dfIndexeddb
dfindexeddb is an experimental Python tool for performing digital forensic analysis of IndexedDB and leveldb files.
It parses leveldb, IndexedDB and javascript structures from these files without requiring native libraries. (Note: only a subset of IndexedDB key types and Javascript types for Chromium-based browsers are currently supported. Safari and Firefox are under development).
The content of IndexedDB files is dependent on what a web application stores locally/offline using the web browser's IndexedDB API. Examples of content might include:
- text from a text/source-code editor application,
- emails and contact information from an e-mail application,
- images and metadata from a photo gallery application
Installation
- [Linux] Install the snappy compression development package
$ sudo apt install libsnappy-dev
- Create a virtual environment and install the package
$ python3 -m venv .venv
$ source .venv/bin/activate
$ pip install dfindexeddb
Installation from source
- [Linux] Install the snappy compression development package
$ sudo apt install libsnappy-dev
-
Clone or download/unzip the repository to your local machine.
-
Create a virtual environment and install the package
$ python3 -m venv .venv
$ source .venv/bin/activate
$ pip install .
Usage
Two CLI tools for parsing IndexedDB/leveldb files are available after installation:
IndexedDB
$ dfindexeddb -h
usage: dfindexeddb [-h] -s SOURCE [--json]
A cli tool for parsing indexeddb files
options:
-h, --help show this help message and exit
-s SOURCE, --source SOURCE
The source leveldb folder
--json Output as JSON
LevelDB
$ dfleveldb -h
usage: dfleveldb [-h] {db,log,ldb,descriptor} ...
A cli tool for parsing leveldb files
positional arguments:
{db,log,ldb,descriptor}
db Parse a directory as leveldb.
log Parse a leveldb log file.
ldb Parse a leveldb table (.ldb) file.
descriptor Parse a leveldb descriptor (MANIFEST) file.
options:
-h, --help show this help message and exit
To parse records from a LevelDB log (.log) file, use the following command:
$ dfleveldb log -s <SOURCE> [--json]
To parse records from a LevelDB table (.ldb) file, use the following command:
$ dfleveldb ldb -s <SOURCE> [--json]
To parse version edit records from a Descriptor (MANIFEST) file:
$ dfleveldb descriptor -s <SOURCE> [--json]
Metadata
Release files for dfindexeddb 20240324
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| dfindexeddb-20240324.tar.gz | 37.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| dfindexeddb-20240324-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 86.2 kB
Release files / dfindexeddb-20240324.tar.gz
| Download URL | dfindexeddb-20240324.tar.gz |
|---|---|
| Size | 37.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5b9de1b2c2c1ce74d2c189c344c5c4caf0c3266e139bd5e67affcc6469c1b0d1
|
|
BLAKE2b-256 checksum How to use checksums |
425b7008d9723c5510515007c4ef4207b03db8554723f09c5bc6966822a65cbf
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/5.0.0 CPython/3.12.2
|
Release files / dfindexeddb-20240324-py3-none-any.whl
| Download URL | dfindexeddb-20240324-py3-none-any.whl |
|---|---|
| Size | 48.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c02990cca3b5b6f515c8f016fa5e66e7c6816445e7f079ebce447f14dea9765e
|
|
BLAKE2b-256 checksum How to use checksums |
bba0a0a3f8a5f0580da1d48464fc9d815d34e69cbbe052e08d9ef7e7e8234b2a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/5.0.0 CPython/3.12.2
|