Files that have been deleted can also be reconstructed, either partially or completely. The Windows operating system will not delete files when the user selects deletion. The operating system will mark the space a deleted file takes up in the Master File Table as available to write new files to. As a result, analysts may be able to view deleted files that have not been overwritten.
To view the deleted files on a system, click on the Deleted Files in the left pane.From here, the analyst can see all of the files that are marked for deletion:
From here, the analyst can search through deleted files.These files may hold evidentiary value. For example, in the case of malicious insider activity, if several sensitive files are found in the deleted files, all deleted within the same time period, it may be indicative of the insider attempting to cover their tracks by deleting suspicious files.