Command reference

SakshyaYantra Mobile Workbench on the command line

Every command this product contains and every parameter it accepts: 14 commands, 59 parameters. Read from the shipping build, version 7.8.10.76. The help text says what a switch does; each entry here adds when a business reaches for it and what it costs.

Before the first command

  • Reading a physical drive needs administrator rights. Working from a disk image needs none.
  • The source is opened read-only for the whole session, and the application refuses a destination on the drive being read.
  • Set the mode before the scan. A recovery-mode scan does not become evidential afterwards.
  • Everything below is available in the application as well; the command line is the scriptable surface, not a separate product.
SakshyaYantra Mobile Workbench workspace
SakshyaYantra Mobile Workbench in the application. Every command below has an equivalent here.
Command

recoveryantra capabilities

--enable

Turn on an advanced method (e.g. checkm8, mtk_bootrom, qualcomm_edl)

When to use it. Turn on an advanced acquisition method for a case that needs it and is authorised for it. These methods interact with the device, so they are off until an examiner opts in on the record.

What it costs. Enabling is recorded in the audit trail with the operator and case. An advanced method can alter the device; decide before the exhibit is in front of you, not during.

--disable

Turn an advanced method back off

When to use it. Turn a method back off once the step that needed it is complete, so the next case starts from the conservative default.

--tools

Show the acquisition toolbox: the public methods (checkm8/mtkclient/edl/adb...), what's installed, and what is equipped for this case

When to use it. Run before an acquisition to see which external tools are actually installed on this machine and which methods are therefore available today.

What it costs. The product orchestrates the operator's own tools for advanced methods; it does not bundle exploits. A method with no tool present is not available however the case is authorised.

--operator

Examiner making the choice (recorded)

When to use it. Name the examiner making the decision. The choice belongs in the record alongside the result it produced.

--case

Case reference (recorded)

When to use it. Tie the capability decision to the case it was made for.

Command

recoveryantra case

<case_cmd>one of new, add, list, status, dedup · positional

When to use it. Group several recovered sources - a laptop disk, a backup stick, a phone image - into one case for a single customer or job, and see everything recovered across them in one place, deduplicated by hash. `new` starts a case; `add` puts a source into it; `list` shows the cases or one case's sources; `status` totals its files and duplicates; `dedup` lists files found in more than one source. Use it when a job is more than one drive and you do not want to hand back the same file three times.

Command

recoveryantra certify

<cecmd>one of draft, verify · positional

When to use it. Draft the Section 63(4) Bharatiya Sakshya Adhiniyam certificate from a case's exhibits, or re-verify one already issued.

Command

recoveryantra detect

--report

Also write the report (HTML, PDF, JSON) into DIR

When to use it. Write the detection report - HTML, PDF and JSON - into this folder: every device with its state, bus, serial and sector size, the hardware Windows can see but cannot use with the code and the fix, and the Plug-and-Play inventory. Use it when a customer or a partner says a drive is not detected: the report replaces "it does not work" with what the machine actually sees.

What it costs. The folder goes through the same pre-flight as every other writing job; the report is small, so only rights and a full disk stop it.

--no-health

Skip the health read of each usable drive (faster)

When to use it. Skip the health read of each usable drive. Detection is then a listing only and returns in a second or two. Use it on a machine with many drives, or when a drive is known to be failing and you do not want even a test read against it before imaging.

--force

Write the report even if the pre-flight objects

When to use it. Write the report even when the pre-flight objects to the folder. Use it only when you have read the objection and it does not apply - a report is a few hundred kilobytes, so the usual reason is a destination the check cannot judge.

What it costs. A refusal you have not read is not one you can override safely.

Command

recoveryantra find-drive

<pattern>positional

A filename, part of one, or a wildcard (e.g. IMG_2019, *.jpg)

When to use it. Search every usable attached device for a file whose name matches PATTERN, without picking a drive first. Free, no licence needed - reads each device's index in seconds, the same tier as `--list`. Use it when the customer cannot say which of several drives holds what they want.

--timeoutdefault 20.0

Give up on one drive after this long (default 20); a slow or failing drive never holds up the others

When to use it. Seconds allowed per device before moving on. A slow or failing device costs only its own row - the sweep never waits on one device at the expense of the rest.

--all

List every drive checked, including the ones with no match

When to use it. Also sweep devices that are not in a normally-usable state, where possible. Use it only once the plain sweep has come back empty.

