Skip to content
OPS // KITitspentest.sh

PE-SQL

sqlite3

Open and query SQLite database files pulled off a host, app, or browser profile.

Official siteBack to catalog

OVERVIEW

sqlite3 (sqlite.org/cli.html) is the official command-line shell for SQLite, the single-file database format that backs Firefox and Chrome profiles, most native mobile apps, and countless desktop tools. In an engagement it is what you reach for once a `.sqlite`, `.db`, or `.sqlite3` file lands in the loot folder — `cookies.sqlite`, a Signal/WhatsApp-style local store, an Electron app’s local storage.

`.tables` lists what is inside, `.schema <table>` shows the column definitions, and a plain `SELECT` reads rows without needing to install anything beyond the shell itself, which ships in most Linux distros and on macOS. Work against a copy of the file, never the original evidence copy, since SQLite can write a `-wal` or `-journal` file the moment you open it read-write.

USE CASES

Practical use cases

  • 01

    Reading cookies, history, or saved logins out of a recovered browser profile.

  • 02

    Inspecting a mobile app’s local SQLite store for tokens, messages, or cached API responses.

  • 03

    Listing tables and schema on an unfamiliar `.db` file before deciding what to extract.

  • 04

    Exporting a specific table to CSV as an appendix for a finding.

QUICK START

When a .sqlite/.db file turns up as loot — a browser profile, a mobile app’s local storage, a desktop app’s cache — and you need to read the tables without a GUI.

  1. Confirm the database file is in-scope loot and work from a copy, not the original.
  2. Open it read-only where possible and run .tables to see what exists.
  3. Use .schema on a table of interest before writing a SELECT against it.
  4. Export only the rows relevant to the finding; delete the working copy afterward.
sqlite3 — bash
sqlite3 -readonly cookies.sqlite '.tables'

BEFORE YOU RUN IT

What to check before running it

A SQLite file pulled off a host, mobile app, or browser profile can contain PII, session tokens, or credentials — handle it under the engagement’s data-handling rules, not as a throwaway test artifact.

Opening a live database read-write can create or rewrite a `-wal`/`-journal` file next to it; use `-readonly` or work from a copy to avoid altering evidence.

A schema alone does not prove a field is unencrypted or sensitive — read a few sample rows before claiming a data-exposure finding.

KEEP EXPLORING

View the whole phase →