Browser History, Cache and Downloads
Also called Chrome History database, places.sqlite, browser forensics, download history, web cache.
- PLATFORM
- Cross-platform
- CATEGORY
- Network and Remote Activity
- INDEX
- 31 of 36
- PROVES
- 5 findings
- CANNOT PROVE
- 6 limits
- QUESTIONS
- 4 answered
Per-profile databases recording pages visited with timestamps and transition types, files downloaded with their source URLs and target paths, and cached copies of retrieved content.
Where it lives
Per-profile databases: Chrome and Edge keep History and related SQLite files under the user data directory; Firefox keeps places.sqlite in the profile folder. Cache is stored alongside in each browser's own format.
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of browser history, cache and downloads” is neither.
What it records
History databases store one row per URL and one per visit, with a timestamp and a transition type distinguishing a typed address from a followed link, a redirect, or a form submission. Download records hold the source URL, the redirect chain, the local target path, the byte count and the start and end times. The cache holds copies of retrieved resources, sometimes including documents and images that exist nowhere else on the machine. Chrome-family browsers expire visit history at a default age, which is why a matter preserved late finds a truncated record.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- That a URL was requested from this profile at a recorded time, and how it was reached
- That a file was downloaded, from where, to what local path, and how large it was — download records are among the most quantitative artifacts on an endpoint
- Access to personal webmail, file-sharing and upload endpoints, timestamped so it can be aligned against file-access records
- Content of retrieved pages and documents from the cache, after the site has changed or the file has been deleted
- Search terms passed in query strings, which frequently survive even when the search provider's own records do not
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- That the visit happened on this device. Where profile sync is enabled, history from the user's other signed-in devices is written into the local database, so a row can describe a phone or a home computer — separating synced from local rows is mandatory before attribution
- That a person requested the page. Redirects, prefetching, embedded resources and scripts create visit rows nobody chose, which is why the transition type field matters
- That anything was read or understood. A visit records a request, not attention or comprehension
- That a download reached its destination intact or was ever opened. The record marks the transfer, not the use
- That the absence of history means no browsing. Chrome-family browsers expire visits at a default age, private browsing writes nothing, and clearing history is a two-click operation
- Which human used the profile, as against anyone with access to the signed-in session
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Identifying rows that arrived through profile sync from another device and were reported as local activity
- Using transition types to show a visit was a redirect or an embedded request rather than a deliberate navigation
- Establishing the default history expiry and showing the examiner's window extends past what the browser retained
- Pointing to shared profiles, shared machines, or a session left signed in
What survives, and for how long
History in Chrome-family browsers is expired at a default age measured in months, so a late preservation finds a truncated record rather than a complete one; Firefox prunes on a size basis instead. Cache is evicted continuously by size. Downloads records generally persist as long as the history database does, and clearing browsing data removes everything in a single step.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
Can browser history come from a different device?
Yes, and it is the mistake most worth checking in any browser-history opinion. Where the user signed into the browser and sync was enabled, visits made on their other devices are written into the local profile database. A row in the History file on a work laptop may describe a phone or a home computer, so rows have to be separated by originating device before anything is attributed to the machine in evidence.
How long does Chrome keep browsing history?
Chrome-family browsers expire visit records at a default age measured in months, so history is not an indefinite archive even where nobody cleared it. Downloads records and other data may persist differently. In practice this means preservation timing determines how far back a browser can speak, and an examination begun a year after the conduct will find the earlier period already gone.
Do download records prove a file was taken?
They prove a transfer occurred: the source URL, the redirect chain, the local target path, the byte count and the timing. That is unusually quantitative for an endpoint artifact. What they do not prove is that the file was opened, kept, or moved anywhere afterwards, and where the download was of the party's own material from a sanctioned system the record is equally consistent with ordinary work.
Does private browsing leave any trace?
Not in the history database, which is the point of the mode. Traces may survive elsewhere — in memory captured in the pagefile or a hibernation file, in network-level records held by the employer, in per-application transfer volumes recorded by SRUM, and in DNS or proxy logs. None of those are guaranteed, and an absence of browser history proves nothing about whether browsing occurred.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
LSQuarantine
A per-user macOS database recording files downloaded by quarantine-aware applications, with the source URL, the downloading application, and a timestamp for each event.
SRUM (System Resource Usage Monitor)
A Windows database attributing network bytes sent and received, and application foreground time, to individual programs and user accounts in hourly buckets.
OneDrive Sync Artifacts
Client-side logs and databases recording which files the OneDrive client synchronised, when, and in which direction — including files that were only ever placeholders locally.
Windows Search Index and WordWheelQuery
The desktop search database indexes file properties and, for many file types, full text — so it can retain the content of documents that were deleted before the index was rebuilt.
Whether the browser history, cache and downloadsevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.