Back

Digital Forensics: Recovery of Deleted Digital Evidence

Digital forensics

Digital technologies are rapidly changing the way people communicate, do business, access health services, learn and govern, and the amount and complexity of cybercrimes are growing. Computers, cell phones, cloud-based systems, and other electronic devices routinely store information today that can be critical evidence in criminal and civil investigations. Digital forensics refers to the aspect of forensic sciences that involves the gathering, analysing, and processing of electronic evidence in a scientifically valid and legally acceptable way. A common misconception that many people have is that when a file is deleted from a computer, it is actually erased from the disk. What actually happens is that the operating system simply removes the pointer for that file in the file system, and hence the content is still there and can be recovered by forensic specialists until it is overwritten or deleted securely.

Understanding Cyber Forensics

Cyber forensics, also known as digital forensics, is a science-based discipline dedicated to the identification, preservation, acquisition, examination, analysis and presentation of digital evidence for investigative and judicial purposes. Its purpose is to recreate a digital event, determine digital user activity, collect electronic evidence, and preserve the integrity and authenticity of the evidence during the investigation. The NIST digital forensic framework and other standardized forensic methods prioritize a systematic approach to evidence recovery, including collection, examination, analysis, and reporting, to maintain the integrity and authenticity of the evidence recovered and its admissibility in court (Audita et al.,2025; NIST SP 800-86),

Digital evidence can come from many sources such as computer systems, mobile phones, portable storage devices, cloud-based services, virtual machines and network systems. Digital evidence differs from physical evidence because it is very susceptible to modifications, overwriting, encryption, and destruction. So, forensic tools and validated procedures are used to preserve the original data, ensure integrity through cryptographic hash values, recover deleted data without altering the source media, and create forensic images. Research always shows that following the standard forensic method is a crucial requirement to preserve the evidential value of retrieved digital artefacts and for them to be accepted in legal proceedings. (Craiger,2005; Wahyudi et al.,2018; Naveen et al., 2025)

What Is Happening When a File Is Deleted?

One of the important principles of cyber forensics is that deleting a file doesn’t really delete the data of the file. Most operating systems only drop the link between the file and the file system when you delete a file, and then they mark the part of the storage occupied by the file as free. All the data is stored on the storage medium and is not deleted until it is overwritten with new data. That is why a deleted file can be recovered using forensic recovery methods, especially if storage sectors are not used again (Audita et al.,2025; Craiger,2005).

The ability to recover deleted information can be determined by various factors such as the type of storage device, file system structure (FAT32, NTFS, ext4), how the data was deleted, and how long after deletion forensic acquisition took place. Typical characteristics of conventional hard disk drives (HDD) are generally that deleted data may still be physically present, resulting in a higher recovery success rate. Solid State Drives (SSDs), on the other hand, have methods in place that can permanently erase deleted information, which can make forensic recovery more difficult. Likewise, the use of secure deletion software, encryption and repeated overwriting reduces the chances of evidence being recovered (Sitompul et al., 2018; Naveen et al., 2025).

In order to preserve the evidence as much as possible, forensic investigators will make a bit-by-bit forensic image of the storage media before analysing it. Using the specialized forensic tools, the recovered image is then studied for evidence of deleted files, metadata analysis, unallocated space, and other digital artefacts which may be recovered without altering the original evidence. This way, the recovered evidence does not compromise and is not allowed to be used in court. (Audita et al., 2025; Wahyudi et al., 2018; NIST SP 800-86).

Recovering Deleted Digital Evidence Methods

Deleted digital evidence can be recovered using scientifically approved forensic methods that preserve the integrity of the evidence by recovering the information. The method of recovery will be based on the storage device, OS, structure of the file system and condition of the evidence. All investigators follow a well-established protocol to make sure that the recovery process is legal and valid, such as the NIST methodology. This approach is clearly structured to reduce contamination of evidence and guarantee recovered information is acceptable in court. (Audita et al., 2025; Wahyudi et al., 2018).

A popular method is file system analysis in which the file allocation tables, Master File Tables (MFT), directory structures and metadata are examined to discover deleted files and determine original file locations. If the files are not found in the file system or if the file system records are damaged, investigators use file carving to recover files without depending on the files’ directory information, only on the file signatures. It is a great way to retrieve deleted videos, documents, images and other multimedia files from unallocated space (Craiger, 2005; Sitompul et al., 2018).

Metadata analysis is another important technique, which looks at the metadata of files, including creation time, modification time, access history, ownership and storage location. Although the original file may be irretrievably lost, metadata may contain useful information about user actions and the sequence of digital events. Additionally, there are a number of studies that emphasize the significance of live acquisition and memory forensics, particularly with regard to encrypted systems or active applications, where passwords, active processes, network connections, encryption keys and more could be lost once the system is turned off (Naveen et al., 2025; Audita et al., 2025).

