

Elusive Data announces Firefly, a new forensic workspace for app data investigations
Elusive Data announces Firefly, a forensic workspace for modern app data evidence, launching August 31 with recovery, validation and reporting workflows.
Migliorate il vostro kit di strumenti con analisi forensi più chiare e precise. Progettate per integrare le vostre piattaforme di fiducia, le nostre soluzioni vi aiutano a lavorare in modo più nitido e preciso.
Imparate a padroneggiare i flussi di lavoro completi della digital forensics attraverso una formazione pratica e coinvolgente. Applicate con sicurezza le vostre competenze in indagini reali.
One forensic workspace for app data investigations, built on provenance. Recover, interpret, validate and report evidence across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB, with every finding traceable back to its source. Launching August 31, 2026.
Decode SQLite variable-length integers and serial type codes in seconds. Calculate the storage length of strings and BLOBs, determine whether a record requires overflow pages, and identify how much of the payload is stored locally on the database page. Built for fast, script-free analysis of SQLite records and data structures.
Trasforma i dati di backup di iOS in strutture di file organizzate e navigabili. Questo strumento gratuito per Windows estrae e normalizza il contenuto del backup di iTunes, completo di verifica degli hash e dei metadati del dispositivo. Accedete ai vostri dati di backup attraverso un file system chiaro e logico, pronto per un'analisi e un reporting efficienti.
Scavate in profondità nelle applicazioni non supportate con l'analisi pratica di SQLite. Utilizzate Python per eseguire script, automatizzare ed estrarre ciò che gli strumenti non riescono a fare. Acquisite un vantaggio tecnico per un'analisi forense avanzata dei dispositivi mobili.
Esplorate a fondo i database SQLite, il livello nascosto sotto le app mobili e i sistemi operativi. Imparate a estrarre, decodificare e interpretare i dati per scoprire le attività degli utenti e gli artefatti forensi.
Learn to manually decode pages, recover deleted records, and confidently validate your findings. Perfect when you need precise, court-ready evidence.
Learn to examine WAL frames and SHM indexes to recover deleted, and pre-checkpoint records and reconstruct transaction timelines. Uncover app activity that automated tools may not show.


Learn when it works for you. 24/7 access to interactive lessons, practical exercises, and real-world forensic scenarios. Work through each module at your own pace.


Partecipate alle sessioni dal vivo da qualsiasi luogo. Fate domande, provate le tecniche e imparate facendo. Tutta l'energia dell'aula, senza gli spostamenti.


