dfIndexeddb
dfindexeddb is an experimental Python tool for performing digital forensic analysis of IndexedDB and leveldb files.
It parses leveldb, IndexedDB and javascript structures from these files without requiring native libraries.
The content of IndexedDB files is dependent on what a web application stores locally/offline using the web browser's IndexedDB API. Examples of content might include:
- text from a text/source-code editor application,
- emails and contact information from an e-mail application,
- images and metadata from a photo gallery application
Installation
$ pip install dfindexeddb
Installation from source
Linux
- Install the snappy compression development package
$ sudo apt install libsnappy-dev
-
Clone or download the repository to your local machine.
-
Create a virutal environemnt and install the package
$ python3 -m venv .venv
$ source .venv/bin/activate
$ pip install .
Usage
A CLI tool is available after installation:
$ dfindexeddb -h
usage: dfindexeddb [-h] -s SOURCE [--json] {log,ldb,indexeddb} ...
A cli tool for the dfindexeddb package
positional arguments:
{log,ldb,indexeddb}
options:
-s SOURCE, --source SOURCE
The source leveldb file
--json Output as JSON
To parse a LevelDB .log file:
$ dfindexeddb -s <SOURCE> log -h
usage: dfindexeddb log [-h] {blocks,physical_records,write_batches,parsed_internal_key,records}
positional arguments:
{blocks,physical_records,write_batches,parsed_internal_key,records}
options:
-h, --help show this help message and exit
To parse a LevelDB .ldb file:
$ dfindexeddb -s <SOURCE> ldb -h
usage: dfindexeddb ldb [-h] {blocks,records}
positional arguments:
{blocks,records}
options:
-h, --help show this help message and exit
To parse a LevelDB .ldb or .log file as IndexedDB:
$ dfindexeddb -s <SOURCE> indexeddb -h
usage: dfindexeddb indexeddb [-h]
options:
-h, --help show this help message and exit
Metadata
Release files for dfindexeddb 20240305
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| dfindexeddb-20240305.tar.gz | 35.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| dfindexeddb-20240305-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 79.2 kB
Release files / dfindexeddb-20240305.tar.gz
| Download URL | dfindexeddb-20240305.tar.gz |
|---|---|
| Size | 35.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6a46ec439640dd4328f6b6413547ba1bb7dba8b3f47ed03f11db57ff2e0175c1
|
|
BLAKE2b-256 checksum How to use checksums |
74e37b9f79f182133e04a1f76cc6ba02a25aafc81b398a0f673cd933dbd8a454
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/4.0.2 CPython/3.11.8
|
Release files / dfindexeddb-20240305-py3-none-any.whl
| Download URL | dfindexeddb-20240305-py3-none-any.whl |
|---|---|
| Size | 44.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
66ec380771037992f325ae9f6c7132da19d27f4c9bae807802e81b6617b0bb0b
|
|
BLAKE2b-256 checksum How to use checksums |
5402ad92dad8cb1c75d528b00d53b376ce3424b76d2f9bf9d7a53b1917b4b1c7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/4.0.2 CPython/3.11.8
|