PuffinSecureBrowser
Author: Andrew Rathbun
Puffin Secure Browser
Paths
Open in CyberChef to decode values extracted from this artifact.
Notes
Puffin is a secure web browser that takes a LOT of work to get set up. If your suspect is using this, they went out of their way to make this their browser of choice. I had to use a credit card/billing address, authorization codes sent to my fake email, sign in multiple times to activate the browser and my membership, etc. It was a pain.
As secure as Puffin claims to be, they store some stuff locally!
Data.db had evidence of tabs I had opened with the browser.
Autocompletes.dat stored some autocomplete data (email, etc) that I entered throughout the setup process.
passwordForms.dat stored the email in plaintext but the password itself is not in plain text.
"subscription" was a file without a file extension (viewable in a text editor) that showed the fake email I used to set up my trial with Puffin.
The image_cache folder will store what appears to be .JPG files but as .ci0 files. I was able to view all the images with IrfanView despite the proprietary file extension.
Collection commands
KAPE, PowerShell, Batch, WSL
Included in collections: SANS_TriageKapeTriageWebBrowsers