Free Download

Sherlock Forensics Recover

Most recovery tools guess. Sherlock Forensics Recover measures, then tells you which it did.

Every competitor says powerful and advanced and shows you a percentage. Sherlock Forensics Recover says this file has been overwritten and shows its working. It reads the true length of what it finds, proves a RAID layout against the data before it trusts it and writes nothing to the drive you are rescuing.

Version 0.1.370 | 3.1 MB installer | Windows 10/11 (64-bit) | EV-signed | SHA256 verified

Why it is different

It Measures Instead of Guessing

Your recovered photos open

Most tools do not know where a carved file ends, so they save the largest possible size: a 20 KB photo written out as 500 MB of surrounding disk. The length is wrong, so nothing opens it. Sherlock Forensics Recover reads the true length from the file itself. On one test drive a photo other methods reported as 524 MB was measured at 24 KB.

It tells you when your data is gone

On most modern SSDs, deleting a file makes the drive erase it within seconds. No software can bring that back. Sherlock Forensics Recover says so before you spend hours scanning, rather than selling you a scan it already knows will come back empty.

RAID that measures instead of guessing

Consumer tools ignore RAID. Professional tools ask you to pick the level, stripe size, disk order and parity rotation from dropdowns. A wrong guess produces an array that looks perfect for the first few files and is garbage after them. Sherlock Forensics Recover reads the array's own metadata first. When that is gone it searches the settings and scores each candidate against the file system structures that must appear at computed offsets. It refuses to assemble an array from an out-of-sync disk rather than producing one that mounts and is wrong. See how this works on a failed array in our RAID data recovery guide.

Nothing is written to the drive you are rescuing

Not a temporary file, not a log, not an index. And it will not let you save recovered files back onto the drive you are rescuing, which is the single most common way people destroy the files they were trying to save.

New in 0.1.370

Results toolbar always reachable

Version 0.1.370: on smaller or scaled screens the Results toolbar could run under the preview pane, so Recover and Clear disappeared and Select all shown was cut off. The toolbar now wraps, so those controls are always reachable.

New in 0.1.369

Read the Pagefile. Open a Broken E01.

Pagefile analysis (Pro)

Open an extracted pagefile.sys or swapfile.sys and read it as text: every string in ASCII and UTF-16 with its offset and page, sorted into URLs, email addresses, file and registry paths, IP addresses, account names, program names, command lines, headers, cookies and credentials, each counted, with a whole-file search in both encodings or by hex bytes and CSV and JSON export. It decodes the memory-compressed pages Windows 10 and 11 write to the pagefile, which Strings, grep and a hex editor cannot read; the decoder is checked against Windows' own compressor. This is where you see what was in memory. A paging file records no time and no owner. A hit means those bytes were in some process's memory at some point. It does not tell you which process, which user or when, and it does not mean a person saw or typed them. Measured on a 1 GiB test file, not a figure for any real pagefile: analysed in 28.5 s, 10.1 million strings, whole-file search in 1.3 s.

Deleted files on large FAT32 volumes are located, not guessed at

On a FAT32 volume past 4 GB (SD cards, USB sticks, camera cards, VeraCrypt volumes) Windows clears half of a deleted file's start address at deletion, so a plain undelete reads the wrong place for nearly every file. Recover reconstructs the start by the file's own signature, by a deleted folder's own dot entry or by assuming the file sat near its folder, and every result says which. This does not mean every deleted file comes back: a file with no signature is placed by assumption and rated Poor, and a file whose signature is at no free location is reported as most likely overwritten. On a real 500 GB volume, 633 of 1,080 deleted entries were affected by the cleared address.

Damaged E01 images open instead of being refused

An EnCase E01 whose chunk table is unreadable or missing, which is what an aborted acquisition leaves, is opened by decoding forward and recovering the chunk boundaries. Regions that cannot be located or decoded are shown as unreadable, counted and named on the source, and the image keeps its true length. This does not repair the image and does not bring back what was lost, and a hash of a partial read is not a hash of the acquisition, which the product states. Measured on a real 700 MB Android acquisition with its table destroyed and 300 KB cut off: 19,975 of 22,400 chunks recovered, the file system browsable, the shortfall stated.

Recovered pictures open at full size

A carved photo opens full-size from the preview pane instead of in a narrow column. A partially decoded image carries its incomplete warning into the full-size view, so a half picture never reads as a whole one.

Changelog 0.1.369: Pagefile analysis, reading an extracted pagefile.sys as text with whole-file search and decoding of Windows memory-compressed pages. Deleted files on large FAT32 volumes are now located by signature rather than read from the wrong place. Damaged E01 images now open with the unreadable regions stated. Recovered pictures open at full size.

Encryption

It Opens Encrypted Drives, Given the Key

Sherlock Forensics Recover opens a BitLocker drive with its passphrase or its 48-digit recovery key. It opens a LUKS-encrypted Linux volume with its passphrase. It decrypts the volume in memory and searches it for deleted files like any other drive. Nothing is written to the source and no decrypted copy is made. What it does not do matters just as much: it does not break, crack or bypass anything. Without the secret it opens nothing. A cipher it does not support is refused by name rather than decrypted into the plausible noise a lesser tool would then carve and report as evidence. For an examiner, a tool that refuses is worth more than one that guesses.

File systems

It Reads the File Systems Your Cases Actually Use

Windows NTFS, FAT and exFAT. The Linux file systems ext, XFS and Btrfs. ZFS pools are read. Mac APFS and HFS+ are read. It works on internal and external drives, SSDs, USB sticks and memory cards. It reads whole disks or single partitions, MBR or GPT. And it opens the disk images an examiner already has: raw dd, E01 and Ex01, VMware and Hyper-V virtual disks.

