Skip to content

Hex Viewer

CodingJeffRoblox edited this page Sep 23, 2026 · 1 revision

Hex Viewer

The Hex Viewer is ByteRescue's byte-level inspector — strictly read-only, it never writes back to the source. Open it from the main toolbar's Hex Viewer button, or by selecting a Recovery Center result and clicking View in Hex Viewer, which jumps to and highlights that result's offset automatically.

Layout

Each line shows the classic three-column hex-dump format:

00000000  89 50 4E 47 0D 0A 1A 0A 00 00 00 0D 49 48 44 52  .PNG........IHDR
  • An 8-digit hexadecimal offset (the byte position from the start of the file/window)
  • The 16 bytes at that offset, as hex pairs
  • The same 16 bytes as ASCII, with non-printable bytes shown as .

Preview window

The Hex Viewer loads a 128 KB window around the region of interest rather than the whole file — this keeps it fast even against a very large source, while still covering headers, footers near the start, and whatever offset you jumped to.

Search

Type into the Search box and click Search:

  • If your input is entirely hex characters (0-9, A-F), it's treated as a byte sequence and searched against the hex column (spacing between byte pairs is re-inserted automatically, so 89504E47 and 89 50 4E 47 behave the same).
  • Otherwise, it's searched as literal text against the ASCII column.

All matches are highlighted, and the status line reports how many were found.

Hex/byte reference lookup

A Lookup Hex box looks up what a given byte value commonly represents (control characters, common ASCII, etc.) — an educational reference (byterescue/recovery/hex_reference.py), not something the scanner itself uses for carving. Clicking a line in the hex dump shows the same kind of explanation for that line's content, so you can make sense of unfamiliar bytes without leaving the window.

Jump-to-offset from a recovery result

Selecting a result in the Recovery Center and clicking View in Hex Viewer opens the Hex Viewer pre-scrolled to and highlighting that result's start offset — useful for eyeballing a carved file's header/footer before deciding whether to trust it, alongside its verified/unverified and validation status.

Related pages

Using ByteRescue · Recovery Center · Recovery Signatures

Clone this wiki locally