Recover and Review Files with PhotoRec GUI¶
Use this workflow on a disposable training source or verified working image. Exact device names and partition layouts vary; make each selection from the recorded evidence identity and investigation question.
Plan the recovery boundary¶
Which deleted file types are relevant, and which partition could contain them?
Allow for carved output, logs and hashes on storage separate from the source.
Record QPhotoRec version, source hash, partition, file-system choice, search area and format filter.
Configure QPhotoRec¶
- Select the exact source from the device or image list. Match its recorded
identifier, capacity and hash; do not choose a similarly sized analyst disk.
If the raw image is not already listed, use Add a raw disk image... and
select the recorded
.dd,.rawor.imgworking copy. - Select the relevant partition. For a Windows user-data question this is commonly the NTFS data partition, not the EFI, reserved or recovery partition.
- Choose the file-system family shown by the source. For NTFS, FAT, exFAT, HFS+ and similar sources, use FAT/NTFS/HFS+/ReiserFS/... rather than the ext2/ext3/ext4 option.
- Choose Free for a focused deleted-file carve from unallocated space on an intact supported file system. Use Whole only when the question or damaged file system justifies scanning the entire partition.
- Open File Formats, clear unnecessary types and enable only those relevant to the case. A narrower selection reduces output volume but does not guarantee that every match is complete or relevant.
- Browse to a case-linked folder on separate controlled storage, then start the search and record start time, completion state, warnings and errors.
Destination selection is an evidence-control decision
Never save carved files to the source being searched. Destination writes can overwrite recoverable sectors and make the result harder to defend. Avoid a FAT32 destination when recovered files may exceed its 4 GB file-size limit.
Review recovered output¶
QPhotoRec writes files into generated recup_dir.* folders. Preserve the
completion message and session log when available, then inventory the output
before opening individual files.
- Count and classify
Record recovered counts by type, total byte size, errors and any incomplete files. - Hash before review
Hash retained recovery output and create a protected copy before analysis or conversion. - Validate safely
Use signatures, parsers and isolated viewers; do not execute recovered programs or enable active content. - State the limitation
A carved file can support content presence in searched sectors, but usually not its original name, path, owner or deletion time.
Create a recovery record containing the source and working-copy hashes, QPhotoRec version, every selection, destination, start and finish times, output counts, retained hashes and an explanation of lost context.