python-forensics-handbook/ch06_databases.html

329 lines
12 KiB
HTML
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

<!DOCTYPE html>
<html class="writer-html5" lang="en" >
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Chapter 6 - Sqlite &amp; MacOS/Mobile/Browsers &mdash; Python Forensics Handbook 0.1.2 documentation</title>
<link rel="stylesheet" href="_static/css/theme.css" type="text/css" />
<link rel="stylesheet" href="_static/pygments.css" type="text/css" />
<!--[if lt IE 9]>
<script src="_static/js/html5shiv.min.js"></script>
<![endif]-->
<script type="text/javascript" id="documentation_options" data-url_root="./" src="_static/documentation_options.js"></script>
<script src="_static/jquery.js"></script>
<script src="_static/underscore.js"></script>
<script src="_static/doctools.js"></script>
<script src="_static/language_data.js"></script>
<script type="text/javascript" src="_static/js/theme.js"></script>
<link rel="index" title="Index" href="genindex.html" />
<link rel="search" title="Search" href="search.html" />
<link rel="prev" title="Chapter 3 - Windows Event Log Parsing" href="ch03_event_logs.html" />
<!-- Global site tag (gtag.js) - Google Analytics -->
<script async src="https://www.googletagmanager.com/gtag/js?id=UA-17386833-12"></script>
<script>
window.dataLayer = window.dataLayer || [];
function gtag(){dataLayer.push(arguments);}
gtag('js', new Date());
gtag('config', 'UA-17386833-12');
</script>
</head>
<body class="wy-body-for-nav">
<div class="wy-grid-for-nav">
<nav data-toggle="wy-nav-shift" class="wy-nav-side">
<div class="wy-side-scroll">
<div class="wy-side-nav-search" >
<a href="index.html" class="icon icon-home" alt="Documentation Home"> Python Forensics Handbook
</a>
<div class="version">
0.1.2
</div>
<div role="search">
<form id="rtd-search-form" class="wy-form" action="search.html" method="get">
<input type="text" name="q" placeholder="Search docs" />
<input type="hidden" name="check_keywords" value="yes" />
<input type="hidden" name="area" value="default" />
</form>
</div>
</div>
<div class="wy-menu wy-menu-vertical" data-spy="affix" role="navigation" aria-label="main navigation">
<p class="caption"><span class="caption-text">Table of Contents:</span></p>
<ul class="current">
<li class="toctree-l1"><a class="reference internal" href="ch01_essentials.html">Chapter 1 - Essential Scripts</a></li>
<li class="toctree-l1"><a class="reference internal" href="ch02_registry.html">Chapter 2 - Registry Parsing</a></li>
<li class="toctree-l1"><a class="reference internal" href="ch03_event_logs.html">Chapter 3 - Windows Event Log Parsing</a></li>
<li class="toctree-l1 current"><a class="current reference internal" href="#">Chapter 6 - Sqlite &amp; MacOS/Mobile/Browsers</a><ul>
<li class="toctree-l2"><a class="reference internal" href="#module-pyforhandbook.ch06_databases.opening_sqlite">Section 6.1 - Opening Sqlite</a><ul>
<li class="toctree-l3"><a class="reference internal" href="#opening-sqlite-configuration">Opening Sqlite configuration</a></li>
<li class="toctree-l3"><a class="reference internal" href="#listing-tables-configuration">Listing Tables configuration</a></li>
</ul>
</li>
<li class="toctree-l2"><a class="reference internal" href="#indices-and-tables">Indices and tables</a></li>
</ul>
</li>
</ul>
</div>
</div>
</nav>
<section data-toggle="wy-nav-shift" class="wy-nav-content-wrap">
<nav class="wy-nav-top" aria-label="top navigation">
<i data-toggle="wy-nav-top" class="fa fa-bars"></i>
<a href="index.html">Python Forensics Handbook</a>
</nav>
<div class="wy-nav-content">
<div class="rst-content">
<div role="navigation" aria-label="breadcrumbs navigation">
<ul class="wy-breadcrumbs">
<li><a href="index.html" class="icon icon-home"></a> &raquo;</li>
