Command reference

RecoverYantra Imager on the command line

Every command this product contains and every parameter it accepts: 13 commands, 66 parameters. Read from the shipping build, version 7.8.10.76. The help text says what a switch does; each entry here adds when a business reaches for it and what it costs.

Before the first command

  • Reading a physical drive needs administrator rights. Working from a disk image needs none.
  • The source is opened read-only for the whole session, and the application refuses a destination on the drive being read.
  • Set the mode before the scan. A recovery-mode scan does not become evidential afterwards.
  • Everything below is available in the application as well; the command line is the scriptable surface, not a separate product.
RecoverYantra Imager workspace
RecoverYantra Imager in the application. Every command below has an equivalent here.
Command

recoveryantra acquire

-oalso --output

Folder to write the image into (default: ./Evidence)

When to use it. Point this at the evidence store for the case, not at the machine's own disk. On a booted rescue USB the default writes to the stick itself, which is usually what you want in the field.

What it costs. The folder must have room for the whole source. The pre-flight refuses rather than filling the disk half way through.

--retriesdefault 3

Retries for bad sectors (default 3)

When to use it. Raise it when the drive is readable but marginal and the case justifies a slow, thorough pass. Lower it to 0 or 1 when the drive is deteriorating and getting a complete-enough image quickly matters more than the last few sectors.

What it costs. Every retry is another read of a failing surface. On a drive that is physically degrading, high retry counts can cost you the areas you have not reached yet.

--force

Start even if the pre-flight checks object.

When to use it. Only when you have read the pre-flight objection and know it is wrong for your situation, for example free space reported incorrectly by a network share.

What it costs. The pre-flight exists to stop a job that cannot finish. Forcing past a genuine space or same-drive objection loses work, and on the same-drive case it can overwrite the very data being recovered.

--write-block

Engage a SOFTWARE write-block (OS read-only) on the source first. Best-effort and not a substitute for a hardware write blocker; layered with the fingerprint.

When to use it. Use on every evidential acquisition where no hardware write blocker is available. It sets the operating system's own read-only flag on the source before the first read.

What it costs. It is best effort at the operating-system level and is not equivalent to a hardware write blocker. State which one you used in the report; do not describe a software block as a hardware one.

--formatone of raw, e01

Image format: raw (.img, resumable) or E01. Asked for when omitted.

When to use it. raw when the image will be recovered from or examined on the same bench and a stopped copy must be resumable (the .map carries on); e01 when it goes to a lab that expects Expert Witness containers or when the destination is smaller than the drive and compression has to make it fit. Asked for on screen when omitted.

What it costs. An E01 copy cannot be resumed part way; a raw copy takes the drive's full size on the destination.

--boot

On the RecoverYantra bootable USB: offer the USB's own DATA partition and any other attached drive as the destination, never the drive being copied or the boot medium; record the read-only protection.

When to use it. Set by the RecoverYantra bootable USB's own launcher: the USB's DATA partition is offered first as the destination, then any other attached drive that is neither the source nor the boot medium, and the manifest records that every disk arrived read-only.

What it costs. Outside the bootable USB there is no live medium, so the flag is ignored with a note and -o decides where the image goes.

--operator

Examiner asserting lawful authority (recorded)

When to use it. Record the individual asserting lawful authority for the acquisition. Required practice for anything that may be produced in proceedings.

--authority

Lawful basis: warrant / consent / statutory power

When to use it. Record the lawful basis: warrant, consent, or a statutory power. Write what it actually is, and keep the underlying document with the case file.

What it costs. This field records the assertion. It is not legal advice and it does not create authority you do not have.

--org

Examiner's organisation (recorded)

When to use it. The examining organisation, as it should appear on the report and in the custody record.

--case

Case / FIR reference (recorded)

When to use it. Your own case or FIR reference. Set it at acquisition so every later artefact carries the same identifier.

What it costs. Adding it afterwards means the earliest records in the trail carry a different reference from the rest.

