IT Forensics · macOS

Forensic analysis of the macOS Trash – examining deleted and moved files

When a file is moved to the Trash, it is not necessarily physically removed from the file system during normal macOS operation. User-specific Trash structures may therefore contain relevant files and metadata. It is only when the Trash is emptied, or as a result of other system processes, that the conditions for a potential recovery change.

Enquire without obligation

From a forensic perspective, a careful distinction must be made between „moved to the Recycle Bin“, „Recycle Bin emptied“ and „physically overwritten or no longer recoverable“. These states are not technically equivalent.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We examine user-specific and – where relevant – volume-specific Trash structures for existing files, directories and metadata. File names, paths, timestamps and other file system information are correlated with FSEvents, APFS snapshots and other traces of activity.

If the Recycle Bin has already been emptied, a separate check is carried out to determine whether other forensic sources still contain any clues or data that can be reconstructed.

Typical areas of application

Investigation of deleted documents
Reconstruction of deletion processes
Insider trading and data leakage investigations
Search for files remaining in the Recycle Bin
Correlation with FSEvents and APFS snapshots
Checking deletion and modification periods
Judicial and non-judicial expert reports

This is how the forensic investigation is carried out

Once the backup has been completed, the relevant Recycle Bin directories for the user or volume context under investigation are identified. Existing objects are hashed, documented and analysed in the context of their file system.

No guarantees of recovery are given once the Recycle Bin has been emptied. APFS, SSD TRIM, encryption and subsequent use of the drive can significantly affect the chances of recovery.

Why is this area of investigation relevant to forensics?

The Recycle Bin is an important source when investigating which files a user had intended to delete or which items were still present before it was emptied.

However, an item in the Recycle Bin does not automatically prove the reason for its deletion or the identity of the person who deleted it. These questions require additional user and activity artefacts.

Frequently Asked Questions

Has a file in the Recycle Bin already been permanently deleted?+
Under normal circumstances, this is not strictly necessary at first. It is located in the Recycle Bin and may often still be there before the Recycle Bin is emptied.
Can an emptied Recycle Bin always be restored?+
No. In particular, APFS, SSD Trim, encryption and continued use may prevent recovery.
Does a file in the Recycle Bin reveal who deleted it?+
Not on its own. The user and session context must also be taken into account.
Can snapshots help with deleted files?+
Existing APFS or Time Machine snapshots may, in certain cases, contain earlier states.

LanCologne – macOS Forensics in Cologne

Do you need a professional investigation into deleted files or the macOS Trash? LanCologne can assist you with forensic-grade data recovery and technically sound reconstruction.

Get in touch now