What it finds

What It Finds and What It Hands Back

It carves photographs including Canon and Nikon RAW, video, audio, documents, archives, databases and email. Two things set the results apart. A recovered Word, Excel or PowerPoint file comes back under its real name rather than as an anonymous archive you open one at a time, because the tool looks inside and names each file for what it is. And recovered mail opens as mail: the sender, the recipients, the subject, the date and the readable body, with attachments listed. Nothing in a message is rendered, fetched or run, so a tracking pixel cannot load and tell a suspect that their mailbox was opened.

Forensic examination

It Is Built for an Examination, Not Just a Recovery

Every recovered file carries a SHA-256 fingerprint and a record of where it came from. Before it calls a deleted file intact, it checks the volume's own allocation bitmap to see whether the space has been handed to something else, then marks a file whose data is gone rather than offering it. It reads the Windows change journal to show what was deleted or renamed and when. It finds data hidden in alternate data streams. It recovers files whose file-system record Windows has already reused, which most tools cannot see at all.

The report is where it separates itself. It is one self-contained HTML file that opens on a machine with no network and prints to PDF unchanged years later. It leads with what the examination did NOT cover: the read errors, the incomplete images, the caps that truncated a result. Every other tool in this space buries that at the end. A report that opens with findings invites the reader to treat the absence of a finding as proof of absence, which is the commonest way a forensic document misleads. An examiner's own notes go in attributed to the examiner, kept separate from what the tool measured.

It also runs a rule set that looks for things worth knowing: persistence, anti-forensics, credential access, web shells, ransomware, exfiltration and evasion. Every rule states what would make it a false positive. That text travels with the finding into the report.

Free and Pro

Free vs Pro

Free covers browsing a volume, previewing files, exporting them and creating a disk image in raw or E01 format. It is a complete FTK Imager equivalent, not a trial and not a limited build. Pro adds deleted-file recovery, carving unallocated space, RAID reconstruction, lost-partition search and the previous versions Windows kept.

CapabilityFreePro
Browse a volume and preview filesYesYes
Export filesYesYes
Create a disk image (raw or E01)YesYes
Deleted-file recoveryNoYes
Carve unallocated spaceNoYes
RAID reconstructionNoYes
Lost-partition searchNoYes
Previous versions Windows keptNoYes

Free

$0
No trial, no limited build. A complete imager.
  • Browse, preview and export
  • Raw and E01 disk imaging
  • EV-signed, Windows 10 and 11

Pro

$295
One-time payment. No subscription.
  • Deleted-file recovery
  • Carving unallocated space
  • RAID reconstruction
  • Lost-partition search
  • Previous versions Windows kept

What it refuses to claim

The Receipts

The difference is what it refuses to claim. Sherlock Forensics Recover ships behind 15 build gates. Its readers are cross-checked against independent implementations that share no code with ours. It is measured against real media rather than fixtures. It carves 71 file formats, each validated against that format's own structure, which is why the number is lower than the 300 to 400 that competitors advertise and why the results carry far fewer invented files. Of those formats, 55 have their true length measured and 28 are proven to come back byte-for-byte identical to the original. Hundreds of detection rules ship with it.

Download

Get Sherlock Forensics Recover

Sherlock Forensics Recover 0.1.370. Windows 10 or 11, 64-bit. The installer is 3.1 MB. The installer and the application inside it are both EV-signed by Sherlock Forensics Ltd and RFC3161 timestamped. The certificate is issued against a verified legal entity, with the signing key held on a hardware token that cannot leave it. No administrator rights are needed to install or to browse. Reading a physical drive directly does need elevation, which the tool requests with a relaunch rather than demanding at startup. Current Windows 10 and 11 include the WebView2 runtime the interface needs. A sealed forensic bench with no network and no WebView2 will stop the install, which is worth knowing before you take it somewhere air-gapped.

File
sherlock-recover-setup.exe
SHA256
a80c56e08d7e1800b2e49cd7b4cdd642902235a41d8e7c1034c4d19961ead111
Version
0.1.370
Size
3.1 MB
Platform
Windows 10/11 (64-bit)

Questions

Data Recovery FAQ

Why will my recovered photo not open?
Most tools do not know where a carved file ends, so they save the largest possible size: a 20 KB photo written out as 500 MB of surrounding disk. The length is wrong, so nothing opens it. Sherlock Forensics Recover reads the true length from the file itself. On one test drive a photo other methods reported as 524 MB was measured at 24 KB.
Can deleted files be recovered from an SSD?
Often not. On most modern SSDs, deleting a file makes the drive erase it within seconds. No software can bring that back. Sherlock Forensics Recover checks for this and tells you before you spend hours on a scan it already knows will come back empty.
What is the difference between a quick scan and a deep scan?
A quick scan reads the file system's own records to list the files it still names, including deleted entries whose records survive. A deep scan carves unallocated space by file signature to find data the file system no longer references. Quick is faster; deep reaches files a format or a wipe removed from the index.
Can I open an E01 image in a data recovery program?
Yes. Sherlock Forensics Recover opens raw dd, E01 and EnCase Ex01 images and searches them for deleted files like any other source. It can also write an E01 when it images a drive.

Get Started

Recover Files That Actually Open

Free data recovery software for examiners, IT teams and anyone facing a lost drive or a broken array. Built by the same team that delivers expert witness testimony in Canadian courts.

Since 2006CISSP, ISSAP, ISSMP certified888.883.4550

Sherlock Forensics Recover is provided for lawful use. Terms of Service

Download

Your email is optional. If you provide it, we send 3 product introduction emails over the next 2 weeks. No long-term marketing. No data sharing. Skip the field and download directly.

While you are here, make us your preferred source in Google:

Sherlock Forensics Recover Pro - $295