Recovery tool magicrescue based on signature file
Recovery tool magicrescue based on signature file
Common types of files contain special bytes to identify the type of file. These bytes are called signatures. On disk, when the cluster that records the storage location of the file is damaged, the file can be recovered based on these signatures. In response to this requirement, Kali Linux provides a dedicated tool, magicrescue. The tool reads the raw data directly from the disk and searches for signatures. Once a known type of signature is found, a third-party tool is called to extract the data and save it according to the extraction strategy provided by the penetration tester. In order to facilitate the collation of the extracted data, the tool also provides deduplication function and classification saving function.