Command

recoveryantra gui

--classic

Use the classic Tkinter wizard

When to use it. Fall back to the classic interface on a machine where the modern window will not start, typically an old or minimal Windows install.

Command

recoveryantra guide

--html

Write the guide as a self-contained, searchable HTML page

When to use it. Produce the manual as a single searchable page to hand to a client, put on an internal share, or carry onto an air-gapped bench.

--markdown

Write the guide as Markdown

When to use it. Produce Markdown when the content is going into your own documentation system or version control.

Command

recoveryantra list

--triage

Also check each device's health (SMART + test reads), how it's connected, and what kind of device it is (CCTV recorder, phone, dashcam, card, ...) with advice on what to do

When to use it. Run before touching anything. It reports each device's health, how it is connected and what kind of device it is, which is what decides whether to recover directly or image first.

What it costs. Triage reads the drive. On a drive that is audibly failing, keep even this brief and go straight to imaging.

Command

recoveryantra phone

--store

A phone SQLite database (mmssms.db, msgstore.db, sms.db, contacts2.db, ...)

When to use it. Point at a single database pulled from a handset when you already know which application's data you need.

--deep

Deep-mine a PULLED phone folder for DELETED data (trash, deleted DB rows, thumbnails of purged photos)

When to use it. Run against a whole pulled phone folder when deleted material matters: trash folders, deleted database rows and thumbnails of photographs that are no longer present.

What it costs. Deep mining takes considerably longer than reading one store, and recovered deleted rows are reported flagged as such.

--app

Force a profile (android_sms, android_calls, whatsapp, ios_imessage); auto-detected if omitted

When to use it. Force a profile when auto-detection picks the wrong one, usually on a renamed or unusually located database.

--key

Decryption key for an encrypted store: path to a WhatsApp `key` file, or a hex key (WhatsApp crypt / SQLCipher: Signal, WeChat, Wickr, ...)

When to use it. Supply the key for an encrypted store: a WhatsApp key file, or a hex key for an SQLCipher database.

What it costs. Without the key the store cannot be read. The product does not attempt to break the encryption and will say so rather than returning partial output.

--deleted-only

Show only recovered deleted records

When to use it. Narrow the output to recovered deleted records when the live data is already available from the handset or a backup.

--areas

Instead of parsing, list the mobile recovery areas (by app + media)

When to use it. Use when scoping. It lists what is recoverable per application and media type, including the areas that are honestly not recoverable locally.

What it costs. Applications listed as not locally recoverable are ephemeral or server-side. Scope them out of the quote rather than promising them.

--types

List recovery by DATA TYPE (Contacts, Messages, Photos, ...) and sources

When to use it. The same scoping question asked by data type: contacts, messages, calls, photographs, and where each comes from.

--ffs-dfu

Identify a checkm8 full-filesystem acquisition from a device's DFU USB serial (e.g. 'CPID:8015 ECID:.. SRTG:[..]') and print the honest, ordered FFS plan

When to use it. Establish whether a full-filesystem acquisition is possible for a specific iPhone before promising one, from the device's own DFU identifiers.

What it costs. The answer for a modern handset is often no, and the plan says so. An unknown chip is never assumed to be vulnerable.

--android-ffs

Plan an Android full-filesystem acquisition from a device descriptor (VID:PID and/or 'chipset:SM8250 android:13 bootloader:locked credential:unknown'): SoC, download mode, and the honest FBE boundary

When to use it. The same question for Android, from the device descriptor. Produces a plan gated on what that specific device actually allows.

--cloud-tokens

Scan a lawfully-acquired artifact/file for cloud-account tokens (OAuth refresh/access, JWT) and print the lawful cloud-acquisition route per provider (identify-only)

When to use it. Scan a lawfully acquired artefact for cloud account tokens, and get the lawful route to the provider rather than to the account.

What it costs. Finding a token is not authority to use it. The output is a lawful acquisition route, and it should be followed.

--methods

List the full mobile-acquisition method registry (in-house protocol / external tool / licensed seam, state, BFU/AFU, certification, provenance)

When to use it. List every mobile-acquisition method the engine carries: in-house protocol, detected external tool, or licensed capability package; the state it yields, whether it works before first unlock, and its certification (proto-proven vs needing a device to certify).

