Elusive Data Firefly logo
Coming August 31, 2026

A new forensic workspace for app-data investigations is coming

From decoded data to source-backed findings

Fast access to top-tier training and expert tools for digital forensics

Accelerate and sharpen your digital forensic work

Expert Tools

Enhance your toolkit with clearer, more precise forensic analysis. Designed to complement your trusted platforms, our solutions help you work sharper and with greater precision.

Training Programs​​

Learn how to master comprehensive digital forensics workflows through immersive, hands-on training. Confidently apply your skills in real investigations.

Micro-Learning

Targeted micro-learning modules to help you rapidly address critical challenges, strengthen expertise, and stay fully up to date.

digital forensics tools

Forensic tools that help you see more, find more, and work faster

elusive data firefly

A new forensic workspace
is coming August 31

One forensic workspace for app-data investigations, built on provenance. Recover, interpret, validate and report evidence across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB, with every finding traceable back to its source. Launching August 31, 2026.

varint calculator

Calculate and decode VarInts

Decode SQLite variable-length integers and serial type codes in seconds. Calculate the storage length of strings and BLOBs, determine whether a record requires overflow pages, and identify how much of the payload is stored locally on the database page. Built for fast, script-free analysis of SQLite records and data structures.

backup2fs

A tool to normalize iOS backups

Transform iOS backup data into organized, navigable file structures. This free Windows tool extracts and normalizes iTunes backup content, complete with hash verification and device metadata. Access your backup data through a clear, logical file system ready for efficient analysis and reporting.

digital forensics training programs

Master forensic fundamentals and uncover evidence your tools overlook​

full advanced program​

Dig deep into unsupported apps with hands-on SQLite analysis. Use Python to script, automate, and extract what tools miss. Gain a technical edge for advanced mobile forensics.

full advanced program available on-demand

Explore SQLite databases in depth, the hidden layer beneath mobile apps and operating systems. Learn how to extract, decode, and interpret data to uncover user activity and forensic artifacts.

micro-course
available on-demand

SQLite Data Structures 5 CPEs

Learn to manually decode pages, recover deleted records, and confidently validate your findings. Perfect when you need precise, court-ready evidence.

micro-course
available on-demand

WAL Frames and SHM Index 5 CPEs

Learn to examine WAL frames and SHM indexes to recover deleted, and pre-checkpoint records and reconstruct transaction timelines. Uncover app activity that automated tools may not show.

Training formats for every schedule

Real-world practice. However you choose to learn.
On-demand learning icon — Elusive Data digital forensics self-paced training

On-Demand Training

Learn when it works for you. 24/7 access to interactive lessons, practical exercises, and real-world forensic scenarios. Work through each module at your own pace.

Live online training icon — Elusive Data digital forensics instructor-led online course

Live Online Training

Join live sessions from anywhere. Ask questions, try out techniques, and learn by doing. All the energy of the classroom, without the commute.

Classroom training icon — Elusive Data in-person digital forensics training courses

Classroom Training

Learn in person from expert forensic practitioners through hands-on labs designed to build deep, practical skills.

Proven methods. Held up by results.

25+ Years of experience behind our training

100% focus on real-world case exercises in every course

5/5 average course rating from professionals

1000+ professionals trained, in 30+ countries

micro-learning | guides & e-books
Free guide

Forensic Guide to GPT Partitioning

This free guide provides a practical walkthrough of GPT-partitioned disks, covering the Protective MBR, GPT Header, and Partition Entry Array. It’s designed to help forensic professionals understand disk structures, recover data, and validate evidence.​

FREE guide

Decrypt Locked Apple Notes on iOS 16.x

This guide provides a practical walkthrough for forensic analysts dealing with encrypted Apple Notes in iOS 16.x. It focuses on identifying and decrypting locked notes stored in the NoteStore.sqlite database extracted from iOS backups.​

Trusted by investigators worldwide

Sarah M. Digital Evidence Specialist, Course: Python for Mobile Forensics

Thank you for a great course! I finally get how to work with unsupported apps. That clicked during this course. I’ve done a few trainings before, but this one stood out because it was actually useful right away. The instructor explained how app data is stored in a way that made sense, and I really appreciated all the real examples. I’ve already used a few techniques in a current case.

Carlos G. Forensic Lab Tech, Course: Mobile Device Forensics

Very good course! Incredibly good teacher and I think that distance learning works at least as well as in the classroom! Thanks again James! Great balance between technical depth and hands-on labs. I liked that we didn’t just rely on tools, but looked under the hood and made sense of the data. It’s definitely helped me write clearer reports and explain findings to investigators.

Emily N. Digital Forensics Student, Course: Introduction to Digital Forensics

Best course I have ever taken. I really enjoyed the week, learned a ton, and everything was clear and easy to keep up with. The labs felt real and made sense, even without loads of experience. The instructor explained things so clearly and made it all feel manageable. I would absolutely recommend it to anyone working with mobile forensics.

Élodie L. Digital Analyst, Course: SQLite Forensics

Wow! I’ve taken other training that felt like a sales pitch. This was different. Everything was clearly explained, and I didn’t feel stuck to one tool. If your work involves unsupported apps or deleted data, this course is a must!

 Martin H. Digital Evidence Analyst, Course: Mobile Device Forensics

Didn’t expect to enjoy this as much as I did. The way the instructor broke stuff down, especially all the app data really made it fun. James really knows his stuff and kept things moving without overwhelming us. Took away real techniques I’ll use back at work. Keep up the good work, James!

FAQ

Frequently Asked Questions

Our courses sharpen the way you investigate digital and mobile evidence. You learn full workflows that go beyond tool buttons, working with raw data, decoding app artifacts, and practicing authentic case scenarios. Labs and CTF challenges give you confidence to handle live investigations under real conditions.

