Skip to main content

dfIndexeddb

dfindexeddb is an experimental Python tool for performing digital forensic analysis of IndexedDB and leveldb files.

It parses leveldb, IndexedDB and javascript structures from these files without requiring native libraries.

The content of IndexedDB files is dependent on what a web application stores locally/offline using the web browser's IndexedDB API. Examples of content might include:

  • text from a text/source-code editor application,
  • emails and contact information from an e-mail application,
  • images and metadata from a photo gallery application

Installation

$ pip install dfindexeddb

Installation from source

Linux

  1. Install the snappy compression development package
    $ sudo apt install libsnappy-dev
  1. Clone or download the repository to your local machine.

  2. Create a virutal environemnt and install the package

    $ python3 -m venv .venv
    $ source .venv/bin/activate
    $ pip install .

Usage

A CLI tool is available after installation:

$ dfindexeddb -h
usage: dfindexeddb [-h] -s SOURCE [--json] {log,ldb,indexeddb} ...

A cli tool for the dfindexeddb package

positional arguments:
  {log,ldb,indexeddb}

options:
  -s SOURCE, --source SOURCE
                        The source leveldb file
  --json                Output as JSON

To parse a LevelDB .log file:

$ dfindexeddb -s <SOURCE> log -h
usage: dfindexeddb log [-h] {blocks,physical_records,write_batches,parsed_internal_key,records}

positional arguments:
  {blocks,physical_records,write_batches,parsed_internal_key,records}

options:
  -h, --help            show this help message and exit

To parse a LevelDB .ldb file:

$ dfindexeddb -s <SOURCE> ldb -h
usage: dfindexeddb ldb [-h] {blocks,records}

positional arguments:
  {blocks,records}

options:
  -h, --help        show this help message and exit

To parse a LevelDB .ldb or .log file as IndexedDB:

$ dfindexeddb -s <SOURCE> indexeddb -h
usage: dfindexeddb indexeddb [-h]

options:
  -h, --help  show this help message and exit

Metadata

Release files for dfindexeddb 20240305

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dfindexeddb 20240305
File Size Uploaded
dfindexeddb-20240305.tar.gz 35.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for dfindexeddb 20240305
File Interpreter ABI Platform
dfindexeddb-20240305-py3-none-any.whl Python 3 none any Details

Total release size: 79.2 kB

Release files / dfindexeddb-20240305.tar.gz

Download URL dfindexeddb-20240305.tar.gz
Size 35.2 kB
Tags Source
SHA-256 checksum
How to use checksums
6a46ec439640dd4328f6b6413547ba1bb7dba8b3f47ed03f11db57ff2e0175c1
BLAKE2b-256 checksum
How to use checksums
74e37b9f79f182133e04a1f76cc6ba02a25aafc81b398a0f673cd933dbd8a454
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/4.0.2 CPython/3.11.8

Release files / dfindexeddb-20240305-py3-none-any.whl

Download URL dfindexeddb-20240305-py3-none-any.whl
Size 44.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
66ec380771037992f325ae9f6c7132da19d27f4c9bae807802e81b6617b0bb0b
BLAKE2b-256 checksum
How to use checksums
5402ad92dad8cb1c75d528b00d53b376ce3424b76d2f9bf9d7a53b1917b4b1c7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/4.0.2 CPython/3.11.8
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page