Popular
Guided On-Demand Training

SQLite Forensics Training On-Demand

Full 24 CPE course
Byte-level labs
WAL/SHM & deleted records
CTF challenges
Certificate
EUR 1,299
Email support + instructor session

Learn SQLite forensics at your own pace in Elusive Data’s flagship On-Demand course for app-data investigations. Built as a guided self-paced format, it combines expert-led lessons with interactive byte-level exercises, realistic app-data training files, downloadable SQLite databases and connected CTF challenges. You work through the SQLite structures investigators need to understand when app data has to be explained: WAL and SHM files, deleted records, freelists, overflow pages and raw bytes. Course-related email support is available as you progress.

Instructor: James Eichbaum
What do you mean by guided On-Demand?

The course is built to help you learn on your own schedule while still feeling supported. Lessons move in a clear sequence from explanation to practice, with interactive byte-level exercises, downloadable SQLite training files and connected CTF challenges that build the workflow step by step.

Will I be on my own during the course?

No. Course-related email support is included as you work through the material. If you want to go deeper into a topic or discuss questions with the instructor, you can also book one complimentary one-hour session during your course access period.

How long do I have access?

Course access is available for 3 months, giving you time to work through the lessons, revisit complex topics and practice with the downloadable training files at your own pace. After the course, you also receive a curated practice resource library to help you keep building the SQLite skills covered in the training.

Who built the course?

The course was designed and taught by James Eichbaum, Co-Founder and Head of Product and Training at Elusive Data. James has decades of digital forensic experience, including law enforcement casework, mobile device investigations, advanced forensic training and product development for forensic professionals. SQLite forensics is one of his core subjects, and this course reflects his focus on practical learning, source-level validation and helping investigators understand the data behind their findings.

Guided self-paced training

The practical feel of a live class. Built for On-Demand learning.

Work through deep SQLite forensic concepts on your own schedule, with structure, interaction, realistic training data and course-related support as you progress.

This course is designed to move you from explanation into forensic work. You inspect purpose-built SQLite training databases, then apply each technique through byte-level exercises and connected CTF challenges. Download the course files, test the same material in your own tools and follow up with course-related questions by email as you progress.

The format keeps the training practical and engaging while preserving the forensic depth Elusive Data is known for: recovery, validation, source-level interpretation and clear explanation. You leave with a repeatable workflow for explaining SQLite findings from the source, down to the file, page and byte offset.

What this video shows

The video gives a short look at how SQLite Forensics On-Demand is built: guided lessons, interactive byte-level exercises, purpose-built SQLite training databases, downloadable course files and connected CTF challenges.

The course format is designed to help investigators work through deep SQLite forensic concepts at their own pace while keeping the structure, support and practical depth Elusive Data is known for. Learners inspect SQLite databases, WAL and SHM files, deleted records, freelists, overflow pages and raw bytes, then apply the workflow through hands-on exercises and practical challenges.

Course-related email support is available as learners progress, and the full course includes 24 hours equivalent training, certificate of completion and 24 CPE credits.

Why Elusive Data On-Demand

Learn SQLite forensics by working through the data yourself

This On-Demand course helps investigators build practical SQLite forensic skill through guided lessons, purpose-built SQLite training databases, byte-level exercises and connected CTF challenges.

You learn how to move from decoded output to the SQLite data behind it, recover what remains, and validate findings from the source.

Guided self-paced format

Follow a structured On-Demand path designed for deep SQLite forensic training.

Purpose-built training files

Work with realistic app-data databases, WAL, SHM and sidecar files.

Connected CTF challenges

Apply each technique in one investigation story that builds through the course.

Source-level validation

Trace findings to the file, page and byte offset.

The value you leave with

A repeatable workflow for recovering, validating and explaining SQLite findings from the source, down to the file, page and byte offset.