--plan

Rank the acquisition methods that apply to a device: an iOS DFU serial (CPID:.. ECID:..) or an Android descriptor (VID:PID / chipset:.. / adb:device / adb:device+root); honest about what this build offers and, if nothing reaches the device, what WOULD and what it needs

When to use it. Rank the methods that actually apply to a described device (an iOS DFU serial or an Android descriptor) - honest about what THIS build offers, and, when nothing reaches the device, which method WOULD and exactly what it needs.

What it costs. A recovery build lists a physical method as NOT offered rather than hiding it; only the Forensic Suite may run one.

--acquire-method

MANUAL acquisition: run ONE method from --methods against a device descriptor (paired with --plan's DESCRIPTOR) into --dest; refused for a build without full mobile acquisition (the recovery family keeps consent-only)

When to use it. Run one named method from --plan's device against --dest. Behind the same lawful-use gate as every forensic acquisition.

What it costs. Refused by naming the PRODUCT when the build lacks full mobile acquisition, and refused structurally (never a fake success) when the physical device, tool or loader it needs was not provided.

--acquire-all

AUTOMATIC acquisition: work DOWN the methods that reach this device in order (checkm8 / EDL / MediaTek BROM / rooted ADB / backup), trying each until one succeeds - acquire on the first success, an honest refusal naming what is needed if none reaches it. Needs --plan DESCRIPTOR and --dest

When to use it. Acquire a phone automatically: try every method that reaches the device in order (checkm8, Qualcomm EDL, MediaTek BootROM, rooted ADB, backup) until one succeeds, when you want the tool to work down the options rather than picking one by hand.

What it costs. It runs real acquisition methods against the device and writes the image to the destination; the operator's stated authority is recorded, and a device no public method reaches is refused, never faked.

--dest

Destination folder for --acquire-method / --acquire-all

When to use it. Where --acquire-method writes the image or the copied files, and the hashed manifest naming the method, its provenance and (for a licensed package) the authority.

--package-install

Install a signed capability package (.sypkg) after verifying its signature and every payload file's hash; refused if tampered, expired, or signed by the wrong key

When to use it. Install a signed capability package (.sypkg) - a vendor's licensed loader/exploit chain under counsel's agreement - after verifying its Ed25519 signature and re-hashing every payload file against the signed manifest.

What it costs. A tampered, expired, or wrong-key package is refused outright and contributes nothing to the method registry; it is never partially installed.

--package-verify

Verify a .sypkg file WITHOUT installing it

When to use it. Check a .sypkg file's signature and payload hashes WITHOUT installing it - for auditing a package before it goes anywhere near a case machine.

--package-list

List installed, currently-verified capability packages

When to use it. List the capability packages currently installed and still verifying (a package that no longer verifies is silently absent from this list, per the module's no-partial-trust rule).

--package-remove

Remove an installed capability package

When to use it. Remove an installed capability package by its package_id, and delete its extracted payload from disk.

--leveldb

Recover key/value records from a LevelDB write-ahead log - the store Chrome, Electron apps (Discord, Slack, WhatsApp Desktop) and browser Local Storage keep. Point it at a `leveldb` folder or a single .log file

When to use it. Point at a LevelDB folder or a single .log file when the data lives in a key/value store rather than SQLite, which is what Chrome, Electron chat apps and browser Local Storage use.

What it costs. Only the write-ahead log (.log) is read; data already compacted into .ldb table files is a stated limit, not everything the store held.

--breadth

Run a breadth pass over an ALREADY-ACQUIRED extraction folder with the signed mobile toolpack (iLEAPP for iOS, ALEAPP for Android) to widen coverage beyond our own parsers; needs --platform. Does nothing if the toolpack is not installed

When to use it. Point at an already-acquired extraction folder to run the signed toolpack (iLEAPP or ALEAPP) over it and widen coverage past our own parsers, when a case needs the long tail of apps.

What it costs. It does nothing when the toolpack is not installed, and its rows are labelled as the tool's, shown under our own parsers as corroboration.

--platformone of ios, android

Which breadth tool to run for --breadth: ios (iLEAPP) or android (ALEAPP)

When to use it. Choose which breadth tool runs on the extraction, ios for iLEAPP or android for ALEAPP, since the two read different artefact layouts.

--operator

Examiner asserting lawful authority (recorded)

When to use it. As on acquire: the examiner asserting lawful authority.

