
ED SQLite Visualizer. See More, Miss Less.
Something new is coming to mobile forensics At Elusive Data, our mission has always been clear: to help forensic professionals work faster, more accurately, and
Explore modern expert tools to accelerate and sharpen your digital forensic work. From iOS backup normalization with Backup 2FS to advanced database analysis with SQLite Visualizer.
Learn how to master comprehensive digital forensics workflows through immersive, hands-on training. Confidently apply your skills in real investigations.
Targeted micro-learning modules to help you rapidly address critical challenges, strengthen expertise, and stay fully up to date.
Start strong with the essentials. Learn how to collect, examine, and explain digital evidence. From data acquisition to reporting, build practical skills through real cases and guided labs. Built for those starting out or refreshing the basics.
Become an expert in mobile forensics, from acquisition to reporting. Built for real cases, updated for today’s Android and iOS challenges. Gain skills that go beyond tool output.
Explore SQLite databases in depth, the hidden layer beneath mobile apps and operating systems. Learn how to extract, decode, and interpret data to uncover user activity and forensic artifacts.
Dig deep into unsupported apps with hands-on SQLite analysis. Use Python to script, automate, and extract what tools miss. Gain a technical edge for advanced mobile forensics.
Learn when it works for you. 24/7 access to real-case modules. Pause, replay, and apply at your own pace.
Join live sessions from anywhere. Ask questions, try out techniques, and learn by doing. All the energy of the classroom, without the commute.
Learn in person from expert forensic practitioners through hands-on labs designed to build deep, practical skills.
Instantly decode variable-length integers from SQLite databases, protobuf messages, and app data structures. This free utility converts hex values to decimal in seconds, perfect for analyzing WhatsApp databases, custom app formats, and messaging data without requiring custom scripts.
ED SQLite Visualizer transforms how you analyze mobile databases. Trace deleted records frame by frame. Map complex schema relationships visually. Recover evidence from WAL files and unallocated space through an intuitive interface designed for modern investigations.
Transform iOS backup data into organized, navigable file structures. This free Windows tool extracts and normalizes iTunes backup content, complete with hash verification and device metadata. Access your backup data through a clear, logical file system ready for efficient analysis and reporting.
Join us at PFIC 2025 as James Eichbaum dives into hidden layers of iOS evidence, focusing on WAL and SHM files to find what most tools miss.
Session: “Beyond the Database”
Learn to extract deleted or uncommitted data from WAL and SHM, reconstruct timelines, and uncover hidden app activity your tools can’t show.
Learn to manually decode pages, recover deleted records, and confidently validate your findings, perfect when you need precise, court-ready evidence.
This free guide provides a practical walkthrough of GPT-partitioned disks, covering the Protective MBR, GPT Header, and Partition Entry Array. It’s designed to help forensic professionals understand disk structures, recover data, and validate evidence.
This guide provides a practical walkthrough for forensic analysts dealing with encrypted Apple Notes in iOS 16.x. It focuses on identifying and decrypting locked notes stored in the NoteStore.sqlite database extracted from iOS backups.
Very good course! Incredibly good teacher and I think that distance learning works at least as well as in the classroom! Thanks again James! Great balance between technical depth and hands-on labs. I liked that we didn’t just rely on tools, but looked under the hood and made sense of the data. It’s definitely helped me write clearer reports and explain findings to investigators.
Best course I have ever taken. I really enjoyed the week, learned a ton, and everything was clear and easy to keep up with. The labs felt real and made sense, even without loads of experience. The instructor explained things so clearly and made it all feel manageable. I would absolutely recommend it to anyone working with mobile forensics.
After decades of solving cases, testifying in court, and training forensic teams around the world, James Eichbaum founded Elusive Data in early 2024.
Well known in the digital forensics community from his former roles as an investigator, Global Trainer Manager, and instructor for some of the leading names in the industry, James started the company with a clear idea: training should be more hands-on, immersive, and reflect the real challenges of daily investigations. It should also be more accessible, giving investigators faster access to the knowledge they need to act quickly, make sense of complex data, and solve cases without delay.