Built for guided On-Demand learning

The course is designed to move you from explanation into forensic work. You inspect the data, apply the technique and reinforce the workflow through interactive exercises and practical challenges.

  • Interactive byte-level workbench inside the lesson
  • Downloadable SQLite, WAL, SHM and sidecar files
  • Ability to test the same material in your own tools
  • Connected CTF challenges that build the workflow step by step
  • Course-related email support from Elusive Data as you progress
Workbench and CTF challenges

Practice the SQLite forensic workflow before casework

The course turns SQLite concepts into practical forensic work. You inspect purpose-built SQLite training files, decode structures, recover findings and validate results from the source.

Inspect the training data

Work with SQLite databases, WAL, SHM and sidecar files used throughout the course.

Decode the structure

Follow records, pages, varints, payloads and byte-level context step by step.

Recover the finding

Locate deleted, residual, overwritten or fragmented SQLite data in practical exercises.

Validate the source

Trace the result back to the file, page and byte offset.

Connected CTF investigation

The CTF challenges connect the lessons into one investigation storyline, so you apply each SQLite forensic technique as part of a workflow rather than as an isolated task.

Why this format works

SQLite skills become stronger when you repeat the same forensic loop across new training files: inspect the data, recover the finding, validate the source and explain the result.

  • Practice directly with purpose-built SQLite training files
  • Download the same files and test them in your own tools
  • Apply each lesson through connected practical challenges
  • Build a repeatable workflow for SQLite forensic analysis
  • Use the workbench to support source-level validation
SQLite skills you build

Build the SQLite skills behind defensible findings

Learn how SQLite stores, changes and preserves app data, then use that understanding to recover deleted records, analyze WAL and SHM files, validate tool output and explain findings from the source.

Deleted record recovery

Recover records from freeblocks, freelists, residual structures and unallocated space.

WAL and SHM analysis

Interpret transaction activity, page versions, checkpoints and data outside the main database.

Records and varints

Decode record headers, serial types, payloads, values and byte-level structures.

Freelists and overflow pages

Follow fragmented records, BLOB content, overflow chains and recoverable page data.

Casework value

Move beyond decoded output by understanding where a SQLite finding came from, how it was recovered and how to validate it at source level.

What you can explain after the course

The goal is not to memorize SQLite terms. The goal is to explain what happened in the database and why the finding can be trusted.

  • Where a record was stored and how it was structured
  • How deleted SQLite data remained recoverable
  • What WAL and SHM activity can show
  • How overflow pages, BLOBs and fragments affect recovery
  • How to validate tool output against the source
Course path and pricing

When you want the complete SQLite workflow

SQLite Forensics On-Demand is the full training path for investigators who want practical confidence with SQLite structure, recovery, WAL/SHM analysis, validation and source-backed explanation.

On-Demand course price
EUR 1,299 per student

Includes 24 hours equivalent training, 24 CPE credits, certificate of completion, interactive byte-level activities, downloadable SQLite training files, connected CTF challenges and course-related email support.

Complete SQLite workflow

Move from database structures to recovery, WAL/SHM analysis, validation and explanation.

Guided On-Demand format

Follow a structured course path designed for self-paced learning with support.

Hands-on practice

Work with interactive exercises, downloadable files and connected CTF challenges.

Professional record

Certificate of completion and 24 CPE credits for training documentation.

Your instructor

Learn from James Eichbaum

James Eichbaum is a well-known digital forensics instructor and practitioner with deep expertise in mobile forensics, SQLite analysis and investigative app-data workflows.

Over the past 17+ years, James has trained thousands of forensic professionals in more than 30 countries, with a consistent focus on practical skills, investigative accuracy and defensible forensic interpretation.

His background spans law enforcement casework, mobile device investigations, advanced forensic training and tool development. Before Elusive Data, James served as Global Training Manager at MSAB, where he developed and delivered advanced training for forensic professionals around the world.

