Skip to main content

dfindexeddb is an experimental Python tool for performing digital forensic analysis of IndexedDB and leveldb files.

Project description

dfIndexeddb

dfindexeddb is an experimental Python tool for performing digital forensic analysis of IndexedDB and leveldb files.

It parses leveldb, IndexedDB and javascript structures from these files without requiring native libraries. (Note: only a subset of IndexedDB key types and Javascript types for Chromium-based browsers are currently supported. Safari and Firefox are under development).

The content of IndexedDB files is dependent on what a web application stores locally/offline using the web browser's IndexedDB API. Examples of content might include:

  • text from a text/source-code editor application,
  • emails and contact information from an e-mail application,
  • images and metadata from a photo gallery application

Installation

  1. [Linux] Install the snappy compression development package
    $ sudo apt install libsnappy-dev
  1. Create a virtual environment and install the package
    $ python3 -m venv .venv
    $ source .venv/bin/activate
    $ pip install dfindexeddb

Installation from source

  1. [Linux] Install the snappy compression development package
    $ sudo apt install libsnappy-dev
  1. Clone or download/unzip the repository to your local machine.

  2. Create a virtual environment and install the package

    $ python3 -m venv .venv
    $ source .venv/bin/activate
    $ pip install .

Usage

Two CLI tools for parsing IndexedDB/leveldb files are available after installation:

IndexedDB

$ dfindexeddb -h
usage: dfindexeddb [-h] -s SOURCE [--json]

A cli tool for parsing indexeddb files

options:
  -h, --help            show this help message and exit
  -s SOURCE, --source SOURCE
                        The source leveldb folder
  --json                Output as JSON

LevelDB

$ dfleveldb -h
usage: dfleveldb [-h] {db,log,ldb,descriptor} ...

A cli tool for parsing leveldb files

positional arguments:
  {db,log,ldb,descriptor}
    db                  Parse a directory as leveldb.
    log                 Parse a leveldb log file.
    ldb                 Parse a leveldb table (.ldb) file.
    descriptor          Parse a leveldb descriptor (MANIFEST) file.

options:
  -h, --help            show this help message and exit

To parse records from a LevelDB log (.log) file, use the following command:

$ dfleveldb log -s <SOURCE> [--json]

To parse records from a LevelDB table (.ldb) file, use the following command:

$ dfleveldb ldb -s <SOURCE> [--json]

To parse version edit records from a Descriptor (MANIFEST) file:

$ dfleveldb descriptor -s <SOURCE> [--json]

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

dfindexeddb-20240324.tar.gz (37.5 kB view details)

Uploaded Source

Built Distribution

dfindexeddb-20240324-py3-none-any.whl (48.7 kB view details)

Uploaded Python 3

File details

Details for the file dfindexeddb-20240324.tar.gz.

File metadata

  • Download URL: dfindexeddb-20240324.tar.gz
  • Upload date:
  • Size: 37.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/5.0.0 CPython/3.12.2

File hashes

Hashes for dfindexeddb-20240324.tar.gz
Algorithm Hash digest
SHA256 5b9de1b2c2c1ce74d2c189c344c5c4caf0c3266e139bd5e67affcc6469c1b0d1
MD5 522cc178b669d3bb6d2373975e103a47
BLAKE2b-256 425b7008d9723c5510515007c4ef4207b03db8554723f09c5bc6966822a65cbf

See more details on using hashes here.

File details

Details for the file dfindexeddb-20240324-py3-none-any.whl.

File metadata

File hashes

Hashes for dfindexeddb-20240324-py3-none-any.whl
Algorithm Hash digest
SHA256 c02990cca3b5b6f515c8f016fa5e66e7c6816445e7f079ebce447f14dea9765e
MD5 996e1ef9b6566ecdeda8f11a56f42672
BLAKE2b-256 bba0a0a3f8a5f0580da1d48464fc9d815d34e69cbbe052e08d9ef7e7e8234b2a

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page