PhotoRec GUI¶
What PhotoRec GUI does¶
Signature-based file recovery
QPhotoRec is the graphical interface for PhotoRec. It scans a disk, partition or supported image for known file signatures and writes recovered content to a separate destination. Because carving does not depend on live directory entries, it can recover content after records have been deleted or file-system metadata is damaged.
- Recover by content
Find supported file types from their internal signatures rather than filenames. - Limit the search
Select one source, partition, search area and proportionate set of file formats. - Preserve derived output
Write recovered files away from the source and retain settings, logs and hashes.
PhotoRec is a recovery and triage tool, not a complete forensic examination platform. Carved output commonly loses the original filename, directory, timestamps and allocation context. Treat each recovered file as a lead and corroborate it with file-system, timeline or application evidence where possible.
Choose your journey¶
Download the TestDisk package, extract it safely and open QPhotoRec.
Complete when the version and executable location are recorded.Beginner · Windows · 10–15 min 02Recover and reviewSelect a verified source, configure a bounded carve and assess the derived output.
Complete when recovered files remain attributable to the run.Practical · Training image · 20–40 min 03Hands-on LabsPractise QPhotoRec in-browser or complete an evidence-driven Full Lab.
Complete when another analyst can review the recovery record.Guided beginner · 20–90 minEvidence workflow¶
Free or whole
Use Free to search unallocated space for deleted content on a supported, intact file system. Use Whole when the file system is damaged or when the question genuinely requires the entire selected partition; expect more noise.
Names are not identity
PhotoRec assigns generated names and recup_dir.* folders. A valid extension or
preview does not restore the original path or establish who created the file.
Before you begin¶
Use a verified working image or authorised training device and record its identity and hash.
Prepare a separate controlled volume with enough space; never recover back to the source.
Define the relevant file types, partition and search area before starting the carve.
Carving trades context for recoverability
PhotoRec may recover content that ordinary file-system tools cannot see, but it can also produce fragments, duplicates and false positives. Preserve the source, settings and output record, and avoid claiming an original filename, path, owner or event time unless another artefact supports it.