Uncovering Deleted Items and File Existence in Digital Forensics.
- Feb 22, 2024
- 2 min read
Updated: Feb 28
When investigating digital forensics cases, confirming which files were deleted or previously existed is crucial. Whether tracking user activity or validating forensic evidence, understanding where and how to find artifacts plays a key role in uncovering the truth.
Many articles on my website discuss different deleted items and file existence artifacts.
However, putting them all together in a structured way helps streamline forensic investigations.
This article serves as a reference guide, consolidating various forensic artifacts that indicate deleted items and file existence, along with their advantages, disadvantages, and relevant analysis techniques.
----------------------------------------------------------------------------------------------------------
Thumbnail Cache (Thumbs.db / Thumbcache)
Artifact: Thumbs.db (Windows XP) and Thumbcache (Windows Vista and later)
Forensic Importance:Â Stores thumbnail previews of images and documents, even after deletion.
Article:
----------------------------------------------------------------------------------------------------------
Recycle Bin
Forensic Importance:Â Stores deleted files before permanent removal.
Article:
----------------------------------------------------------------------------------------------------------
User Typed Paths
Registry Path:Â HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths
Forensic Importance:Â Tracks file paths typed in the Windows Explorer address bar.
Article:
----------------------------------------------------------------------------------------------------------
Windows Search Database
Artifact:Â Windows.edb
Forensic Importance:Â Stores indexed metadata of files searched on the system.
Article:
----------------------------------------------------------------------------------------------------------
Search WordWheelQuery
Registry Hive:Â NTUSER.DAT
Registry
Key:Â NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQueryForensic Importance:Â
Stores user-searched keywords from the Start menu.
Analysis Tool:Â
Registry Explorer

----------------------------------------------------------------------------------------------------------
Conclusion
Analyzing deleted files and file existence artifacts plays a vital role in forensic investigations. By leveraging Windows registry artifacts, cache files, and search history, investigators can reconstruct user activity, track deleted files, and build a strong case with digital evidence. A structured approach to investigating these artifacts ensures efficiency and thoroughness in forensic analysis.
When investigating digital forensics cases, confirming which files are deleted or file existed is crucial. Whether tracking user activity or validating forensic evidence, understanding where and how to find artifacts plays a key role in uncovering the truth.
-------------------------------------------------Dean------------------------------------------------------