<li>Chapter 6 - Sqlite &amp; MacOS/Mobile/Browsers</li>
<li class="wy-breadcrumbs-aside">
<a href="_sources/ch06_databases.rst.txt" rel="nofollow"> View page source</a>
</li>
</ul>
<hr/>
</div>
<div role="main" class="document" itemscope="itemscope" itemtype="http://schema.org/Article">
<div itemprop="articleBody">
<div class="section" id="chapter-6-sqlite-macos-mobile-browsers">
<h1>Chapter 6 - Sqlite &amp; MacOS/Mobile/Browsers<a class="headerlink" href="#chapter-6-sqlite-macos-mobile-browsers" title="Permalink to this headline"></a></h1>
<div class="toctree-wrapper compound">
</div>
<div class="section" id="module-pyforhandbook.ch06_databases.opening_sqlite">
<span id="section-6-1-opening-sqlite"></span><h2>Section 6.1 - Opening Sqlite<a class="headerlink" href="#module-pyforhandbook.ch06_databases.opening_sqlite" title="Permalink to this headline"></a></h2>
<p>Example for opening and exploring Sqlite databases.</p>
<p>Example Usage:</p>
<blockquote>
<div><p><code class="docutils literal notranslate"><span class="pre">$</span> <span class="pre">python</span> <span class="pre">opening_sqlite.py</span> <span class="pre">history_db</span></code></p>
</div></blockquote>
<p>References:</p>
<ul class="simple">
<li><p><a class="reference external" href="https://docs.python.org/3/library/argparse.html">https://docs.python.org/3/library/argparse.html</a></p></li>
<li><p><a class="reference external" href="https://docs.python.org/3/library/os.html">https://docs.python.org/3/library/os.html</a></p></li>
<li><p><a class="reference external" href="https://docs.python.org/3/library/sqlite3.html">https://docs.python.org/3/library/sqlite3.html</a></p></li>
</ul>
<div class="section" id="opening-sqlite-configuration">
<h3>Opening Sqlite configuration<a class="headerlink" href="#opening-sqlite-configuration" title="Permalink to this headline"></a></h3>
<p>This function shows an example of opening a Sqlite database with Python.
Additional information regarding Sqlite modules can be
seen at <a class="reference external" href="https://docs.python.org/3/library/sqlite3.html">https://docs.python.org/3/library/sqlite3.html</a>.</p>
<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="k">def</span> <span class="nf">open_sqlite</span><span class="p">(</span><span class="n">input_db</span><span class="p">):</span>
<span class="sd">&quot;&quot;&quot;Open a SQLite database</span>
<span class="sd"> Args:</span>
<span class="sd"> input_db: Path to a SQLite database to open</span>
<span class="sd"> Returns:</span>
<span class="sd"> A connection to a SQLite database</span>
<span class="sd"> &quot;&quot;&quot;</span>
<span class="nb">print</span><span class="p">(</span><span class="s2">&quot;Provided Database: </span><span class="si">{}</span><span class="s2">&quot;</span><span class="o">.</span><span class="n">format</span><span class="p">(</span><span class="n">input_db</span><span class="p">))</span>
<span class="k">return</span> <span class="n">sqlite3</span><span class="o">.</span><span class="n">connect</span><span class="p">(</span><span class="n">input_db</span><span class="p">)</span>
</pre></div>
</div>
</div>
<div class="section" id="listing-tables-configuration">
<h3>Listing Tables configuration<a class="headerlink" href="#listing-tables-configuration" title="Permalink to this headline"></a></h3>
<p>This function shows an example of listing available tables in an opened Sqlite
database.</p>
<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="k">def</span> <span class="nf">list_tables</span><span class="p">(</span><span class="n">conn</span><span class="p">):</span>
<span class="sd">&quot;&quot;&quot;List all tables in a SQLite database</span>
<span class="sd"> Args:</span>
