Alles wat je nodig hebt om zelf mobiele en app-gegevens te analyseren

Gecertificeerde SQLite forensische training, volledig programma

advanced level | 24 cpe's | updated 2026

Leer SQLite forensisch onderzoek through a certified, hands-on training course built for professionals investigating mobile app data. Updated for 2026, this course teaches you how to manually analyze and recover data that standard tools often miss, including deleted records, WAL files, and unallocated space.

De training is ontworpen rond realistische scenario's en nieuwe CTF-uitdagingen en richt zich op diepgaande forensische interpretatie, decodering op paginaniveau en praktische vaardigheden voor geavanceerde digitale onderzoeken.

Certified Training

Gecertificeerde SQLite Forensisch Training

Advanced SQLite forensics training for investigators who need to recover, decode, validate, and explain SQLite evidence from mobile apps and digital systems.

What you will learn

  • Understand SQLite internals, pages, records, freelists, and overflow structures
  • Analyze WAL/SHM files and reconstruct forensic timelines
  • Recover deleted data and rebuild records from fragments
  • Validate findings for reporting, review, and testimony
  • Apply practical workflows using SQLite Visualizer software

Who it is for

Forensic examiners, investigators, incident responders, and analysts who need to go beyond standard tool output and understand SQLite evidence at a deeper level.

Why teams choose it

  • Certificate of completion and 24 CPE credits
  • Built for modern mobile and app-based investigations
  • Hands-on labs with realistic forensic scenarios
  • Available On-Demand, Live Online, or Onsite
  • Bundled with SQLite Visualizer Basic or Advanced

Want the full syllabus or help choosing a training format?

Training Formats

Kies je trainingsformaat

Choose the delivery format that fits your team. Each training package includes certified SQLite Forensics training and a SQLite Visualizer license.

Certificate + 24 CPE credits
Hands-on labs and CTF challenges
SQLite Visualizer included
Not sure which training format is right? Ask us for a recommendation ⟶
Inhoud van de cursus - Gecertificeerd SQLite Forensisch Onderzoek
Leerresultaten

What You’ll Learn

Build the skills to interpret SQLite evidence with confidence — from raw database structures to deleted records, WAL activity, and court-defensible reporting.

Core Skills

  • Begrijpen hoe SQLite gegevens opslaat See how apps write, delete, and structure data inside SQLite databases.
  • Vol vertrouwen onbewerkte databasebestanden lezen Explore SQLite files manually without relying only on black-box tools.
  • Herstel verwijderde of verborgen gegevens Extract freelist content, overflow records, and fragments others often miss.
  • Use a repeatable forensic workflow Navigate unsupported databases and validate findings step by step.
  • Explain findings clearly Present what you found and how you found it in reports or testimony.

Included in Your Training

  • Realistic mobile app datasets Work hands-on with data based on practical forensic scenarios.
  • CTF-style forensic challenges Apply recovery and validation skills in structured practical exercises.
  • SQLite internals explained visually Learn headers, pages, freelists, overflow chains, WAL, and SHM step by step.
  • Flexible delivery formats Train on-demand, live online, or onsite depending on your team’s needs.
  • Certificate and 24 CPE credits Receive verifiable completion documentation for professional records.

Ready to explore the full training package?

Cursusinhoud

Training Modules

A practical, structured course covering SQLite fundamentals, database internals, deleted data recovery, and WAL/SHM analysis.

