Background to iOS File Systems
Apple continually updates their iOS operating system used on iPhone and iPad devices to increase the privacy and security of the end user which includes the employment of greater levels of encryption to prevent or restrict the amount of data that can be retrieved.
Within an iPhone or iPad, files are stored via file based encryption, meaning that there are unique encryption keys for each file. When a file is deleted, the encryption key is removed, preventing the recovery of the encrypted file.
This can make the recovery of deleted data impossible and can even increase the difficulty of retrieving live data particularly give that, as part of the operation of the device, Apple employs the use of SQLite databases to store user data.
SQLite Databases within iOS File Systems
Normally, when an entry is deleted within an SQLite database, the entry flag is changed to ‘Deleted’ yet the entry itself remains until the system defragments or removes that entry from the database.

Therefore, in earlier versions of iOS, it was possible to recover deleted data from SQLite databases, which may include iMessages, SMS messages or Internet history, stored contacts, ‘Notes’ and Internet Bookmark entries.
From iOS12, this possibility was reduced as Apple introduced a non-standard process within SQLite databases of the removal of deleted entries almost immediately, meaning that messages or Internet history are not recoverable soon after deleted as they have been wiped from the database rather than the entry only being made available.
However, it is still possible to recover some data from a later iOS based device. For example, when a user deleted a photograph or a video, the image is moved to a folder named ‘Recently Deleted’ that can be accessed within a directory named ‘Other Albums’.
Images moved to the ‘Recently Deleted’ folder are, therefore, not immediately deleted and are normally retained within that location for 30 days before eventually being removed. During that 30 day period the images remain accessible and can be retrieved, however, after the 30 days period when the are removed, they cannot then be recovered.
It may also be possible to recover data from the WAL files (write ahead logs), however, this would involve a full file system extraction which is only possible if the device can be jailbroken and is unlikely to include significant amounts of deleted data, if any.

About Athena Forensics
For information on our digital forensic services or if you require any advice or assistance please contact a member of our team on 0330 123 4448 or via email on enquiries@athenaforensics.co.uk, further details are available on our contact us page.
Our client’s confidentiality is of the utmost importance. All correspondence is treated with discretion, from initial contact to the conclusion of any computer forensic investigation.
Our digital forensics experts are fully aware of the significance and importance of the information that they encounter and we have been accredited to ISO 9001 for 10 years.
Our forensic experts are all security cleared and we offer non-disclosure agreements if required. Our premises along with our security procedures have been inspected and approved by law enforcement agencies.
Athena Forensics do not disclose personal information to other companies or suppliers.
https://athenaforensics.co.uk/service/computer-forensic-experts/
https://athenaforensics.co.uk/service/mobile-phone-forensic-experts/