Skip to content

Recycle Bin

Data Type: recycle_bin
Python Parser: RecycleBin

Description

Each row represents Recycle Bin metadata for a deleted item, with original path, item size, deletion time, and format header. Use it to place a file or directory in a deletion timeline and correlate its former location with filesystem records. It does not identify the actor or prove permanent deletion, and metadata may be absent after cleanup or bypassing the Recycle Bin.

Timeline

Timeline Field Data Field
Description path
Additional Description size

Fields

Output Name Data Type Description
path String original full path of the deleted file before it was sent to the Recycle Bin
size Int size, in bytes, of the original file that was deleted
header String INFO2 file version identifier (1 = Vista/7, 2 = Windows 10+)
uninstall_date DateTime timestamp when the file was removed (deleted) and placed in the Recycle Bin