01 Inleiding tot SQLite Forensisch Onderzoek +
  • PLists en XML-bestanden begrijpen
  • Werken met base64-gecodeerde gegevens
  • Introduction to SQLite databases
  • Overzicht van protocolbuffers
  • De B-Tree-indeling verkennen
  • Quiz + Practicum inbegrepen
02 SQLite databasestructuur +
  • The database header
  • Page headers
  • Variable-length integers, or VarInts
  • Manual record parsing
  • Freeblocks en fragmentatie
  • Freelist pages and deleted data
  • Overflow pages and large record chains
  • Quiz + Practicum inbegrepen
03 SQLite-databases maken en ermee navigeren +
  • Creating tables and schema
  • Inserting and adding records
  • Running and analyzing SQL statements
  • Deleting records and forensic implications
  • Quiz + Practicum inbegrepen
04 Database Reconstructie en herstel +
  • Case study introduction
  • Structural analysis of SQLite files
  • Freeblock recovery techniques
  • Rebuilding freelist trunk pages
  • Recreating interior table leaf pages
  • Finalizing reconstruction
  • Quiz + Practicum inbegrepen
05 WAL & SHM Analysis +
  • Waarom SQLite WAL en SHM gebruikt
  • Dissecting the WAL file
  • Understanding SHM and page frame mapping
  • Visualizing WAL growth over time
  • Forensic use of WAL/SHM in investigations
  • Quiz + Practicum inbegrepen
Also Included

Wat er nog meer inbegrepen is

The course is designed to support practical learning, repeatable workflows, and defensible forensic analysis.

Interactive CTF Challenges Work through realistic forensic puzzles using mobile app data.
SQLite Visualizer Software Training packages include SQLite Visualizer Basic or Advanced.
Downloadable Labs Practice with deleted, fragmented, and overflowed SQLite content.
Expert Guidance Instructor support and guidance for course-related questions.
Flexible Access Choose on-demand, live online, or onsite delivery formats.
Certificate + CPE Receive a certificate of completion and 24 CPE credits.

Need help choosing the right training format?

Voor wie is deze cursus - Gecertificeerd SQLite Forensisch Onderzoek
Who It’s For

Built for Digital Forensic Professionals

This course is designed for investigators and analysts who need to go beyond standard tool output and interpret SQLite evidence with confidence, precision, and defensibility.

It’s especially valuable if you:

  • Work with mobile app data Analyze SQLite evidence from iOS, Android, and other app-based sources.
  • Need to validate tool output Understand what commercial tools found — and what they may have missed.
  • Investigate unsupported apps Build confidence working with databases that are not fully parsed by existing tools.
  • Recover deleted or hidden evidence Extract deleted records, freelist content, overflow data, WAL activity, and fragments.
  • Prepare reports or expert opinions Explain database artifacts clearly for review, reporting, testimony, or court.
  • Want structured, expert-led training Learn SQLite forensics through a practical workflow rather than isolated theory.
Geen codering of scripts nodig.

The course is designed for investigators — not developers. Techniques are visual, practical, and explained step by step.

Want to see the full course outline?

Why It’s Different

Practical, Visual, and Case-Focused

This course is built to develop real forensic capability. You’ll work hands-on with realistic data, solve investigative challenges, and learn how SQLite behaves in real cases.

CTF-Style Challenges Solve forensic puzzles, decode structures, and uncover hidden SQLite evidence.
SQLite Visualizer Included Use visual workflows to examine pages, records, WAL activity, and deleted data.
Step-by-Step Recovery Labs Practice recovery from freelist pages, overflow chains, WAL frames, and fragments.
Realistic Datasets Train with instructor-created examples based on modern apps and case scenarios.
Tool-Agnostic Skills Use your existing tools while learning how to validate and explain the underlying data.
SQLite Internals Master B-Trees, VarInts, serial types, freelists, overflow pages, WAL and SHM.
Premium Packages
Available as software + training bundles.

Choose On-Demand + Basic, On-Demand + Advanced, Live Online + Advanced, or Onsite + Advanced depending on your workflow and team size.

Not sure which training format fits your team?

Uw instructeur - Gecertificeerd SQLite Forensisch Onderzoek
Je instructeur

Learn From James Eichbaum

James Eichbaum is a seasoned digital forensics instructor and practitioner with deep expertise in mobile forensics, SQLite analysis, and real-world investigative workflows.

