Elusive Data Firefly logo

One forensic workspace for app data investigations. Built on provenance.

 

Recover, interpret, validate and report app data evidence across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB, with findings traceable back to their source.

When the output isn’t enough, the investigation shouldn’t stop

Mobile devices create a constant stream of app data evidence. Extraction brings that data into the case, but decoded output is not the end of the investigation. Apps go unsupported, and updates can break support overnight. Even supported apps can produce results that are incomplete or inaccurate. Firefly gives examiners one workspace to recover, interpret, validate and report app data evidence, with a clear path back to the source.

Findings you can stand behind

What still remains

Decoded output does not always tell the whole story. Firefly helps you examine deleted records, BLOBs, timestamps, sidecars and nested structures across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB, giving you a more complete picture of the evidence.

Where it came from

Findings trace back to the file, page and byte offset they came from. See how they were recovered. See how they were interpreted. Check the interpretation against the raw bytes. The source remains visible throughout the review, so findings can be verified in context.

The original, left untouched

Firefly works from hash-verified copies validated with SHA-256. The original evidence is never altered. You can recover, review and report without changing the source.

Every app data investigation starts in one place

One workspace for SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB. Supported app databases open from the same launcher, so examiners work consistently across every format.

Follow the evidence back to its source​

Recover

Recover deleted, modified and replaced records where the data survives. See what surfaced each one, WAL files, journals, freelist pages, LevelDB logs, SSTables, deletion markers and residual RealmDB structures.

Interpret

Read records, artifacts, timestamps and location data in context, not as isolated values.

Validate

Trace findings back to the file, page and byte offset they came from, and check the interpretation against the source.

Report

Create interactive HTML reports that preserve the examiner’s working view: columns, aliases, interpreted timestamps and sort order.

Built for the databases modern apps use​

From database
to nested byte

Supporting files and nested data structures

Work with Apple Plists, Android Binary XML and layered app data using dedicated viewers and Firefly’s Tree Decoder. Recursively decode embedded Base64 Plists, gzipped Protobufs and other nested content without unpacking each layer by hand.

App databases

Analyze SQLite, RealmDB, LevelDB and IndexedDB in one forensic workspace, with shared viewers and a consolidated Hex Workbench.

Reporting and platform

Create interactive HTML reports that preserve the examiner’s working view. Windows 10 / 11 · .NET 9 · Native x64 and ARM64

Integrity and provenance

Read-only evidence handling. Source-context tracking. Evidence hash manifests. Optional tamper-evident activity logging.

Apple Biome / SEGB

Decode Biome streams, query with SEGBQL and extract patterns such as coordinates, URLs, emails, bundle IDs, addresses, phone numbers, search queries and device identifiers.

Built for teams who need
source-backed findings.

Firefly illustration for public safety and justice teams

Public safety & justice​

For examiners, investigators, prosecutors and defense teams who need source-backed findings they can stand behind in court.​

Firefly illustration for corporate enterprise and eDiscovery teams

Corporate enterprise
& eDiscovery

For forensic teams, eDiscovery examiners, litigation support and counsel who need clear, reviewable app data evidence.

Firefly illustration for military and intelligence teams

Military & intelligence​

For CID teams, field investigators and intelligence analysts who need fast access to app data findings, activity and location data, with source context.

Firefly at a glance

  • Deleted-record recovery across SQLite, RealmDB, LevelDB and IndexedDB
  • Recursive decoding of nested structures with Tree Decoder
  • 17 timestamp formats, confidence-ranked
  • Animated location route playback
  • Content decoders for Apple Binary Plist, NSKeyedArchiver plists, Android Binary XML, Base64, JSON and XML
  • Read-only evidence handling
  • SHA-256 evidence-set validation
  • Optional tamper-evident activity logging
  • Encrypted SQLite (SQLCipher) support
  • Interactive HTML reporting
  • Runs locally. Evidence data is not sent anywhere.
  • Windows 10/11, native x64 and ARM64

Strengthen what happens after extraction

Reduce the risk of missed app evidence

Continue the investigation when decoded output is incomplete, unsupported or conflicting and examine deleted or historical data when it remains available.

Increase confidence in critical findings

Trace findings back to the source file, page and byte offset, and examine the underlying data behind the interpretation.

Build a stronger, more consistent capability across the team

Bring specialist app data recovery, interpretation, validation and reporting into one forensic workflow.

Strengthen review, quality and defensibility

Preserve source and analysis context so another examiner, a quality reviewer or a court can follow how an important finding was reached.

Keep sensitive evidence under your control

Firefly runs locally, uses read-only evidence handling and does not send evidence data elsewhere.

Get more from the forensic tools you already use

Firefly picks up after extraction, bringing the specialist app data workflow into one place instead of a chain of separate utilities.

– Any tool can show you a value. The real question is whether you can prove where it came from. That is what we built Firefly around: recover what was deleted, interpret it in context, and keep a clear path back to the source, so a finding holds up when it is questioned.

James Eichbaum
Head of Product & Training
Co-founder Elusive Data

Book a demo

See Firefly in action

Schedule a live walkthrough and see how Firefly helps you recover, interpret, validate and report app data across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB. We’ll focus on the workflows, data types or challenges most relevant to your work.

Get in touch

Have a question?

Send us a message and we’ll get back to you as soon as possible.

FAQ

Frequently Asked Questions

One forensic workspace for app data investigations, built on provenance. It is made for the work that begins after extraction: recovering, interpreting, validating and reporting the data inside the databases modern apps run on.

No. Extraction gets the data off the device. Firefly is what you do with it afterwards. It complements your existing toolkit.

Firefly supports SQLite, including encrypted SQLite (SQLCipher), RealmDB, LevelDB and IndexedDB, plus Apple Biome / SEGB streams.

It recovers records where the data survives, and shows the mechanism that surfaced each one. Firefly shows its work rather than promising more than the data supports.

Firefly keeps findings connected to their source context, so examiners can explain what was found, where it came from and how it was interpreted.

Pricing and licensing will depend on the team, use case and deployment needs. Contact us at contact@elusivedata.io and we will help you find the right option.

Firefly connects SQLite forensics to modern app data investigations

Investigators may start by looking for a SQLite forensic tool, but the casework often expands beyond one database. Firefly is built as a forensic workspace for SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB, with recovery, validation and reporting tied back to source artifacts.

Is Firefly a SQLite forensic tool?

Yes. Firefly includes SQLite forensic analysis, including WAL, deleted records, freelists, freeblocks, page-level review and source-backed validation. It is also broader than SQLite alone, because modern app evidence often spans several storage formats.

How is Firefly different from a database viewer?

A database viewer can help open tables. Firefly is designed for forensic work after extraction: recover what remains, interpret records in context, validate findings against source data and preserve provenance for reporting.

How does the SQLite forensic tool guide relate to Firefly?

The guide explains what investigators should look for when evaluating SQLite and app data tooling. Firefly is the Elusive Data workspace for that source-backed workflow.