User guide

Illustrated guide for Datattoo Recovery Technician. The PDF matches the signed download currently published on this site.

Download User-Guide.pdf

Manual
Datattoo-Recovery-Technician-User-Guide.pdf
PDF size
2,997,591 bytes
PDF SHA-256
81e586ef708f4328747a6711b9521a759b73868aa63409ee6603cecd1468702f
Application
DatattooRecovery.exe 1.0.0
Executable SHA-256
74ced500a4cb19256794616a8b4584bc419456c3ad09527231c3bf2f2235f550
  1. Safety before scanning: Stop writing to the affected drive. Never recover onto the source. SSD TRIM can erase recoverable clusters.
  2. Portable launch and signature verification: When a signed build is published, verify Authenticode publisher and SHA-256 before running. Datattoo is fully portable—you can copy the executable to a thumb drive or memory card and run it from there. Accept the EULA when prompted; no separate installer is required for portable use.
  3. Required privileges: Run with the privileges needed for volume access (often Administrator).
  4. Select the correct source: Drive letter, partition, physical source where exposed, or raw disk image.
  5. Opening a raw image: Provide the image file and optional partition offset. Unsupported formats are not claimed.
  6. Quick Metadata scan: Metadata-oriented discovery. It does not silently become Deep Carving.
  7. Deep Carving scan: Signature-oriented discovery that may generate fallback names when metadata is missing.
  8. Pause, resume, cancel, and safe exit: Stop long jobs cleanly; do not force power-off mid-write to the destination.
  9. Search, filtering, sorting, and selection: Narrow candidates before recovery.
  10. Filename provenance and original-path confidence: Treat missing or low-confidence names/paths as evidence limits, not product defects. FAT deleted short names may show an explicit [unknown] first-character marker when the deletion marker overwrote the original byte and no authoritative LFN survives.
  11. Recoverability condition versus final outcome: Pre-recovery conditions estimate chance/quality of evidence. Complete / Partial / Unverified / Failed are assigned after recovery and validation.
  12. Preview and warnings: Read warnings before selecting candidates.
  13. Choosing a destination: Different volume, enough free space, source ≠ destination.
  14. Recovering files: Recover selected candidates, then read the validation report.
  15. Final report and SHA-256: Keep hashes and warnings with the job record.
  16. Logs: Installed builds use %APPDATA%\DatattooRecovery\Logs; portable runs use Data\Logs beside the executable.
  17. When to stop: Clicking, burnt smell, flood damage, or unreliable detection → hardware laboratory, not another logical scan.
Datattoo Recovery controlled-test screenshot of the results review screen
Controlled-test screenshot of evidence review. Sensitive filenames should never appear in published screenshots.

Troubleshooting

  • No useful candidates: Data may be overwritten or TRIMed.
  • Permission errors: Elevate privileges and ensure no exclusive lock blocks the source.
  • Partial or Unverified after recovery: Treat as validation outcomes; do not relabel them as Complete.