Over the past 17+ years, James has trained thousands of professionals in more than 30 countries, with a consistent focus on practical skills, investigative accuracy, and defensible forensic interpretation.

He has led advanced forensic training programs for law enforcement, defense, and private sector teams worldwide, including national police agencies and forensic labs.

In this certified course, James guides you step by step through SQLite internals — from page structures and WAL files to deleted data recovery and validation — using structured labs, realistic app data, and CTF-style challenges.

Maak verbinding met James op LinkedIn
Hoogtepunten carrière
  • 17+ years teaching digital and mobile forensics
  • Voormalig Global Training Manager bij MSAB
  • Californië P.O.S.T. Gecertificeerd instructeur
  • Former Detective, Sacramento Valley High Tech Crimes Task Force
  • Former Special Deputy U.S. Marshal, FBI Cyber Crimes Task Force
  • Recipient of HTCIA “Case of the Year” award

Want to review the full curriculum or discuss training options?

Certified SQLite Forensics

Practical Training for Real Casework

Built around real-world forensic problems, practical recovery methods, and clear interpretation of SQLite evidence.

James Eichbaum — digital forensics instructor teaching SQLite analysis to investigators
17+ Years teaching forensics
30+ Countries trained
24 CPE credits included
Trainingsaanpak

The course is designed to make complex SQLite structures easier to understand, validate, and explain — without requiring coding or scripting experience.

Opleidingsmogelijkheden - Gecertificeerd SQLite Forensisch Onderzoek

Kies je trainingsformaat

Choose the training format that fits your workflow. Each option includes Certified SQLite Forensics training and a SQLite Visualizer license.

Op aanvraag Self-paced

On-Demand + Basic

Certified self-paced training with Basic software

€1,490
$1,750 · CAD $2,400
Per deelnemer
  • Certified SQLite Forensics training
  • SQLite Visualizer Basic included
  • Online learning platform access
  • Hands-on labs & CTF-style challenges
  • Updates, support & onboarding
  • Certificate + 24 CPE credits
Best for self-paced training
with Basic software.
Contact Sales
Op aanvraag Self-paced

On-Demand + Advanced

Certified self-paced training with Advanced software

€1,950
$2,300 · CAD $3,125
Per deelnemer
  • Certified SQLite Forensics training
  • SQLite Visualizer Advanced included
  • LevelDB Viewer included
  • Online learning platform access
  • Hands-on labs & CTF-style challenges
  • Certificate + 24 CPE credits
Best for advanced analysis
and self-paced training.
Contact Sales
Online leven Instructor-led

Live Online + Advanced

Certified instructor-led remote training for teams

€2,290
Per deelnemer
Available for groups of 3+
  • Certified SQLite Forensics training
  • Instructor-led live online delivery
  • SQLite Visualizer Advanced included
  • LevelDB Viewer included
  • Real-time Q&A and guided labs
  • Certificate + 24 CPE credits
Best for teams that want
guided remote training.
Contact Sales
Onsite In-person

Onsite + Advanced

Certified in-person training for teams

From €3,890
Per deelnemer
Available for groups of 5+
  • Certified SQLite Forensics training
  • Onsite instructor-led delivery
  • SQLite Visualizer Advanced included
  • LevelDB Viewer included
  • Delivered at your location or partner-hosted venue
  • Certificate + 24 CPE credits
Best for larger teams
and partner-hosted training.
Contact Sales
Planning to train your whole team? We can help you choose the right training format based on group size, delivery preference, and software needs.
Get in touch for training options ⟶
Certificering - Gecertificeerd SQLite Forensisch Onderzoek
Certification

Certificate + 24 CPE Credits

Participants receive verifiable completion documentation designed for professional records, internal reporting, audits, and continuing education requirements.

