

Elusive Data announces Firefly, a new forensic workspace for app data investigations
Elusive Data announces Firefly, a forensic workspace for modern app data evidence, launching August 31 with recovery, validation and reporting workflows.
Verbeter uw gereedschapskist met duidelijkere, nauwkeurigere forensische analyse. Onze oplossingen zijn ontworpen als aanvulling op uw vertrouwde platforms en helpen u om scherper en nauwkeuriger te werken.
Leer hoe je uitgebreide digitale forensische workflows onder de knie krijgt door middel van meeslepende, praktijkgerichte training. Pas uw vaardigheden vol vertrouwen toe in echte onderzoeken.
One forensic workspace for app data investigations, built on provenance. Recover, interpret, validate and report evidence across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB, with every finding traceable back to its source. Launching August 31, 2026.
Decode SQLite variable-length integers and serial type codes in seconds. Calculate the storage length of strings and BLOBs, determine whether a record requires overflow pages, and identify how much of the payload is stored locally on the database page. Built for fast, script-free analysis of SQLite records and data structures.
Zet back-upgegevens van iOS om in georganiseerde, navigeerbare bestandsstructuren. Deze gratis Windows tool extraheert en normaliseert iTunes back-up inhoud, compleet met hash verificatie en apparaat metadata. Krijg toegang tot je back-upgegevens via een duidelijk, logisch bestandssysteem, klaar voor efficiënte analyse en rapportage.
Graaf diep in niet-ondersteunde apps met praktische SQLite-analyse. Gebruik Python om te scripten, automatiseren en extraheren wat tools missen. Krijg een technische voorsprong voor geavanceerd mobiel forensisch onderzoek.
Verken SQLite-databases grondig, de verborgen laag onder mobiele apps en besturingssystemen. Leer hoe je gegevens kunt extraheren, decoderen en interpreteren om gebruikersactiviteiten en forensische artefacten bloot te leggen.
Learn to manually decode pages, recover deleted records, and confidently validate your findings. Perfect when you need precise, court-ready evidence.
Learn to examine WAL frames and SHM indexes to recover deleted, and pre-checkpoint records and reconstruct transaction timelines. Uncover app activity that automated tools may not show.


Learn when it works for you. 24/7 access to interactive lessons, practical exercises, and real-world forensic scenarios. Work through each module at your own pace.


Neem deel aan live sessies vanaf elke locatie. Stel vragen, probeer technieken uit en leer door te doen. Alle energie van het klaslokaal, zonder het woon-werkverkeer.


