Skip to main content

dfIndexeddb

dfindexeddb is an experimental Python tool for performing digital forensic analysis of IndexedDB and leveldb files.

It parses leveldb, IndexedDB and javascript structures from these files without requiring native libraries.

The content of IndexedDB files is dependent on what a web application stores locally/offline using the web browser's IndexedDB API. Examples of content might include:

  • text from a text/source-code editor application,
  • emails and contact information from an e-mail application,
  • images and metadata from a photo gallery application

Installation from source

Linux

  1. Install the snappy compression development package
    $ sudo apt install libsnappy-dev
  1. Clone or download the repository to your local machine.

  2. Create a virutal environemnt and install the package

    $ python3 -m venv .venv
    $ source .venv/bin/activate
    $ pip install .

Tools

This repository contains a number of scripts which demonstrate how one can use this library. To run these tools, please install the click python package.

  • tools/indexeddb_dump.py - parses structures from an IndexedDB and prints them to standard output.
    • Optionally, you can also install the leveldb python package if you would prefer to use a native leveldb library instead of the leveldb parser in this repository.
  • tools/ldb_dump.py - parses structures from a LevelDB .ldb file and prints them to standard output.
  • tools/log_dump.py - parses structures from a LevelDB .log file and prints them to standard output.
    $ pip install click leveldb

Metadata

Release files for dfindexeddb 20240225

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dfindexeddb 20240225
File Size Uploaded
dfindexeddb-20240225.tar.gz 31.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for dfindexeddb 20240225
File Interpreter ABI Platform
dfindexeddb-20240225-py3-none-any.whl Python 3 none any Details

Total release size: 68.6 kB

Release files / dfindexeddb-20240225.tar.gz

Download URL dfindexeddb-20240225.tar.gz
Size 31.3 kB
Tags Source
SHA-256 checksum
How to use checksums
c11ce1855acb5739a4bb3d906d6b814664453046938cc8bc59ddafbccf2e9a2a
BLAKE2b-256 checksum
How to use checksums
fd27d99d9707c63e41db0cad4fcf1a43e400f3f638a0d4c55ca1d5c9ee3089a6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/4.0.2 CPython/3.11.8

Release files / dfindexeddb-20240225-py3-none-any.whl

Download URL dfindexeddb-20240225-py3-none-any.whl
Size 37.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ed15df5ed3f9188d4064a23c830a6f1226030221563d2536b8dc1fd902ed1b03
BLAKE2b-256 checksum
How to use checksums
3847b054956a7a687765e26a6123fdbe8a4426f5b9e5b020a74908863782bc2c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/4.0.2 CPython/3.11.8
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page