Certificaat van voltooiing A signed, verifiable certificate confirming successful completion of the Certified SQLite Forensics Course.
24 CPE Credits Supports continuing education requirements for forensic, cyber, and investigative professionals.
Veilig en controleerbaar Each certificate is individually issued with identifying details suitable for documentation and audit purposes.
Wereldwijd relevant Designed for investigators and forensic teams working across law enforcement, corporate, and private sectors.
Professional Record
Built for defensible professional development.

The course is designed to support practical skills, formal training records, and repeatable forensic workflows that can be explained clearly.

Need confirmation about certification or CPE documentation?

Full Course Track

What You’ll Gain From the Full Course

A deep, practical training track for professionals who work with mobile extractions, forensic tools, app databases, and SQLite-based evidence.

Course Focus

Over three packed days — or through the self-paced format — you learn how to read, interpret, recover, and validate data directly from raw SQLite structures.

The training combines guided explanation with hands-on practice using realistic datasets, deleted records, freelist recovery, overflow content, WAL/SHM interpretation, and CTF-style forensic challenges.

The Full Course Includes

  • Handmatig decoderen van WAL- en SHM-bestanden
  • Herstel van freelist ketens en niet-toegewezen pagina's
  • Praktijkgerichte oefeningen met realistische datasets
  • SQLite Visualizer software included in Premium packages
  • CTF-style challenges designed for forensic use
  • 24 CPE credits en een verifieerbaar certificaat
Premium Packages
Available as software + training bundles.

Choose On-Demand + Basic, On-Demand + Advanced, Live Online + Advanced, or Onsite + Advanced depending on your workflow and team size.

Want help choosing the right training package?

FAQ - Gecertificeerd SQLite forensisch onderzoek
FAQ

Veelgestelde vragen

Answers to common questions about course format, access, certification, tools, labs, and Premium software + training bundles.

01 Hoe lang duurt het om de volledige cursus te volgen? +

Live: Drie volle dagen met sessies onder leiding van een instructeur, labs en interactieve casestudies.

On-demand: Same core content, but self-paced. Access terms may vary by package and delivery format.

02 Is the training updated for 2026? +

Yes — the course content is updated for 2026 and reflects current SQLite forensic workflows, modern app data, WAL/SHM analysis, and practical recovery scenarios.

03 Is het geschikt voor teams of training voor het hele agentschap? +

Yes. Live Online training is available for groups of 3+, and Onsite training is available for groups of 5+. We can help recommend the right package based on team size and delivery preference.

04 Heb ik ervaring met databases nodig? +

No prior database expertise is required. The course starts from the ground up and explains SQLite internals visually, with practical labs and forensic use cases throughout.

05 Welke soorten labs zijn inbegrepen? +

Labs include parsing deleted records, rebuilding overflow chains, exploring WAL/SHM files, recovering fragmented content, and solving scenario-based challenges using realistic forensic datasets.

06 Wie geeft deze cursus? +

The course is taught by James Eichbaum, a digital forensics instructor and practitioner with 17+ years of experience training law enforcement, forensic examiners, DFIR consultants, and investigative teams worldwide.

07 What if I use tools like Magnet, Cellebrite, Oxygen, or MSAB? +

This course complements commercial forensic platforms. You learn how to validate tool output, investigate unsupported apps, and understand SQLite evidence beneath automated parsing results.

08 Wordt het certificaat erkend? +

Participants receive a verifiable certificate of completion with 24 CPE credits. It is designed for professional records, internal documentation, audits, and continuing education tracking.

09 Kan ik vragen stellen of ondersteuning krijgen tijdens de cursus? +

Yes. Live participants can ask questions during sessions. On-Demand participants receive support according to their package and access terms.

10 Zal ik dit kunnen toepassen in echte onderzoeken? +

Yes. The course is built around realistic app data, practical recovery workflows, and forensic scenarios that map directly to mobile and application database investigations.

11 Bevat de cursus uitdagingen in CTF-stijl? +

Yes. You work through CTF-style forensic challenges designed to reinforce technical SQLite concepts with practical investigation scenarios and realistic datasets.

