Free Download

Sherlock Forensics Recover

Most recovery tools guess. Sherlock Forensics Recover measures, then tells you which it did.

Every competitor says powerful and advanced and shows you a percentage. Sherlock Forensics Recover says this file has been overwritten and shows its working. It reads the true length of what it finds, proves a RAID layout against the data before it trusts it and writes nothing to the drive you are rescuing.

Version 0.1.366 | 3.0 MB installer | Windows 10/11 (64-bit) | EV-signed | SHA256 verified

Why it is different

It Measures Instead of Guessing

Your recovered photos open

Most tools do not know where a carved file ends, so they save the largest possible size: a 20 KB photo written out as 500 MB of surrounding disk. The length is wrong, so nothing opens it. Sherlock Forensics Recover reads the true length from the file itself. On one test drive a photo other methods reported as 524 MB was measured at 24 KB.

It tells you when your data is gone

On most modern SSDs, deleting a file makes the drive erase it within seconds. No software can bring that back. Sherlock Forensics Recover says so before you spend hours scanning, rather than selling you a scan it already knows will come back empty.

RAID that measures instead of guessing

Consumer tools ignore RAID. Professional tools ask you to pick the level, stripe size, disk order and parity rotation from dropdowns. A wrong guess produces an array that looks perfect for the first few files and is garbage after them. Sherlock Forensics Recover reads the array's own metadata first. When that is gone it searches the settings and scores each candidate against the file system structures that must appear at computed offsets. It refuses to assemble an array from an out-of-sync disk rather than producing one that mounts and is wrong. See how this works on a failed array in our RAID data recovery guide.

Nothing is written to the drive you are rescuing

Not a temporary file, not a log, not an index. And it will not let you save recovered files back onto the drive you are rescuing, which is the single most common way people destroy the files they were trying to save.

Encryption

It Opens Encrypted Drives, Given the Key

Sherlock Forensics Recover opens a BitLocker drive with its passphrase or its 48-digit recovery key. It opens a LUKS-encrypted Linux volume with its passphrase. It decrypts the volume in memory and searches it for deleted files like any other drive. Nothing is written to the source and no decrypted copy is made. What it does not do matters just as much: it does not break, crack or bypass anything. Without the secret it opens nothing. A cipher it does not support is refused by name rather than decrypted into the plausible noise a lesser tool would then carve and report as evidence. For an examiner, a tool that refuses is worth more than one that guesses.

File systems

It Reads the File Systems Your Cases Actually Use

Windows NTFS, FAT and exFAT. The Linux file systems ext, XFS and Btrfs. ZFS pools are read. Mac APFS and HFS+ are read. It works on internal and external drives, SSDs, USB sticks and memory cards. It reads whole disks or single partitions, MBR or GPT. And it opens the disk images an examiner already has: raw dd, E01 and Ex01, VMware and Hyper-V virtual disks.

What it finds

What It Finds and What It Hands Back

It carves photographs including Canon and Nikon RAW, video, audio, documents, archives, databases and email. Two things set the results apart. A recovered Word, Excel or PowerPoint file comes back under its real name rather than as an anonymous archive you open one at a time, because the tool looks inside and names each file for what it is. And recovered mail opens as mail: the sender, the recipients, the subject, the date and the readable body, with attachments listed. Nothing in a message is rendered, fetched or run, so a tracking pixel cannot load and tell a suspect that their mailbox was opened.

Forensic examination

It Is Built for an Examination, Not Just a Recovery

Every recovered file carries a SHA-256 fingerprint and a record of where it came from. Before it calls a deleted file intact, it checks the volume's own allocation bitmap to see whether the space has been handed to something else, then marks a file whose data is gone rather than offering it. It reads the Windows change journal to show what was deleted or renamed and when. It finds data hidden in alternate data streams. It recovers files whose file-system record Windows has already reused, which most tools cannot see at all.

The report is where it separates itself. It is one self-contained HTML file that opens on a machine with no network and prints to PDF unchanged years later. It leads with what the examination did NOT cover: the read errors, the incomplete images, the caps that truncated a result. Every other tool in this space buries that at the end. A report that opens with findings invites the reader to treat the absence of a finding as proof of absence, which is the commonest way a forensic document misleads. An examiner's own notes go in attributed to the examiner, kept separate from what the tool measured.