Today, Elusive Data helps professionals around the world learn through immersive, hands-on training. Courses include interactive labs, CTF challenges, and practical exercises built around real case data. Training is available on-demand, live online, and on-site.
Elusive Data also supports active investigations through expert consulting and forensic services, for a field that never stands still.
Get help uncovering and explaining digital evidence. We deliver clear, reliable results for investigations, legal cases, and internal reviews.
Build stronger forensic capabilities with expert guidance. From setting up labs to improving workflows. We help you work smarter, faster.
We’ve trained thousands of professionals, and these are the most common questions we hear before they enroll, from what’s in the course to how it fits into busy caseloads.
Our training is designed for real-world investigations. Each course is built around authentic forensic scenarios, hands-on labs, and exclusive CTF challenges. You’ll work with raw data, decode real app artifacts, and build skills that go beyond tool output — using methods that stand up in reports and courtrooms. Every module reflects the workflows of professional analysts in the field.
Yes. All training has been fully updated to match the current forensic landscape. That includes support for modern iOS and Android environments, new app structures, updated CTF scenarios, and deep dives into advanced topics like SQLite freelist recovery and manual decoding of WAL/SHM files.
You can choose the format that fits your goals and schedule:
Micro-Courses: Short, focused live sessions (60–90 minutes) on specific topics like GPT, SQLite, and encrypted apps — ideal for fast, practical learning.
On-Demand Courses: Access certified, self-paced training 24/7. Replay labs, follow guided exercises, and apply techniques at your own speed.
Live Online Courses: Join expert-led classes in real time. Participate in case discussions, ask questions, and complete labs with instructor feedback.
Classroom Training: Learn face-to-face through immersive sessions and hands-on labs led by experienced digital forensics professionals.
Yes. All full-length courses include a verified certificate of completion and CPE credits, recognized by many professional bodies.
Our training supports all experience levels. You can start with foundational skills like acquisition and validation, or deepen your expertise with advanced techniques such as parsing app databases and scripting with Python for forensic automation.
Something new is coming to mobile forensics At Elusive Data, our mission has always been clear: to help forensic professionals work faster, more accurately, and
New course out now: Gain control over app data like never before. Learn to uncover, validate, and defend hidden evidence — no waiting, no travel.
Instantly decode VarInts from mobile app databases with Elusive Data’s free forensic tool. Convert hex, binary, and decimal values for faster, more accurate investigations.
Discover Backup2FS, a free tool from Elusive Data that simplifies iOS backup analysis by normalizing backups into an easy-to-navigate file system.
Discover how I decrypted a locked Apple Note from an iOS 16.7.10 device using open-source tools like Hashcat, Python, and CyberChef. This step-by-step forensic workflow reveals the process behind extracting and decrypting hidden content from Apple’s Notes app. A must-read for digital investigators and mobile forensics professionals.
SQLite overflow pages store fragmented data that doesn’t fit within a single database page, requiring forensic analysts to reconstruct them for complete evidence recovery.
Varints are the backbone of SQLite’s efficient data storage, encoding values in a compact format that digital forensic investigators must decode to uncover critical evidence. This blog dives into the decoding process, real-world examples, and tools like the Varint Calculator to simplify forensic analysis.
Unlock the secrets of SQLite freeblocks and learn how to recover deleted records using forensic techniques.
Gain a deeper understanding of the GPT Partition Entry Array and its significance in digital forensic analysis. This guide explores key techniques and insights to enhance your forensic investigations.
Be the first to hear about new digital and mobile forensics training opportunities, free tools, case-based blog posts, and practical insights. Our monthly newsletter is built to help you learn faster, solve cases smarter, and keep up in a field that never stands still.
Fill in your email to sign up.
We noticed you're visiting from Sweden. We've updated our prices to Swedish krona for your shopping convenience. Use United States (US) dollar instead. Dismiss
Thank you for a great course! I finally get how to work with unsupported apps. That clicked during this course. I’ve done a few trainings before, but this one stood out because it was actually useful right away. The instructor explained how app data is stored in a way that made sense, and I really appreciated all the real examples. I’ve already used a few techniques in a current case.