Elusive Data Firefly logo

Coming August 31, 2026

One forensic workspace
for app data investigations.
Built on provenance.

Recover, interpret, validate and report app data evidence across SQLite, RealmDB, LevelDB,
IndexedDB and Apple Biome/SEGB, with every finding traceable back to its source.

Beyond decoding, the investigation continues

The step after extraction

Mobile devices create a constant stream of app data evidence. Extraction gets the data out. The next job is understanding what it means, where it came from and whether it can be trusted.

Apps change. Support can break overnight. Even supported apps can produce results that are incomplete or inaccurate.

Firefly gives examiners one workspace to recover, interpret, validate and report app data evidence, with a clear path back to the source.

Findings you can stand behind

What still remains

Decoded output does not always tell the whole story. Firefly helps you examine deleted records, BLOBs, timestamps, sidecars and nested structures across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB, giving you a more complete picture of the evidence.

Where it came from

Every finding traces back to the file, page and byte offset it came from. See how it was recovered. See how it was interpreted. Check it against the raw bytes. The source remains visible throughout the review, so every finding can be verified in context.

The original, left untouched

Firefly works from hash-verified copies validated with SHA-256. The original evidence is never altered. You can recover, review and report without changing the source.

Every app data investigation starts
in one place.

One workspace for SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB. Supported app databases open from the same launcher, so examiners work consistently across every format.

Follow the evidence back to its source​

Recover

Recover deleted, modified and replaced records where the data survives. See what surfaced each one, WAL files, journals, freelist pages, LevelDB logs, SSTables, deletion markers and residual RealmDB structures.

Interpret

Read records, artifacts, timestamps and location data in context, not as isolated values.

Validate

Trace findings back to the file, page and byte offset they came from, and check the interpretation against the source.

Report

Create interactive HTML reports that preserve the examiner’s working view: columns, aliases, interpreted timestamps and sort order.

Built for the databases modern apps use​

From database
to nested byte

Supporting files and nested data structures

Work with Apple Plists, Android Binary XML and layered app data using dedicated viewers and Firefly’s Tree Decoder. Recursively decode embedded Base64 Plists, gzipped Protobufs and other nested content without unpacking each layer by hand.

App databases

Analyze SQLite, RealmDB, LevelDB and IndexedDB in one forensic workspace, with shared viewers and a consolidated Hex Workbench.

Reporting and platform

Create interactive HTML reports that preserve the examiner’s working view. Windows 10 / 11 · .NET 9 · Native x64 and ARM64

Integrity and provenance

Read-only evidence handling. Source-context tracking. Evidence hash manifests. Optional tamper-evident activity logging.

Apple Biome / SEGB

Decode Biome streams, query with SEGBQL and extract patterns such as coordinates, URLs, emails, bundle IDs, addresses, phone numbers, search queries and device identifiers.

Built for teams who need
source-backed findings.

Firefly illustration for public safety and justice teams

Public safety & justice​

For examiners, investigators, prosecutors and defense teams who need source-backed findings they can stand behind in court.​

Firefly illustration for corporate enterprise and eDiscovery teams

Corporate enterprise
& eDiscovery

For forensic teams, eDiscovery examiners, litigation support and counsel who need clear, reviewable app data evidence.

Firefly illustration for military and intelligence teams

Military & intelligence​

For CID teams, field investigators and intelligence analysts who need fast access to app data findings, activity and location data, with source context.

Firefly at a glance

  • Deleted-record recovery across SQLite, RealmDB, LevelDB and IndexedDB
  • Recursive decoding of nested structures with Tree Decoder
  • 17 timestamp formats, confidence-ranked
  • Animated location route playback
  • Content decoders for Apple Binary Plist, NSKeyedArchiver plists, Android Binary XML, Base64, JSON and XML
  • Read-only evidence handling
  • SHA-256 evidence-set validation
  • Optional tamper-evident activity logging
  • Encrypted SQLite support with SQLCipher
  • Interactive HTML reporting
  • Runs locally. Evidence data is not sent anywhere.
  • Windows 10/11, native x64 and ARM64

– Any tool can show you a value. The real question is whether you can prove where it came from. That is what we built Firefly around: recover what was deleted, interpret it in context, and keep a clear path back to the source, so a finding holds up when it is questioned.

James Eichbaum
Head of Product & Training
Co-founder Elusive Data

sign up to join the launch webinar

See Firefly first.
Join the launch Webinar
August 31.

Register for the launch webinar on August 31, 2026. See the Firefly workspace, the recovery workflow, and how a finding traces back to its source.

TALK TO US BEFORE LAUNCH

Questions, demos or early conversations?

Have a question, want to book an early demo, or need to speak with us before launch? Send us a note and we’ll get back to you.

FAQ

Frequently Asked Questions

One forensic workspace for app data investigations, built on provenance. It is made for the work that begins after extraction: recovering, interpreting, validating and reporting the data inside the databases modern apps run on.

No. Extraction gets the data off the device. Firefly is what you do with it afterwards. It complements your existing toolkit.

SQLite, including encrypted SQLite, RealmDB, LevelDB and IndexedDB.

It recovers records where the data survives, and shows the mechanism that surfaced each one. Firefly shows its work rather than promising more than the data supports.

Firefly keeps findings connected to their source context, so examiners can explain what was found, where it came from and how it was interpreted.

Pricing and licensing will depend on the team, use case and deployment needs. Contact us at contact@elusivedata.io and we will help you find the right option.

Elusive Data Firefly launches August 31, 2026. Register for the launch webinar above, download the brochure, or contact us at contact@elusivedata.io.