12 Do I get access to SQLite Visualizer? +

Yes. Premium software + training bundles include SQLite Visualizer Basic or Advanced, depending on the selected package. Advanced packages also include LevelDB Viewer.

13 What training package options are available? +

There are four Premium software + training bundle options: On-Demand + Basic, On-Demand + Advanced, Live Online + Advanced, and Onsite + Advanced.

14 Hoe technisch is de cursus? +

It is a deep forensic course, but it is designed to be accessible. You go into SQLite internals such as WAL, B-Trees, VarInts, freelists, and overflow pages, with visual explanations and practical labs.

15 Met wat voor datasets ga ik werken? +

The labs use realistic app databases involving messaging, location, application activity, deleted records, WAL activity, fragmented content, and unsupported or partially parsed app data.

16 Is deze cursus geschikt voor experts? +

Yes. Experienced examiners, trainers, and tool specialists use the course to deepen their understanding of SQLite internals, deleted data recovery, and validation workflows.

17 Omvat het WAL- en SHM-analyses? +

Yes. WAL and SHM analysis are core parts of the course, including how to interpret database changes, reconstruct timelines, and identify data not present in the main database file.

18 Is de training leverancier-neutraal? +

Yes. The course focuses on SQLite forensic principles and validation methods that apply regardless of which forensic platform you use.

19 What background is recommended? +

Some experience in digital forensics, mobile analysis, DFIR, or investigative work is helpful. Coding, scripting, or prior database training is not required.

20 Kan ik deze kennis ook buiten de mobiele forensische wetenschap toepassen? +

Yes. SQLite is used in desktop applications, IoT devices, browsers, cloud sync tools, and many other systems. The recovery and validation skills apply anywhere SQLite appears.

Wat professionals over deze cursus zeggen

Akira H.

Analist digitale criminaliteit
⭐️⭐️⭐️⭐️⭐️
Deze cursus overtrof alle verwachtingen. De uitleg over WAL/SHM-structuren en handmatige herstelworkflows gaf me het vertrouwen om de beperkingen van tools aan te pakken in echte onderzoeken.

Renata S.

Mobiel Forensisch Adviseur
⭐️⭐️⭐️⭐️⭐️
Ik heb veel trainingen gevolgd, maar geen enkele zo meeslepend en praktisch als deze. De combinatie van hands-on labs, CTF's en SQLite internals maakte het ongelooflijk waardevol voor mijn werk met Android app data.

Jeroen V.

Onderzoeker Cybercrime-eenheid
⭐️⭐️⭐️⭐️⭐️
Het handmatig heropbouwen van freelistpagina's en het decoderen van varints hielpen me al weken na de training een zaak op te lossen. James heeft het zeldzame vermogen om complexe onderwerpen duidelijk en praktisch uit te leggen.

SQLite Visualizer.
Visualize, Decode, Explore. All-in-One SQLite Analysis Suite.

SQLite Visualizer was developed to enhance the way forensic professionals interact with SQLite data, both during training and in real investigations. This forensic suite was originally designed specifically for this course to complement the techniques you’ll learn and make advanced database analysis more accessible and efficient.

De suite brengt decodering, visualisatie en interpretatie samen in één interface. Het vereenvoudigt het werken met WAL-bestanden, varints, overflow-pagina's en gestructureerde records en helpt je om duidelijkere inzichten te krijgen in complexe gegevens van mobiele apps.

In de SQLite Forensics cursus gebruik je de tool tijdens de cursus in labs en real-world scenario's, en je houdt het na afloop. Het is een hulpmiddel waarop u kunt vertrouwen bij het onderzoeken van app-gegevens, het herstellen van verwijderde records of het nauwkeurig valideren van bevindingen.

This reflects our belief that effective training should leave you with practical skills and the tools and methods to apply them right away.

