SKIP TO CONTENT
NETWORK AND REMOTE ACTIVITY31 / 36

Browser History, Cache and Downloads

Also called Chrome History database, places.sqlite, browser forensics, download history, web cache.

PLATFORM
Cross-platform
CATEGORY
Network and Remote Activity
INDEX
31 of 36
PROVES
5 findings
CANNOT PROVE
6 limits
QUESTIONS
4 answered
WHAT IT IS

Per-profile databases recording pages visited with timestamps and transition types, files downloaded with their source URLs and target paths, and cached copies of retrieved content.

Where it lives

Per-profile databases: Chrome and Edge keep History and related SQLite files under the user data directory; Firefox keeps places.sqlite in the profile folder. Cache is stored alongside in each browser's own format.

Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of browser history, cache and downloads” is neither.

What it records

History databases store one row per URL and one per visit, with a timestamp and a transition type distinguishing a typed address from a followed link, a redirect, or a form submission. Download records hold the source URL, the redirect chain, the local target path, the byte count and the start and end times. The cache holds copies of retrieved resources, sometimes including documents and images that exist nowhere else on the machine. Chrome-family browsers expire visit history at a default age, which is why a matter preserved late finds a truncated record.

What it proves — and what it cannot

These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.

What it proves

FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.

  • That a URL was requested from this profile at a recorded time, and how it was reached
  • That a file was downloaded, from where, to what local path, and how large it was — download records are among the most quantitative artifacts on an endpoint
  • Access to personal webmail, file-sharing and upload endpoints, timestamped so it can be aligned against file-access records
  • Content of retrieved pages and documents from the cache, after the site has changed or the file has been deleted
  • Search terms passed in query strings, which frequently survive even when the search provider's own records do not

What it cannot prove

INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.

  • That the visit happened on this device. Where profile sync is enabled, history from the user's other signed-in devices is written into the local database, so a row can describe a phone or a home computer — separating synced from local rows is mandatory before attribution
  • That a person requested the page. Redirects, prefetching, embedded resources and scripts create visit rows nobody chose, which is why the transition type field matters
  • That anything was read or understood. A visit records a request, not attention or comprehension
  • That a download reached its destination intact or was ever opened. The record marks the transfer, not the use
  • That the absence of history means no browsing. Chrome-family browsers expire visits at a default age, private browsing writes nothing, and clearing history is a two-click operation
  • Which human used the profile, as against anyone with access to the signed-in session

How the finding is attacked

An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.

  • Identifying rows that arrived through profile sync from another device and were reported as local activity
  • Using transition types to show a visit was a redirect or an embedded request rather than a deliberate navigation
  • Establishing the default history expiry and showing the examiner's window extends past what the browser retained
  • Pointing to shared profiles, shared machines, or a session left signed in

What survives, and for how long

History in Chrome-family browsers is expired at a default age measured in months, so a late preservation finds a truncated record rather than a complete one; Firefox prunes on a size basis instead. Cache is evicted continuously by size. Downloads records generally persist as long as the history database does, and clearing browsing data removes everything in a single step.

More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.

Questions counsel ask

Can browser history come from a different device?

Yes, and it is the mistake most worth checking in any browser-history opinion. Where the user signed into the browser and sync was enabled, visits made on their other devices are written into the local profile database. A row in the History file on a work laptop may describe a phone or a home computer, so rows have to be separated by originating device before anything is attributed to the machine in evidence.

How long does Chrome keep browsing history?

Chrome-family browsers expire visit records at a default age measured in months, so history is not an indefinite archive even where nobody cleared it. Downloads records and other data may persist differently. In practice this means preservation timing determines how far back a browser can speak, and an examination begun a year after the conduct will find the earlier period already gone.

Do download records prove a file was taken?

They prove a transfer occurred: the source URL, the redirect chain, the local target path, the byte count and the timing. That is unusually quantitative for an endpoint artifact. What they do not prove is that the file was opened, kept, or moved anywhere afterwards, and where the download was of the party's own material from a sanctioned system the record is equally consistent with ordinary work.

Does private browsing leave any trace?

Not in the history database, which is the point of the mode. Traces may survive elsewhere — in memory captured in the pagefile or a hibernation file, in network-level records held by the employer, in per-application transfer volumes recorded by SRUM, and in DNS or proxy logs. None of those are guaranteed, and an absence of browser history proves nothing about whether browsing occurred.

Terms used on this page

Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.

No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.

A FINDING ON THIS ARTIFACT

Whether the browser history, cache and downloadsevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

  • Can This Artifact Prove That?

    Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.

  • Computer forensics

    The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.

  • The artifact index

    All 36 entries, grouped by what they bear on and filterable by platform.

  • Daubert and digital evidence

    Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.

← BACK TO THE ARTIFACT INDEX

Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.