<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>TestDisk</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/TestDisk"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-TestDisk rootpage-TestDisk skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">TestDisk</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1295905060">
/* start https://en.wikipedia.org/ */
.mw-parser-output .infobox-subbox{padding:0;border:none;margin:-3px;width:auto;min-width:100%;font-size:100%;clear:none;float:none;background-color:transparent}.mw-parser-output .infobox-3cols-child{margin:auto}.mw-parser-output .infobox .navbar{font-size:100%}@media screen{html.skin-theme-clientpref-night .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media(min-width:640px){body.skin--responsive .mw-parser-output .infobox-table{display:table!important}body.skin--responsive .mw-parser-output .infobox-table>caption{display:table-caption!important}body.skin--responsive .mw-parser-output .infobox-table>tbody{display:table-row-group}body.skin--responsive .mw-parser-output .infobox-table th,body.skin--responsive .mw-parser-output .infobox-table td{padding-left:inherit;padding-right:inherit}}
/* end https://en.wikipedia.org/ */
</style><table class="infobox vevent"><tbody><tr><td colspan="2" class="infobox-image logo"></td></tr><tr><td colspan="2" class="infobox-image logo"></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Programmer" title="Programmer">Developer(s)</a></th><td class="infobox-data">Christophe Grenier</td></tr><tr style="display: none;"><td colspan="2" class="infobox-full-data"></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_release_life_cycle" title="Software release life cycle">Stable release</a></th><td class="infobox-data"><div style="margin:0px;">7.2
/ February 22, 2024<span style="display: none;"> (<span class="bday dtstart published updated itvstart">2024-02-22</span>)</span></div></td></tr><tr style="display:none"><td colspan="2">
</td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Repository_(version_control)" title="Repository (version control)">Repository</a></th><td class="infobox-data"><style data-mw-deduplicate="TemplateStyles:r1126788409">
/* start https://en.wikipedia.org/ */
.mw-parser-output .plainlist ol,.mw-parser-output .plainlist ul{line-height:inherit;list-style:none;margin:0;padding:0}.mw-parser-output .plainlist ol li,.mw-parser-output .plainlist ul li{margin-bottom:0}
/* end https://en.wikipedia.org/ */
</style><div class="plainlist"><ul><li><span class="url"><a rel="nofollow" class="external text" href="https://git.cgsecurity.org/cgit/testdisk/">git<wbr>.cgsecurity<wbr>.org<wbr>/cgit<wbr>/testdisk<wbr>/</a></span> </li></ul>
</div></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;">Written in</th><td class="infobox-data"><a href="C_(programming_language)" title="C (programming language)">C</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_categories#Categorization_approaches" title="Software categories">Type</a></th><td class="infobox-data"><a href="Data_recovery" title="Data recovery">Data recovery</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_license" title="Software license">License</a></th><td class="infobox-data"><a href="GNU_General_Public_License" title="GNU General Public License">GPL</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;">Website</th><td class="infobox-data"><span class="url"><a rel="nofollow" class="external text" href="https://www.cgsecurity.org/wiki/TestDisk">www<wbr>.cgsecurity<wbr>.org<wbr>/wiki<wbr>/TestDisk</a></span></td></tr></tbody></table>
<p><b>TestDisk</b> is a <a href="Free_and_open-source" class="mw-redirect" title="Free and open-source">free and open-source</a> <a href="Data_recovery" title="Data recovery">data recovery</a> utility that helps users recover lost <a href="Partition_(computing)" class="mw-redirect" title="Partition (computing)">partitions</a> or repair corrupted filesystems.<sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> TestDisk can collect detailed information about a corrupted drive, which can then be sent to a technician for further analysis. TestDisk supports <a href="DOS" title="DOS">DOS</a>, <a href="Microsoft_Windows" title="Microsoft Windows">Microsoft Windows</a> (i.e. <a href="Windows_NT_4.0" title="Windows NT 4.0">NT 4.0</a>, <a href="Windows_2000" title="Windows 2000">2000</a>, <a href="Windows_XP" title="Windows XP">XP</a>, <a href="Windows_Server_2003" title="Windows Server 2003">Server 2003</a>, <a href="Windows_Server_2008" title="Windows Server 2008">Server 2008</a>, <a href="Windows_Vista" title="Windows Vista">Vista</a>, <a href="Windows_7" title="Windows 7">Windows 7</a>, <a href="Windows_8.1" title="Windows 8.1">Windows 8.1</a>, <a href="Windows_10" title="Windows 10">Windows 10</a>), <a href="Linux" title="Linux">Linux</a>, <a href="FreeBSD" title="FreeBSD">FreeBSD</a>, <a href="NetBSD" title="NetBSD">NetBSD</a>, <a href="OpenBSD" title="OpenBSD">OpenBSD</a>, <a href="SunOS" title="SunOS">SunOS</a>, and <a href="MacOS" title="MacOS">MacOS</a>. TestDisk handles non-partitioned and partitioned media.<sup id="cite_ref-grenier2021_2-0" class="reference"><a href="#cite_note-grenier2021-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> In particular, it recognizes the <a href="GUID_Partition_Table" title="GUID Partition Table">GUID Partition Table</a> (GPT), <a href="Apple_partition_map" class="mw-redirect" title="Apple partition map">Apple partition map</a>, PC/Intel BIOS partition tables, Sun <a href="Solaris_(operating_system)" class="mw-redirect" title="Solaris (operating system)">Solaris</a> <a href="Slice_(disk)" class="mw-redirect" title="Slice (disk)">slice</a> and <a href="Xbox_(console)" title="Xbox (console)">Xbox</a> fixed partitioning scheme. TestDisk uses a <a href="Command-line_interface" title="Command-line interface">command line user interface</a>. TestDisk can recover deleted files with 97% accuracy.<sup id="cite_ref-:0_3-0" class="reference"><a href="#cite_note-:0-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Features">Features</h2></div>
<p>TestDisk can recover deleted partitions, rebuild partition tables or rewrite the <a href="Master_boot_record" title="Master boot record">master boot record</a> (MBR).<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:0_3-1" class="reference"><a href="#cite_note-:0-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Partition_recovery">Partition recovery</h3></div>
<p>TestDisk retrieves the <a href="Logical_block_addressing" title="Logical block addressing">LBA</a> size and <a href="Cylinder-head-sector" title="Cylinder-head-sector">CHS</a> geometry of attached <a href="Data_storage_device" class="mw-redirect" title="Data storage device">data storage devices</a> (i.e. <a href="Hard_disk" class="mw-redirect" title="Hard disk">hard disks</a>, <a href="Memory_card" title="Memory card">memory cards</a>, <a href="USB_flash_drive" title="USB flash drive">USB flash drives</a>, and <a href="Virtual_disk" class="mw-redirect" title="Virtual disk">virtual disk</a> images) from the <a href="BIOS" title="BIOS">BIOS</a> or the <a href="Operating_system" title="Operating system">operating system</a>. The geometry information is required for a successful recovery. TestDisk reads sectors on the storage device to determine if the partition table or filesystem on it requires repair (see next section).
</p><p>TestDisk is able to recognize the following partition table formats:<sup id="cite_ref-grenier2021_2-1" class="reference"><a href="#cite_note-grenier2021-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</p>
<ul><li>Apple partition map</li>
<li>GUID Partition Table</li>
<li>Humax</li>
<li>PC/Intel Partition Table (master boot record)</li>
<li>Sun Solaris slice</li>
<li>Xbox fixed partitioning scheme</li>
<li>Non-partitioned media</li></ul>
<p>TestDisk can perform deeper checks to locate partitions that have been deleted from the partition table.<sup id="cite_ref-grenier2021_2-2" class="reference"><a href="#cite_note-grenier2021-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> However, it is up to the user to look over the list of possible partitions found by TestDisk and to select those that they wish to recover.
</p><p>After partitions are located, TestDisk can rebuild the partition table and rewrite the MBR.<sup id="cite_ref-grenier2021_2-3" class="reference"><a href="#cite_note-grenier2021-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Filesystem_repair">Filesystem repair</h3></div>
<p>TestDisk can deal with some specific logical filesystem corruption.<sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="File_recovery">File recovery</h3></div>
<p>When a file is deleted, the list of disk clusters occupied by the file is erased, marking those sectors available for use by other files created or modified thereafter. TestDisk can recover deleted files especially if the file was not fragmented and the clusters have not been reused.
