Skip to content

PhotoRec GUI

What PhotoRec GUI does

Signature-based file recovery

QPhotoRec is the graphical interface for PhotoRec. It scans a disk, partition or supported image for known file signatures and writes recovered content to a separate destination. Because carving does not depend on live directory entries, it can recover content after records have been deleted or file-system metadata is damaged.

  • Recover by content
    Find supported file types from their internal signatures rather than filenames.
  • Limit the search
    Select one source, partition, search area and proportionate set of file formats.
  • Preserve derived output
    Write recovered files away from the source and retain settings, logs and hashes.

PhotoRec is a recovery and triage tool, not a complete forensic examination platform. Carved output commonly loses the original filename, directory, timestamps and allocation context. Treat each recovered file as a lead and corroborate it with file-system, timeline or application evidence where possible.

Choose your journey

Evidence workflow

1 Verify source2 Select partition3 Bound formats4 Recover separately5 Validate and report

Free or whole

Use Free to search unallocated space for deleted content on a supported, intact file system. Use Whole when the file system is damaged or when the question genuinely requires the entire selected partition; expect more noise.

Names are not identity

PhotoRec assigns generated names and recup_dir.* folders. A valid extension or preview does not restore the original path or establish who created the file.

Before you begin

Source

Use a verified working image or authorised training device and record its identity and hash.

Destination

Prepare a separate controlled volume with enough space; never recover back to the source.

Question

Define the relevant file types, partition and search area before starting the carve.

Carving trades context for recoverability

PhotoRec may recover content that ordinary file-system tools cannot see, but it can also produce fragments, duplicates and false positives. Preserve the source, settings and output record, and avoid claiming an original filename, path, owner or event time unless another artefact supports it.

Analyst decisionWhere should QPhotoRec write recovered files?