Command

recoveryantra capabilities

--enable

Turn on an advanced method (e.g. checkm8, mtk_bootrom, qualcomm_edl)

When to use it. Turn on an advanced acquisition method for a case that needs it and is authorised for it. These methods interact with the device, so they are off until an examiner opts in on the record.

What it costs. Enabling is recorded in the audit trail with the operator and case. An advanced method can alter the device; decide before the exhibit is in front of you, not during.

--disable

Turn an advanced method back off

When to use it. Turn a method back off once the step that needed it is complete, so the next case starts from the conservative default.

--tools

Show the acquisition toolbox: the public methods (checkm8/mtkclient/edl/adb...), what's installed, and what is equipped for this case

When to use it. Run before an acquisition to see which external tools are actually installed on this machine and which methods are therefore available today.

What it costs. The product orchestrates the operator's own tools for advanced methods; it does not bundle exploits. A method with no tool present is not available however the case is authorised.

--operator

Examiner making the choice (recorded)

When to use it. Name the examiner making the decision. The choice belongs in the record alongside the result it produced.

--case

Case reference (recorded)

When to use it. Tie the capability decision to the case it was made for.

Command

recoveryantra check

--device

Raw device path (e.g. \\.\PhysicalDrive1 or /dev/sdb)

When to use it. Run the feasibility check the moment a drive arrives, before quoting, before imaging and before any promise to the client: it measures how much of the drive is unreadable and states the chances in plain words.

What it costs. A few hundred sampled reads - seconds on a healthy drive, and one gentle attempt per area on a failing one. Far cheaper than discovering mid-copy that the job was never viable.

--image

An existing image file to check instead

When to use it. Check an existing image instead of a drive - for example to confirm a copy received from a client or another lab reads cleanly before work is billed against it.

--pdf

Also write the answer as a PDF report at this path

When to use it. Write the verdict as a PDF wherever a client, insurer or case file needs the answer on record. The report states its numbers as ranges and says it is based on a sample.

--samplesdefault 160

How many areas of the drive to test (default 160)

When to use it. More samples narrow the stated range and cost more reads of the drive. The default suits a first assessment; raise it when the estimate must be tighter than a few percent.

What it costs. Each extra sample is another read of a drive that may be dying. On clearly failing hardware, keep the default and move to the copy.

Command

recoveryantra detect

--report

Also write the report (HTML, PDF, JSON) into DIR

When to use it. Write the detection report - HTML, PDF and JSON - into this folder: every device with its state, bus, serial and sector size, the hardware Windows can see but cannot use with the code and the fix, and the Plug-and-Play inventory. Use it when a customer or a partner says a drive is not detected: the report replaces "it does not work" with what the machine actually sees.

What it costs. The folder goes through the same pre-flight as every other writing job; the report is small, so only rights and a full disk stop it.

--no-health

Skip the health read of each usable drive (faster)

When to use it. Skip the health read of each usable drive. Detection is then a listing only and returns in a second or two. Use it on a machine with many drives, or when a drive is known to be failing and you do not want even a test read against it before imaging.

--force

Write the report even if the pre-flight objects

When to use it. Write the report even when the pre-flight objects to the folder. Use it only when you have read the objection and it does not apply - a report is a few hundred kilobytes, so the usual reason is a destination the check cannot judge.

What it costs. A refusal you have not read is not one you can override safely.

Command

recoveryantra find-drive

<pattern>positional

A filename, part of one, or a wildcard (e.g. IMG_2019, *.jpg)

When to use it. Search every usable attached device for a file whose name matches PATTERN, without picking a drive first. Free, no licence needed - reads each device's index in seconds, the same tier as `--list`. Use it when the customer cannot say which of several drives holds what they want.

--timeoutdefault 20.0

Give up on one drive after this long (default 20); a slow or failing drive never holds up the others

When to use it. Seconds allowed per device before moving on. A slow or failing device costs only its own row - the sweep never waits on one device at the expense of the rest.

