-
-
Notifications
You must be signed in to change notification settings - Fork 1
Features
CodingJeffRoblox edited this page Sep 23, 2026
·
1 revision
- Windows physical disk detection (metadata only) — model, capacity, interface, status via WMI/CIM
- HDD / SSD / USB device listing, with best-effort SSD/NVMe TRIM warnings
- Folder analysis
- File analysis with SHA-256 hashing
- Hex viewer with search, a hex/byte reference lookup, click-a-line explanations, and jump-to-offset from a recovery result — strictly read-only, it never writes back to the source
- Recovery Center: signature-based recovery, text-pattern recovery, chunked "Deep / Raw Scan" reading, and FAT12/16/32 filesystem-aware recovery, plus an in-window Help/Docs tab — see Recovery Center and Recovery Signatures
- Structural validation of recovered files (Pillow / zipfile / sqlite3 / wave / gzip), duplicate detection, pause/resume/stop scan controls, live progress, and an exportable JSON recovery report
- Recovery destination selection with a same-drive-as-source warning
- Read-oriented analysis interface, dark desktop GUI
-
Live console + file logging (
logs/byterescue.log) — every run logs its environment (version, Python build, OS, elevation status) at startup; setBYTERESCUE_DEBUGfor verbose output
Physical-drive scanning requires Administrator privileges on Windows. Recovered files are never written back to the source — you always choose a separate destination folder.
Important: SSD TRIM can make deleted data unrecoverable, and ByteRescue cannot bypass it. Signature and text-pattern carving are read-only, best-effort recovery methods — a match is not a guarantee.
- Accidental deletion — recover files that were accidentally deleted from a drive
- Corrupted storage — analyze drives that are having read issues or corruption
- Drive analysis — understand the health, capacity, and interface of storage devices
- File inspection — examine file contents using hex view and verify integrity with SHA-256
- Data forensics — perform read-only analysis for investigative purposes (not a certified forensic suite)
- USB recovery — recover files from USB drives that may have been improperly ejected
- Backup verification — hash files to verify backup integrity
- Not a certified forensic acquisition tool (no hashed imaging, chain-of-custody, or write-blocking enforcement)
- Not a TRIM bypass — nothing can recover SSD data that TRIM has actually erased
- Not a RAID recovery tool — no RAID metadata parsing or member reconstruction
- Not an NTFS/exFAT recovery tool yet — see Supported File Systems
See the Home page for the full navigation, or FAQ for specific "can it do X" questions.
Getting Started
Recovery
Help
Developers