Deleted files · Recycle Bin · recoverability · $I records · overwriting · TRIM
Deleted files and the Recycle Bin. Deleting a file removes the label, not the contents, until the space is reused; much of what people think is gone is not.
Deleting a file does not erase its contents. It removes the file's entry from the index and marks its space as available, but the data itself remains until that space is reused by something else, which is why deleted files are so often recoverable. The standard report recovers deleted files from the examined image and gives each a recoverability indicator, from fully intact to badly fragmented, so you can see at a glance which recovered files are complete. The Recycle Bin keeps its own records, in hidden $I files, of each item's original path, its size and the time it was deleted, so even where the content is gone the fact and timing of a deletion can be shown. The honest limits are two: data that has been overwritten by later use is unrecoverable, and on a modern SSD the drive's own TRIM housekeeping erases deleted data quickly, so recovery from an SSD is far more limited than from a traditional hard disk. The report is clear about which applies to your exhibit.
Rather talk it through? An engineer answers the bench line
0800 6890668
How recovery works, and where it stops.
When a file is deleted, the file system removes its directory entry and marks the clusters it occupied as free, but it does not touch the data in those clusters. Until the operating system reuses that space for another file, the data remains, and an examination can recover it. The recoverability indicator reflects how much of a deleted file's data is still intact and contiguous: a high value means the file is largely whole, a low value means later writes have reused some of its clusters and the recovery is partial.
The Recycle Bin adds a second layer. When a file is sent to the Recycle Bin, Windows stores a hidden $I record of its original path, its size and the time it was deleted, alongside the file's data in a $R file. Even when the Recycle Bin has been emptied, the $I records can often be recovered, so the examination can show what was deleted, from where, and when, which is frequently what matters, independent of whether the content survives.
Two limits are stated plainly in every relevant report. Overwriting: once the space a deleted file occupied has been reused, that file's data is gone, and no tool recovers it. SSD TRIM: a solid-state drive runs a housekeeping process that erases the contents of deleted blocks soon after deletion, so a deleted file on an SSD is often unrecoverable within a short time of being deleted, even though the same file on a traditional hard disk might be recovered months later. We identify which type of drive your exhibit is and what that means for recovery.
What it records, and what it means.
Describe your situation →| What is recorded | Where it comes from | What it shows, and does not |
|---|---|---|
| Deleted files recovered | The examined image, with a recoverability indicator | What was recovered; overwritten files are not recoverable |
| What was in the Recycle Bin | The $I and $R records | Original path, size and deletion time; even after emptying |
| When files were deleted | Recycle Bin $I times and the journal | When; not who deleted them |
| How complete a recovered file is | The recoverability indicator | Whether a partial file is usable; a low value means fragments |
From the exhibit arriving to the report.
Work we have closed →The first conversation, and the authority check Free
Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.
Imaging behind a write blocker, and the hashes
When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.
The examination, on the image
The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.
The report
The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.
From the bench
- Stop using the device immediately; every new file written reduces what can be recovered, especially on the drive holding the deleted data.
- Act faster still for an SSD; TRIM erases deleted data quickly, so time matters even more than on a hard disk.
- Ask what the $I records show; the fact and timing of a deletion can matter even where the content is gone.
Emptying the Recycle Bin removes the files but often leaves the $I records of what was in it: the original path, size and deletion time of each item.
What helps, and what harms.
Do this much first
- Stop using the device and keep it powered off
- Preserve it as it is; record who has held it
- Gather your proof of ownership or authority
- Tell us the questions you need answered
What sets us back
- Letting IT or anyone open it to have a look
- Reinstalling, wiping or running recovery software
- Carrying on using the device
- Assuming artefacts prove who was at the keyboard
Questions answered before you instruct.
Can you recover deleted files?
Often, yes, especially from a traditional hard disk, because deletion removes the pointer not the data until the space is reused. The report recovers deleted files and rates each for how complete it is. The limits are overwriting, which makes data unrecoverable, and, on an SSD, the TRIM feature, which erases deleted data quickly.
Why can you not recover deleted files from my SSD?
A solid-state drive runs a housekeeping process called TRIM that erases the contents of deleted blocks soon after deletion, so a deleted file on an SSD is often gone within a short time, even though the same file on a hard disk might be recovered much later. We identify whether your exhibit is an SSD and explain what that means for recovery, honestly.
The Recycle Bin was emptied. Is there any record?
Often, yes. Emptying the Recycle Bin removes the files, but the hidden $I records of what was in it, each item's original path, size and deletion time, can frequently be recovered, so the examination can show what was deleted and when even after emptying.
What does the recoverability indicator mean?
It reflects how much of a deleted file's data is still intact. A high value means the file is largely whole and should open normally; a low value means later writes have reused some of its space and only fragments remain. It lets you see at a glance which recovered files are complete.
What does it cost?
Deleted-file recovery is part of the standard forensic report, £800 + VAT for a one-disk system. The first conversation is free.
The record is on the device; preserve it first.
The first conversation is free. Tell us the situation and who owns the device, and we will tell you what the evidence can show, what it cannot, and whether we can take it on. Until then, stop using the device and preserve it as it is.