</p><p>There are two file recovery mechanisms in the TestDisk package:<sup id="cite_ref-grenier2021_2-4" class="reference"><a href="#cite_note-grenier2021-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</p>
<ul><li>TestDisk proper uses knowledge of the filesystem structure to perform "undelete".</li>
<li><a href="PhotoRec" title="PhotoRec">PhotoRec</a> is a "file carver". It does not need any knowledge of the file system, but instead looks for patterns of known file formats in the partition or disk image. It works best on unfragmented files and cannot recover the file name.</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Digital_forensics">Digital forensics</h2></div>
<p>TestDisk can be used in <a href="Digital_forensics" title="Digital forensics">digital forensics</a> to retrieve partitions that were deleted long ago.<sup id="cite_ref-:0_3-2" class="reference"><a href="#cite_note-:0-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> It can mount various types of disk images including the <a href="EnCase#Expert_Witness_File_Format" title="EnCase">Expert Witness File Format</a> used by <a href="EnCase" title="EnCase">EnCase</a>.<sup id="cite_ref-grenier2021_2-5" class="reference"><a href="#cite_note-grenier2021-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-altheide2011_6-0" class="reference"><a href="#cite_note-altheide2011-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> Binary <a href="Disk_image" title="Disk image">disk images</a>, such as those created with <a href="Ddrescue" title="Ddrescue">ddrescue</a>, can be read by TestDisk as though they were storage devices.<sup id="cite_ref-nemeth2015_7-0" class="reference"><a href="#cite_note-nemeth2015-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p><p>In TestDisk versions prior to version 7, a malformed disk or its image can be used to inject malicious code into a running TestDisk application on <a href="Cygwin" title="Cygwin">Cygwin</a>.<sup id="cite_ref-nemeth2015_7-1" class="reference"><a href="#cite_note-nemeth2015-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="File_system_support">File system support</h2></div>
<p>File system support for TestDisk is shown in the table:
</p>
<table class="wikitable sortable plainrowheaders" style="text-align:center;">
<tbody><tr>
<th rowspan="2" scope="col">Name<sup id="cite_ref-grenier2021_2-6" class="reference"><a href="#cite_note-grenier2021-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</th>
<th scope="col">Partition Recovery
</th>
<th colspan="2" scope="col">Filesystem Recovery
</th>
<th scope="col">File Recovery
</th></tr>
<tr>
<th scope="col">Find filesystem
</th>
<th scope="col">Boot sector/<br>superblock Restore
</th>
<th scope="col">File table repair
</th>
<th scope="col">Undelete<sup id="cite_ref-grenier2021_2-7" class="reference"><a href="#cite_note-grenier2021-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</th></tr>
<tr>
<th scope="row"><a href="File_Allocation_Table" title="File Allocation Table">FAT12/16/32</a>
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes<sup id="cite_ref-BootSectorParameters_8-0" class="reference"><a href="#cite_note-BootSectorParameters-8"><span class="cite-bracket">[</span>a<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-RestoreBackup_9-0" class="reference"><a href="#cite_note-RestoreBackup-9"><span class="cite-bracket">[</span>b<span class="cite-bracket">]</span></a></sup></td>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes<sup id="cite_ref-RestoreTwoCopiesFat_10-0" class="reference"><a href="#cite_note-RestoreTwoCopiesFat-10"><span class="cite-bracket">[</span>c<span class="cite-bracket">]</span></a></sup></td>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes
</td></tr>
<tr>
<th scope="row"><a href="ExFAT" title="ExFAT">exFAT</a>
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes<sup id="cite_ref-RestoreBackup_9-1" class="reference"><a href="#cite_note-RestoreBackup-9"><span class="cite-bracket">[</span>b<span class="cite-bracket">]</span></a></sup></td>
<td style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">Use <a href="Fsck" title="Fsck">fsck</a></td>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes
</td></tr>
<tr>
<th scope="row"><a href="NTFS" title="NTFS">NTFS</a>
