One forensic workspace for app data investigations, built on provenance. Recover, interpret, validate and report evidence across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB, with every finding traceable back to its source.
Instantly decode variable-length integers from SQLite databases, identifying the lengths of cells, strings, and blobs. This utility converts varint hex values to decimal in seconds, perfect for analyzing app databases and parsing records for accurate serial type decoding.
Transform iOS backup data into organized, navigable file structures. This free Windows tool normalizes iTunes backup content, complete with hash verification and device metadata. Access your backup data through a clear, logical file system ready for efficient analysis and reporting.
Our tools are built around real forensic workflows and the questions examiners need to answer after extraction. They complement the platforms you already use, helping you work with the underlying data when you need more context, deeper analysis or an independent way to verify a finding.
Firefly brings SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB into one forensic workspace for recovery, interpretation, validation and reporting, with a clear path back to the source.
SQLite Visualizer was our dedicated SQLite analysis and recovery tool. Its workflows and capabilities now form part of Firefly, extending the same approach into a broader app-data forensic workspace.
VarInt Calculator provides fast, script-free analysis of SQLite variable-length integers, serial type codes, payload sizes and overflow pages.
Backup2FS transforms iOS backups into structured, navigable file systems while preserving hashes, metadata and device information.
The common principle is simple: make the data easier to investigate without hiding how the result was reached.
We first built SQLite Visualizer because we needed a clearer way to investigate SQLite in real cases. The same questions kept coming back: what was deleted, when did it change, where did this record come from, and how can I explain it in a report?
SQLite Visualizer filled that gap for SQLite. It shows deleted records frame by frame, maps schema relationships visually, and recovers data from WAL, freelists and unallocated space. Built from casework and refined in hands-on labs, it makes database analysis faster, clearer and easier to explain.
Firefly takes that same idea further. SQLite is still central, but modern app evidence lives across RealmDB, LevelDB, IndexedDB, Apple Biome / SEGB, BLOBs, timestamps, sidecars and nested structures. Firefly brings that work into one forensic workspace after extraction, so examiners can recover what remains, interpret it in context, validate it against the source and report findings with a clear path back.
From August 31, SQLite Visualizer becomes part of Elusive Data Firefly.
Our approach is built around a simple forensic principle: a decoded value is only useful if you can understand how it was derived and trace it back to the underlying data.
Firefly keeps that source context visible throughout the investigation. Examiners can move between interpreted data, database structures and raw bytes, recover historical or deleted records, and review how a finding was surfaced before carrying that context into the report.
Key capabilities include:
Source traceability
Follow findings back to the underlying file, page and byte offset where applicable.
Integrated structure and hex analysis
Move between records, database structures and raw bytes without breaking the investigative context.
Deleted and historical data recovery
Examine what remains in SQLite WAL, rollback journals and freelists, as well as supported recovery workflows across RealmDB, LevelDB and IndexedDB.
Evidence integrity
Work with read-only evidence handling, evidence-set validation and file hashing as part of the forensic workflow.
Reporting with context
Preserve interpreted values, queries, timestamps, selected records and supporting context in interactive reports.
The result is a workflow designed to make important app-data findings easier to verify, review and explain.
No. The tools are built to make complex forensic work easier to follow, verify and explain. Whether you are decoding VarInts, navigating an iOS backup or investigating database internals, the goal is to make the process clearer and faster without hiding the underlying evidence.
When you purchase SQLite Visualizer today, a one-hour onboarding session is included to help you get started. After August 31, the same applies to Firefly.
If you need more training, just contact us. We also offer advanced SQLite forensics training, including a certified course where the tools are used as part of the practical workflow.