Introduction
Mozilla Firefox is one of the world’s most widely used web browsers. It is a free and open-source browser developed by the Mozilla Foundation and its subsidiary, mozilla.org.
Firefox is known for its strong focus on privacy, security, customization, and adherence to open web standards. It is available on multiple platforms including Windows, macOS, Linux, Android, and iOS.
From a digital forensics perspective, Firefox can contain significant evidential data relating to a user’s online activities, making it an important source during forensic investigations.
History of Mozilla Firefox
Firefox originated from the Mozilla project, which was created after Netscape Communications released the source code of its browser suite in 1998.
Key milestones include:
2002 – Phoenix – The browser was initially released under the name Phoenix. The name was later changed due to trademark issues.
2003 – Firebird – Phoenix was renamed Firebird, but further trademark conflicts required another name change.
2004 – Firefox Launch – Firefox 1.0 was officially released in November 2004. It quickly gained popularity as an alternative to Internet Explorer due to its improved security and tabbed browsing features.
2008 – Firefox 3 – Firefox 3 introduced performance improvements and achieved a Guinness World Record for the most software downloads within 24 hours.
2017 – Firefox Quantum – Firefox Quantum represented a major redesign, providing substantial speed improvements and enhanced memory management.
Present Day
Firefox continues to evolve with features such as Enhanced Tracking Protection, DNS-over-HTTPS, container tabs, and advanced privacy controls.
Mozilla Firefox in Digital Forensics
Firefox stores a large amount of user activity locally on a device. During forensic examinations, investigators can analyse browser artefacts to reconstruct user behaviour, internet usage, and online interactions.
Potential evidence includes:
- Websites visited
- Search engine queries
- Downloaded files
- Saved passwords
- Cookies
- Bookmarks
- Session information
- Form data
- Login history
- Browser extensions
- Cached content
Key Firefox Forensic Artefacts
Places.sqlite
One of the most important Firefox databases.
Location (Windows): C:\Users\<User>\AppData\Roaming\Mozilla\Firefox\Profiles\<Profile>\
Contains:
- Browsing history
- Bookmark records
- Visit timestamps
- URL information
This SQLite database is often the primary source for reconstructing web activity.
Cookies.sqlite
Stores website cookies.
Contains:
- Authentication tokens
- User preferences
- Session identifiers
- Website tracking information
Cookies may demonstrate that a user accessed a particular website or account.
Formhistory.sqlite
Contains information entered into web forms.
Examples include:
- Search terms
- Usernames
- Addresses
- Other autofill entries
This artefact may reveal information that was typed by a user even when browsing history has been deleted.
Logins.json
Stores saved usernames and passwords.
Contains:
- Saved website credentials
- Login URLs
- Encryption metadata
Passwords are encrypted but may be recoverable when combined with additional Firefox files.
Key4.db
Stores encryption keys used to protect saved passwords.
Investigators often analyse this file alongside:
Logins.json
Together they may enable recovery of stored credentials where lawful and appropriate.
Downloads History
Download activity can be found within:
- Places.sqlite
- Download metadata records
- Evidence may include:
- File names
- Download URLs
- Download times
- Local storage locations
Cache Files
Firefox maintains cached copies of web content.
Location: AppData\Local\Mozilla\Firefox\Profiles\
Cached content may include:
- Images
- HTML pages
- JavaScript files
- Media files
This can provide evidence of websites viewed even when history has been cleared.
Session Restore Files
Firefox maintains session recovery information.
Files include:
- Plain text
- recovery.jsonlz4
- previous.jsonlz4
- These may reveal:
- Open tabs
- Open windows
- Recently viewed websites
- Browser state before shutdown
Bookmark Backups
Firefox periodically creates bookmark backups.
Location: bookmarkbackups\
Investigators may recover:
- Saved bookmarks
- Historical bookmark information
- User interests and browsing habits
Extensions and Add-ons
Firefox stores information about installed browser extensions.
Files include: extensions.json and addons.json
These can reveal:
- Privacy tools
- Cryptocurrency wallets
- Download managers
- Security-related software
- Deleted Firefox Artefacts
Even when a user clears browsing history, forensic analysis may recover evidence from:
- Unallocated disk space
- Volume Shadow Copies
- System backups
- Memory dumps
- Restore points
Artefact recovery depends on device usage and whether data has been overwritten.
Forensic Value of Firefox Artefacts
Firefox artefacts can help investigators:
- Establish internet usage patterns
- Identify websites visited
- Correlate user activity with timelines
- Recover deleted browsing evidence
- Attribute activity to specific user profiles
- Support civil, family, corporate, and criminal investigations
Conclusion
Mozilla Firefox is a widely used privacy-focused web browser that stores extensive information about a user’s online activities.
Key forensic artefacts such as Places.sqlite, Cookies.sqlite, Formhistory.sqlite, Logins.json, and session restore files can provide valuable evidence during digital forensic investigations.
Proper forensic acquisition and analysis of these artefacts can help reconstruct browsing behaviour, establish timelines, and uncover critical digital evidence relevant to legal and investigative proceedings.
About Athena Forensics
For information on our digital forensic services or if you require any advice or assistance please contact a member of our team on 0330 123 4448 or via email on enquiries@athenaforensics.co.uk, further details are available on our contact us page.
Our client’s confidentiality is of the utmost importance. All correspondence is treated with discretion, from initial contact to the conclusion of any computer forensics investigation.
Our digital forensic experts are fully aware of the significance and importance of the information that they encounter and we have been accredited to ISO 9001 for 10 years. Our forensic experts are all security cleared and we offer non-disclosure agreements if required. Our premises along with our security procedures have been inspected and approved by law enforcement agencies.
Athena Forensics do not disclose personal information to other companies or suppliers.