In this On-Demand course, James guides you through SQLite internals in a way that connects technical depth to casework: page structures, WAL and SHM activity, deleted record recovery, validation and source-backed explanation.

Teaching approach

James is known for making complex SQLite concepts understandable without making them shallow. The course follows a practical investigative workflow, so learners can see how each structure, recovery method and validation step supports a finding that needs to be explained.

FAQ

Questions before you start?

Answers for investigators, team leads and training approvers considering SQLite Forensics On-Demand.

For investigators and analysts

Practical questions about the On-Demand format, training files, course depth and what you will be able to do after the course.

01 What is included in the full On-Demand course? +

The full course includes 24 hours equivalent training, interactive byte-level exercises, downloadable SQLite training files, connected CTF challenges, course-related email support, a certificate of completion and 24 CPE credits.

02 Is this the same depth as live SQLite forensics training? +

Yes. The On-Demand course is built as the full SQLite Forensics training path, with the same focus on SQLite internals, recovery, validation, source-level interpretation and practical forensic explanation.

03 Do I need prior SQLite or SQL experience? +

Basic digital forensic knowledge is helpful, but advanced SQLite or SQL experience is not required. The course explains SQLite internals visually and applies each concept through forensic exercises.

04 Do I need coding or scripting experience? +

No. The course is designed for investigators, analysts and forensic teams. You work visually with database structures, records, pages, WAL and SHM files, raw bytes and validation workflows.

05 What training files do I work with? +

You work with purpose-built SQLite training databases, WAL files, SHM files and related sidecar files. The exercises cover deleted records, freelists, freeblocks, overflow pages, BLOBs, fragments and source-level validation.

06 Are the course files downloadable? +

Yes. The course includes downloadable SQLite training files so you can inspect the material yourself, repeat exercises and compare results in your own forensic tools.

07 Does the course include CTF challenges? +

Yes. The connected CTF challenges continue through the course as one investigation storyline. You apply each SQLite forensic technique in context rather than completing isolated exercises.

08 Does this help if I already use forensic tools? +

Yes. The course helps you validate tool output, investigate unsupported apps, understand what automated parsing is showing and explain findings from the underlying SQLite data.

What you leave with

A repeatable workflow for recovering, validating and explaining SQLite findings from the source, down to the file, page and byte offset.

For managers and training approvers

Questions about value, documentation, training records, course support and whether this is the right fit for a forensic team.

09 How much does the full On-Demand course cost? +

The full On-Demand SQLite Forensics course is EUR 1,299 per student. Focused microcourses are available separately for EUR 450 each.

10 Do learners receive a certificate and CPE credits? +

Yes. The full On-Demand course includes a certificate of completion and 24 CPE credits for professional records, audits, internal documentation and continuing education tracking.

11 Is this suitable for experienced examiners? +

Yes. The course is designed for professionals who need deeper SQLite understanding, including deleted record recovery, WAL and SHM analysis, validation, unsupported app data and source-level interpretation.

12 Why choose the full course instead of a microcourse? +

The full course is the complete SQLite forensic workflow. It connects structure-level analysis, deleted record recovery, WAL and SHM analysis, validation and explanation. The microcourses are focused modules for one topic area.

13 Can learners ask questions during the On-Demand course? +

Yes. On-Demand learners can contact Elusive Data with course-related questions while working through the material.

14 What makes this useful for a forensic team? +

The course helps create a shared SQLite forensic workflow across a team: how to inspect app databases, recover deleted data, validate findings, explain tool output and document source-backed conclusions.

15 How does this support review, reporting and quality assurance? +

Learners build the habit of tracing findings back to source data. That supports internal review, peer discussion, reporting and situations where an examiner needs to explain how a SQLite finding was recovered and validated.

16 How can I justify the training internally? +

Use the course outline and justification letter to explain the training value, course content, CPE credits and practical relevance for app-data investigations, unsupported databases, deleted records and forensic tool validation.

Need approval before enrolling?

