Skip to content

Recovery Signatures

CodingJeffRoblox edited this page Sep 23, 2026 · 1 revision

Recovery Signatures (what is actually implemented)

Every entry below has real carving logic behind it in byterescue/recovery/signatures.py — this list is intentionally short rather than padded, and each row says plainly whether the recovered file's end offset is actually proven or just an estimate.

Format End offset Notes
JPEG Heuristic (last End-of-Image before a size cap) Handles embedded EXIF thumbnails correctly; still a heuristic, not a proof
PNG Verified (checksummed IEND footer)
PDF Heuristic (last %%EOF before a size cap) Captures multi-revision (incrementally saved) PDFs
ZIP Verified (real End Of Central Directory) A multi-entry ZIP is carved as one archive, not one fragment per entry. Recognized as .docx/.xlsx/.pptx when the archive contents say so — OOXML files are ordinary ZIPs
GZIP, 7-Zip, FLAC Unverified (no footer exists for these formats; capped)
WAV / AVI / WebP (RIFF) Verified (exact length stored in the RIFF header)
SQLite Verified (exact length from page size × page count)
BMP Verified when accepted The 2-byte "BM" magic alone is too weak to trust; a candidate is rejected outright unless its embedded size field and DIB header size both look real
Windows PE (.exe/.dll) Verified when accepted "MZ" alone is too weak to trust; rejected outright unless it leads to a real PE header, whose section table (and signature block, if present) gives the real end
ELF Verified when accepted End computed from the section header table; a stripped binary with no section headers is rejected, not guessed at
MP4 / MOV Verified when accepted End computed by walking the ISO-BMFF box structure from the ftyp box
GIF, TIFF, RAR, legacy Office (OLE), MKV/WebM Unverified (no simple footer or requires a full container parser not yet written; capped)
MP3 Not really — detects an ID3v2 tag only Raw MPEG frame-sync bytes are deliberately not used as a signature; they occur constantly inside valid audio and would produce far too many false positives

Not implemented

Camera RAW formats (.cr2/.nef/etc.), legacy/plain document formats with no binary signature (.txt/.csv/.rtf — use Recover Text Files for these instead), and video/audio container internals beyond what's listed above are not implemented.

Structural validation

Beyond carving, recovered files are checked with real parsers, not just a signature match:

Format(s) Validated with
JPEG / PNG / GIF / BMP / TIFF / WEBP Pillow
ZIP zipfile
SQLite PRAGMA integrity_check
WAV the wave module
GZIP decompression

Every result is labeled Passed / Partial / Failed / Unknown — a signature match alone is never reported as a successful recovery.

See Recovery Center for how these signatures are used across the four recovery modes.

Clone this wiki locally