ED SQLite Visualizer — forensic SQLite analysis tool showing database structure, WAL frames and deleted record recovery
SQLITE forensisch onderzoek
Mobile Forensics 2026

Why SQLite Still Matters in Mobile Forensics

SQLite remains the backbone of mobile app storage, powering everything from chat histories and location logs to app settings, cached media, and application artifacts.

Tools extract the data. SQLite knowledge explains it.

While forensic tools handle basic extraction well, they often stop short of revealing what is stored deeper inside database internals such as Write-Ahead Logs, overflow chains, freelists, or custom schemas unique to each app.

As mobile software evolves rapidly, examiners increasingly face situations where data is only partially decoded, misinterpreted, or missed altogether. Understanding the inner workings of SQLite has become essential for reliable mobile analysis.

This course was built with that reality in mind. You’ll learn how to break down SQLite at the structural level, recover data manually, interpret how records are organized, and spot patterns or anomalies that tools alone may not explain.

Practical outcome More control in complex or time-critical mobile investigations.

Related content

Deze gerichte walkthrough voorziet onderzoekers van duidelijke, praktische technieken voor het extraheren van versleutelde Apple Notes van iOS 16.x-apparaten. Je volgt een praktisch, stapsgewijs proces dat is ontworpen om verder te gaan dan de standaard output van tools, waardoor je het inzicht en vertrouwen krijgt om complexe zaken effectief af te handelen.

Het handmatig decoderen van VarInts kan een knelpunt vormen in je forensisch proces, vooral wanneer je door inconsistente of onbekende databases moet navigeren. Deze tool versnelt de interpretatie, zodat u zich kunt concentreren op diepere analyses. Het is gratis te gebruiken en speciaal gebouwd voor onderzoekers die hands-on werken met SQLite internals.

SQLiteVisualizer unifies visual exploration, decoding, SQL analysis, and deleted-data recovery into one seamless workflow. No exports, no tool switching, no lost context.

This article shows how protobuf varints differ from SQLite varints and why that distinction matters in mobile forensics. It includes a full hands-on walkthrough of decoding a protobuf blob, extracting fields, and decrypting the final message.

A transformative, certified program designed to take digital forensic professionals from basic experience to confident Python proficiency. Newly updated for 2026, this hands-on training teaches you to build your own scripts to extract, parse, and analyze hidden evidence from app data.

Wanneer een enkele SQLite-pagina geen grote inhoud zoals afbeeldingen of media kan bevatten, komen die gegevens terecht op overlooppagina's. In deze handleiding wordt uitgelegd hoe je gefragmenteerde records handmatig kunt herstellen, waarbij bewijsmateriaal wordt onthuld dat typische snijgereedschappen vaak over het hoofd zien.

blijf op de hoogte

Blijf op de hoogte. Meld je aan voor onze maandelijkse nieuwsbrief.

Hoor als eerste over nieuwe trainingsmogelijkheden, gratis tools, blogposts over casussen en praktische inzichten. Onze maandelijkse nieuwsbrief is gemaakt om je te helpen sneller te leren, cases slimmer op te lossen en bij te blijven in een vakgebied dat nooit stilstaat.

Vul je e-mailadres in om je aan te melden.

Request Training

Deze aanvraag is volledig vrijblijvend. Laat ons weten welke data voor jou geschikt zijn en met hoeveel deelnemers je wilt komen. We nemen zo snel mogelijk contact met je op om samen de beste opties te bespreken.

This SQLite forensics training is designed for digital forensics investigators who need to go beyond tool output. You’ll learn to manually parse SQLite database structures including B-tree pages, cell arrays, freelist pages, overflow chains, WAL files, SHM data, VarInt encoding, freeblock recovery, and protocol buffer interpretation. Whether you are investigating mobile device data, app databases, browser artifacts, or cloud-synced SQLite files, the course gives you the skills to extract, validate, and explain SQLite evidence with confidence. SQLite Visualizer is included with training packages to support hands-on analysis throughout the course.

Liever leren in uw eigen tempo?

Beschikbaar on-demand →