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes<sup id="cite_ref-BootSectorParameters_8-1" class="reference"><a href="#cite_note-BootSectorParameters-8"><span class="cite-bracket">[</span>a<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-RestoreBackup_9-2" class="reference"><a href="#cite_note-RestoreBackup-9"><span class="cite-bracket">[</span>b<span class="cite-bracket">]</span></a></sup></td>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes<sup id="cite_ref-RestoreMft_11-0" class="reference"><a href="#cite_note-RestoreMft-11"><span class="cite-bracket">[</span>d<span class="cite-bracket">]</span></a></sup></td>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes
</td></tr>
<tr>
<th scope="row"><a href="Ext2" title="Ext2">ext2</a>, <a href="Ext3" title="Ext3">ext3</a>, and <a href="Ext4" title="Ext4">ext4</a>
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes<sup id="cite_ref-FindSuperBlock_12-0" class="reference"><a href="#cite_note-FindSuperBlock-12"><span class="cite-bracket">[</span>e<span class="cite-bracket">]</span></a></sup></td>
<td style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">Use <a href="Fsck" title="Fsck">fsck</a></td>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes
</td></tr>
<tr>
<th scope="row">HFS, <a href="HFS%2B" class="mw-redirect" title="HFS+">HFS+</a>, HFSX
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes<sup id="cite_ref-RestoreBackup_9-3" class="reference"><a href="#cite_note-RestoreBackup-9"><span class="cite-bracket">[</span>b<span class="cite-bracket">]</span></a></sup></td>
<td style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">Use <a href="Fsck" title="Fsck">fsck</a></td>
<td style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">No
</td></tr>
<tr>
<th scope="row"><a href="BeOS" title="BeOS">BeOS</a>
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td colspan="2" rowspan="12" style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">No</td>
<td style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">No
</td></tr>
<tr>
<th scope="row"><a href="BSD_disklabel" title="BSD disklabel">BSD disklabel</a> (FreeBSD/OpenBSD/NetBSD)
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">No
</td></tr>
<tr>
<th scope="row"><a href="Cramfs" title="Cramfs">Cramfs</a>
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">No
</td></tr>
<tr>
<th scope="row"><a href="IBM_Journaled_File_System_2_(JFS2)" class="mw-redirect" title="IBM Journaled File System 2 (JFS2)">IBM JFS2</a>
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">No
</td></tr>
<tr>
<th scope="row">Linux RAID (<a href="Mdadm" title="Mdadm">mdadm</a>)<sup id="cite_ref-13" class="reference"><a href="#cite_note-13"><span class="cite-bracket">[</span>f<span class="cite-bracket">]</span></a></sup>
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">No
</td></tr>
<tr>
<th scope="row">Linux Swap 1 and 2
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">No
</td></tr>
<tr>
<th scope="row"><a href="Logical_Volume_Manager" class="mw-redirect" title="Logical Volume Manager">LVM and LVM2</a>
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">No
</td></tr>
<tr>
<th scope="row"><a href="Novell_Storage_Services" title="Novell Storage Services">Novell Storage Services</a> (NSS)
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">No
</td></tr>
<tr>
<th scope="row"><a href="ReiserFS" title="ReiserFS">ReiserFS</a> 3.5, 3.6 and 4
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">No
</td></tr>
<tr>
<th scope="row">Sun Solaris i386 disklabel
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">No
</td></tr>
<tr>
<th scope="row"><a href="Unix_File_System" title="Unix File System">UFS and UFS2</a> (Sun/BSD/…)
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">No
</td></tr>
<tr>
<th scope="row"><a href="XFS" title="XFS">XFS</a> from SGI
</th>
<td style="background:#9EFF9E;color:black;vertical-align:middle;text-align:center;" class="table-yes">Yes</td>
<td style="background:#FFC7C7;color:black;vertical-align:middle;text-align:center;" class="table-no">No
</td></tr></tbody></table>
<p>Some features, such as partition table editing and PhotoRec "carving", do not depend on the file system at all.