<span class="sd"> conn: An open connection from a SQLite database</span>
<span class="sd"> Returns:</span>
<span class="sd"> list: List of table names found in the database</span>
<span class="sd"> &quot;&quot;&quot;</span>
<span class="n">cur</span> <span class="o">=</span> <span class="n">conn</span><span class="o">.</span><span class="n">cursor</span><span class="p">()</span>
<span class="n">cur</span><span class="o">.</span><span class="n">execute</span><span class="p">(</span><span class="s2">&quot;SELECT name FROM sqlite_master&quot;</span><span class="p">)</span>
<span class="k">return</span> <span class="p">[</span><span class="n">i</span><span class="p">[</span><span class="mi">0</span><span class="p">]</span> <span class="k">for</span> <span class="n">i</span> <span class="ow">in</span> <span class="n">cur</span><span class="o">.</span><span class="n">fetchall</span><span class="p">()]</span>
</pre></div>
</div>
<dl class="py function">
<dt id="pyforhandbook.ch06_databases.opening_sqlite.list_tables">
<code class="sig-name descname">list_tables</code><span class="sig-paren">(</span><em class="sig-param"><span class="n">conn</span></em><span class="sig-paren">)</span><a class="headerlink" href="#pyforhandbook.ch06_databases.opening_sqlite.list_tables" title="Permalink to this definition"></a></dt>
<dd><p>List all tables in a SQLite database</p>
<dl class="field-list simple">
<dt class="field-odd">Parameters</dt>
<dd class="field-odd"><p><strong>conn</strong> An open connection from a SQLite database</p>
</dd>
<dt class="field-even">Returns</dt>
<dd class="field-even"><p>List of table names found in the database</p>
</dd>
<dt class="field-odd">Return type</dt>
<dd class="field-odd"><p>list</p>
</dd>
</dl>
</dd></dl>
<dl class="py function">
<dt id="pyforhandbook.ch06_databases.opening_sqlite.open_sqlite">
<code class="sig-name descname">open_sqlite</code><span class="sig-paren">(</span><em class="sig-param"><span class="n">input_db</span></em><span class="sig-paren">)</span><a class="headerlink" href="#pyforhandbook.ch06_databases.opening_sqlite.open_sqlite" title="Permalink to this definition"></a></dt>
<dd><p>Open a SQLite database</p>
<dl class="field-list simple">
<dt class="field-odd">Parameters</dt>
<dd class="field-odd"><p><strong>input_db</strong> Path to a SQLite database to open</p>
</dd>
<dt class="field-even">Returns</dt>
<dd class="field-even"><p>A connection to a SQLite database</p>
</dd>
</dl>
</dd></dl>
</div>
</div>
<div class="section" id="indices-and-tables">
<h2>Indices and tables<a class="headerlink" href="#indices-and-tables" title="Permalink to this headline"></a></h2>
<ul class="simple">
<li><p><a class="reference internal" href="genindex.html"><span class="std std-ref">Index</span></a></p></li>
<li><p><a class="reference internal" href="py-modindex.html"><span class="std std-ref">Module Index</span></a></p></li>
<li><p><a class="reference internal" href="search.html"><span class="std std-ref">Search Page</span></a></p></li>
</ul>
</div>
</div>
</div>
</div>
<footer>
<div class="rst-footer-buttons" role="navigation" aria-label="footer navigation">
<a href="ch03_event_logs.html" class="btn btn-neutral float-left" title="Chapter 3 - Windows Event Log Parsing" accesskey="p" rel="prev"><span class="fa fa-arrow-circle-left"></span> Previous</a>
</div>
<hr/>
<div role="contentinfo">
<p>
&copy; Copyright 2020, Chapin Bryce
</p>
</div>
Built with <a href="http://sphinx-doc.org/">Sphinx</a> using a
<a href="https://github.com/rtfd/sphinx_rtd_theme">theme</a>
provided by <a href="https://readthedocs.org">Read the Docs</a>.
</footer>
</div>
</div>
</section>
</div>
<script type="text/javascript">
jQuery(function () {
SphinxRtdTheme.Navigation.enable(true);
});
</script>
</body>
</html>