Recent research also shows that the deleted information can be retrieved from traditional hard drives, Android smartphones, virtual machines, cloud storage and removable media using specialized forensic tools and validated acquisition processes. The extent of success, however, is dependent on storage technology, overwriting activities, encryption technologies, and anti-forensic methods, making recovery technology specific to each investigation very important (Naveen et al., 2025; Sitompul et al., 2018; Audita et al., 2025).

Challenges in Recovering Deleted Digital Evidence

Although there are a number of developments in the field of digital forensic technologies, the recovery of deleted digital evidence is still a challenging and evolving problem. The reviewed studies agree that numerous technical and procedural issues are crucial in successful evidence recovery, such as the type of storage device, file system, deletion procedure, and condition of the storage media. The likelihood of recovery of deleted data is significantly reduced when new data is added to the disk, and this is why it is important to perform forensic acquisition in a timely manner for recovery of digital evidence (Audita et al., 2025; Sitompul et al., 2018).

Advanced storage methods are complicating forensic procedures. Traditional hard disk drives are now facing fewer problems with the rise of cloud storage, virtual environment, secured devices, and solid-state drives (SSDs) among users. Digital evidence may be erased or concealed with methods like TRIM, secure deletion, encryption, etc., which have made it difficult for traditional recovery techniques. Likewise, the variety of operating systems and file systems may mean that investigators need to customize their forensic methodology to suit the file system and operating system characteristics of each digital environment (Naveen et al., 2025; Wahyudi et al., 2018).

Future Directions

The literature reviewed shows that cyber forensics is an evolving discipline to cope with the new digital technologies and the increasingly complex cyber threats. Going forward, further studies will be aimed at developing advanced forensic tools and techniques to recover data from solid-state drives (SSDs), cloud storage, virtualized storage, Internet of Things (IoT) systems, and encrypted storage technologies, where traditional recovery methods are frequently insufficient. The importance of Artificial Intelligence (AI) and Machine Learning (ML) in automating evidence identification, file classification and anomaly detection and the impact on the ability to save time spent on investigation and the accuracy of the analysis, is also mentioned in several studies. Additionally, standardized forensic practices and interoperable forensic tools will help to increase the trustworthiness, repeatability, and admissibility of recovered digital evidence in court. Seamless and ongoing cooperation between the research community, practitioners, and law enforcement will be crucial to the success of cyber forensic investigations in the ever-changing digital world (Naveen et al., 2025; Audita et al., 2025; Wahyudi et al., 2018; NIST SP 800-86).

Conclusion

As a result of technological advances, cyber forensics has become an essential and undeniable part of the modern forensic investigation and has enabled investigators to retrieve and extract digital evidence that may have been deleted for good reason and would otherwise seem lost forever. The reviewed studies show that the application of standardized forensic methodologies, validated recovery techniques and appropriate forensic tools, in addition to the characteristics of the storage device and the file system, are key elements to successful evidence recovery. While technology-related issues like SSD, cloud computing, the employment of encryption, and anti-forensic methods are emerging at the forefront, continued research and methodological advancements are enhancing forensic investigators’ ability to recover digital evidence while maintaining its integrity and evidentiary value. As cybercrime is ever-changing and evolving, it will continue to be vital to have scientifically sound forensic practices in place and to keep investigative methods updated in order to ensure that recovered digital evidence can be used to effectively support criminal investigations and judicial proceedings.

Reference:

  1. Craiger, P. (2006). Recovering Digital Evidence from Linux Systems. In: Pollitt, M., Shenoi, S. (eds) Advances in Digital Forensics. DigitalForensics 2005. IFIP — The International Federation for Information Processing, vol 194. Springer, Boston, MA. https://doi.org/10.1007/0-387-31163-7_19
  2. Digital Forensic Analysis of Data Recovery in File Deletion Cases Using the National Institute of Standards and Technology (NIST) Method. (2025). Akiratech2(1), 9-19. https://doi.org/10.63935/akiratech.v2i1.99
  3. Wahyudi, E., Riadi, I., & Prayudi, Y. (2018). Virtual machine forensic analysis and recovery method for recovery and analysis of digital evidence. International Journal of Computer Science and Information Security16.
  4. Sitompul, O. S., Handoko, A., & Rahmat, R. F. (2018). File reconstruction in digital forensic. TELKOMNIKA (Telecommunication Computing Electronics and Control)16(2), 776-794.
  5. R, Naveen & A, Vijayarajan & P, Archana. (2025). Recovery of Deleted Files : Challenges and Techniques. International Journal For Multidisciplinary Research. 7. 10.36948/ijfmr.2025.v07i02.41088.

LEGAL DESIRE NEWSLETTER

Where the legal industry reads first.

Enjoyed this article? Get the biggest legal industry updates, deals, appointments, insights and expert interviews in your inbox, free.

No spam. Unsubscribe anytime.
Dopathi Nithin
Dopathi Nithin