It also runs a rule set that looks for things worth knowing: persistence, anti-forensics, credential access, web shells, ransomware, exfiltration and evasion. Every rule states what would make it a false positive. That text travels with the finding into the report.

Free and Pro

Free vs Pro

Free covers browsing a volume, previewing files, exporting them and creating a disk image in raw or E01 format. It is a complete FTK Imager equivalent, not a trial and not a limited build. Pro adds deleted-file recovery, carving unallocated space, RAID reconstruction, lost-partition search and the previous versions Windows kept.

CapabilityFreePro
Browse a volume and preview filesYesYes
Export filesYesYes
Create a disk image (raw or E01)YesYes
Deleted-file recoveryNoYes
Carve unallocated spaceNoYes
RAID reconstructionNoYes
Lost-partition searchNoYes
Previous versions Windows keptNoYes

Free

$0
No trial, no limited build. A complete imager.
  • Browse, preview and export
  • Raw and E01 disk imaging
  • EV-signed, Windows 10 and 11

Pro

$295
One-time payment. No subscription.
  • Deleted-file recovery
  • Carving unallocated space
  • RAID reconstruction
  • Lost-partition search
  • Previous versions Windows kept

What it refuses to claim

The Receipts

The difference is what it refuses to claim. Sherlock Forensics Recover ships behind 15 build gates. Its readers are cross-checked against independent implementations that share no code with ours. It is measured against real media rather than fixtures. It carves 71 file formats, each validated against that format's own structure, which is why the number is lower than the 300 to 400 that competitors advertise and why the results carry far fewer invented files. Of those formats, 55 have their true length measured and 28 are proven to come back byte-for-byte identical to the original. Hundreds of detection rules ship with it.

Download

Get Sherlock Forensics Recover

Sherlock Forensics Recover 0.1.366. Windows 10 or 11, 64-bit. The installer is 3.0 MB. The installer and the application inside it are both EV-signed by Sherlock Forensics Ltd and RFC3161 timestamped. The certificate is issued against a verified legal entity, with the signing key held on a hardware token that cannot leave it. No administrator rights are needed to install or to browse. Reading a physical drive directly does need elevation, which the tool requests with a relaunch rather than demanding at startup. Current Windows 10 and 11 include the WebView2 runtime the interface needs. A sealed forensic bench with no network and no WebView2 will stop the install, which is worth knowing before you take it somewhere air-gapped.

File
sherlock-recover-setup.exe
SHA256
dc188db50e62594c4b0e7503859d83e1c06475805b3f55a9aeaedee82d0f3f49
Version
0.1.366
Size
3.0 MB
Platform
Windows 10/11 (64-bit)

Questions

Data Recovery FAQ

Why will my recovered photo not open?
Most tools do not know where a carved file ends, so they save the largest possible size: a 20 KB photo written out as 500 MB of surrounding disk. The length is wrong, so nothing opens it. Sherlock Forensics Recover reads the true length from the file itself. On one test drive a photo other methods reported as 524 MB was measured at 24 KB.
Can deleted files be recovered from an SSD?
Often not. On most modern SSDs, deleting a file makes the drive erase it within seconds. No software can bring that back. Sherlock Forensics Recover checks for this and tells you before you spend hours on a scan it already knows will come back empty.
What is the difference between a quick scan and a deep scan?
A quick scan reads the file system's own records to list the files it still names, including deleted entries whose records survive. A deep scan carves unallocated space by file signature to find data the file system no longer references. Quick is faster; deep reaches files a format or a wipe removed from the index.
Can I open an E01 image in a data recovery program?
Yes. Sherlock Forensics Recover opens raw dd, E01 and EnCase Ex01 images and searches them for deleted files like any other source. It can also write an E01 when it images a drive.

Get Started

Recover Files That Actually Open

Free data recovery software for examiners, IT teams and anyone facing a lost drive or a broken array. Built by the same team that delivers expert witness testimony in Canadian courts.

Since 2006CISSP, ISSAP, ISSMP certified888.883.4550

Sherlock Forensics Recover is provided for lawful use. Terms of Service

Download

Your email is optional. If you provide it, we send 3 product introduction emails over the next 2 weeks. No long-term marketing. No data sharing. Skip the field and download directly.

While you are here, make us your preferred source in Google:

Sherlock Forensics Recover Pro - $295