Skip to content

Scalpel

File carving tool that recovers deleted files from disk images by searching for known file headers and footers.

When I Use It

  • Recovering deleted files when the file system metadata is gone or damaged
  • Finding files with custom signatures, such as challenge files with a known header

Scalpel is no longer actively developed. Foremost and PhotoRec are common alternatives.

Installation

  • Debian / Ubuntu: sudo apt install scalpel

Common Tasks

Task How
Choose file types Uncomment the types to recover in /etc/scalpel/scalpel.conf, or copy it and pass the copy with -c /path/to/new.conf
Run scalpel -b -o /empty/output/directory DiskImage.img
Add a custom file type Add a line with extension, case sensitivity, max size, header, and footer, for example txt y 10000 BTL1 1LTB
Read recovered text strings /path/to/recovered/file

The output directory must be empty.

Reading the Output

  • Recovered files are named by offset, not by their original names, because carving does not use file system metadata
  • Carving finds fragments and false positives, especially for types with short or common headers; check each result

Resources