We offer two certification programs at the moment: SQLite Forensics, and Python for Mobile Forensics. Each program builds practical skills that complement your existing tools and help you see more, find more, and deliver precise results that hold up in reports and courtrooms.

Yes. The training has been fully updated to match the current forensic landscape. That includes support for modern iOS and Android environments, new app structures, updated CTF scenarios, and deep dives into advanced topics like SQLite freelist recovery and manual decoding of WAL/SHM files.

Our tools are built to meet today’s forensic challenges. They do not replace your trusted platforms, they extend them. Some give you quick answers when time is short. Others open up evidence in ways standard tools often miss.

VarInt Calculator
Decode variable-length integers instantly from SQLite databases. No scripts, no guesswork. Just clear values when you need them.

Backup2FS
Transform iOS backups into structured, navigable file systems with hashes and metadata preserved. From confusion to clarity in one step.

SQLite Visualizer
Analyze SQLite databases in depth. Visualize structures, follow deleted records across time, and recover hidden evidence from WAL, freelists and unallocated space. Built from years of training and investigations, SQLite Visualizer reveals what standard tools often miss.

From August 31, SQLite Visualizer becomes part of Elusive Data Firefly, carrying the workflow into a broader forensic workspace for modern app-data investigations.

Elusive Data Firefly
Launching August 31, Firefly is built for the work that begins after extraction. It brings SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome SEGB into one workspace. Recover what remains in the data, interpret it in context, validate findings against the source, and report with clear path back to the file, page and byte offset.

Together, these tools give you sharper insight, clearer reporting and source-backed findings you can stand behind in real investigations.

We first built SQLite Visualizer because we needed a clearer way to investigate SQLite in real cases. The same questions kept coming back: what was deleted, when did it change, where did this record come from, and how can I explain it in a report?

SQLite Visualizer filled that gap for SQLite. It shows deleted records frame by frame, maps schema relationships visually, and recovers data from WAL, freelists and unallocated space. Built from casework and refined in hands-on labs, it makes database analysis faster, clearer and easier to explain.

Firefly takes that same idea further. SQLite is still central, but modern app evidence lives across RealmDB, LevelDB, IndexedDB, Apple Biome / SEGB, BLOBs, timestamps, sidecars and nested structures. Firefly brings that work into one forensic workspace after extraction, so examiners can recover what remains, interpret it in context, validate it against the source and report findings with a clear path back.

From August 31, SQLite Visualizer becomes part of Elusive Data Firefly.

Our tools are built around the questions forensic examiners actually need to answer. It is not enough to show a decoded value. You need to understand where it came from, how it was recovered, and whether you can explain it when the finding is reviewed.

SQLite Visualizer brought that approach to SQLite. It lets examiners follow database history in the WAL, explore schemas visually, move between structure and hex, and recover deleted data from WAL, freelists and unallocated space without losing context.

Firefly takes the same idea beyond SQLite. From August 31, SQLite Visualizer becomes part of Firefly, a broader forensic workspace for modern app-data investigations across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB.

Key capabilities include:

WAL timeline analysis
See database history unfold record by record.

Visual schema navigation
Map tables and relationships as an interactive canvas.

Integrated hex and structure view
Move between records, pages, structures and bytes without losing the path back to the source.

Deleted-record recovery
Recover what remains in WAL, freelists, unallocated space and supported modern app databases.

Provenance and reporting
Validate findings against the source and carry the working view into reports.

Together, these capabilities give examiners a faster, clearer and more defensible way to work with app data. They help you move from decoded values to source-backed findings you can stand behind.

You can choose the format that fits your goals and schedule:

  • Micro-Courses: Short, focused live sessions (60–90 minutes) on specific topics like GPT, SQLite, and encrypted apps — ideal for fast, practical learning.

  • On-Demand Courses: Access certified, self-paced training 24/7. Replay labs, follow guided exercises, and apply techniques at your own speed.

  • Live Online Courses: Join expert-led classes in real time. Participate in case discussions, ask questions, and complete labs with instructor feedback.

  • Classroom Training: Learn face-to-face through immersive sessions and hands-on labs led by experienced digital forensics professionals.

Yes. All full-length courses include a verified certificate of completion and CPE credits, recognized by many professional bodies.

Our training supports all experience levels. You can start with foundational skills like acquisition and validation, or deepen your expertise with advanced techniques such as parsing app databases and scripting with Python for forensic automation.

No. The tools are built to make complex forensic work easier to follow, verify and explain. Whether you are decoding VarInts, navigating an iOS backup or investigating database internals, the goal is to make the process clearer and faster without hiding the underlying evidence.

When you purchase SQLite Visualizer today, a one-hour onboarding session is included to help you get started. After August 31, the same applies to Firefly.

If you need more training, just contact us. We also offer advanced SQLite forensics training, including a certified course where the tools are used as part of the practical workflow.

Latest insights & updates

SQLite Forensics

SQLite Forensics Explained

SQLite forensics explained in simple terms. Learn how SQLite databases store data, where evidence is hidden, and why it matters in digital investigations.

Read More
Protocol Buffers varint decoding in Python for digital forensics analysis

Protocol Buffers for Forensic Examiners: The Varint Trap

Protobuf varints are not SQLite varints. Learn how to parse Protocol Buffer data from Apple Notes and mobile forensic artifacts, decode LEB128 varints step by step, and build a Python decoder with bitwise operations. Includes a hands-on XOR decryption challenge.

Read More
Varint Calculator

VarInt Calculator Now Available as an iOS App

Small time-savers can make a big difference in mobile forensics.
That’s why VarInt Calculator is now available as a dedicated iOS app—bringing fast VarInt decoding and clear SQLite insights straight to your iPhone or iPad.

Read More