Mobile devices create a constant stream of app data evidence. Extraction brings that data into the case, but decoded output is not the end of the investigation. Apps go unsupported, and updates can break support overnight. Even supported apps can produce results that are incomplete or inaccurate. Firefly gives examiners one workspace to recover, interpret, validate and report app data evidence, with a clear path back to the source.
Decoded output does not always tell the whole story. Firefly helps you examine deleted records, BLOBs, timestamps, sidecars and nested structures across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB, giving you a more complete picture of the evidence.
Findings trace back to the file, page and byte offset they came from. See how they were recovered. See how they were interpreted. Check the interpretation against the raw bytes. The source remains visible throughout the review, so findings can be verified in context.
Firefly works from hash-verified copies validated with SHA-256. The original evidence is never altered. You can recover, review and report without changing the source.
One workspace for SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB. Supported app databases open from the same launcher, so examiners work consistently across every format.
Recover deleted, modified and replaced records where the data survives. See what surfaced each one, WAL files, journals, freelist pages, LevelDB logs, SSTables, deletion markers and residual RealmDB structures.
Read records, artifacts, timestamps and location data in context, not as isolated values.
Trace findings back to the file, page and byte offset they came from, and check the interpretation against the source.
Create interactive HTML reports that preserve the examiner’s working view: columns, aliases, interpreted timestamps and sort order.
Work with Apple Plists, Android Binary XML and layered app data using dedicated viewers and Firefly’s Tree Decoder. Recursively decode embedded Base64 Plists, gzipped Protobufs and other nested content without unpacking each layer by hand.
Analyze SQLite, RealmDB, LevelDB and IndexedDB in one forensic workspace, with shared viewers and a consolidated Hex Workbench.
Create interactive HTML reports that preserve the examiner’s working view. Windows 10 / 11 · .NET 9 · Native x64 and ARM64
Read-only evidence handling. Source-context tracking. Evidence hash manifests. Optional tamper-evident activity logging.
Decode Biome streams, query with SEGBQL and extract patterns such as coordinates, URLs, emails, bundle IDs, addresses, phone numbers, search queries and device identifiers.
For examiners, investigators, prosecutors and defense teams who need source-backed findings they can stand behind in court.
For forensic teams, eDiscovery examiners, litigation support and counsel who need clear, reviewable app data evidence.
For CID teams, field investigators and intelligence analysts who need fast access to app data findings, activity and location data, with source context.
Continue the investigation when decoded output is incomplete, unsupported or conflicting and examine deleted or historical data when it remains available.
Trace findings back to the source file, page and byte offset, and examine the underlying data behind the interpretation.
Bring specialist app data recovery, interpretation, validation and reporting into one forensic workflow.
Preserve source and analysis context so another examiner, a quality reviewer or a court can follow how an important finding was reached.
Firefly runs locally, uses read-only evidence handling and does not send evidence data elsewhere.
Firefly picks up after extraction, bringing the specialist app data workflow into one place instead of a chain of separate utilities.
James Eichbaum
Head of Product & Training
Co-founder
Elusive Data
Schedule a live walkthrough and see how Firefly helps you recover, interpret, validate and report app data across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB. We’ll focus on the workflows, data types or challenges most relevant to your work.
Send us a message and we’ll get back to you as soon as possible.
One forensic workspace for app data investigations, built on provenance. It is made for the work that begins after extraction: recovering, interpreting, validating and reporting the data inside the databases modern apps run on.
No. Extraction gets the data off the device. Firefly is what you do with it afterwards. It complements your existing toolkit.
Firefly supports SQLite, including encrypted SQLite (SQLCipher), RealmDB, LevelDB and IndexedDB, plus Apple Biome / SEGB streams.
It recovers records where the data survives, and shows the mechanism that surfaced each one. Firefly shows its work rather than promising more than the data supports.
Firefly keeps findings connected to their source context, so examiners can explain what was found, where it came from and how it was interpreted.
Pricing and licensing will depend on the team, use case and deployment needs. Contact us at contact@elusivedata.io and we will help you find the right option.
Investigators may start by looking for a SQLite forensic tool, but the casework often expands beyond one database. Firefly is built as a forensic workspace for SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB, with recovery, validation and reporting tied back to source artifacts.
Yes. Firefly includes SQLite forensic analysis, including WAL, deleted records, freelists, freeblocks, page-level review and source-backed validation. It is also broader than SQLite alone, because modern app evidence often spans several storage formats.
A database viewer can help open tables. Firefly is designed for forensic work after extraction: recover what remains, interpret records in context, validate findings against source data and preserve provenance for reporting.
The guide explains what investigators should look for when evaluating SQLite and app data tooling. Firefly is the Elusive Data workspace for that source-backed workflow.