the code will not work for this. Profiles were not taken into consideration. I will make a fix to Autopsy and my Macos RA Module to fix this and get back with you shortly with the fix.

---

<div class="post-metadata">

**Author:** ![nika](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/nika/32/1574_2.png) [@nika](https://sleuthkit.discourse.group/u/nika)\
**Post date:** [May 18, 2022, 4:06pm UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/15 "2022-05-18T16:06:59Z")

</div>

Thank you @Mark_McKinnon. _Very_ appreciated!

And just to ensure I was being clear, I am experiencing the above Profiles issue on Windows. I haven’t run into this on MACOS…yet. Not sure if this is even an issue.

---

<div class="post-metadata">

**Author:** ![Mark\_McKinnon](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/mark_mckinnon/32/42_2.png) [@Mark\_McKinnon](https://sleuthkit.discourse.group/u/Mark_McKinnon)\
**Post date:** [May 18, 2022, 6:36pm UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/16 "2022-05-18T18:36:10Z")

</div>

Yes, that is where I am fixing it first on Autopsy. I will next fix it on my Macos RA NBM plugin as I see that you can also have profiles on Macos as well. I will check to see if this functionality is also on Linux as well.

---

<div class="post-metadata">

**Author:** ![nika](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/nika/32/1574_2.png) [@nika](https://sleuthkit.discourse.group/u/nika)\
**Post date:** [May 18, 2022, 7:31pm UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/17 "2022-05-18T19:31:17Z")

</div>

Thanks for clarifying Mark. Sounds great. In the mean time I renamed “Profile 1” to “Default” and imported it into the project as a separate data source. A bit messy, but it works.

---

<div class="post-metadata">

**Author:** ![Mark\_McKinnon](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/mark_mckinnon/32/42_2.png) [@Mark\_McKinnon](https://sleuthkit.discourse.group/u/Mark_McKinnon)\
**Post date:** [May 18, 2022, 8:34pm UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/18 "2022-05-18T20:34:21Z")

</div>

PR # 7625 has been submitted with the fixes for the Chrome Profiles. I also checked and Linux has the same functionality as well.

---

<div class="post-metadata">

**Author:** ![nika](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/nika/32/1574_2.png) [@nika](https://sleuthkit.discourse.group/u/nika)\
**Post date:** [May 20, 2022, 1:27am UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/19 "2022-05-20T01:27:03Z")

</div>

Thanks Mark.

Not to be a pest, and whenever you get around to the Macos RA NBM, I suppose you’ll DM it to me or do I get it from Github?

---

<div class="post-metadata">

**Author:** ![Mark\_McKinnon](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/mark_mckinnon/32/42_2.png) [@Mark\_McKinnon](https://sleuthkit.discourse.group/u/Mark_McKinnon)\
**Post date:** [May 20, 2022, 2:02am UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/20 "2022-05-20T02:02:22Z")

</div>

I will just reply here and put a version of the NBM out in my repo so you can grab it from there.

---

<div class="post-metadata">

**Author:** ![Fabrice](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/fabrice/32/1520_2.png) [@Fabrice](https://sleuthkit.discourse.group/u/Fabrice)\
**Post date:** [June 17, 2022, 7:14am UTC](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100/21 "2022-06-17T07:14:36Z")

</div>

Hi! Same for me, no infos on a Chrome folder on a W10 image… The location of the database is there :  
\Users\XXXXXX\AppData\Local\Google\Chrome\User Data\System Profile\History  
I did it with DBbrowser, but RA is a real help!  
Is it possible to test some results from the favicons. In a brief we had, we’ve had nice result while history was empty.  
In my office, they have notice that RA get no infos from Brave and Opera. Parsing those two could be very nice.  
Thanx for all the good job!!!

[Next page](https://sleuthkit.discourse.group/t/trouble-chrome-history-recent-activity/3100.md?page=2)