</p>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist reflist-lower-alpha">
<div class="mw-references-wrap"><ol class="references">
<li id="cite_note-BootSectorParameters-8"><span class="mw-cite-backlink">^ <a href="#cite_ref-BootSectorParameters_8-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-BootSectorParameters_8-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text">Find filesystem parameters to rewrite a valid <a href="BIOS_parameter_block" title="BIOS parameter block">BIOS parameter block</a> (analogous to "superblocks" in Unix file systems)</span>
</li>
<li id="cite_note-RestoreBackup-9"><span class="mw-cite-backlink">^ <a href="#cite_ref-RestoreBackup_9-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-RestoreBackup_9-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-RestoreBackup_9-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-RestoreBackup_9-3"><sup><i><b>d</b></i></sup></a></span> <span class="reference-text">Restore the BPB using its backup (NTFS, FAT32, exFAT)</span>
</li>
<li id="cite_note-RestoreTwoCopiesFat-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-RestoreTwoCopiesFat_10-0">^</a></b></span> <span class="reference-text">Use the two copies of the FAT to rewrite a coherent version</span>
</li>
<li id="cite_note-RestoreMft-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-RestoreMft_11-0">^</a></b></span> <span class="reference-text">Restore the Master File Table (MFT) from its backup</span>
</li>
<li id="cite_note-FindSuperBlock-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-FindSuperBlock_12-0">^</a></b></span> <span class="reference-text">Find backup superblock location to assist <a href="Fsck" title="Fsck">fsck</a></span>
</li>
<li id="cite_note-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-13">^</a></b></span> <span class="reference-text">RAID 1: mirroring, RAID 4: striped array with parity device, RAID 5: striped array with distributed parity information and RAID 6: striped array with distributed dual redundancy information</span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1266661725">
/* start https://en.wikipedia.org/ */
.mw-parser-output .portalbox{padding:0;margin:0.5em 0;display:table;box-sizing:border-box;max-width:175px;list-style:none}.mw-parser-output .portalborder{border:1px solid var(--border-color-base,#a2a9b1);padding:0.1em;background:var(--background-color-neutral-subtle,#f8f9fa)}.mw-parser-output .portalbox-entry{display:table-row;font-size:85%;line-height:110%;height:1.9em;font-style:italic;font-weight:bold}.mw-parser-output .portalbox-image{display:table-cell;padding:0.2em;vertical-align:middle;text-align:center}.mw-parser-output .portalbox-link{display:table-cell;padding:0.2em 0.2em 0.2em 0.3em;vertical-align:middle}@media(min-width:720px){.mw-parser-output .portalleft{margin:0.5em 1em 0.5em 0}.mw-parser-output .portalright{clear:right;float:right;margin:0.5em 0 0.5em 1em}}
/* end https://en.wikipedia.org/ */
</style>
<ul><li><a href="PhotoRec" title="PhotoRec">PhotoRec</a></li>
<li><a href="List_of_data_recovery_software" class="mw-redirect" title="List of data recovery software">List of data recovery software</a></li>
<li><a href="List_of_free_and_open-source_software_packages" title="List of free and open-source software packages">List of free and open-source software packages</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<div class="reflist">
<div class="mw-references-wrap"><ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><cite id="CITEREFMoggridge2017" class="citation journal cs1">Moggridge, J. (2017). <a rel="nofollow" class="external text" href="https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5308389">"Security of patient data when decommissioning ultrasound systems"</a>. <i>Ultrasound</i>. <b>25</b> (1). Leeds, England: <span class="nowrap">16–</span>24. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1177%2F1742271X16688043">10.1177/1742271X16688043</a>. <a href="PMC_(identifier)" class="mw-redirect" title="PMC (identifier)">PMC</a> <span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5308389">5308389</a></span>. <a href="PMID_(identifier)" class="mw-redirect" title="PMID (identifier)">PMID</a> <a rel="nofollow" class="external text" href="https://pubmed.ncbi.nlm.nih.gov/28228821">28228821</a>.</cite></span>
</li>