Use the justification letter to explain the course value, CPE credits and practical benefits to a manager or training approver.

Interactive workbench

Inspect SQLite structures, records, pages and byte offsets directly inside the lesson.

Downloadable evidence

Use the same SQLite databases, WAL and SHM files in your own forensic tools.

Connected CTF investigation

Apply each lesson in one investigation story that builds through the course.

Source-backed validation

Trace findings back to the file, page and byte offset so results can be explained and verified.

What professionals say about this course

Akira H.

Digital Crime Analyst
⭐️⭐️⭐️⭐️⭐️
This course went way beyond expectations. The explanation of WAL/SHM structures and manual recovery workflows gave me confidence to challenge tool limitations in real investigations.

Renata S.

Mobile Forensics Consultant
⭐️⭐️⭐️⭐️⭐️
I’ve taken many trainings, but none as immersive and practical as this. The combination of hands-on labs, CTFs, and SQLite internals made it incredibly valuable for my work with Android app data.

Jeroen V.

Cybercrime Unit Investigator
⭐️⭐️⭐️⭐️⭐️
Rebuilding freelist pages manually and decoding varints helped me crack a case just weeks after the training. James has a rare ability to explain complex topics clearly and practically.

Related content

This focused walkthrough equips investigators with clear, hands-on techniques for extracting encrypted Apple Notes from iOS 16.x devices. You’ll follow a practical, step-by-step process designed to go beyond default tool output, giving you the insight and confidence to handle complex cases effectively.

Manually decoding VarInts can bottleneck your forensic process, especially when navigating inconsistent or unfamiliar databases. This tool speeds up interpretation, helping you stay focused on deeper analysis. It’s free to use and purpose-built for investigators working hands-on with SQLite internals.

Meet Firefly. One forensic workspace for app data investigations, built on provenance. Recover, interpret, validate and report evidence across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB, with every finding traceable back to its source.

This article shows how protobuf varints differ from SQLite varints and why that distinction matters in mobile forensics. It includes a full hands-on walkthrough of decoding a protobuf blob, extracting fields, and decrypting the final message.

A transformative, certified program designed to take digital forensic professionals from basic experience to confident Python proficiency. Newly updated for 2026, this hands-on training teaches you to build your own scripts to extract, parse, and analyze hidden evidence from app data.

When a single SQLite page can’t hold large content like images or media, that data spills into overflow pages. This guide walks you through how to manually recover fragmented records, revealing evidence that typical carving tools often overlook.

On-Demand SQLite forensics

Self-paced SQLite forensics training with structure, practice and depth.

This On-Demand course is built for investigators who want to learn SQLite forensics on their own schedule, with a format designed around guided lessons, realistic app-data training files, interactive exercises, connected CTF challenges and course-related email support.

Built to move you from explanation into forensic work.

The course is designed to make deep SQLite concepts easier to work through without reducing the forensic depth. You inspect purpose-built SQLite training databases, WAL and SHM files, deleted records, freelists, overflow pages and raw bytes, then apply each technique through byte-level exercises and connected CTF challenges.

Downloadable course files let you test the same material in your own tools. As you progress, course-related email support gives you a way to follow up with Elusive Data when questions come up during the training.

The format keeps the learning practical and engaging while preserving the depth Elusive Data is known for: recovery, validation, source-level interpretation and clear explanation of SQLite findings.

Practical outcome

A repeatable workflow for explaining SQLite findings from the source, down to the file, page and byte offset.

Structure

Guided path through SQLite internals and app-data analysis

Practice

Byte-level exercises and connected CTF challenges

Support

Course-related questions by email as you progress

Depth

Recovery, WAL/SHM, validation and source-level explanation

Start the full On-Demand course when you want the complete SQLite workflow.

Built for investigators, analysts and forensic teams who need practical confidence with SQLite databases, deleted records, WAL and SHM analysis, validation and source-backed findings.