Build practical digital forensics skills
Digital and mobile forensics training in SQLite, Python, mobile device forensics and foundational digital forensics. Learn to examine source data, validate findings and explain what the evidence supports.
Don't let missed app evidence determine the outcome
Forensic software for app data investigations. Specialist digital and mobile forensics training.
Digital and mobile forensics training in SQLite, Python, mobile device forensics and foundational digital forensics. Learn to examine source data, validate findings and explain what the evidence supports.
Work with supported SQLite, Encrypted SQLite (SQLCipher), RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB data in one workspace. Interpret, validate and report findings with a clear path back to the source.
Use Backup2FS to turn supported iOS backup content into a browsable file system, or the VarInt Calculator to examine SQLite variable-length integers and record structures.
One workspace to examine, interpret, validate and report app data after extraction. Built to complement the forensic tools you already use.
Bring the analysis together as you move from underlying app data to interpretation, validation and reporting.
Investigate historical or deleted records where recoverable data remains in supported source files. What can be recovered depends on the files available and the condition of the data.
Review records, timestamps and nested content alongside the data they belong to. Look beyond an isolated value to understand how it has been interpreted.
Inspect the source behind an interpretation, including the file, page and byte offset where applicable. Use the Hex Workbench to examine the underlying bytes.
Create interactive HTML reports that preserve the examiner’s working view, including selected columns, aliases, interpreted timestamps and sort order.
Build practical skills from digital forensics foundations to SQLite, mobile forensics and Python, with training designed around real examination work.
Understand SQLite structures, deleted records, WAL and SHM files, then validate findings against the source.
Focus on one SQLite topic at a time with shorter On-Demand training built around practical forensic analysis.
Build practical scripts to parse app data and make repeatable forensic tasks easier to carry out.
Develop practical skills in mobile acquisition, app data examination and forensic reporting.
Build a working foundation in evidence collection, file systems, examination and clear reporting.
Inspect SQLite structures, records, pages and byte offsets directly inside the lesson.
Work with the same SQLite, WAL, SHM and sidecar files in your own forensic tools.
Apply each technique as part of an investigation storyline rather than as an isolated exercise.
Course-related email support is included, with one complimentary one-hour instructor session during your access period.
Certificate of completion included. No coding or scripting experience required.
Free forensic tools
A clearer file structure. A closer look at a SQLite record. Practical tools for specific parts of the work.
Free Windows tool Turn iOS backup content into a browsable file system. Backup2FS 3.0 supports encrypted iTunes and Finder backups when you provide the backup password, with selectable hash verification.
Explore Backup2FS
SQLite record analysis Decode SQLite variable-length integers, convert between hexadecimal and decimal, and examine how values and payloads are represented in a record.
Explore VarInt Calculator
Why Elusive Data
Having the data and understanding it are different things. That gap shapes the tools we build, the training we deliver and the resources we share.
James Eichbaum’s background in forensic casework, specialist training and product development connects what we teach with the questions investigators need to answer.
About Elusive DataDiscuss private Live Online or On-Site training, or a Firefly walkthrough focused on your team’s app data workflow.
Talk about your team’s needsGuides & practical learning
Take a closer look at a structure, work through a specific technique or put your skills to the test.
A practical reference to the Protective MBR, GPT Header and Partition Entry Array.
Read the GPT partitioning guideA focused walkthrough for examining encrypted notes in the NoteStore.sqlite database from iOS 16.x backups.
Read the Apple Notes guideExplore our forensic challenges and the practical, scenario-based approach behind them.
Explore forensic CTF challengesA few useful answers
Questions about the training, the software or the right setup for your team?
Read all frequently asked questionsWhat students say
Thank you for a great course! I finally get how to work with unsupported apps. That clicked during this course. I’ve done a few trainings before, but this one stood out because it was actually useful right away. The instructor explained how app data is stored in a way that made sense, and I really appreciated all the real examples. I’ve already used a few techniques in a current case.
Very good course! Incredibly good teacher and I think that distance learning works at least as well as in the classroom! Thanks again James! Great balance between technical depth and hands-on labs. I liked that we didn’t just rely on tools, but looked under the hood and made sense of the data. It’s definitely helped me write clearer reports and explain findings to investigators.
Best course I have ever taken. I really enjoyed the week, learned a ton, and everything was clear and easy to keep up with. The labs felt real and made sense, even without loads of experience. The instructor explained things so clearly and made it all feel manageable. I would absolutely recommend it to anyone working with mobile forensics.
Wow! I’ve taken other training that felt like a sales pitch. This was different. Everything was clearly explained, and I didn’t feel stuck to one tool. If your work involves unsupported apps or deleted data, this course is a must!
Didn’t expect to enjoy this as much as I did. The way the instructor broke stuff down, especially all the app data really made it fun. James really knows his stuff and kept things moving without overwhelming us. Took away real techniques I’ll use back at work. Keep up the good work, James!
From Elusive Data
Practical perspectives on app data forensics, forensic validation and the work beyond decoded output.