

Elusive Data announces Firefly, a new forensic workspace for app data investigations
Elusive Data announces Firefly, a forensic workspace for modern app data evidence, launching August 31 with recovery, validation and reporting workflows.
One forensic workspace for app data investigations, built on provenance. Recover, interpret, validate and report evidence across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB, with every finding traceable back to its source. Launching August 31, 2026.
Decode SQLite variable-length integers and serial type codes in seconds. Calculate the storage length of strings and BLOBs, determine whether a record requires overflow pages, and identify how much of the payload is stored locally on the database page. Built for fast, script-free analysis of SQLite records and data structures.
iOS 백업 데이터를 체계적이고 탐색 가능한 파일 구조로 변환하세요. 이 무료 Windows 도구는 해시 확인 및 장치 메타데이터를 통해 iTunes 백업 콘텐츠를 추출하고 정규화합니다. 효율적인 분석과 보고를 위해 준비된 명확하고 논리적인 파일 시스템을 통해 백업 데이터에 액세스할 수 있습니다.
실습용 SQLite 분석을 통해 지원되지 않는 앱에 대해 자세히 알아보세요. Python을 사용하여 도구가 놓치는 부분을 스크립팅, 자동화 및 추출하세요. 고급 모바일 포렌식을 위한 기술적 우위를 확보하세요.
모바일 앱과 운영 체제 아래의 숨겨진 계층인 SQLite 데이터베이스를 심층적으로 살펴보세요. 데이터를 추출, 디코딩, 해석하여 사용자 활동과 포렌식 아티팩트를 발견하는 방법을 알아보세요.
Learn to manually decode pages, recover deleted records, and confidently validate your findings. Perfect when you need precise, court-ready evidence.
Learn to examine WAL frames and SHM indexes to recover deleted, and pre-checkpoint records and reconstruct transaction timelines. Uncover app activity that automated tools may not show.


Learn when it works for you. 24/7 access to interactive lessons, practical exercises, and real-world forensic scenarios. Work through each module at your own pace.


어디서나 라이브 세션에 참여하세요. 질문하고, 기술을 사용해보고, 직접 해보면서 배우세요. 출퇴근 없이도 강의실의 모든 에너지를 누릴 수 있습니다.


심층적이고 실용적인 기술을 쌓을 수 있도록 설계된 실습을 통해 전문 포렌식 실무자에게 직접 배워보세요.
이 무료 가이드는 보호 MBR, GPT 헤더 및 파티션 항목 배열을 다루는 GPT 파티션 디스크에 대한 실용적인 안내를 제공합니다. 포렌식 전문가가 디스크 구조를 이해하고, 데이터를 복구하고, 증거를 검증하는 데 도움이 되도록 설계되었습니다.
이 가이드는 iOS 16.x에서 암호화된 Apple 메모를 다루는 포렌식 분석가를 위한 실용적인 안내서입니다. iOS 백업에서 추출한 NoteStore.sqlite 데이터베이스에 저장된 잠긴 메모를 식별하고 암호를 해독하는 데 중점을 둡니다.
Our courses sharpen the way you investigate digital and mobile evidence. You learn full workflows that go beyond tool buttons, working with raw data, decoding app artifacts, and practicing authentic case scenarios. Labs and CTF challenges give you confidence to handle live investigations under real conditions.
We offer two certification programs at the moment: SQLite 포렌식및 모바일 포렌식을 위한 파이썬. 각 프로그램은 기존 도구를 보완하고 더 많이 보고, 더 많이 찾고, 보고서와 법정에서 견딜 수 있는 정확한 결과를 제공하는 데 도움이 되는 실용적인 기술을 구축합니다.
Yes. The training has been fully updated to match the current forensic landscape. That includes support for modern iOS and Android environments, new app structures, updated CTF scenarios, and deep dives into advanced topics like SQLite freelist recovery and manual decoding of WAL/SHM files.
Our tools are built to meet today’s forensic challenges. They do not replace your trusted platforms, they extend them. Some give you quick answers when time is short. Others open up evidence in ways standard tools often miss.
VarInt 계산기
Decode variable-length integers instantly from SQLite databases. No scripts, no guesswork. Just clear values when you need them.
Backup2FS
Transform iOS backups into structured, navigable file systems with hashes and metadata preserved. From confusion to clarity in one step.
SQLite 비주얼라이저
Analyze SQLite databases in depth. Visualize structures, follow deleted records across time, and recover hidden evidence from WAL, freelists and unallocated space. Built from years of training and investigations, SQLite Visualizer reveals what standard tools often miss.
From August 31, SQLite Visualizer becomes part of 찾기 힘든 데이터 반딧불이, carrying the workflow into a broader forensic workspace for modern app data investigations.
찾기 힘든 데이터 반딧불이
Launching 8월 31, 반딧불 is built 위를 더 work that begins after extraction. It brings SQLite, RealmDB, LevelDB, IndexedDB 그리고 Apple Biome / SEGB into one workspace. 복구 what remains in 더 data, 해석 it in context, validate findings against 더 source, 그리고 report with a clear path 뒤로 에 더 file, page 그리고 byte offset.
Together, these tools give you sharper insight, clearer reporting and source-backed findings you can stand behind in real investigations.
We first built SQLite Visualizer because we needed a clearer way to investigate SQLite in real cases. The same questions kept coming back: what was deleted, when did it change, where did this record come from, and how can I explain it in a report?
SQLite Visualizer filled that gap for SQLite. It shows deleted records frame by frame, maps schema relationships visually, and recovers data from WAL, freelists and unallocated space. Built from casework and refined in hands-on labs, it makes database analysis faster, clearer and easier to explain.
Firefly takes that same idea further. SQLite is still central, but modern app evidence lives across RealmDB, LevelDB, IndexedDB, Apple Biome / SEGB, BLOBs, timestamps, sidecars and nested structures. Firefly brings that work into one forensic workspace after extraction, so examiners can recover what remains, interpret it in context, validate it against the source and report findings with a clear path back.
From August 31, SQLite Visualizer becomes part of Elusive Data Firefly.
Our tools are built around the questions forensic examiners actually need to answer. It is not enough to show a decoded value. You need to understand where it came from, how it was recovered, and whether you can explain it when the finding is reviewed.
SQLite Visualizer brought that approach to SQLite. It lets examiners follow database history in the WAL, explore schemas visually, move between structure and hex, and recover deleted data from WAL, freelists and unallocated space without losing context.
Firefly takes the same idea beyond SQLite. From August 31, SQLite Visualizer becomes part of Firefly, a broader forensic workspace for modern app data investigations across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB.
주요 기능은 다음과 같습니다:
WAL timeline analysis
See database history unfold record by record.
Visual schema navigation
Map tables and relationships as an interactive canvas.
Integrated hex and structure view
Move between records, pages, structures and bytes without losing the path back to the source.
Deleted-record recovery
Recover what remains in WAL, freelists, unallocated space and supported modern app databases.
Provenance and reporting
Validate findings against the source and carry the working view into reports.
Together, these capabilities give examiners a faster, clearer and more defensible way to work with app data. They help you move from decoded values to source-backed findings you can stand behind.
목표와 일정에 맞는 형식을 선택할 수 있습니다:
마이크로 코스: GPT, SQLite, 암호화된 앱과 같은 특정 주제에 대한 짧고 집중적인 라이브 세션(60~90분)으로 빠르고 실용적인 학습에 이상적입니다.
온디맨드 코스: 24시간 연중무휴로 인증된 자기 주도형 교육에 액세스하세요. 실습을 다시 보고, 안내에 따라 연습하고, 나만의 속도로 기술을 적용해 보세요.
라이브 온라인 강좌: 전문가가 진행하는 수업에 실시간으로 참여하세요. 사례 토론에 참여하고, 질문하고, 강사의 피드백을 받아 실습을 완료하세요.
강의실 교육: 숙련된 디지털 포렌식 전문가가 진행하는 몰입형 세션과 실습을 통해 대면 학습을 진행합니다.
예. 모든 정규 과정에는 여러 전문 기관에서 인정하는 검증된 수료증과 CPE 학점이 포함되어 있습니다.
저희 교육은 모든 경험 수준을 지원합니다. 수집 및 유효성 검사와 같은 기본 기술부터 시작하거나 앱 데이터베이스 구문 분석, 포렌식 자동화를 위한 Python 스크립팅과 같은 고급 기술을 통해 전문성을 심화할 수 있습니다.
No. The tools are built to make complex forensic work easier to follow, verify and explain. Whether you are decoding VarInts, navigating an iOS backup or investigating database internals, the goal is to make the process clearer and faster without hiding the underlying evidence.
When you purchase SQLite Visualizer today, a one-hour onboarding session is included to help you get started. After August 31, the same applies to Firefly.
If you need more training, just contact us. We also offer advanced SQLite forensics training, including a certified course where the tools are used as part of the practical workflow.


