Digital Forensics involves acquiring digital evidence such as disk drives from computers, memory sticks from phones, portable memory like flash drives. The collected hard drives and portable memory are copied bit by bit in a process called disk imaging and the copies are analyzed.
When a file is deleted, the directory entry for it is wiped out, but the actual file contents are not erased from the disk. Deleted files can be recovered unless overwritten by new files.
FTK Imager is a forensic took kit that can create memory image files and analyze them to see if there are any deleted files.