--all

List every drive checked, including the ones with no match

When to use it. Also sweep devices that are not in a normally-usable state, where possible. Use it only once the plain sweep has come back empty.

Command

recoveryantra gui

--classic

Use the classic Tkinter wizard

When to use it. Fall back to the classic interface on a machine where the modern window will not start, typically an old or minimal Windows install.

Command

recoveryantra guide

--html

Write the guide as a self-contained, searchable HTML page

When to use it. Produce the manual as a single searchable page to hand to a client, put on an internal share, or carry onto an air-gapped bench.

--markdown

Write the guide as Markdown

When to use it. Produce Markdown when the content is going into your own documentation system or version control.

Command

recoveryantra image

--device

Raw device path (e.g. \\.\PhysicalDrive1 or /dev/sdb)

When to use it. Image the drive first whenever it is failing, whenever the original must go back to the client untouched, or whenever the matter may be produced. Every later step runs against the image.

What it costs. Imaging reads the whole drive once. On a drive that is actively dying that single pass is the best chance you get, so choose the retry policy before starting, not after.

--source

Existing image/file to re-image

When to use it. Re-image an existing file, for example to convert a raw image to E01 or to make a working copy of an evidence image.

-oalso --output

Output image path (.img or .E01)

When to use it. The image path on the case store. Name it for the exhibit, not for the machine.

--retriesdefault 3

Retries for bad sectors (default 3)

When to use it. Same trade-off as on acquire: more retries recover more marginal sectors and cost more reads of a failing surface.

--formatone of raw, e01 · default raw

raw .dd/.img (default) or compressed .E01 evidence image

When to use it. Use e01 for evidential work: it is compressed and carries the acquisition metadata other forensic tools expect. Use raw when the image will be mounted or read by tooling that only takes a flat image.

What it costs. Raw images are the size of the whole drive, including empty space.

--targeted

Filesystem-aware (read-once): image only the space the filesystems say holds data, skipping free space without reading it. Faster and gentler on a failing drive, and a smaller image. Deleted files still in free space are NOT captured - use a full image for those.

When to use it. Filesystem-aware, read-once imaging: the filesystems' own allocation maps say which space holds data, and only that is read and copied - free space is skipped without touching the drive. Use it to image a large or failing drive faster and more gently, and to get a smaller image, when the live files are what matter.

What it costs. Deleted files still sitting in free space are NOT captured - free space is exactly where they live. When deleted data matters, take a full image (omit --targeted). A filesystem we cannot read a map for is imaged in full, so it is never wrong, only sometimes not smaller.

--entropy-map

Measure the entropy of the data as it is copied and record which spans are high-entropy (encrypted or compressed) in the image's .map.json.

When to use it. Measure the entropy of the data as it is copied and record which spans are high-entropy - encrypted or compressed - in the image's .map.json. Use it to see at a glance whether a drive (or a region) is encrypted before spending time on recovery.

What it costs. Entropy cannot tell encryption from compression; a high-entropy span may be either. It is a signpost, not a verdict.

--force

Start even when the pre-flight checks say this cannot finish: too little room, or writing onto the drive being recovered.

When to use it. Only after reading the objection. See acquire.

Command

recoveryantra list

--triage

Also check each device's health (SMART + test reads), how it's connected, and what kind of device it is (CCTV recorder, phone, dashcam, card, ...) with advice on what to do

When to use it. Run before touching anything. It reports each device's health, how it is connected and what kind of device it is, which is what decides whether to recover directly or image first.

What it costs. Triage reads the drive. On a drive that is audibly failing, keep even this brief and go straight to imaging.

Command

recoveryantra recover

--device

Raw device path (e.g. \\.\PhysicalDrive1 or /dev/sdb)

When to use it. Recover directly from the attached drive when it is healthy, the job is not evidential, and time matters.

What it costs. If the drive is failing, image it first. A direct scan reads the whole surface and can be the read that finishes a dying drive.

--image

Disk image file (.dd/.img/.iso)

When to use it. The default choice for anything evidential, anything failing, and anything where the original must be returned untouched.