Leer persoonlijk van deskundige forensische praktijkmensen door middel van praktijkgerichte labs die zijn ontworpen om diepgaande, praktische vaardigheden op te bouwen.
Deze gratis gids biedt een praktische doorloop van GPT-gepartitioneerde schijven, waarbij de beschermende MBR, GPT-header en Partition Entry Array worden behandeld. Het is ontworpen om forensische professionals te helpen schijfstructuren te begrijpen, gegevens te herstellen en bewijs te valideren.
Deze handleiding biedt een praktische handleiding voor forensisch analisten die te maken hebben met versleutelde Apple notities in iOS 16.x. De handleiding richt zich op het identificeren en ontsleutelen van vergrendelde notities die zijn opgeslagen in de NoteStore.sqlite-database die uit iOS-back-ups is gehaald.
Zeer goede cursus! Ongelooflijk goede leraar en ik denk dat afstandsonderwijs minstens zo goed werkt als klassikaal! Nogmaals bedankt James! Geweldige balans tussen technische diepgang en hands-on labs. Ik vond het leuk dat we niet alleen op tools vertrouwden, maar ook onder de motorkap keken en de gegevens snapten. Het heeft me zeker geholpen om duidelijkere rapporten te schrijven en bevindingen uit te leggen aan onderzoekers.
Beste cursus die ik ooit heb gevolgd. Ik heb echt genoten van de week, heb veel geleerd en alles was duidelijk en makkelijk bij te houden. De labs voelden echt aan en waren zinvol, zelfs zonder veel ervaring. De instructeur legde alles zo duidelijk uit en maakte het allemaal behapbaar. Ik zou het absoluut aanraden aan iedereen die met mobiel forensisch onderzoek werkt.
Ik had niet verwacht dat ik hier zoveel plezier aan zou beleven. De manier waarop de instructeur dingen uitsplitste, vooral alle app-gegevens, maakte het echt leuk. James weet echt waar hij het over heeft en hield alles in beweging zonder ons te overweldigen. Ik heb echte technieken geleerd die ik op mijn werk kan gebruiken. Ga zo door, James!
Our courses sharpen the way you investigate digital and mobile evidence. You learn full workflows that go beyond tool buttons, working with raw data, decoding app artifacts, and practicing authentic case scenarios. Labs and CTF challenges give you confidence to handle live investigations under real conditions.
We offer two certification programs at the moment: SQLite forensisch onderzoeken Python voor mobiel forensisch onderzoek. Elk programma bouwt praktische vaardigheden op die je bestaande hulpmiddelen aanvullen en je helpen meer te zien, meer te vinden en nauwkeurige resultaten te leveren die standhouden in rapporten en rechtszalen.
Yes. The training has been fully updated to match the current forensic landscape. That includes support for modern iOS and Android environments, new app structures, updated CTF scenarios, and deep dives into advanced topics like SQLite freelist recovery and manual decoding of WAL/SHM files.
Our tools are built to meet today’s forensic challenges. They do not replace your trusted platforms, they extend them. Some give you quick answers when time is short. Others open up evidence in ways standard tools often miss.
VarInt rekenmachine
Decode variable-length integers instantly from SQLite databases. No scripts, no guesswork. Just clear values when you need them.
Backup2FS
Transform iOS backups into structured, navigable file systems with hashes and metadata preserved. From confusion to clarity in one step.
SQLite visualisatie
Analyze SQLite databases in depth. Visualize structures, follow deleted records across time, and recover hidden evidence from WAL, freelists and unallocated space. Built from years of training and investigations, SQLite Visualizer reveals what standard tools often miss.
From August 31, SQLite Visualizer becomes part of Ontwijkende Datasprinkhaan, carrying the workflow into a broader forensic workspace for modern app data investigations.
Ontwijkende Datasprinkhaan
Launching Augustus 31, Vuurvliegje is built voor de work that begins after extraction. It brings SQLite, RealmDB, LevelDB, IndexedDB en Apple Biome / SEGB into one workspace. Herstellen what remains in de data, interpreteren it in context, validate findings against de source, en report with a clear path terug naar de file, page en byte offset.
Together, these tools give you sharper insight, clearer reporting and source-backed findings you can stand behind in real investigations.
We first built SQLite Visualizer because we needed a clearer way to investigate SQLite in real cases. The same questions kept coming back: what was deleted, when did it change, where did this record come from, and how can I explain it in a report?
SQLite Visualizer filled that gap for SQLite. It shows deleted records frame by frame, maps schema relationships visually, and recovers data from WAL, freelists and unallocated space. Built from casework and refined in hands-on labs, it makes database analysis faster, clearer and easier to explain.
Firefly takes that same idea further. SQLite is still central, but modern app evidence lives across RealmDB, LevelDB, IndexedDB, Apple Biome / SEGB, BLOBs, timestamps, sidecars and nested structures. Firefly brings that work into one forensic workspace after extraction, so examiners can recover what remains, interpret it in context, validate it against the source and report findings with a clear path back.
From August 31, SQLite Visualizer becomes part of Elusive Data Firefly.
Our tools are built around the questions forensic examiners actually need to answer. It is not enough to show a decoded value. You need to understand where it came from, how it was recovered, and whether you can explain it when the finding is reviewed.
SQLite Visualizer brought that approach to SQLite. It lets examiners follow database history in the WAL, explore schemas visually, move between structure and hex, and recover deleted data from WAL, freelists and unallocated space without losing context.
Firefly takes the same idea beyond SQLite. From August 31, SQLite Visualizer becomes part of Firefly, a broader forensic workspace for modern app data investigations across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB.
De belangrijkste mogelijkheden zijn:
WAL timeline analysis
See database history unfold record by record.
Visual schema navigation
Map tables and relationships as an interactive canvas.
Integrated hex and structure view
Move between records, pages, structures and bytes without losing the path back to the source.
Deleted-record recovery
Recover what remains in WAL, freelists, unallocated space and supported modern app databases.
Provenance and reporting
Validate findings against the source and carry the working view into reports.
Together, these capabilities give examiners a faster, clearer and more defensible way to work with app data. They help you move from decoded values to source-backed findings you can stand behind.
Je kunt de indeling kiezen die bij jouw doelen en schema past:
Micro-Cursussen: Korte, gerichte live sessies (60-90 minuten) over specifieke onderwerpen zoals GPT, SQLite en versleutelde apps - ideaal voor snel, praktisch leren.
Cursussen op aanvraag: 24/7 toegang tot gecertificeerde training in eigen tempo. Herhaal labs, volg begeleide oefeningen en pas technieken toe in je eigen tempo.
Live online cursussen: Neem in realtime deel aan lessen onder leiding van experts. Neem deel aan casusbesprekingen, stel vragen en voer labs uit met feedback van de docent.
Klassikale training: Leer face-to-face door middel van meeslepende sessies en hands-on labs onder leiding van ervaren professionals op het gebied van digitaal forensisch onderzoek.
Ja. Alle volledige cursussen bevatten een geverifieerd certificaat van voltooiing en CPE-credits, erkend door vele beroepsorganisaties.
Onze training ondersteunt alle ervaringsniveaus. Je kunt beginnen met basisvaardigheden zoals acquisitie en validatie, of je expertise verdiepen met geavanceerde technieken zoals het parsen van app-databases en scripts maken met Python voor forensische automatisering.
No. The tools are built to make complex forensic work easier to follow, verify and explain. Whether you are decoding VarInts, navigating an iOS backup or investigating database internals, the goal is to make the process clearer and faster without hiding the underlying evidence.
When you purchase SQLite Visualizer today, a one-hour onboarding session is included to help you get started. After August 31, the same applies to Firefly.
If you need more training, just contact us. We also offer advanced SQLite forensics training, including a certified course where the tools are used as part of the practical workflow.


