What browsers does Sherlock Forensics Browser Viewer support?
Sherlock Forensics Browser Viewer supports Chrome, Edge, Firefox, Brave, Opera, Opera GX, Vivaldi and Tor. It auto-detects every installed browser and all profiles on the system.
Does it work while the browser is open?
Yes. Sherlock Forensics Browser Viewer copies browser databases to a temporary file before reading them. This means it works while browsers are running and never locks or interferes with active browser sessions.
Is the analysis read-only and forensically sound?
Yes. The tool copies browser databases to a temp location and reads only from the copy. The original browser data files are never modified. This preserves forensic integrity and ensures the source evidence remains unaltered.
What artifacts does it extract?
Sixteen artifact categories: history, bookmarks, downloads, extensions, sessions, saved forms and autofill, tab state, deep browser storage, caches, per-site permissions, hardware and network cache. Saved forms include stored card metadata such as expiry and cardholder name, never the card number. Saved-credential records expose the username, origin and the created and last-used dates, never the password itself. Deep storage surfaces IndexedDB, local storage and session storage, with the AI chat service records flagged. It also recovers deleted history, cookies, web data and login records from SQLite freelist pages and write-ahead logs.
Does it extract cookies or saved passwords?
Yes, with a forensic boundary. Version 2.2.0 extracts cookies and web-data records and reads saved-credential metadata: the username, origin and the created and last-used dates. The encrypted password blob itself is never read or decrypted. Saved-card metadata such as expiry and cardholder name is read, never the card number.
Does my data stay local?
Yes. Sherlock Forensics Browser Viewer runs entirely on your local machine. No browser data is transmitted to any server. All analysis happens locally on your workstation.
What is the difference between Free and Forensic Edition?
The Free edition previews half the rows of every artifact table, with the hidden count shown. It includes search, filter and sort across all detected browsers and profiles. The Forensic Edition at $49 USD unlocks the complete data set, adds CSV export of any filtered tab and a report panel to mark findings across tabs and export them as one CSV.
Does it support Tor Browser?
Yes. Sherlock Forensics Browser Viewer detects and extracts artifacts from Tor Browser installations. This includes browsing history, bookmarks, downloads and extensions stored locally by the Tor Browser.
Does Sherlock Forensics Browser Viewer work on Linux?
No. Version 2.2.0 is a Windows 10 and 11 application. The earlier native Linux build is not compatible with the 2.2.0 rewrite and has been withdrawn. A tested Linux build may return in a future release.
What is browser forensics?
Browser forensics is the discipline of extracting and analyzing browsing artifacts (history, bookmarks, downloads, extensions, cookies, cache, session data) as digital evidence. It supports HR investigations, civil and criminal litigation e-discovery, incident response, internal investigations and compliance audits. Sherlock Forensics Browser Viewer performs read-only browser forensics across 8 browsers (Chrome, Edge, Firefox, Brave, Opera, Opera GX, Vivaldi, Tor) with optional CSV export at $49 for forensic reports.
Can I recover deleted browser history with Sherlock Forensics Browser Viewer?
Yes, within the browser's own databases. Version 2.2.0 carves deleted history, cookies, web data and login records out of the SQLite freelist pages and the write-ahead log, so activity a user recently cleared is often still recoverable. Records lost to a full database vacuum or overwritten on disk are beyond that and need unallocated-page carving against a disk image: Sherlock Forensics Disk Imager handles the acquisition and we offer the disk-image-carving service separately.
Can Sherlock Forensics Browser Viewer extract incognito browsing history?
Not from disk alone. Chrome incognito, Edge InPrivate, Firefox private browsing and Brave private windows are designed to not persist incognito history to local storage. Sherlock reads the disk-persisted state, so by design it will not surface incognito history from a normal profile read. Incognito history can sometimes be reconstructed from DNS cache, browser cache leaks under crash recovery, network logs, OS prefetch and RAM dumps. Sherlock covers the disk side; pair with memory forensics for the full private browsing timeline.
How is Sherlock Forensics Browser Viewer different from Nirsoft BrowsingHistoryView?
Nirsoft BrowsingHistoryView is the long-standing free Windows-only browsing history view utility. It enumerates browser history records but offers no chain of custody manifest, no Tor Browser support, no deleted-record recovery and no unified browser timeline across the Chromium and Gecko families. Sherlock Forensics Browser Viewer is the Nirsoft alternative built for forensic-grade work: sixteen artifact categories, deleted-record recovery from SQLite freelist and WAL, Tor Browser support, chain of custody manifest in the Forensic Edition, unified cross-browser timeline normalization and the full $49 CSV export pipeline for legal evidence.
What browser data can be used as evidence in HR investigations?
In an HR investigation browser review, the high-signal artifacts are visited URLs, search queries, downloaded files, browser session data, form-fill records and the browser timeline reconstruction. Visited URLs prove navigation, search queries reveal intent, downloads document data exfiltration, the browser timeline anchors when activity occurred. Sherlock Forensics Browser Viewer extracts all of these read-only and exports them via the Forensic Edition CSV. The full operational playbook is in our browser history evidence in HR investigation guide.
Does Sherlock Forensics Browser Viewer work on Mac or Linux?
Version 2.2.0 ships as a Windows x64 native binary for Windows 10 and 11. macOS and Linux are not currently supported. For macOS or Linux browser forensics today, the Sherlock workflow is to acquire the browser profiles via a forensic disk image and analyze them on a Windows machine.
Can I extract browser history from a forensic disk image?
Yes, indirectly. Sherlock Forensics Browser Viewer reads from a live filesystem path, so the standard workflow is to mount the forensic disk image read-only (using OSFMount, FTK Imager, Linux losetup or similar) and point Sherlock at the mounted profile path. The tool then enumerates chrome history, firefox history, edge history, bookmarks, downloads and extensions exactly as it would on a live system, with the disk image acting as the read-only source.
How long does Chrome, Firefox or Edge keep deleted browsing history?
Once a user clicks "Clear browsing data" the live records are removed from the SQLite urls and visits tables. After that point the records sit as unallocated SQLite pages until the database is vacuumed or the underlying storage is overwritten. The retention window is not deterministic and varies by browser-version, configured profile size and user activity since the deletion. Sherlock Forensics Browser Viewer 2.2.0 carves deleted rows from the SQLite freelist pages and the write-ahead log, recovering many recently-deleted records before a vacuum. Records lost to a full vacuum or overwritten on disk need unallocated-page carving against a forensic disk image and the carving service.