Elusive Data announces Firefly, a forensic workspace for modern app data evidence, launching August 31 with recovery, validation and reporting workflows.


James Eichbaum on the idea behind Elusive Data Firefly, why provenance matters after extraction, and why honesty is a forensic feature.


SQLite forensics explained in simple terms. Learn how SQLite databases store data, where evidence is hidden, and why it matters in digital investigations.


Protobuf varints are not SQLite varints. Learn how to parse Protocol Buffer data from Apple Notes and mobile forensic artifacts, decode LEB128 varints step by step, and build a Python decoder with bitwise operations. Includes a hands-on XOR decryption challenge.


Making digital forensics training more accessible Elusive Data was founded in early 2024 with a clear purpose: to make advanced digital forensics training more accessible,


PRESS RELEASE Stockholm, Sweden – December 9, 2025 Elusive Data has officially released SQLiteVisualizer™, a next-generation forensicplatform that gives investigators unprecedented insight into how mobile


Small time-savers can make a big difference in mobile forensics.
That’s why VarInt Calculator is now available as a dedicated iOS app—bringing fast VarInt decoding and clear SQLite insights straight to your iPhone or iPad.


모바일 포렌식에 새로운 변화가 다가옵니다. Elusive Data의 사명은 항상 명확했습니다. 포렌식 전문가가 더 빠르고 정확하게 작업할 수 있도록 돕는 것입니다.


지금 새로운 과정을 시작하세요: 이전과는 전혀 다른 방식으로 앱 데이터를 제어하세요. 기다릴 필요도, 이동할 필요도 없이 숨겨진 증거를 발견하고, 검증하고, 방어하는 방법을 알아보세요.
훌륭한 강좌에 감사드립니다! 드디어 지원되지 않는 앱으로 작업하는 방법을 알게 되었습니다. 이 강의를 들으면서 깨달았어요. 이전에 몇 가지 교육을 받았지만 이 교육은 실제로 바로 유용했기 때문에 눈에 띄었습니다. 강사가 앱 데이터가 어떻게 저장되는지 이해하기 쉽게 설명해 주었고, 모든 실제 예제가 정말 좋았습니다. 현재 진행 중인 프로젝트에서 몇 가지 기술을 이미 사용했습니다.