-
-
Notifications
You must be signed in to change notification settings - Fork 1
Glossary
Plain-English definitions for terms used throughout this wiki. See also the in-app "What am I looking at?" tab (Using ByteRescue) for a GUI-focused version of some of these.
Carving / signature carving — Recovering a file by searching raw bytes for a known magic header (and, where possible, a footer or length field), without any help from filesystem metadata. Used by "Recover by Signature" and "Deep / Raw Scan." See Recovery Signatures.
Magic bytes / signature — A fixed byte sequence near the start of a file format that identifies it,
e.g. \x89PNG\r\n\x1a\n for PNG.
Header / footer — The magic bytes marking where a carved candidate starts / where the format itself says it ends (when such a marker exists).
Verified vs. unverified (end offset) — Verified means the recovered item's true end was proven from the format's own structure (an exact length field, checksummed footer, or fully walked container table). Unverified means no such marker exists for that format, so a size cap was used as a guess instead. See Recovery Signatures.
Validation (Passed / Partial / Failed / Unknown) — A separate check, after carving, that actually
tries to parse the recovered bytes with a real library (Pillow, zipfile, sqlite3, etc.). A signature
match is not proof of a valid file; validation is. See How It Works.
Structural check / structural validation — Same idea as above: confirming a format's internal structure is coherent, not just that its magic bytes matched.
False positive — A byte sequence that happens to match a format's magic bytes by coincidence, without actually being that format. Weak/short magics are more prone to this — see How It Works.
Text-pattern recovery — Finding plausible runs of readable ASCII/UTF-8/UTF-16 text by pattern rather than by signature, since plain text has no magic header.
Chunked scanning / overlap buffer — Reading a very large source in fixed-size chunks (instead of loading it all into memory) with an overlap region between chunks, so a signature split across a chunk boundary is still detected. See How It Works.
FAT12/16/32 — The FAT family of filesystems ByteRescue can read directly (boot sector, directory entries, deleted entries) for "Recover by File System." See Supported File Systems.
Cluster / cluster chain — A cluster is a filesystem's basic storage unit; a multi-cluster file's cluster chain records which clusters (in order) hold its data. On FAT, deleting a file erases this chain from the FAT table, not just the file's directory entry.
Contiguous allocation assumption — Since a deleted FAT file's real cluster chain is usually gone, ByteRescue assumes its clusters were stored back-to-back (contiguous) when recovering a multi-cluster deleted file — the same approach classic FAT-undelete tools use. Results built on this assumption are marked lower confidence.
NTFS / exFAT — Newer Windows filesystems. Not implemented for filesystem-aware recovery; selecting "Recover by File System" against one reports a clear error rather than silently finding nothing.
TRIM — An SSD/NVMe command that tells the drive's firmware a block is no longer in use, letting the drive erase it at the flash level ahead of reuse. Once TRIM has actually erased a block, no software — ByteRescue included — can recover what was there.
Deleted entry — A directory entry marking a file as deleted (its data may still be physically present until overwritten), as opposed to a currently-referenced file.
Physical drive — A raw storage device (e.g. \\.\PhysicalDrive0), as opposed to a mounted volume or
drive letter. Scanning one directly requires Administrator privileges.
OOXML — The Office Open XML format family (.docx/.xlsx/.pptx); structurally, these are ordinary
ZIP archives, which is why ByteRescue recognizes them once a carved ZIP's contents say so.
ISO-BMFF — The box-based container structure underlying MP4/MOV (and other formats). ByteRescue
verifies MP4/MOV by walking this box structure from the ftyp box.
mmap — Memory-mapping a file so it can be addressed like an in-memory buffer without loading it all into RAM at once; used for ordinary file/disk-image sources. See How It Works.
Destination-safety check — ByteRescue's check for whether a chosen recovery destination could overwrite the very data being recovered (same path, same folder, or same physical drive as the source).
Getting Started
Recovery
Help
Developers