AADF · SQLite and database forensics training

Advanced Applied Database Forensics (AADF)

Deep-dive database forensics: SQLite internals and deleted-record recovery (freeblocks, freelists, WAL and journals), SQL querying, Chromium SNSS, LevelDB, Realm and binary plists across Windows, Mac, Android and iOS.

Dates
22–26 Feb 2027
Duration
5 days, 08:00–17:00
Level
Advanced
Seats
Limited number of seats
SQLite and database forensics training – Advanced Applied Database Forensics (AADF)

Course overview

Delve into the intricate world of database forensics across multiple platforms with our comprehensive course. Learn to harness various applications and utilities to adeptly identify, process, understand, and exploit diverse database structures.

Gain invaluable insights into the functioning of databases, unravelling the intricate storage of records and fields of information essential for supporting front-end applications. Delve deep into SQLite, mastering techniques to recover deleted information from Freeblocks, Free Pages and page unallocated space within primary and journal files using sophisticated scripting techniques.

Explore a myriad of additional databases including SNSS Files, LevelDBs, Realm databases and Binary Plists, equipping yourself with a versatile skill set crucial for forensic investigations across various platforms. Throughout the course, students will examine data that can be found on a range of systems including Mac, Windows, Android, and iOS, providing a holistic understanding of database forensics across diverse environments. Hands-on labs and student exercises provide practical application of acquired knowledge, utilizing a blend of open-source and leading forensic applications. By engaging in multiple hands-on activities, participants refine their skills, gaining proficiency in examining key artifacts crucial for successful forensic investigations.

By the end of the course, participants will be equipped with advanced database forensics skills, ready to extract active and deleted data from databases across a wide range of systems with confidence and precision.

Who should attend

Examiners with intermediate or advanced forensic training who want to go beyond tool extractions and recover active and deleted data from databases.

Course modules (11)

Database Fundamentals
  • Relational vs NoSQL databases
  • Discuss relational database concepts
  • Learn about relationships between different database tables
  • Gain an understanding of database terminology
Introduction to SQLite Databases
  • SQLite Overview
  • Introduction to SQLite data files
  • Discuss different SQLite page types
  • Explore the main database file header
Navigating SQLite B-Trees
  • Introduction to SQLite B-Trees
  • Explore SQLite B-Tree Page Structures:
    • Define Page Header
    • Learn How to Interpret the Cell Pointer Array
    • Understand Page Unallocated Space
  • Navigating SQLite B-Trees:
    • Table Interior Page Cell Structures
    • Introduction to Decoding Varints
Examining SQLite B-Tree Leaf Pages
  • Exploring the structure of SQLite B-Tree Table Leaf Pages:
    • Mapping the Cell Content Area
  • Introduction to Decoding Cells:
    • Explore Freeblocks
  • Understand the concept of Secure_Delete
SQLite Overflow Pages & Freelist Pages
  • Learn how overflow pages are used:
    • Explore page structure
  • Learn how to identify freelist pages in a database:
    • Explore the freelist trunk page structure
    • Discuss the importance of freelist pages
Examining SQLite Journal Files
  • Learn how Rollback Journals Work
  • Examining Rollback Journals:
    • File Structure
    • Understanding Page Records
  • Learn how write-ahead logging works
  • Examining Write-Ahead Logs:
    • File Structure
    • Understanding WAL Frames
  • Understand the Forensic Relevance of SQLite Journal Files
SQLite Database Schema and Querying
  • Explore SQLite database schema:
    • Tables
    • Indexes
    • Triggers
    • Views
  • Discuss value of the information found in the schema when writing SQLite queries
  • Introduction to the SQLite query language
  • Learn how to construct queries to interrogate database tables:
    • Learn how to extract meaningful data
    • Learn how to join tables in a query
    • Explore process for converting datetime stamps
Chromium SNSS Files
  • Introduction to Chromium SNSS files
  • Understand the structure of the Session and Tab files
  • Extracting records from SNSS Files
LevelDB Analysis
  • Deep Dive into LevelDB structures
  • Understand how LevelDBs Work
  • Extracting Key Value pairs from LevelDBs
Examining Realm Databases
  • Introduction to Realm Database Structure
  • Working with Realm Databases
Apple Plist Files
  • Introduction to Plist Files
  • Review of HTML/JSON Plist Files
  • Decoding Binary Plists
  • Understand how to recognize obfuscated data inside a Binary Plist

Prerequisites

To get the most out of this class, you should:

  • Be familiar with the basics of digital forensics examinations and investigations
  • Understand basic data structures and methodologies beyond simple tool extractions
  • Attended a Spyder Forensics Intermediate or Advanced level training or similar program in the last 18 months

Tools and techniques

  • SQLite tools and scripts
  • open-source and leading commercial forensic applications

Class materials and software

You will receive a student manual, lab exercises and other class-related material.

The course will adhere to adult learning principles, employing training aids such as presentations, diagrams, and practical instructor-led examples. Each covered artifact will be presented in either one or two 50-minute sessions, followed by review questions. Students will have opportunities throughout the course to ask questions and delve into covered objectives in greater detail. Practical exercises will be assigned each day to reinforce the topics.

Certificate

Official e-DiFTA certificate

Every participant who passes the course receives an official e-DiFTA certificate confirming successful completion of the class and recognising the training hours completed.

Instructor

Damien Attoe

Damien Attoe

Senior Trainer / Developer – Director of Professional Services, Spyder Forensics

Damien Attoe is a digital forensics educator, course developer and practitioner with more than a decade of experience in digital forensics and eDiscovery. As a member of Spyder Forensics, he specialises in transforming complex forensic concepts into…

Full profile →

Frequently asked questions

What experience do I need for AADF?

You should know the basics of digital forensic examinations, understand data structures beyond simple tool extractions, and have attended Spyder Forensics Intermediate or Advanced training (or a similar programme) in the last 18 months.

Who can attend this course?

Attendance is intended exclusively for law enforcement personnel, military personnel engaged in digital forensic activities and private-sector investigators.

What is included in the €2,500 fee?

Five days of hands-on training (08:00–17:00), an official certificate of successful completion recognising the training hours, a buffet lunch and morning and afternoon coffee breaks every day.

How are seats allocated?

Seats are limited and allocated on a “first paid – first confirmed” basis. Your registration is confirmed once payment is received; the payment deadline is 25 December 2026.

Do I receive a certificate?

Yes. Every participant who passes the course receives an official e-DiFTA certificate confirming successful completion of the class and recognising the training hours completed.

Is VAT charged?

Invoices are issued from France. Private individuals and organisations in France pay French VAT (20%). Organisations outside France are invoiced without French VAT when they provide a valid VAT number, TIN or EIN. Full VAT rules.

Related courses

All 8 courses →
€2,500AADF · 22–26 Feb 2027
Register →