I'm exhausted so if you respond, ill see it tomorrow, but to be clear, when browsing history is reviewed via the browser’s database, it isn’t limited to "just today," it’s everything since the last time history was cleared. That’s how the artifact works, and every analyst who has pulled that file knows it. You can see this yourself, pull your history.db file from Edge/Chrome, and open it in DB Browser for SQLite.
Pair that with the fact Huntress is an EDR + MDR/SOC product: once alerts fire, it’s the SOC’s responsibility to investigate by whatever means are needed (within our ToS and EULA, of course) to scope the incident. Every alert is treated as a potential attack until proven otherwise, and customers receive reports showing exactly what was pulled and remediated.
And honestly, be glad we don’t do what some EDRs do, like full HTTPS traffic decryption with ingestion into the telemetry platform. That’s far more invasive than validating a browser history artifact when alerts fire. 😅