Free Page (SQLite)
Definition
A SQLite database page that has been deallocated after a delete operation but not yet reused. Residual message data in free pages is a primary source of deleted record recovery in mobile forensics.
- Database
- SQLite
- Cause
- Page deallocated after a DELETE, not yet overwritten
- Forensic value
- Primary source for deleted record recovery
- Common target
- Mobile messaging app databases
Common questions
Why can deleted SQLite records still be recovered from free pages?+
SQLite marks a page as free on the freelist rather than zeroing its content, so the old row data physically remains until a later write reuses that page. A carving tool can walk the freelist and extract byte patterns matching the table's record format before that overwrite happens.
What limits how long recovery from a free page remains possible?+
Once SQLite reuses the freed page for a new insert or during a VACUUM operation, the residual data is overwritten and unrecoverable, so the window depends entirely on how much subsequent write activity the database sees after the deletion.
Related terms
- Content Provider (Android)
- An Android system component that mediates access to shared data such as call logs and SMS. Forensic logical extractions query content providers...
- Message Status Flag
- An integer column in a messaging database that encodes the state of a message: sent, delivered, read, failed, or draft. The exact...
- SQLCipher
- An open-source SQLite extension that encrypts the entire database file using AES-256. Used by Signal and some other security-focused messaging apps. Without...
- SQLite
- A lightweight, serverless relational database engine used pervasively on both iOS and Android to store structured app data including messages, call logs,...
- Unix Epoch Timestamp
- An integer representing the number of seconds (or, in some databases, milliseconds or nanoseconds) since 00:00:00 UTC on 1 January 1970. Mobile...