Digital forensics software and training for app data investigations

Don't let missed app evidence determine the outcome

Go beyond decoded output

Forensic software for app data investigations. Specialist digital and mobile forensics training.

Training

Build practical digital forensics skills

Digital and mobile forensics training in SQLite, Python, mobile device forensics and foundational digital forensics. Learn to examine source data, validate findings and explain what the evidence supports.

Firefly

Investigate app data after extraction with Firefly

Work with supported SQLite, Encrypted SQLite (SQLCipher), RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB data in one workspace. Interpret, validate and report findings with a clear path back to the source.

Tools

Use free forensic tools for focused analysis

Use Backup2FS to turn supported iOS backup content into a browsable file system, or the VarInt Calculator to examine SQLite variable-length integers and record structures.

Strengthen what happens after extraction with Firefly

One workspace to examine, interpret, validate and report app data after extraction. Built to complement the forensic tools you already use.

Bring the analysis together as you move from underlying app data to interpretation, validation and reporting.

  • SQLite
  • Encrypted SQLite (SQLCipher)
  • RealmDB
  • LevelDB
  • IndexedDB
  • Apple Biome / SEGB

Recover what remains

Investigate historical or deleted records where recoverable data remains in supported source files. What can be recovered depends on the files available and the condition of the data.

Interpret records in context

Review records, timestamps and nested content alongside the data they belong to. Look beyond an isolated value to understand how it has been interpreted.

Validate findings at the source

Inspect the source behind an interpretation, including the file, page and byte offset where applicable. Use the Hex Workbench to examine the underlying bytes.

Report with analysis context

Create interactive HTML reports that preserve the examiner’s working view, including selected columns, aliases, interpreted timestamps and sort order.

Digital and mobile forensics training for practical investigative work

Build practical skills from digital forensics foundations to SQLite, mobile forensics and Python, with training designed around real examination work.

Choose your area of focus

  • SQLite 24 CPE

    SQLite Forensics

    Understand SQLite structures, deleted records, WAL and SHM files, then validate findings against the source.

  • Microcourses

    SQLite Data Structures + WAL & SHM

    Focus on one SQLite topic at a time with shorter On-Demand training built around practical forensic analysis.

  • Python 24 CPE

    Python for Mobile Forensics

    Build practical scripts to parse app data and make repeatable forensic tasks easier to carry out.

  • Mobile 24 CPE

    Mobile Device Forensics

    Develop practical skills in mobile acquisition, app data examination and forensic reporting.

  • Foundations 40 CPE

    Introduction to Digital Forensics

    Build a working foundation in evidence collection, file systems, examination and clear reporting.

SQLite Forensics
Learn by working through the data yourself

  • Interactive byte-level workbenches

    Inspect SQLite structures, records, pages and byte offsets directly inside the lesson.

  • Downloadable evidence files

    Work with the same SQLite, WAL, SHM and sidecar files in your own forensic tools.

  • Connected CTF investigation

    Apply each technique as part of an investigation storyline rather than as an isolated exercise.

  • Support while you work through the course

    Course-related email support is included, with one complimentary one-hour instructor session during your access period.

Certificate of completion included. No coding or scripting experience required.

24 CPE Certificate included
90 days Course access
8 Interactive workbenches
5 Connected challenges

Free forensic tools

Work through the detail with focused tools

A clearer file structure. A closer look at a SQLite record. Practical tools for specific parts of the work.

An examiner reviewing iOS backup information at a workstation Free Windows tool

Backup2FS

Turn iOS backup content into a browsable file system. Backup2FS 3.0 supports encrypted iTunes and Finder backups when you provide the backup password, with selectable hash verification.

Explore Backup2FS
A forensic practitioner working at a desktop computer SQLite record analysis

VarInt Calculator

Decode SQLite variable-length integers, convert between hexadecimal and decimal, and examine how values and payloads are represented in a record.

Explore VarInt Calculator
James Eichbaum, Co-founder and Head of Product and Training at Elusive Data
James Eichbaum Co-founder & Head of Product and Training

Why Elusive Data

Built around the gap between access and understanding

Having the data and understanding it are different things. That gap shapes the tools we build, the training we deliver and the resources we share.

James Eichbaum’s background in forensic casework, specialist training and product development connects what we teach with the questions investigators need to answer.

About Elusive Data

Build capability across your team

Discuss private Live Online or On-Site training, or a Firefly walkthrough focused on your team’s app data workflow.

Talk about your team’s needs

Guides & practical learning

Keep learning between cases

Take a closer look at a structure, work through a specific technique or put your skills to the test.

Free forensic guide

Understand disk partitioning

A practical reference to the Protective MBR, GPT Header and Partition Entry Array.

Read the GPT partitioning guide
Free forensic guide · iOS 16.x

Investigate locked Apple Notes

A focused walkthrough for examining encrypted notes in the NoteStore.sqlite database from iOS 16.x backups.

Read the Apple Notes guide
Capture the Flag

Put your methods to work

Explore our forensic challenges and the practical, scenario-based approach behind them.

Explore forensic CTF challenges

A few useful answers

Before you get started

Questions about the training, the software or the right setup for your team?

Read all frequently asked questions
Is the training tied to one forensic tool?
No. The focus is on forensic methods, understanding data and validating findings. The skills are designed to complement the tools your organisation already uses. Explore training at https://elusivedata.io/digital-and-mobile-forensics-training/. Explore our digital and mobile forensics training .
Will I have support during SQLite On-Demand?
Yes. The full course includes course-related email support, a course chat where you can ask for support while you work through the material, and one complimentary, bookable one-hour instructor session where you can discuss questions, findings or areas you would like to work through with the instructor. Read more about SQLite Forensics On-Demand or start the course in the Academy .
Does Firefly replace device extraction?
No. Firefly is designed for the work after extraction. It helps you examine underlying app data, interpret records in context, validate findings at the source and report your analysis alongside the forensic tools you already use. Discover Firefly or see Firefly live and book a demo .
What Firefly licence options are available?
Annual licences cover 12 months. One-month and three-month licences are also available. Government and Law Enforcement discounts are available for eligible customers. Explore Firefly at https://elusivedata.io/firefly/ or contact Elusive Data for a quotation. Explore Firefly , see Firefly live and book a demo , or contact us for a quotation .
What digital and mobile forensics training does Elusive Data offer?
Elusive Data offers training in SQLite forensics, Python for mobile forensics, mobile device forensics and foundational digital forensics, alongside focused SQLite microcourses. Delivery options include Live Online, On-Site and guided On-Demand training depending on the course. Explore training at https://elusivedata.io/digital-and-mobile-forensics-training/. Explore all training or learn more about guided On-Demand training .
What app data formats can Firefly work with?
Firefly supports app data analysis across supported SQLite, Encrypted SQLite (SQLCipher), RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB sources. Available Analyzers and functions vary by source format and licence. Learn more at https://elusivedata.io/firefly/. See Firefly capabilities or see Firefly live and book a demo .
Can Firefly recover deleted or historical app data?
Firefly can help examine historical or deleted records where recoverable data remains in supported source files, such as relevant database pages, WAL data, journals or other supported structures. Recovery is not guaranteed and capabilities differ by source format and the condition of the available data. Learn more about Firefly or see Firefly live and book a demo .
Can Elusive Data provide private training for forensic teams?
Yes. Private Live Online training is available for teams, and On-Site delivery can also be arranged. We can discuss the course, group size, dates and practical setup with your organisation. Explore our training or contact us about a private session .

What students say

Proven methods. Held up by results.

From Elusive Data

Latest insights & updates

Practical perspectives on app data forensics, forensic validation and the work beyond decoded output.