PhotoRec GUI Hands-on Labs¶
Choose the browser simulation for coached practice, or complete the Full Lab with QPhotoRec and a supplied, verified raw training image.
Hands-on file-recovery proof of concept
Bound it. Carve it. Qualify it.
Recover two controlled file types from unallocated space, preserve the derived output and explain what signature-based carving can and cannot show.
Interactive Lab¶
Full Lab¶
PhotoRec GUI Full Lab
Outcome-led recovery
Interface labels and supported formats can vary by version. Record meaningful differences and judge success from the recovery record, not from matching a screenshot pixel for pixel.
Use supplied or authorised training evidence
Work from a verified copy. Never recover to the searched source, and never execute carved files. Use isolated viewers and controlled output storage.
Before you begin
You need: an isolated Windows analysis VM, QPhotoRec, a supplied raw image containing harmless deleted JPG and PDF training files, source hash information, and a separate controlled output volume with adequate capacity.
Case question
Can a bounded unallocated-space carve recover the supplied image and document file signatures, and what evidential context is lost during recovery?
Objective¶
For case SUSA-PR-042, recover JPG and PDF content from the NTFS data partition
of a verified training image, inventory and hash the recovered output, and make
a conclusion that distinguishes recovered content from original file-system
identity and user activity.
01
Activity 1: Establish the recovery boundary¶
- Record authority, case question, image filename, format, byte size and supplied SHA-256.
- Calculate the working-copy hash and stop if it does not match.
- Record QPhotoRec version, executable path, workstation time zone and start time.
- Prepare
X:\SUSA-PR-042\recoveredon storage separate from the image. - Confirm the destination has enough free space and is initially empty.
Expected result The verified working image and empty destination are identifiable without opening protected original evidence.
02
Activity 2: Run the bounded carve¶
- Open QPhotoRec and select the verified training image, matching its name and capacity. Use Add a raw disk image... if it is not already listed.
- Select the NTFS data partition; record its displayed number, size and label.
- Select FAT/NTFS/HFS+/ReiserFS/... and Free.
- In File Formats, clear the defaults and enable only JPG/JPEG and PDF.
- Select
X:\SUSA-PR-042\recovered, start the search and record the exact settings. - Record start and finish times, completion message, recovered counts, errors and session-log location.
Expected result QPhotoRec creates one or more `recup_dir.*` folders containing candidate JPG and PDF files.
03
Activity 3: Validate and report¶
- Inventory output paths, counts, sizes and extensions without executing files.
- Hash the protected recovery output, then create a working review copy.
- Validate a sample with file signatures and safe parsers or isolated viewers.
- Record incomplete, duplicate or false-positive candidates and any QPhotoRec warnings.
- State whether JPG and PDF content was recovered and explicitly identify the lost filename, path, ownership and timestamp context.
- Identify one independent source that could corroborate the recovered content, such as
$MFT,$UsnJrnl, browser history or application metadata.
Use this structure:
Case and question:
Source image, partition and SHA-256:
QPhotoRec version and settings:
Destination, times and completion state:
Recovered counts and retained hashes:
Validated observations:
Conclusion and confidence:
Context not recovered by carving:
Corroboration required:
Full Lab evidence checklist¶
-
Core completion¶
Required for a reviewable carving exercise.
Troubleshooting¶
| Symptom | First check |
|---|---|
| Expected image or disk is absent | Confirm the image format, path, permissions and whether the version supports it directly. |
| Search remains unavailable | Select a source, partition, file-system family, search area and valid separate destination. |
| Output is unexpectedly large | Recheck Free versus Whole and limit File Formats to the case question. |
| No expected files are recovered | Confirm the correct partition and type signatures; the sectors may be overwritten, fragmented or outside the selected area. |
| Recovered files do not open | Treat them as possible fragments or false positives and validate headers, structure and QPhotoRec errors. |
Clean up¶
Close QPhotoRec, protect the recovery record and retained output, remove disposable working copies when authorised, detach training storage and restore the analysis VM snapshot if required.