<li id="cite_note-grenier2021-2"><span class="mw-cite-backlink">^ <a href="#cite_ref-grenier2021_2-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-grenier2021_2-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-grenier2021_2-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-grenier2021_2-3"><sup><i><b>d</b></i></sup></a> <a href="#cite_ref-grenier2021_2-4"><sup><i><b>e</b></i></sup></a> <a href="#cite_ref-grenier2021_2-5"><sup><i><b>f</b></i></sup></a> <a href="#cite_ref-grenier2021_2-6"><sup><i><b>g</b></i></sup></a> <a href="#cite_ref-grenier2021_2-7"><sup><i><b>h</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFGrenier2021" class="citation cs2">Grenier, Christophe (2021-05-31), <a rel="nofollow" class="external text" href="https://www.cgsecurity.org/testdisk_doc/"><i>TestDisk Documentation</i></a>, CG Security</cite> (<a rel="nofollow" class="external text" href="https://www.cgsecurity.org/testdisk.pdf">PDF</a>)</span>
</li>
<li id="cite_note-:0-3"><span class="mw-cite-backlink">^ <a href="#cite_ref-:0_3-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:0_3-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-:0_3-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFkumarSaharanPanda2020" class="citation book cs1">kumar, Hany; Saharan, Ravi; Panda, Saroj Kumar (March 2020). <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/9132869">"Identification of Potential Forensic Artifacts in Cloud Storage Application"</a>. <i>2020 International Conference on Computer Science, Engineering and Applications (ICCSEA)</i>. pp. <span class="nowrap">1–</span>5. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FICCSEA49143.2020.9132869">10.1109/ICCSEA49143.2020.9132869</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-1-7281-5830-3</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:220367251">220367251</a>.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text">Debra Littlejohn Shinder, Michael Cross (2002). <i>Scene of the cybercrime</i>, page 328. Syngress. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-1-931836-65-4</bdi>.</span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text">Jack Wiles, Kevin Cardwell, Anthony Reyes (2007). <i>The best damn cybercrime and digital forensics book period</i>, page 373. Syngress. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-1-59749-228-7</bdi>.</span>
</li>
<li id="cite_note-altheide2011-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-altheide2011_6-0">^</a></b></span> <span class="reference-text">Altheide, C., & Carvey, H. (2011). File System and Disk Analysis. In Digital Forensics with Open Source Tools. Elsevier. <a rel="nofollow" class="external free" href="https://booksite.elsevier.com/samplechapters/9781597495868/Chapter_3.pdf">https://booksite.elsevier.com/samplechapters/9781597495868/Chapter_3.pdf</a></span>
</li>
<li id="cite_note-nemeth2015-7"><span class="mw-cite-backlink">^ <a href="#cite_ref-nemeth2015_7-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-nemeth2015_7-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFNémeth2015" class="citation book cs1">Németh, Z. L. (2015). <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/7325394">"Modern binary attacks and defences in the windows environment — Fighting against microsoft EMET in seven rounds"</a>. <i>2015 IEEE 13th International Symposium on Intelligent Systems and Informatics (SISY)</i>. pp. <span class="nowrap">275–</span>280. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FSISY.2015.7325394">10.1109/SISY.2015.7325394</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-1-4673-9388-1</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:18914754">18914754</a>.</cite></span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><a rel="nofollow" class="external text" href="https://www.cgsecurity.org/wiki/TestDisk">TestDisk Wiki</a></li>
<li><a rel="nofollow" class="external text" href="https://www.cgsecurity.org/wiki/In_The_News">List of news articles about TestDisk and PhotoRec</a></li>
<li><a rel="nofollow" class="external text" href="https://www.howtoforge.com/data_recovery_with_testdisk">Data Recovery With TestDisk</a>, Falko Timme, HowtoForge</li>
<li><a rel="nofollow" class="external text" href="https://www.digitalforensics.ch/nikkel05b.pdf">Digital Forensics using Linux and Open Source Tools</a></li></ul>
<p>Test Disk Team:<br>
Main Contributor: Christophe Grenier. Location: Paris, France. URL: cgsecurity.org. He started the project in 1998 and is still the main developer. He is also responsible for the packaging of TestDisk & PhotoRec for DOS, Windows, Linux (generic version), MacOS X, and Fedora distribution.
</p></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-01-08" href="https://en.wikipedia.org/wiki/?title=TestDisk&oldid=1268122439">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>