See SQLite evidence clearly. From records to raw pages.
SQLite Visualizer brings together database browsing, SQL analysis, WAL inspection, deleted-record recovery, B-tree exploration, hex review, and reporting in one forensic workflow.
The tool is available in two software editions: Basic for professional SQLite forensic analysis, and متقدم for cases that also require LevelDB analysis.
Browse tables, run SQL queries, inspect schemas and relationships, review records, and understand how app data is structured.
Inspect WAL files, freelist pages, deleted records, page-level artifacts, and source attribution to understand where evidence came from.
Use the B-Tree Visualizer, page view, hex inspection, and artifact context to verify findings before export or reporting.


The core of the platform is a visual canvas that displays every table, every relationship, every record count, and any custom views as virtual table cards. This delivers an immediate, clear understanding of how an application structures its data, helping examiners grasp the database at a glance.


SQLiteVisualizer includes integrated decoding for plists, protobufs, Base64, GZIP, JSON stitching, Markdown, GPS data, and timestamp formats, everything interpreted directly inside the platform with no exporting or external tools required.


SQLiteVisualizer provides a complete set of examiner-focused recovery tools that expose deleted, historical, and overwritten content across all SQLite storage layers. It recovers data from WAL frames with timeline views, extracts remnants from freelist pages, carves fragmented records from freeblocks, analyzes rollback-journal history, and reconstructs records with full forensic metadata for validation.


SQLiteVisualizer includes a dedicated Hex Analysis Engine built specifically for SQLite forensics, offering automatic decoding of database structures, smart context-aware templates, smooth navigation across pages and frames, fast value and timestamp interpretation, and support for reconstructing fragmented records.


SQLiteVisualizer streamlines SQL work with visual, intuitive tools, letting you build queries directly from the canvas, create context-aware JOINs with a single click, save results as reusable virtual tables, and keep everything organized in a structured, searchable query library.


SQLiteVisualizer generates clear, defensible reports for any case, with flexible evidence and table summaries, interactive HTML output, automatic inclusion of case metadata and hash information, secure ZIP packaging options, and fully customizable report sections to match your agency’s requirements.


Analyze LevelDB stores used by Chromium-based browsers, Electron applications, messaging tools, and cloud-synced apps. Inspect keys, values, sequence data, overwritten artifacts, and encoded application content in a forensic workflow built for rapid review and validation.


Go beyond traditional SQLite databases and examine application evidence stored in modern web-backed formats. Advanced helps investigators identify cached content, synchronized records, browser artifacts, and app data that may not appear in standard SQLite views.


Correlate SQLite records with LevelDB artifacts to understand how application data was created, cached, synchronized, modified, or removed across multiple storage layers. This gives examiners a clearer picture of activity in complex or partially parsed apps.


SQLiteVisualizer includes a full case-management workflow designed for forensic defensibility. It works in read-only mode, creates protected evidence copies, verifies hashes across multiple algorithms, and captures case metadata and custom fields. Your analysis state and history are preserved across sessions, ensuring every step of your work remains transparent, reliable, and fully repeatable.


SQLiteVisualizer includes a built-in forensic chatbot that you can use in any language, making guidance and SQL assistance accessible to every examiner. It helps you write complex queries, explains SQLite structures like WAL and freelists in simple terms, and supports your workflow without ever accessing evidence data, only the schema. A faster, clearer way to get help right inside the tool.
What I appreciate most is that nothing feels hidden or confusing. I can follow how an app changes its data, notice unusual behavior, and review deleted records without struggling with the tool. It really feels like someone finally built a SQLite tool for how investigators actually work. It’s been extremely helpful.
When I first used it during the course, it immediately made my workflow simpler. Everything I used to juggle between different tools was suddenly all in one place. No exporting, no jumping around. I’ve watched it develop over time, and it’s become something I rely on every day. It genuinely saves time and helps me find things I would have missed.
Gain immediate insight into how an application structures, links, and organizes its information the moment the database loads.
Get immediate clarity on how the app stores, links, and evolves its data.
Extract deleted, historical, and fragmented records across WAL, freelist, journals, and freeblocks with full forensic context.
Analyze complex formats without exporting files, switching tools, or losing your investigative flow.
Interpret plists, protobufs, Base64, GZIP, JSON stitching, timestamps, and GPS data inside one unified forensic workspace.
Back every conclusion with transparent evidence sources, structured metadata, and documented origin for each recovered record.
Documented recovery context for each record helps ensure conclusions hold up in reports, peer review, and testimony.
Move from visual exploration to SQL, joins, custom views, and reporting without exporting data or switching between external tools.
Generate structured reports with filters, transformations, metadata, hashes, images, maps, and interactive elements , all guided and case-ready.
Use these guides when you need to check a WAL file, recover deleted SQLite records, or explain how a database stores evidence. They support the same source-first workflow used in SQLite Visualizer.
I didn’t expect a SQLite tool to make this big a difference, but honestly, it’s shaved hours off my cases. The moment I open a database, I actually understand what I’m looking at. And the deleted data it uncovered… we would never have found that with our old workflow! It’s just made my job easier, plain and simple.