--ios-backup

An iOS (iTunes/Finder) backup folder (Manifest.db)

When to use it. Point at an iTunes or Finder backup folder when the handset itself is unavailable, locked, or must not be touched.

--slabmap

Storage Spaces slab-map JSON: reassemble a pool virtual disk from member images and recover from it

When to use it. Reassemble a Storage Spaces virtual disk from member images and recover from the assembled volume.

-oalso --output

Output directory for recovered files (required unless --list)

When to use it. Always a separate drive from the source. The product refuses a destination on the drive being read.

--modeone of smart, fs, carve · default smart

smart=metadata+carving (default), fs=named files only, carve=signatures only

When to use it. Leave at smart. It parses the file system for original names and folders AND carves free space for what the metadata no longer covers. Use fs when you want named files quickly from an intact file system; use carve on formatted or badly damaged media where the metadata is gone.

What it costs. fs alone misses everything the file system no longer indexes. carve alone returns files without their original names or folders. smart is what maximises the result.

--resume

Carry on from where an earlier scan of the same source into the same output folder stopped, instead of starting again from the beginning

When to use it. Continue a scan that was stopped, on the same source into the same output folder. A large drive is an overnight job and does not need to be restarted.

What it costs. The checkpoint belongs to the DRIVE, not the path. A different disk in the same slot restarts from the beginning, with the reason stated.

--include-intact

Also recover currently-existing (non-deleted) files

When to use it. Add whenever the loss is a volume rather than a deletion: a reformatted disk, a RAW volume, a failed array. In those cases the files were never deleted and the default deleted-only view will look almost empty.

What it costs. It substantially increases the output size, because it recovers everything present as well as everything deleted.

--list

Print the drive's folder tree from its index (live and deleted files) and stop. Fast; nothing is written. -o is not needed.

When to use it. Look before you scan. Reads the filesystem index only and prints the folder tree - live and deleted files, deleted ones marked - in seconds, writing nothing. Use it first on any drive whose index is intact: it tells you whether the folder the customer wants is still named, so you can recover that alone with --only instead of reading the whole drive.

What it costs. Free, and needs no licence. What it cannot show is anything whose index entry is gone - a formatted card, a wiped table - which still needs the full scan.

--only

Recover only this folder or file (repeatable). Paths are the volume's own, e.g. --only /Users/jo/Documents/ --only /Photos/IMG_0042.jpg. Implies --mode fs and --include-intact.

When to use it. Recover one folder or file rather than everything: the customer wants the Documents folder, not four hours and a terabyte of working folder. Repeat the switch for several paths; a folder path takes everything under it, and 1:/Folder/ names the folder on partition 1 only. Paths are the volume's own, as --list prints them.

What it costs. Implies --mode fs and --include-intact. Every content check, the manifest and the organising run exactly as in a full scan; a use is still charged for the drive.

--engineone of native, photorec, auto · default native

native=built-in (default), photorec=use TestDisk's PhotoRec, auto=PhotoRec if installed

When to use it. Leave at native. Select photorec only to cross-check a result with a second implementation, which is occasionally useful in a disputed matter.

What it costs. The external engine must be installed separately and does not carry this product's validation or its verdicts.

--workers

Carving processes: 0=auto/all cores (default, byte-identical output, ~3x faster), 1=single-threaded, N=that many

When to use it. Leave at 0 so the carve uses the available cores. Set 1 when you need the machine responsive for other work, or when reproducing a result exactly for a report.

What it costs. Output is byte-identical either way; only the time changes. Below about 128 MB the product stays single-threaded because process start-up costs more than it saves.

--sector-sizedefault 512

Bytes per sector (default 512)

When to use it. Change from 512 only for 4K-native drives, where the wrong value prevents the volume being recognised.

--password

Unlock an encrypted drive. A BitLocker 48-digit recovery password, a LUKS passphrase, or a key in hexadecimal.

When to use it. Supply the BitLocker recovery password, LUKS passphrase or hex key for an encrypted volume.