Imparate di persona da esperti forensi attraverso laboratori pratici progettati per costruire competenze pratiche e approfondite.
Questa guida gratuita fornisce un'analisi pratica dei dischi con partizione GPT, coprendo l'MBR protettivo, l'intestazione GPT e il Partition Entry Array. È stata progettata per aiutare i professionisti forensi a comprendere le strutture dei dischi, a recuperare i dati e a convalidare le prove.
Questa guida fornisce una guida pratica per gli analisti forensi che si occupano di Apple Notes crittografate in iOS 16.x. Si concentra sull'identificazione e la decrittografia delle note bloccate memorizzate nel database NoteStore.sqlite estratto dai backup di iOS.
Un corso molto buono! Insegnante incredibilmente bravo e credo che l'apprendimento a distanza funzioni almeno quanto quello in classe! Grazie ancora James! Ottimo equilibrio tra profondità tecnica e laboratori pratici. Mi è piaciuto il fatto che non ci siamo affidati solo agli strumenti, ma abbiamo guardato sotto il cofano e dato un senso ai dati. Mi ha sicuramente aiutato a scrivere relazioni più chiare e a spiegare i risultati agli investigatori.
Il miglior corso che abbia mai frequentato. Mi sono davvero divertito durante la settimana, ho imparato moltissimo e tutto era chiaro e facile da seguire. I laboratori erano reali e avevano senso, anche senza molta esperienza. L'istruttore ha spiegato le cose in modo così chiaro e ha reso tutto gestibile. Lo consiglierei assolutamente a chiunque lavori con la mobile forensics.
Non mi aspettavo di divertirmi così tanto. Il modo in cui l'istruttore ha suddiviso le cose, in particolare tutti i dati delle applicazioni, ha reso il corso davvero divertente. James sa davvero il fatto suo e ha mantenuto le cose in movimento senza sopraffarci. Ho portato via tecniche reali che userò al lavoro. Continua a lavorare bene, James!
Our courses sharpen the way you investigate digital and mobile evidence. You learn full workflows that go beyond tool buttons, working with raw data, decoding app artifacts, and practicing authentic case scenarios. Labs and CTF challenges give you confidence to handle live investigations under real conditions.
We offer two certification programs at the moment: Forensics di SQLite, e Python per la mobile forensics. Ogni programma sviluppa competenze pratiche che integrano gli strumenti esistenti e aiutano a vedere di più, a trovare di più e a fornire risultati precisi che siano validi nei rapporti e nelle aule di tribunale.
Yes. The training has been fully updated to match the current forensic landscape. That includes support for modern iOS and Android environments, new app structures, updated CTF scenarios, and deep dives into advanced topics like SQLite freelist recovery and manual decoding of WAL/SHM files.
Our tools are built to meet today’s forensic challenges. They do not replace your trusted platforms, they extend them. Some give you quick answers when time is short. Others open up evidence in ways standard tools often miss.
Calcolatrice VarInt
Decode variable-length integers instantly from SQLite databases. No scripts, no guesswork. Just clear values when you need them.
Backup2FS
Transform iOS backups into structured, navigable file systems with hashes and metadata preserved. From confusion to clarity in one step.
Visualizzatore SQLite
Analyze SQLite databases in depth. Visualize structures, follow deleted records across time, and recover hidden evidence from WAL, freelists and unallocated space. Built from years of training and investigations, SQLite Visualizer reveals what standard tools often miss.
From August 31, SQLite Visualizer becomes part of Luci-luce elusiva, carrying the workflow into a broader forensic workspace for modern app data investigations.
Luci-luce elusiva
Launching Agosto 31, Lucciola is built per il work that begins after extraction. It brings SQLite, RealmDB, LevelDB, IndexedDB e Apple Biome / SEGB into one workspace. Recuperare what remains in il data, interpretare it in context, validate findings against il source, e report with a clear path Indietro a il file, page e byte offset.
Together, these tools give you sharper insight, clearer reporting and source-backed findings you can stand behind in real investigations.
We first built SQLite Visualizer because we needed a clearer way to investigate SQLite in real cases. The same questions kept coming back: what was deleted, when did it change, where did this record come from, and how can I explain it in a report?
SQLite Visualizer filled that gap for SQLite. It shows deleted records frame by frame, maps schema relationships visually, and recovers data from WAL, freelists and unallocated space. Built from casework and refined in hands-on labs, it makes database analysis faster, clearer and easier to explain.
Firefly takes that same idea further. SQLite is still central, but modern app evidence lives across RealmDB, LevelDB, IndexedDB, Apple Biome / SEGB, BLOBs, timestamps, sidecars and nested structures. Firefly brings that work into one forensic workspace after extraction, so examiners can recover what remains, interpret it in context, validate it against the source and report findings with a clear path back.
From August 31, SQLite Visualizer becomes part of Elusive Data Firefly.
Our tools are built around the questions forensic examiners actually need to answer. It is not enough to show a decoded value. You need to understand where it came from, how it was recovered, and whether you can explain it when the finding is reviewed.
SQLite Visualizer brought that approach to SQLite. It lets examiners follow database history in the WAL, explore schemas visually, move between structure and hex, and recover deleted data from WAL, freelists and unallocated space without losing context.
Firefly takes the same idea beyond SQLite. From August 31, SQLite Visualizer becomes part of Firefly, a broader forensic workspace for modern app data investigations across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB.
Le capacità principali includono:
WAL timeline analysis
See database history unfold record by record.
Visual schema navigation
Map tables and relationships as an interactive canvas.
Integrated hex and structure view
Move between records, pages, structures and bytes without losing the path back to the source.
Deleted-record recovery
Recover what remains in WAL, freelists, unallocated space and supported modern app databases.
Provenance and reporting
Validate findings against the source and carry the working view into reports.
Together, these capabilities give examiners a faster, clearer and more defensible way to work with app data. They help you move from decoded values to source-backed findings you can stand behind.
Potete scegliere il formato più adatto ai vostri obiettivi e al vostro programma:
Micro-corsi: Sessioni dal vivo brevi e mirate (60-90 minuti) su argomenti specifici come GPT, SQLite e applicazioni crittografate, ideali per un apprendimento pratico e veloce.
Corsi su richiesta: Accesso alla formazione certificata e autogestita 24 ore su 24, 7 giorni su 7. Riproducete i laboratori, seguite gli esercizi guidati e applicate le tecniche alla vostra velocità.
Corsi online dal vivo: Partecipate alle lezioni condotte da esperti in tempo reale. Partecipate alle discussioni sui casi, ponete domande e completate i laboratori con il feedback dell'istruttore.
Formazione in aula: Imparate faccia a faccia attraverso sessioni coinvolgenti e laboratori pratici condotti da professionisti esperti di digital forensics.
Sì. Tutti i corsi completi includono un certificato di completamento verificato e crediti CPE, riconosciuti da molti organismi professionali.
La nostra formazione supporta tutti i livelli di esperienza. È possibile iniziare con competenze fondamentali come l'acquisizione e la convalida, oppure approfondire le proprie conoscenze con tecniche avanzate come il parsing dei database delle app e lo scripting con Python per l'automazione forense.
No. The tools are built to make complex forensic work easier to follow, verify and explain. Whether you are decoding VarInts, navigating an iOS backup or investigating database internals, the goal is to make the process clearer and faster without hiding the underlying evidence.
When you purchase SQLite Visualizer today, a one-hour onboarding session is included to help you get started. After August 31, the same applies to Firefly.
If you need more training, just contact us. We also offer advanced SQLite forensics training, including a certified course where the tools are used as part of the practical workflow.


