PE-SQL
sqlite3
Open and query SQLite database files pulled off a host, app, or browser profile.
OVERVIEW
sqlite3 (sqlite.org/cli.html) is the official command-line shell for SQLite, the single-file database format that backs Firefox and Chrome profiles, most native mobile apps, and countless desktop tools. In an engagement it is what you reach for once a `.sqlite`, `.db`, or `.sqlite3` file lands in the loot folder — `cookies.sqlite`, a Signal/WhatsApp-style local store, an Electron app’s local storage.
`.tables` lists what is inside, `.schema <table>` shows the column definitions, and a plain `SELECT` reads rows without needing to install anything beyond the shell itself, which ships in most Linux distros and on macOS. Work against a copy of the file, never the original evidence copy, since SQLite can write a `-wal` or `-journal` file the moment you open it read-write.
USE CASES
Practical use cases
- 01
Reading cookies, history, or saved logins out of a recovered browser profile.
- 02
Inspecting a mobile app’s local SQLite store for tokens, messages, or cached API responses.
- 03
Listing tables and schema on an unfamiliar `.db` file before deciding what to extract.
- 04
Exporting a specific table to CSV as an appendix for a finding.
QUICK START
When a .sqlite/.db file turns up as loot — a browser profile, a mobile app’s local storage, a desktop app’s cache — and you need to read the tables without a GUI.
- Confirm the database file is in-scope loot and work from a copy, not the original.
- Open it read-only where possible and run .tables to see what exists.
- Use .schema on a table of interest before writing a SELECT against it.
- Export only the rows relevant to the finding; delete the working copy afterward.
sqlite3 -readonly cookies.sqlite '.tables'BEFORE YOU RUN IT
What to check before running it
A SQLite file pulled off a host, mobile app, or browser profile can contain PII, session tokens, or credentials — handle it under the engagement’s data-handling rules, not as a throwaway test artifact.
Opening a live database read-write can create or rewrite a `-wal`/`-journal` file next to it; use `-readonly` or work from a copy to avoid altering evidence.
A schema alone does not prove a field is unencrypted or sensitive — read a few sample rows before claiming a data-exposure finding.