-
-
Notifications
You must be signed in to change notification settings - Fork 1
Recovery Center
The Recovery Center has four modes, all of which do real recovery:
| Mode | What it actually does |
|---|---|
| Recover by Signature | Searches a chosen file or disk image for the byte signatures listed in Recovery Signatures. |
| Recover Text Files | Searches for long, plausible runs of readable ASCII/UTF-8/UTF-16 text and scores each one's confidence. Plain text has no magic header, so this is pattern detection, not signature matching. |
| Deep / Raw Scan | The same signature search as "Recover by Signature", but reads the source in fixed-size chunks with an overlap buffer instead of memory-mapping it, so a signature split across a chunk boundary is still found and very large sources don't need to fit in memory. Intended for raw physical-drive sources. |
| Recover by File System | Reads the volume's actual FAT12/16/32 directory table (byterescue/recovery/filesystem.py) — including deleted entries — to recover files the other modes can miss, with the original filename when one is found. NTFS and exFAT are not implemented and report a clear error rather than silently finding nothing. A deleted file spanning more than one cluster is recovered by assuming contiguous allocation (FAT deletion normally erases the real cluster chain, not just the directory entry) — every such result says so and is marked lower confidence; a file that fits in a single cluster needs no such assumption and is marked High confidence. |
A verified recovered item had its end offset proven from the format's own structure (an exact length field, a checksummed footer, or a fully walked container/section table). An unverified item had no reliable end marker, so a safety cap was used instead — treat it as a guess, not a confirmed result.
Every item also gets a separate structural validation result (Passed / Partial / Failed / Unknown) from actually trying to parse it, because a matching signature is not proof of a complete, undamaged file.
- Pause / Resume / Stop a running scan
- Live progress: offset, scanned/total, speed, ETA, candidates found/valid/rejected
- Duplicate detection
- Exportable JSON recovery report
- Hex Viewer integration — selecting a result jumps the Hex Viewer to and highlights its offset
-
Open Log button — opens
logs/byterescue.logdirectly - An in-window Help/Docs tab explaining every mode, control, and results-table column
Recovered files are never written back to the source drive/path — you always pick a separate destination folder, and the Recovery Center warns if the destination is on the same physical drive as the source.
- Recovery Signatures — exactly which file formats are carved, and how their end offset is determined
- Supported File Systems — what "Recover by File System" actually supports
- Best Practices — how to do a recovery attempt safely
Getting Started
Recovery
Help
Developers