Skip to content

Recover and Review Files with PhotoRec GUI

Use this workflow on a disposable training source or verified working image. Exact device names and partition layouts vary; make each selection from the recorded evidence identity and investigation question.

Plan the recovery boundary

Question

Which deleted file types are relevant, and which partition could contain them?

Capacity

Allow for carved output, logs and hashes on storage separate from the source.

Context

Record QPhotoRec version, source hash, partition, file-system choice, search area and format filter.

Configure QPhotoRec

  1. Select the exact source from the device or image list. Match its recorded identifier, capacity and hash; do not choose a similarly sized analyst disk. If the raw image is not already listed, use Add a raw disk image... and select the recorded .dd, .raw or .img working copy.
  2. Select the relevant partition. For a Windows user-data question this is commonly the NTFS data partition, not the EFI, reserved or recovery partition.
  3. Choose the file-system family shown by the source. For NTFS, FAT, exFAT, HFS+ and similar sources, use FAT/NTFS/HFS+/ReiserFS/... rather than the ext2/ext3/ext4 option.
  4. Choose Free for a focused deleted-file carve from unallocated space on an intact supported file system. Use Whole only when the question or damaged file system justifies scanning the entire partition.
  5. Open File Formats, clear unnecessary types and enable only those relevant to the case. A narrower selection reduces output volume but does not guarantee that every match is complete or relevant.
  6. Browse to a case-linked folder on separate controlled storage, then start the search and record start time, completion state, warnings and errors.
1 Source2 Partition3 File system4 Free or whole5 Formats and destination

Destination selection is an evidence-control decision

Never save carved files to the source being searched. Destination writes can overwrite recoverable sectors and make the result harder to defend. Avoid a FAT32 destination when recovered files may exceed its 4 GB file-size limit.

Review recovered output

QPhotoRec writes files into generated recup_dir.* folders. Preserve the completion message and session log when available, then inventory the output before opening individual files.

  • Count and classify
    Record recovered counts by type, total byte size, errors and any incomplete files.
  • Hash before review
    Hash retained recovery output and create a protected copy before analysis or conversion.
  • Validate safely
    Use signatures, parsers and isolated viewers; do not execute recovered programs or enable active content.
  • State the limitation
    A carved file can support content presence in searched sectors, but usually not its original name, path, owner or deletion time.

Create a recovery record containing the source and working-copy hashes, QPhotoRec version, every selection, destination, start and finish times, output counts, retained hashes and an explanation of lost context.