Free · Open Beta · Windows

Recover files after a ransomware attack

PocketRescue combines RAM key scanning, signature-based decryption, VSS harvesting and AI triage into a single tool — giving you the best chance of getting your files back.

Download for Windows See how it works
Windows 10 / 11  ·  Requires administrator privileges
8+
Ransomware families
4
Recovery methods
NTFS
File system support
Free
Always

Four layers of recovery

Each layer activates automatically when the previous one can't fully recover your data.

🧠

RAM Key Scanner

While the system is still running, many ransomware strains keep their AES or ChaCha20 keys in memory. PocketRescue scans live RAM to capture them before they disappear.

MemScanner
🗂️

Signature Database

A built-in SQLite database of known ransomware families, YARA rules and their encryption weaknesses. When a match is found, the corresponding decryptor is applied automatically.

SignatureDB
💿

VSS & Disk Carving

Ransomware often fails to fully delete Volume Shadow Copies. PocketRescue reads raw sectors via DeviceIoControl to harvest VSS remnants and carve files from unallocated space.

DiskCarver
🤖

AI-Powered Triage

When no signature matches, an ONNX-based ML model analyzes entropy patterns, file headers and extension changes to predict the ransomware family and suggest a recovery path.

RansomClassifier

Simple to use,
powerful under the hood

No technical knowledge required. PocketRescue guides you through every step.

1

Run as administrator

Launch PocketRescue with administrator rights. Raw disk and memory access require elevated privileges.

2

Select your drive

Choose the affected volume or physical drive. PocketRescue auto-detects NTFS partitions and their size.

3

Start the scan

All four recovery layers run in sequence — RAM scan, signature match, VSS harvest, disk carving. Progress is shown in real time.

4

Export recovered files

Recovered files are placed in a quarantine folder. An HTML/PDF report lists every file with its SHA-256 hash and recovery status.

Supported ransomware families

Coverage grows with every release. Community contributions welcome.

Family Encrypted extension Encryption Decryptor
WannaCry .WNCRY AES-128 + RSA-2048 Full recovery
LockBit 2.0 .lockbit AES-256 + RSA-2048 Partial
Dharma / Crysis .dharma AES-256 Full recovery
STOP / Djvu .djvu Salsa20 Offline key only
Conti v2 .CONTI AES-256 Full recovery
REvil / Sodinokibi .sodinokibi Salsa20 + EC v2.2 only
Ryuk .RYK AES-256 + RSA Partial
BlackCat (ALPHV) .alphv AES-256 + ChaCha20 Detection only

Start recovering your files now

Free to use. No installation required. No data leaves your machine.

Download PocketRescue
Windows 10 / 11 ~15 MB Admin rights required