ShadowExplorer¶
What ShadowExplorer does¶
Point-in-time Windows file recovery
ShadowExplorer presents available Windows Volume Shadow Copies as a familiar folder tree. An analyst can select a volume and snapshot time, browse its point-in-time files, and export a file or folder to separate controlled storage.
- Compare snapshots
Select a restore point and compare a historical file version with live or later content. - Recover safely
Export a selected file or folder without restoring it over the live source path. - Preserve context
Record volume, snapshot time, full path, displayed metadata, destination and hashes.
ShadowExplorer is a recovery and triage interface, not a forensic acquisition tool. Presence in a shadow copy supports point-in-time availability; it does not alone prove authorship, execution, deletion time or malicious intent.
Choose your journey¶
Verify, install and launch ShadowExplorer in an authorised Windows lab.
Complete when tool and dependency state are recorded.Beginner · Windows · 20–30 min 02Browse and exportSelect a snapshot, locate a historical file and export it separately.
Complete when source and export remain attributable.Practical · VSS required · 20–35 min 03Hands-on LabsPractise the interface or investigate a supplied snapshot in the Full Lab.
Complete when another analyst can reproduce the recovery.Guided beginner · 20–90 minHow the workflow fits together¶
Snapshot context matters
Record the selected volume and displayed snapshot time. The same path may hold different content across multiple shadow copies.
Export is collection activity
The export has a new destination and file-system metadata. Preserve the original displayed metadata separately and hash the exported bytes.
Before you begin¶
Use an owned or explicitly authorised Windows training system.
Confirm the required volume has at least one accessible shadow copy.
Prepare a separate case-linked export directory with sufficient space.
Do not overwrite the source
Export to separate controlled storage. Do not restore a historical file over the live path, and do not treat ShadowExplorer as acquisition.