Skip to content

PhotoRec GUI Hands-on Labs

Choose the browser simulation for coached practice, or complete the Full Lab with QPhotoRec and a supplied, verified raw training image.

Hands-on file-recovery proof of concept

Bound it. Carve it. Qualify it.

Recover two controlled file types from unallocated space, preserve the derived output and explain what signature-based carving can and cannot show.

⏱ Setup: 20–30 min · Exercise: 40–60 min◆ Guided beginner✓ Evidence required

Interactive Lab

Full Lab

Isolated Windows VM · Setup: 20–30 min · Exercise: 40–60 min

PhotoRec GUI Full Lab

QPhotoRec, verified raw image and separate recovery storage required

Outcome-led recovery

Interface labels and supported formats can vary by version. Record meaningful differences and judge success from the recovery record, not from matching a screenshot pixel for pixel.

Use supplied or authorised training evidence

Work from a verified copy. Never recover to the searched source, and never execute carved files. Use isolated viewers and controlled output storage.

Before you begin

You need: an isolated Windows analysis VM, QPhotoRec, a supplied raw image containing harmless deleted JPG and PDF training files, source hash information, and a separate controlled output volume with adequate capacity.

Case question

Can a bounded unallocated-space carve recover the supplied image and document file signatures, and what evidential context is lost during recovery?

Objective

For case SUSA-PR-042, recover JPG and PDF content from the NTFS data partition of a verified training image, inventory and hash the recovered output, and make a conclusion that distinguishes recovered content from original file-system identity and user activity.

01

Activity 1: Establish the recovery boundary

  1. Record authority, case question, image filename, format, byte size and supplied SHA-256.
  2. Calculate the working-copy hash and stop if it does not match.
  3. Record QPhotoRec version, executable path, workstation time zone and start time.
  4. Prepare X:\SUSA-PR-042\recovered on storage separate from the image.
  5. Confirm the destination has enough free space and is initially empty.
Milestone 1Recovery boundary recordedSource identity, integrity, question and separate output location are reviewable.

Expected result The verified working image and empty destination are identifiable without opening protected original evidence.

02

Activity 2: Run the bounded carve

  1. Open QPhotoRec and select the verified training image, matching its name and capacity. Use Add a raw disk image... if it is not already listed.
  2. Select the NTFS data partition; record its displayed number, size and label.
  3. Select FAT/NTFS/HFS+/ReiserFS/... and Free.
  4. In File Formats, clear the defaults and enable only JPG/JPEG and PDF.
  5. Select X:\SUSA-PR-042\recovered, start the search and record the exact settings.
  6. Record start and finish times, completion message, recovered counts, errors and session-log location.
Milestone 2Bounded carve completedThe output can be tied to the selected source, partition, search area, formats and run time.

Expected result QPhotoRec creates one or more `recup_dir.*` folders containing candidate JPG and PDF files.

03

Activity 3: Validate and report

  1. Inventory output paths, counts, sizes and extensions without executing files.
  2. Hash the protected recovery output, then create a working review copy.
  3. Validate a sample with file signatures and safe parsers or isolated viewers.
  4. Record incomplete, duplicate or false-positive candidates and any QPhotoRec warnings.
  5. State whether JPG and PDF content was recovered and explicitly identify the lost filename, path, ownership and timestamp context.
  6. Identify one independent source that could corroborate the recovered content, such as $MFT, $UsnJrnl, browser history or application metadata.

Use this structure:

Case and question:
Source image, partition and SHA-256:
QPhotoRec version and settings:
Destination, times and completion state:
Recovered counts and retained hashes:
Validated observations:
Conclusion and confidence:
Context not recovered by carving:
Corroboration required:
Milestone 3Recovery is reviewableAnother analyst can reproduce the carve and distinguish recovered content from unsupported provenance claims.

Full Lab evidence checklist

  • Core completion

    Required for a reviewable carving exercise.

0 of 7 recorded Mark each item after saving it.

Troubleshooting

Symptom First check
Expected image or disk is absent Confirm the image format, path, permissions and whether the version supports it directly.
Search remains unavailable Select a source, partition, file-system family, search area and valid separate destination.
Output is unexpectedly large Recheck Free versus Whole and limit File Formats to the case question.
No expected files are recovered Confirm the correct partition and type signatures; the sectors may be overwritten, fragmented or outside the selected area.
Recovered files do not open Treat them as possible fragments or false positives and validate headers, structure and QPhotoRec errors.

Clean up

Close QPhotoRec, protect the recovery record and retained output, remove disposable working copies when authorised, detach training storage and restore the analysis VM snapshot if required.