-
-
Notifications
You must be signed in to change notification settings - Fork 1
Recovery Signatures
Every entry below has real carving logic behind it in byterescue/recovery/signatures.py — this list is
intentionally short rather than padded, and each row says plainly whether the recovered file's end offset
is actually proven or just an estimate.
| Format | End offset | Notes |
|---|---|---|
| JPEG | Heuristic (last End-of-Image before a size cap) | Handles embedded EXIF thumbnails correctly; still a heuristic, not a proof |
| PNG | Verified (checksummed IEND footer) | |
Heuristic (last %%EOF before a size cap) |
Captures multi-revision (incrementally saved) PDFs | |
| ZIP | Verified (real End Of Central Directory) | A multi-entry ZIP is carved as one archive, not one fragment per entry. Recognized as .docx/.xlsx/.pptx when the archive contents say so — OOXML files are ordinary ZIPs |
| GZIP, 7-Zip, FLAC | Unverified (no footer exists for these formats; capped) | |
| WAV / AVI / WebP (RIFF) | Verified (exact length stored in the RIFF header) | |
| SQLite | Verified (exact length from page size × page count) | |
| BMP | Verified when accepted | The 2-byte "BM" magic alone is too weak to trust; a candidate is rejected outright unless its embedded size field and DIB header size both look real |
| Windows PE (.exe/.dll) | Verified when accepted | "MZ" alone is too weak to trust; rejected outright unless it leads to a real PE header, whose section table (and signature block, if present) gives the real end |
| ELF | Verified when accepted | End computed from the section header table; a stripped binary with no section headers is rejected, not guessed at |
| MP4 / MOV | Verified when accepted | End computed by walking the ISO-BMFF box structure from the ftyp box |
| GIF, TIFF, RAR, legacy Office (OLE), MKV/WebM | Unverified (no simple footer or requires a full container parser not yet written; capped) | |
| MP3 | Not really — detects an ID3v2 tag only | Raw MPEG frame-sync bytes are deliberately not used as a signature; they occur constantly inside valid audio and would produce far too many false positives |
Camera RAW formats (.cr2/.nef/etc.), legacy/plain document formats with no binary signature
(.txt/.csv/.rtf — use Recover Text Files for these instead), and video/audio container internals
beyond what's listed above are not implemented.
Beyond carving, recovered files are checked with real parsers, not just a signature match:
| Format(s) | Validated with |
|---|---|
| JPEG / PNG / GIF / BMP / TIFF / WEBP | Pillow |
| ZIP | zipfile |
| SQLite | PRAGMA integrity_check |
| WAV | the wave module |
| GZIP | decompression |
Every result is labeled Passed / Partial / Failed / Unknown — a signature match alone is never reported as a successful recovery.
See Recovery Center for how these signatures are used across the four recovery modes.
Getting Started
Recovery
Help
Developers