Elusive Data / FAQ

Frequently asked questions

Answers about our training, Firefly and forensic utilities. Find the details you need before you enrol, purchase or get started.

01 / TRAINING

Courses & formats

Choose the subject and delivery format that fit your work.

Which digital forensics courses do you offer?

Our courses include SQLite Forensics, Python for Mobile Forensics, Mobile Device Forensics and Introduction to Digital Forensics. We also offer focused SQLite microcourses covering data structures and WAL/SHM analysis. Check the individual course page for available formats.

Who is the training designed for?

Our training is designed for people who examine digital evidence, including law enforcement examiners, private forensic practitioners, corporate investigation teams and digital forensic consultants. Course levels range from foundational training to specialist app-data analysis.

What training formats are available?

Guided On-Demand lets you study on your own schedule. Live Online provides real-time instructor-led training. On-Site brings the training to your team. Availability depends on the course; not every course is available in every format.

Is your training vendor-neutral?

Yes. The focus is on understanding the data, applying forensic methods and validating findings, rather than memorising one product's interface. The skills complement the forensic platforms your organisation already uses.

Can we arrange private training for our team?

Yes. For SQLite Forensics, private Live Online training is available by quotation for 3 or more participants, and On-Site training for 5 or more. Contact us with your team size, preferred dates and training goals to discuss a suitable setup.

Who teaches the SQLite Forensics course?

The course is designed and taught by James Eichbaum, Co-founder and Head of Product & Training at Elusive Data. His background combines forensic casework, specialist training and product development, including his previous role as Global Training Manager at MSAB.

Explore training

02 / LEARN ON YOUR SCHEDULE

Guided On-Demand

Self-paced learning, practical work and instructor support.

What does guided On-Demand mean?

Guided On-Demand combines self-paced learning with course-related instructor support. In SQLite Forensics On-Demand, you follow structured lessons, work through interactive byte-level exercises and use downloadable training databases in connected Capture the Flag (CTF) challenges.

How long do I have access to SQLite Forensics On-Demand?

You have 3 months of course access. The full course is equivalent to 24 hours of training, which you can work through and revisit during that access period.

Can I ask questions during SQLite Forensics On-Demand?

Yes. Course-related email support is included as you progress. The full SQLite Forensics On-Demand course also includes one complimentary, bookable one-hour instructor session during your course access period.

Do I need coding or advanced SQL experience for SQLite Forensics?

No. Basic digital forensic knowledge is helpful, but coding, scripting and advanced SQL experience are not required. The course explains SQLite structures visually and applies each concept through practical exercises.

Can I download the training files and practise in my own tools?

Yes. SQLite Forensics On-Demand includes downloadable SQLite databases, WAL, SHM and related training files so you can repeat exercises and compare results in your own forensic tools.

Should I choose the full course or a microcourse?

Choose the full SQLite Forensics course for a connected workflow covering database structures, recovery, WAL/SHM analysis and validation. A microcourse is a focused option when you need to concentrate on a particular topic, such as SQLite Data Structures or WAL Frames and SHM Index.

Explore SQLite On-Demand

03 / PROFESSIONAL DEVELOPMENT

Certificates & CPE

What your course documentation covers.

Will I receive a certificate and CPE credits?

The full SQLite Forensics course includes a certificate of completion and 24 CPE credits. Other courses have their own training hours and completion documentation, shown on their course pages.

What do I need to do to complete the SQLite course?

Complete the course requirements, including the knowledge checks and practical work. The course combines understanding SQLite structures with applying the techniques to forensic exercises; completion is not based only on watching the lessons.

Can I use the certificate for my professional records?

Yes. You can add your completed training to your CV, professional profile and internal training record. For CPE acceptance towards an external qualification, check with the relevant professional body. A course completion certificate does not automatically award a separate third-party certification.

View the full course

04 / APP-DATA FORENSICS

Firefly

Where Firefly fits into your forensic workflow.

What is Elusive Data Firefly?

Firefly is a forensic workspace for investigating application data after extraction. It helps examiners interpret, validate and report underlying app data, and recover additional data where the source supports it.

Does Firefly replace my extraction tool?

No. Firefly complements your existing extraction and forensic tools. It is designed for examining the underlying app data after it has been acquired, not for replacing device extraction.

What happened to SQLite Visualizer?

