Tools for hard drive diagnostics, repair, and data recovery
Post a reply

Hetman Software Data Recovery Lab: Real Hardware, Real Failu

September 5th, 2026, 7:06

Hello everyone,

In this thread, I plan to share results from our testing lab for Hetman RAID Recovery and Hetman Partition Recovery.

We test the software with different RAID configurations, NAS devices, storage controllers, file systems, virtual disks, encryption, disk images, and various data loss scenarios.

I would be interested in feedback from HDDGuru members, especially from people who work with data recovery in practice.

Please feel free to comment on the tests themselves. If you think the methodology is weak, an important scenario is missing, or the test does not reflect a realistic recovery case, I would like to hear it.

You can also suggest:
    RAID, NAS, or controller configurations to test;
    file systems or encryption technologies;
    damaged or incomplete RAID scenarios;
    virtual disks and VM storage;
    forensic image formats;
    other recovery cases that would be useful to reproduce.

If there is functionality you would like to see in Hetman RAID Recovery or Hetman Partition Recovery, you are also welcome to describe it here. We can review such requests and, where they make sense, consider them for future versions.

I will use this thread to post test results, technical notes, screenshots, and related videos.

Feedback and criticism are welcome.

Re: Hetman Software Data Recovery Lab: Real Hardware, Real F

September 5th, 2026, 7:57

We heard you the first time, after 4 posts it's beginning to feel like spam again.

Re: Hetman Software Data Recovery Lab: Real Hardware, Real F

September 5th, 2026, 9:29

In the latest version, we added support for VeraCrypt containers and encrypted partitions, including both standard and hidden volumes. Hetman Partition Recovery can unlock VeraCrypt volumes using a password, PIM, keyfile, or their combination, and then analyze the decrypted filesystem for existing and deleted files.

In this test video: https://www.youtube.com/watch?v=NlgMI807V2I

we covered three scenarios:
    a VeraCrypt container protected with a password, PIM, and keyfile, with some test files deleted before recovery;
    a USB drive containing a standard VeraCrypt volume and a hidden volume, both password-protected;
    the same USB drive after its partition information was removed with the clean command in DiskPart.

In all three cases, the volumes were unlocked and their contents were accessible for analysis and recovery.

If you work with VeraCrypt in practice, please share the scenarios or features you would like us to support — we can review them for future versions.

Re: Hetman Software Data Recovery Lab: Real Hardware, Real F

September 5th, 2026, 11:12

Michael; your spamming now - a single thread can suffice.

Re: Hetman Software Data Recovery Lab: Real Hardware, Real F

September 6th, 2026, 2:52

One area we have been working on in Hetman RAID Recovery is support for RAID controller metadata. When supported metadata is present on the member disks, the software reads it and reconstructs the array automatically, so it is available for further analysis. In recent versions, we added support for Infortrend EonStor DS 1000 / ESDS 1012 RC metadata used in Infortrend storage systems.

In this test:
https://www.youtube.com/watch?v=tSKfPN-k2Ho

we covered:
  • automatic RAID detection and manual reconstruction with RAID Constructor;
  • the main parameters required for manual reconstruction;
  • Thin and Thick volumes and SANWatch snapshots;
  • recovery after deleting files or partitions inside an iSCSI LUN;
  • recovery after removing Thin/Thick volumes in SANWatch;
  • recovery of files from a SANWatch snapshot.

We have also tested RAID metadata from a number of other hardware and motherboard controllers:
Dell: PERC 6/i, H310, H700
LSI / 3ware: 3081E-R, MegaRAID SAS 84016E, 9280-4i4e, 9265-8i, 3ware 9750, 9650SE-4LPML
Adaptec: ASR-6405, ASR-6805T
Areca: ARC-1210, ARC-1260
HP/HPE Smart Array: P410/P410i, P822
IBM: ServeRAID M5016
Fujitsu: D3116, D2516-C11 GS1
Supermicro: AOC-USAS-S8iR
Dawicontrol: DC-624E
InLine: 76696C
AMD: RAIDXpert2
Intel: Rapid Storage Technology
Infortrend: EonStor DS 1000 / ESDS 1012 RC

The corresponding tests on our YouTube channel also contain practical information that can be useful for manual reconstruction, including disk order, stripe/block size, block/parity order, byte order, and disk offset.

If there is a controller or metadata format that you regularly encounter in real recovery cases and would like us to test, please suggest it.


WebClaw, Lardman,

Understood. The purpose of this new thread is exactly to keep all future Hetman Software tests and related technical updates in one place. I’ll contact the forum administrator and ask to have the other Hetman-created threads in this section removed, so that going forward I will use only this thread for our tests and updates.

Re: Hetman Software Data Recovery Lab: Real Hardware, Real F

Yesterday, 3:36

Another area we are working on is support for different disk image formats.

Forensic images. Recent versions added support for EnCase / EWF (.e01, .s01, .ex01), AFF (.aff, .afm, .afd), AFF4 (.aff4), and AFF4 Directory Volumes. Single-file, split/multi-segment and compressed images are supported where applicable.

In this test:
https://www.youtube.com/watch?v=UlN933-iRLA

we created forensic images of a USB drive with Exterro FTK Imager. The drive contained a prepared test dataset, with some files deleted before imaging. We then mounted the resulting images and tested recovery of both existing and deleted files.

Apple disk images. We also added support for .dmg (UDRO, UDRW, UDZO, UDBZ, ULFO, ULMO, UDSP, UDSB), .asif, .sparsebundle, .sparseimage, .cdr, .toast and .iso. Regular, split, sparse, compressed and encrypted images are supported where applicable.

In this test:
https://www.youtube.com/watch?v=jhkg52Tx2bY

we mounted several image types, scanned their filesystems and recovered files from them.

Support for .sparsebundle is also useful when working with Time Machine backups stored on devices such as Time Capsule, NAS systems or network storage. Another practical case is a partially damaged image that can no longer be mounted by its original software or operating system. In such cases, the image can still be opened and scanned to determine whether part of the filesystem and files can be recovered.

Raw / sector-by-sector images. The software can create a sector-by-sector image of an entire disk, a partition, or a selected range defined by starting sector and size. It can also work with raw byte-for-byte images created by other tools, including GNU ddrescue, FTK Imager, PC-3000 Data Extractor, Guymager and X-Ways Imager. This is particularly useful when repeated access to the original media should be avoided, for example when a drive has bad sectors or behaves unstably. Once mounted, an image is handled much like a physical disk: it can be scanned for existing and deleted files, encrypted volumes can be unlocked, and supported encrypted files can be processed. If RAID metadata is present, it can also be used to reconstruct the array. Physical disks and disk images can be combined when working with RAID arrays or storage pools.

I would be particularly interested in feedback from people working in digital forensics: which image formats, metadata, validation features or forensic workflows are still missing for your day-to-day work?
Post a reply