Versions:

  • 0.10.1
  • 0.10.0
  • 0.1.0

sqlite4n6 is a read-only SQLite forensic command-line tool published by SecurityRonin, currently at version 0.10.1, with three versions released to date. Its purpose is the forensic examination and recovery of data from SQLite database files, making it a relevant entry in the digital forensics and incident response category of the catalog. The tool's core capability is carving deleted records out of a database's free, unallocated space, allowing analysts to recover rows that a live SQL query against the database cannot return. Specifically, it targets four sources of recoverable data: freelist pages, which hold pages released from active use; in-page free blocks, which contain remnants within otherwise allocated pages; dropped-table pages, which may still retain the contents of removed tables; and an uncheckpointed WAL overlay, covering records present in the write-ahead log that have not yet been merged into the main database file. Beyond record recovery, sqlite4n6 grades forensically notable anomalies and organizes them into severity-ranked findings, helping investigators prioritize the most significant evidence within a database. A defining operational characteristic of the tool is its strict read-only behavior: it opens the evidence file without write access and never writes to the database file or its sidecars, preserving the integrity of the original evidence throughout analysis. This design makes sqlite4n6 suitable for use cases in which maintaining an unaltered evidence source is essential, such as forensic investigations, audit reviews, and incident analysis involving SQLite-backed applications. Common application scenarios include recovering deleted records from mobile or desktop application databases, examining browser or messaging data stores, and assessing databases for signs of tampering or unusual activity. With version 0.10.1 representing the latest of its three published releases, sqlite4n6 offers a focused, evidence-safe approach to SQLite data recovery and anomaly triage.

Tags: