Skip to content

Recovery Center

CodingJeffRoblox edited this page Sep 23, 2026 · 1 revision

Recovery Center

The Recovery Center has four modes, all of which do real recovery:

Mode What it actually does
Recover by Signature Searches a chosen file or disk image for the byte signatures listed in Recovery Signatures.
Recover Text Files Searches for long, plausible runs of readable ASCII/UTF-8/UTF-16 text and scores each one's confidence. Plain text has no magic header, so this is pattern detection, not signature matching.
Deep / Raw Scan The same signature search as "Recover by Signature", but reads the source in fixed-size chunks with an overlap buffer instead of memory-mapping it, so a signature split across a chunk boundary is still found and very large sources don't need to fit in memory. Intended for raw physical-drive sources.
Recover by File System Reads the volume's actual FAT12/16/32 directory table (byterescue/recovery/filesystem.py) — including deleted entries — to recover files the other modes can miss, with the original filename when one is found. NTFS and exFAT are not implemented and report a clear error rather than silently finding nothing. A deleted file spanning more than one cluster is recovered by assuming contiguous allocation (FAT deletion normally erases the real cluster chain, not just the directory entry) — every such result says so and is marked lower confidence; a file that fits in a single cluster needs no such assumption and is marked High confidence.

Verified vs. unverified results

A verified recovered item had its end offset proven from the format's own structure (an exact length field, a checksummed footer, or a fully walked container/section table). An unverified item had no reliable end marker, so a safety cap was used instead — treat it as a guess, not a confirmed result.

Every item also gets a separate structural validation result (Passed / Partial / Failed / Unknown) from actually trying to parse it, because a matching signature is not proof of a complete, undamaged file.

Controls

  • Pause / Resume / Stop a running scan
  • Live progress: offset, scanned/total, speed, ETA, candidates found/valid/rejected
  • Duplicate detection
  • Exportable JSON recovery report
  • Hex Viewer integration — selecting a result jumps the Hex Viewer to and highlights its offset
  • Open Log button — opens logs/byterescue.log directly
  • An in-window Help/Docs tab explaining every mode, control, and results-table column

Destination safety

Recovered files are never written back to the source drive/path — you always pick a separate destination folder, and the Recovery Center warns if the destination is on the same physical drive as the source.

Related pages

Clone this wiki locally