What it costs. Without the correct credential the volume cannot be read by anyone. The product states that rather than returning fragments. The credential is not retained for a later resume.

--force

Start even when the pre-flight checks say this cannot finish: too little room, or writing onto the drive being recovered.

When to use it. Only when you have read the pre-flight objection and established that it is wrong for your situation.

What it costs. The two objections it can override are both serious: too little room means the scan stops part way, and writing onto the drive being recovered overwrites the data you are trying to get back.

--report

Generate a recovery report after scanning (comma-separated: pdf,docx,html; default all)

When to use it. Generate the report at the end of the scan whenever the result goes to somebody else: a client, an insurer, or a case file.

--profileone of forensic, recovery

Override the mode for this run (forensic=hash+manifest+evidence, recovery=fast+by-type). Defaults to the saved global mode.

When to use it. Override the saved mode for this one run, for example a single evidential job on a bench normally used for commercial recovery.

What it costs. Setting it per run avoids the more common error, which is leaving a bench in forensic mode and hashing every file on high-volume commercial work.

--apfs-snapshots

List the APFS snapshots on the source (point-in-time views that may hold deleted/overwritten files) and stop

When to use it. Run first on any Mac volume. Snapshots are point-in-time views that often still hold the file as it was before it was deleted or overwritten.

--apfs-snapshot

Recover files as they were in this named APFS snapshot (byte-exact from the copy-on-write extents)

When to use it. Recover from the named snapshot. Where the file exists in a snapshot, this returns it byte-exact and is far better than carving for it.

--vss-list

List the Windows Volume Shadow Copies on the source (previous versions - originals from before deletion or ransomware) and stop

When to use it. Run first on any Windows volume, and always in a ransomware incident. Shadow copies hold previous versions from before the deletion or the encryption.

--vss-snapshot

Recover files as they were in this shadow copy: the snapshot-time volume is reconstructed and scanned

When to use it. Reconstruct the volume as it was at that snapshot and recover from it. This is frequently the fastest complete recovery available.

Command

recoveryantra steps

<workflow>positional

Workflow id (e.g. forensics, data_recovery); omit to list them by category

When to use it. Show the full procedure for one job - every stage, what it is for, the safety gates that cannot be skipped, and the command that carries each one out. Use it when a technician is doing a job for the first time, when a job is done rarely enough that nobody remembers the order, or when a reviewer asks why the work was done the way it was.

--categoryone of recovery, forensics

Show only one category's workflows

When to use it. Show only data recovery, or only forensics. The two follow different orders because they are for different things: a recovery is judged on how much comes back, an examination on whether you can prove what you did. Verification therefore ends a recovery and sits in the MIDDLE of an examination, before any analysis. Use this to hand a new examiner only the sequence that applies to them.

--commands

Print only the commands, in order, ready to copy

When to use it. Print only the commands, in order, ready to paste. Use it to build a runbook, to script a job that is done the same way every time, or to check a script somebody else wrote actually follows the procedure.

--standards

Show the published practice each step comes from

When to use it. Show the published practice each stage comes from - ISO/IEC 27037, NIST SP 800-86, the ACPO principles. Use it when a client, an auditor or a court asks why a step exists, and when training staff who need to know the procedure is not this vendor's opinion.

Command

recoveryantra which

<situation>positional

What is happening, in plain words (e.g. "drive is clicking"); omit to list every situation

When to use it. Describe what is happening in your own words - "drive is clicking", "formatted the wrong disk", "Outlook will not open it" - and get the feature to use, why that one rather than the obvious alternative, a worked example, the commands, and what NOT to do. Use it when somebody hands you a job and you are not sure which part of the product it belongs to, and give it to new staff before you give them anything else.

--all

Show every situation, grouped, rather than searching

When to use it. List every situation, grouped, instead of searching. Use it to see the whole range at once - useful when scoping what a product will cover for a customer, and for training.

What it costs. Situations the product you are running does not include are marked, so the list stays honest about what this build can actually do.