如何使用Osquery转换Chrome浏览器历史记录Sqlite时间戳

问题描述 投票:0回答:3

据我了解,Chrome浏览器将WebKit时间格式用于浏览器历史记录数据库中的时间戳。 WebKit时间以自1601年1月以来的毫秒数表示。

我发现了很多文章似乎都可以回答我的问题,但是到目前为止,都没有任何一篇。常见的答案是使用以下公式将WebKit转换为人类可读的本地时间:

SELECT datetime((time/1000000)-11644473600, 'unixepoch', 'localtime') AS time FROM table;

来源:https://linuxsleuthing.blogspot.com/2011/06/decoding-google-chrome-timestamps-in.htmlWhat is the format of Chrome's timestamps?

我正在尝试使用以下配置通过Osquery收集数据时转换时间戳。

"chrome_browser_history" : {
        "query" : "SELECT urls.id id, urls.url url, urls.title title, urls.visit_count visit_count, urls.typed_count typed_count, urls.last_visit_time last_visit_time, urls.hidden hidden, visits.visit_time visit_time, visits.from_visit from_visit, visits.visit_duration visit_duration, visits.transition transition, visit_source.source source FROM urls JOIN visits ON urls.id = visits.url LEFT JOIN visit_source ON visits.id = visit_source.id",
        "path" : "/Users/%/Library/Application Support/Google/Chrome/%/History",
        "columns" : ["path", "id", "url", "title", "visit_count", "typed_count", "last_visit_time", "hidden", "visit_time", "visit_duration", "source"],
        "platform" : "darwin"
    }

"schedule": {
    "chrome_history": {
    "query": "select distinct url,datetime((last_visit_time/1000000)-11644473600, 'unixepoch', 'localtime') AS time from chrome_browser_history where url like '%nhl.com%';",
    "interval": 10
    }
}

结果事件具有从1600年开始的时间戳:

"time":"1600-12-31 18:46:16"

如果更改配置以不进行转换就提取原始时间戳,则会得到如下图章:

"last_visit_time":"1793021894"

根据我对WebKit时间的了解,它以17位数字表示,这显然不是我所看到的。因此,我目前不确定这是Osquery,Chrome还是查询问题。感谢所有帮助和见识!

sqlite google-chrome webkit datetime-conversion osquery
3个回答
1
投票

尝试:

SELECT datetime(last_visit_time/1000000-11644473600, \"unixepoch\") as last_visited, url, title, visit_count FROM urls;

这是我前一段时间写的东西-一种带有ATC配置的运行osqueryi以读取chrome历史记录文件,导出为json并将json卷曲到API端点的单行代码

https://gist.github.com/defensivedepth/6b79581a9739fa316b6f6d9f97baab1f


0
投票

您正在使用的东西是非常直的sqlite。因此,我将从在sqlit中进行调试开始。

首先,您应该验证数据是否符合您的期望。在我的机器上,我看到:

$ cp   Library/Application\ Support/Google/Chrome/Profile\ 1/History /tmp/
$ sqlite3 /tmp/History "select last_visit_time from urls limit 2"
13231352154237916
13231352154237916

第二,我将验证基础数学:

sqlite> select datetime(last_visit_time/1000000-11644473600, "unixepoch") from urls limit 2;
2020-04-14 15:35:54
2020-04-14 15:35:54

如果您将配置代码段包含为文本,我们可以复制/粘贴,则测试它会更容易。


0
投票

已解决。日期时间转换需要在表定义查询中进行。

"chrome_browser_history" : {
        "query" : "SELECT urls.id id, urls.url url, urls.title title, urls.visit_count visit_count, urls.typed_count typed_count, datetime(urls.last_visit_time/1000000-11644473600, 'unixepoch') last_visit_time, urls.hidden hidden, visits.visit_time visit_time, visits.from_visit from_visit, visits.visit_duration visit_duration, visits.transition transition, visit_source.source source FROM urls JOIN visits ON urls.id = visits.url LEFT JOIN visit_source ON visits.id = visit_source.id",
        "path" : "/Users/%/Library/Application Support/Google/Chrome/%/History",
        "columns" : ["path", "id", "url", "title", "visit_count", "typed_count", "last_visit_time", "hidden", "visit_time", "visit_duration", "source"],
        "platform" : "darwin"
    }

"schedule": {
    "chrome_history": {
    "query": "select distinct url,last_visit_time from chrome_browser_history where url like '%nhl.com%';",
    "interval": 10
    }
}

[尝试在osquery计划的查询中进行转换(就像我之前尝试的那样)将不起作用。即:

"schedule": {
"chrome_history": {
"query": "select distinct url,datetime((last_visit_time/1000000)-11644473600, 'unixepoch', 'localtime') AS time from chrome_browser_history where url like '%nhl.com%';",
"interval": 10
}

}

© www.soinside.com 2019 - 2024. All rights reserved.