Elusive Data announces Firefly, a forensic workspace for modern app data evidence, launching August 31 with recovery, validation and reporting workflows.


James Eichbaum on the idea behind Elusive Data Firefly, why provenance matters after extraction, and why honesty is a forensic feature.


SQLite forensics explained in simple terms. Learn how SQLite databases store data, where evidence is hidden, and why it matters in digital investigations.


Protobuf varints are not SQLite varints. Learn how to parse Protocol Buffer data from Apple Notes and mobile forensic artifacts, decode LEB128 varints step by step, and build a Python decoder with bitwise operations. Includes a hands-on XOR decryption challenge.


Making digital forensics training more accessible Elusive Data was founded in early 2024 with a clear purpose: to make advanced digital forensics training more accessible,


PRESS RELEASE Stockholm, Sweden – December 9, 2025 Elusive Data has officially released SQLiteVisualizer™, a next-generation forensicplatform that gives investigators unprecedented insight into how mobile


Small time-savers can make a big difference in mobile forensics.
That’s why VarInt Calculator is now available as a dedicated iOS app—bringing fast VarInt decoding and clear SQLite insights straight to your iPhone or iPad.


Er komt iets nieuws aan voor mobiel forensisch onderzoek Bij Elusive Data is onze missie altijd duidelijk geweest: forensische professionals helpen sneller, nauwkeuriger en efficiënter te werken.


Nieuwe cursus nu uit: Krijg als nooit tevoren controle over app-gegevens. Leer verborgen bewijs te ontdekken, te valideren en te verdedigen - zonder wachten, zonder reizen.
Bedankt voor de geweldige cursus! Ik snap nu eindelijk hoe ik moet werken met apps die niet worden ondersteund. Dat klikte tijdens deze cursus. Ik heb al een paar trainingen gedaan, maar deze sprong eruit omdat ik er meteen iets aan had. De docent legde uit hoe app-gegevens worden opgeslagen op een manier die logisch was, en ik waardeerde alle echte voorbeelden. Ik heb al een paar technieken gebruikt in een actueel geval.