CYBERDELIA LAZARUS RECOVERY WORKBENCH v0.1.0-alpha ================================================ STATUS ------ Alpha field build. Read-first. Standard-library Python 3. No installer and no paid dependency. Lazarus exists because data-recovery programs rarely agree with one another. One tool follows filesystem metadata, another carves signatures, another handles marginal reads better, and every one of them eventually misses something embarrassing. The long-term design is therefore a workbench with independent recovery passes whose results can be compared and merged instead of pretending a single algorithm is omniscient. THIS ALPHA DOES FOUR USEFUL THINGS NOW -------------------------------------- 1. Lists physical disks on Windows and Linux. 2. Inspects MBR/GPT partition tables and identifies common NTFS, FAT32, exFAT and BitLocker signatures without mounting or repairing the source. 3. Clones a disk or image into an image file with a JSONL read journal, resume cursor, coarse first pass, bad-range tracking, and recursive retry down to a configurable minimum block size. 4. Signature-carves JPEG, PNG, PDF and ZIP-family files. ZIP candidates are re-labeled as DOCX, XLSX or PPTX when their internal markers identify an Office Open XML container. 5. Calculates SHA-256 for a source or image. The next recovery layer is filesystem-aware NTFS MFT and FAT32 deleted-entry recovery. That is intentionally separate from this first field build so the imaging and carving behavior can be beaten on real hardware before more parser code is stacked on top of it. SOURCE SAFETY ------------- Lazarus opens source media read-only. It does not run CHKDSK, repair a filesystem, take ownership, mount a volume, format a disk, rewrite a partition table, or write recovery output back to the source. The clone command refuses a raw physical-drive destination in v0.1. Clone into an image file. Destructive wipe/format tooling belongs in a separate program with an explicit arming step so a recovery utility cannot casually become a disk eraser because a human mistyped one argument at 3:00 AM. IMPORTANT LIMITATION FOR SICK HARD DRIVES ----------------------------------------- This program can catch ordinary read errors and short reads, skip bad regions, journal them, and retry at smaller block sizes. It cannot force a hard disk, USB bridge, SATA controller, or operating-system storage driver to return from a kernel-level I/O hang. If attaching a disk freezes the storage stack for minutes at a time, stop repeatedly scanning the original. Hardware-level resets, controller-specific timeouts and direct-AHCI recovery are a separate layer. REQUIREMENTS ------------ Python 3.10 or newer is recommended. Raw physical-disk access normally requires Administrator on Windows or root on Linux. The destination filesystem must have enough free space for a full disk image. QUICK START / WINDOWS --------------------- Open PowerShell or Terminal as Administrator. List disks: python lazarus.py devices Inspect a physical disk: python lazarus.py inspect "\\.\PhysicalDrive2" Clone the disk into an image file: python lazarus.py clone "\\.\PhysicalDrive2" D:\recovery\drive2.img Use a larger fast-pass block and one retry pass: python lazarus.py clone "\\.\PhysicalDrive2" D:\recovery\drive2.img --chunk 8MiB --retry-passes 1 Resume an interrupted clone: python lazarus.py clone "\\.\PhysicalDrive2" D:\recovery\drive2.img --resume Carve the IMAGE, not the original disk: python lazarus.py carve D:\recovery\drive2.img D:\recovery\carved Hash the completed image: python lazarus.py hash D:\recovery\drive2.img QUICK START / LINUX ------------------- List disks: sudo python3 lazarus.py devices Inspect: sudo python3 lazarus.py inspect /dev/sdb Clone: sudo python3 lazarus.py clone /dev/sdb /recovery/drive.img Carve the clone as an ordinary user if permissions allow: python3 lazarus.py carve /recovery/drive.img /recovery/carved CLONE OUTPUT ------------ For destination drive2.img Lazarus also creates: drive2.img.lazarus-map.jsonl Append-only event journal containing successful ranges, failed ranges, cursor positions, errors and retry-pass results. drive2.img.lazarus-map.jsonl.summary.json Compact list of any byte ranges still unrecovered after the requested retry passes. The image is pre-sized. Unreadable regions therefore remain unwritten/zero-filled in the image and are explicitly identified in the map rather than silently disappearing. CARVING OUTPUT -------------- Recovered files receive names based on their source byte offset plus the first 12 hexadecimal characters of their SHA-256 digest. Example: 0000000018bc2000_4f613da9128a.jpg The output directory also receives carve-manifest.jsonl with the source offset, detected type, byte count, digest and output filename for every successful carve. WHY MULTIPLE RECOVERY PASSES MATTER ----------------------------------- Filesystem metadata and raw carving answer different questions. Metadata can recover filenames, sizes, allocation runs and directory context when those structures survive. Carving ignores that structure and searches the underlying bytes for recognizable file boundaries, which can recover data after metadata is damaged but can also lose filenames and produce false positives. A serious recovery workbench needs both. PLANNED NEAR-TERM ENGINES ------------------------- - NTFS MFT parsing, deleted FILE records, resident data and nonresident runlists. - FAT32 deleted directory entries, surviving chains and contiguous-cluster fallback with confidence labels. - More bounded carvers: 7z, SQLite, WAV/AVI, BMP/TIFF, MP4/MOV, RAR and additional document containers. - Result de-duplication by SHA-256 across metadata recovery and carving passes. - File preview/integrity validation so a signature hit is not automatically treated as a good recovery. - Better graphical/TUI front end after the command behavior survives real-disk testing. - Optional read scheduling that separates fast salvage from aggressive retry passes. LICENSE ------- MIT License. See LICENSE.txt. AUTHORIZED USE -------------- Use Lazarus on media you own or are explicitly authorized to examine. Recovery output may contain deleted or private material; possession of a drive does not magically erase every legal or ethical obligation attached to its contents. Humans apparently required that sentence to be written down.