SQLite Forensic Tool Adds Deleted-Record Recovery

A new version of the open-source SQLite GUI Analyzer is giving digital-forensics investigators more options for examining deleted and hidden data stored inside SQLite databases.
The tool can recover records from Write-Ahead Log (WAL) files and freed database pages, potentially revealing information that is no longer visible when a database is opened normally. SQLite’s own documentation confirms that WAL files can retain database changes separately from the main database before checkpointing occurs, making these artifacts particularly relevant during forensic examination.
The updated analyzer also introduces timestamp conversion for formats commonly encountered during investigations, including Unix, Chrome, FILETIME and Mac timestamps. Investigators can additionally examine relationships between database tables, decode BLOB data and search across tables from a single interface.
A key forensic consideration is that the analyzer is designed to examine databases without altering the original source. This is important when SQLite files are being handled as digital evidence.
SQLite is widely embedded in browsers, mobile applications and desktop software, meaning database artifacts frequently appear during digital investigations. Deleted records and WAL data can sometimes provide information that investigators would miss by examining only active database entries.
The latest release makes those artifacts easier to examine through a graphical interface, bringing several SQLite forensic-analysis functions into a single open-source tool.