Elusive Data announces Firefly, a forensic workspace for modern app data evidence, launching August 31 with recovery, validation and reporting workflows.


James Eichbaum on the idea behind Elusive Data Firefly, why provenance matters after extraction, and why honesty is a forensic feature.


SQLite forensics explained in simple terms. Learn how SQLite databases store data, where evidence is hidden, and why it matters in digital investigations.


Protobuf varints are not SQLite varints. Learn how to parse Protocol Buffer data from Apple Notes and mobile forensic artifacts, decode LEB128 varints step by step, and build a Python decoder with bitwise operations. Includes a hands-on XOR decryption challenge.


Making digital forensics training more accessible Elusive Data was founded in early 2024 with a clear purpose: to make advanced digital forensics training more accessible,


COMUNICATO STAMPA Stoccolma, Svezia – 9 dicembre 2025 Elusive Data ha ufficialmente rilasciato SQLiteVisualizer™, una piattaforma forense di nuova generazione che offre agli investigatori una visione senza precedenti di come i dispositivi mobili


Small time-savers can make a big difference in mobile forensics.
That’s why VarInt Calculator is now available as a dedicated iOS app—bringing fast VarInt decoding and clear SQLite insights straight to your iPhone or iPad.


La missione di Elusive Data è sempre stata chiara: aiutare i professionisti del settore forense a lavorare in modo più rapido, accurato e con un'ottima qualità.


Nuovo corso in uscita: Ottenere il controllo sui dati delle app come mai prima d'ora. Imparate a scoprire, convalidare e difendere le prove nascoste, senza attese né viaggi.
Grazie per l'ottimo corso! Finalmente ho capito come lavorare con le app non supportate. Questo corso mi ha permesso di capire come lavorare con le app non supportate. Ho seguito alcuni corsi in precedenza, ma questo si è distinto perché mi è stato utile fin da subito. L'istruttore ha spiegato come vengono memorizzati i dati delle app in modo sensato e ho apprezzato molto tutti gli esempi reali. Ho già utilizzato alcune tecniche in un caso attuale.