Skip to content

ShadowExplorer

What ShadowExplorer does

Point-in-time Windows file recovery

ShadowExplorer presents available Windows Volume Shadow Copies as a familiar folder tree. An analyst can select a volume and snapshot time, browse its point-in-time files, and export a file or folder to separate controlled storage.

  • Compare snapshots
    Select a restore point and compare a historical file version with live or later content.
  • Recover safely
    Export a selected file or folder without restoring it over the live source path.
  • Preserve context
    Record volume, snapshot time, full path, displayed metadata, destination and hashes.

ShadowExplorer is a recovery and triage interface, not a forensic acquisition tool. Presence in a shadow copy supports point-in-time availability; it does not alone prove authorship, execution, deletion time or malicious intent.

Choose your journey

How the workflow fits together

1 Record source2 Select snapshot3 Locate version4 Export separately5 Hash and explain

Snapshot context matters

Record the selected volume and displayed snapshot time. The same path may hold different content across multiple shadow copies.

Export is collection activity

The export has a new destination and file-system metadata. Preserve the original displayed metadata separately and hash the exported bytes.

Before you begin

Authority

Use an owned or explicitly authorised Windows training system.

Availability

Confirm the required volume has at least one accessible shadow copy.

Destination

Prepare a separate case-linked export directory with sufficient space.

Do not overwrite the source

Export to separate controlled storage. Do not restore a historical file over the live path, and do not treat ShadowExplorer as acquisition.

Analyst decisionWhich record best supports a recovered file?