SQLite Visualizer's analysis and recovery workflows are now part of Firefly. Firefly builds on that SQLite foundation and extends the workspace to additional app-data formats. Existing customers can contact us with their licence details for help with their transition.

Which databases and data formats does Firefly support?

Firefly supports SQLite, including Encrypted SQLite (SQLCipher), RealmDB, LevelDB and IndexedDB, plus Apple Biome / SEGB. Available Analyzers and functions depend on your licence and the data format. Built-in viewers also support working with formats such as Plist, XML and JSON.

Can Firefly help with deleted or historical data?

Firefly can help examine and recover deleted or historical records where recoverable data remains in supported source files. Results depend on the database format, the available files and the condition of the data.

Recovery is not guaranteed. Data missing from a decoded view is not necessarily deleted, and findings need to be checked against the available source data.

How does Firefly help me validate and report findings?

Firefly helps you review findings against their source context, including the file, page and byte offset where applicable. You can inspect the underlying data and carry analysis context into interactive HTML reports for review and explanation.

Does Firefly upload my evidence to the cloud?

No. Firefly runs locally and does not send evidence data elsewhere. Its workflow uses read-only evidence handling and evidence-set validation. Contact us to discuss licensing and deployment for your particular environment.

Which operating systems does Firefly support?

Firefly is a Windows application supporting Windows 10 and 11, with native x64 and ARM64 builds. Contact us before ordering if you need to confirm compatibility with your workstation or organisation's deployment requirements.

Explore Firefly

05 / CHOOSING FIREFLY

Licensing & demos

Editions, licence terms and purchasing options.

What is the difference between Base + SQLite and All-Access?

Firefly Base + SQLite Analyzer includes the Firefly workspace, SQLite Analyzer and built-in viewers and utilities. RealmDB, LevelDB and IndexedDB Analyzers can be added separately. Firefly All-Access includes all four of these database Analyzers, together with the built-in viewers and utilities.

What licence terms are available?

Firefly is available with an annual licence (12 months). 1-month and 3-month licences are also available. Your quotation will confirm the edition, included Analyzers and licence period.

How do annual licence renewals work?

An annual licence covers a 12-month period. Contact us before the end of your term to arrange renewal. Your renewal quotation will confirm the licence options, price and applicable update and support terms.

Do you offer Government, Law Enforcement or team pricing?

Yes. Government and Law Enforcement discounts are available for eligible customers. Contact us to confirm eligibility and request a quotation. For a team quotation, please include the number of licences and the Analyzers you need.

Is a Firefly licence included with a training course?

Check the specific course offer or quotation for any included Firefly access, the available Analyzers and the licence term. Course access and software licensing are not the same thing. Contact us before ordering to confirm the right combination of training and software for your team.

Can I see Firefly before purchasing?

Yes. Book a personal live walkthrough and tell us which databases, workflows or challenges matter to your team. To discuss an evaluation licence, contact us so we can confirm the available setup and terms.

See Firefly live

06 / TOOLS & PRACTICAL HELP

Utilities & support

Backup2FS, VarInt Calculator and getting started.

What is Backup2FS, and is it free?

Backup2FS is a free Windows utility for normalising iOS backup content into a browsable file-system structure. It includes device information and selectable hash verification to support review of the extracted files. Read about Backup2FS.

Can Backup2FS process encrypted iOS backups?

Yes. Backup2FS 3.0 supports encrypted iTunes and Finder backups when you provide the backup password. It decrypts and normalises the backup into a browsable file system. This is not a password-bypass feature.

What does VarInt Calculator do?

VarInt Calculator helps you decode SQLite variable-length integers and examine record structures, including serial types and payload sizes. It is a focused utility for working with SQLite internals, not a replacement for a forensic analysis platform. Explore VarInt Calculator.

Is help available when I start using Firefly?

Yes. Contact us for help with setup, licensing or getting started. We can also discuss onboarding or additional training for your team. Your quotation will confirm any included onboarding.

How do I get help with a product or course?

Use our contact page or email contact@elusivedata.io. Include the product or course name and a brief description of the issue. For software questions, add your version and operating system. Please do not send case evidence or sensitive personal data without agreeing a suitable transfer method first.

Contact our team

Still have a question?

Tell us which course or product you’re considering and what you need to know. We’ll help you find the right next step.