--authority

Lawful basis: warrant / consent / statutory power

When to use it. As on acquire: the lawful basis for touching this device.

--org

Examiner's organisation (recorded)

When to use it. The examining organisation, recorded against the acquisition so the custody record names the body accountable for it.

--case

Case / FIR reference (recorded)

When to use it. The case reference, set consistently across every step.

Command

recoveryantra report

--case

The case folder

When to use it. Point at the case folder you want to hand to another tool or lab. `report` exports it in a standardized interchange format rather than a PDF, so an examiner on different software can load the same evidence, timeline and provenance. The case folder is read only.

--formatone of case-uco · default case-uco

Export format (default case-uco)

When to use it. Choose the interchange format for the export; today that is CASE-UCO, the community standard the major forensic tools read, so findings travel to another examiner without being retyped. Leave it at the default unless a receiving lab asks for a specific one.

-oalso --output

Path to write the export to

When to use it. Where to write the exported file. Choose a path outside the case folder and the evidence drive so the export never lands among the files it describes; writing it does not change the case.

--force

Write even if the pre-flight objects

When to use it. Write the export even when the pre-flight raises an objection, such as too little free space at the destination. Use it only after you have read the warning and accept it.

What it costs. The pre-flight is what stops a half-written export or a destination that cannot hold the file; forcing past it can leave an incomplete export that another tool will reject as malformed.

Command

recoveryantra stego

<path>positional

The image or file to analyse

When to use it. The image or file to examine for hidden data, run whenever an exhibit might carry a concealed payload - a picture that is larger than its content explains, a file a suspect treated as important, or anything flagged for a second look. Reading only; the exhibit is never changed.

--extract

Also carve out and save any hidden data that is found

When to use it. Add this when the examination should also carve out and save what it finds, so recovered appended data, embedded files and LSB payloads land in a folder you can open, not only in the on-screen verdict.

What it costs. It writes new files to the output folder; it never alters the exhibit, and an unconfirmed carve is labelled so it is not mistaken for proven.

--out

Folder to write recovered hidden data into (with --extract)

When to use it. Where the recovered hidden data is written when extraction is on, used when the default folder beside the exhibit is not where the case keeps its working files. Choose a case folder, never the exhibit's own media.

--json

Print the full report as JSON instead of as text

When to use it. Print the full report as JSON instead of text, used when another tool or a case script consumes the result rather than a person reading it.

Command

recoveryantra steps

<workflow>positional

Workflow id (e.g. forensics, data_recovery); omit to list them by category

When to use it. Show the full procedure for one job - every stage, what it is for, the safety gates that cannot be skipped, and the command that carries each one out. Use it when a technician is doing a job for the first time, when a job is done rarely enough that nobody remembers the order, or when a reviewer asks why the work was done the way it was.

--categoryone of recovery, forensics

Show only one category's workflows

When to use it. Show only data recovery, or only forensics. The two follow different orders because they are for different things: a recovery is judged on how much comes back, an examination on whether you can prove what you did. Verification therefore ends a recovery and sits in the MIDDLE of an examination, before any analysis. Use this to hand a new examiner only the sequence that applies to them.

--commands

Print only the commands, in order, ready to copy

When to use it. Print only the commands, in order, ready to paste. Use it to build a runbook, to script a job that is done the same way every time, or to check a script somebody else wrote actually follows the procedure.

--standards

Show the published practice each step comes from

When to use it. Show the published practice each stage comes from - ISO/IEC 27037, NIST SP 800-86, the ACPO principles. Use it when a client, an auditor or a court asks why a step exists, and when training staff who need to know the procedure is not this vendor's opinion.

Command

recoveryantra which

<situation>positional

What is happening, in plain words (e.g. "drive is clicking"); omit to list every situation

When to use it. Describe what is happening in your own words - "drive is clicking", "formatted the wrong disk", "Outlook will not open it" - and get the feature to use, why that one rather than the obvious alternative, a worked example, the commands, and what NOT to do. Use it when somebody hands you a job and you are not sure which part of the product it belongs to, and give it to new staff before you give them anything else.

--all

Show every situation, grouped, rather than searching

When to use it. List every situation, grouped, instead of searching. Use it to see the whole range at once - useful when scoping what a product will cover for a customer, and for training.

What it costs. Situations the product you are running does not include are marked, so the list stays honest about what this build can actually do.