Skip to main content

dfIndexeddb

dfindexeddb is an experimental Python tool for performing digital forensic analysis of IndexedDB and LevelDB files.

It parses LevelDB, IndexedDB and JavaScript structures from these files without requiring native libraries. (Note: only a subset of IndexedDB key types and JavaScript types for Firefox, Safari and Chromium-based browsers are currently supported).

The content of IndexedDB files is dependent on what a web application stores locally/offline using the web browser's IndexedDB API. Examples of content might include:

  • text from a text/source-code editor application,
  • emails and contact information from an e-mail application,
  • images and metadata from a photo gallery application

Installation

  1. [Linux] Install the snappy compression development package
    $ sudo apt install libsnappy-dev
  1. Create a virtual environment and install the package
    $ python3 -m venv .venv
    $ source .venv/bin/activate
    $ pip install dfindexeddb

Optional plugins

To also install the dependencies for leveldb/indexeddb plugins, run

    $ pip install 'dfindexeddb[plugins]'

Installation from source

  1. [Linux] Install the snappy compression development package
    $ sudo apt install libsnappy-dev
  1. Clone or download/unzip the repository to your local machine.

  2. Create a virtual environment and install the package

    $ python3 -m venv .venv
    $ source .venv/bin/activate
    $ pip install .

Optional plugins

To also install the dependencies for leveldb/indexeddb plugins, run

    $ pip install '.[plugins]'

Usage

Two CLI tools for parsing IndexedDB/LevelDB files are available after installation:

IndexedDB

$ dfindexeddb -h
usage: dfindexeddb [-h] {blink,gecko,db,ldb,log} ...

A cli tool for parsing IndexedDB files

positional arguments:
  {blink,gecko,db,ldb,log}
    blink               Parse a file as a blink-encoded value.
    gecko               Parse a file as a gecko-encoded value.
    db                  Parse a directory/file as IndexedDB.
    ldb                 Parse a ldb file as IndexedDB.
    log                 Parse a log file as IndexedDB.

options:
  -h, --help    show this help message and exit

Examples:

Platform / Source Format Command
Firefox (sqlite) JSON dfindexeddb db -s SOURCE --format firefox -o json
Safari (sqlite) JSON-L dfindexeddb db -s SOURCE --format safari -o jsonl
Chrome (LevelDB/sqlite) JSON dfindexeddb db -s SOURCE --format chrome
Chrome (.ldb) JSON-L dfindexeddb ldb -s SOURCE -o jsonl
Chrome (.log) Python repr dfindexeddb log -s SOURCE -o repr
Chrome (Blink) JSON dfindexeddb blink -s SOURCE
Filter Records by key JSON dfindexeddb db -s SOURCE --format chrome --filter_key search_term
Filter Records by value JSON dfindexeddb db -s SOURCE --format chrome --filter_value "search_term"

LevelDB

$ dfleveldb -h
usage: dfleveldb [-h] {db,log,ldb,descriptor} ...

A cli tool for parsing leveldb files

positional arguments:
  {db,log,ldb,descriptor}
    db                  Parse a directory as leveldb.
    log                 Parse a leveldb log file.
    ldb                 Parse a leveldb table (.ldb) file.
    descriptor          Parse a leveldb descriptor (MANIFEST) file.

options:
  -h, --help            show this help message and exit

Examples

Source Type Command
LevelDB Folder Records dfleveldb db -s SOURCE
Log file (.log) Physical Records dfleveldb log -s SOURCE -t physical_records
Log file (.log) Blocks dfleveldb log -s SOURCE -t blocks
Log file (.log) Write Batches dfleveldb log -s SOURCE -t write_batches
Log file (.log) Internal Key Records dfleveldb log -s SOURCE -t parsed_internal_key
Table file (.ldb) Records dfleveldb ldb -s SOURCE -t record
Table file (.ldb) Blocks dfleveldb ldb -s SOURCE -t blocks
Descriptor (MANIFEST) Version Edits dfleveldb descriptor -s SOURCE -t versionedit

Optional Plugins

To apply a plugin parser for a leveldb file/folder, add the --plugin [Plugin Name] argument. Currently, there is support for the following artifacts:

Plugin Name Artifact Name
ChromeNotificationRecord Chrome/Chromium Notifications

Metadata

Release files for dfindexeddb 20260205

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dfindexeddb 20260205
File Size Uploaded
dfindexeddb-20260205.tar.gz 65.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for dfindexeddb 20260205
File Interpreter ABI Platform
dfindexeddb-20260205-py3-none-any.whl Python 3 none any Details

Total release size: 152.3 kB

Release files / dfindexeddb-20260205.tar.gz

Download URL dfindexeddb-20260205.tar.gz
Size 65.4 kB
Tags Source
SHA-256 checksum
How to use checksums
e1351dd1b96f4b48c43f8de7e138c339f87b9dcf23368ddd62f95caa3a633af3
BLAKE2b-256 checksum
How to use checksums
a1abea2830bf057bf44825bd96abfebfe1992c09fc831e2104c154ff735fc589
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Feb 5, 2026.

Transparency log

Release files / dfindexeddb-20260205-py3-none-any.whl

Download URL dfindexeddb-20260205-py3-none-any.whl
Size 86.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
49da12f60f221fe63b994ea8573e276a38fb0e6f85ae8aa3feb758876acafc1d
BLAKE2b-256 checksum
How to use checksums
a3f56fb972c9195add9f38230d2bd1e48a57e29e424c352fa9c14722094a3052
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Feb 5, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page