PocketRescue combines RAM key scanning, signature-based decryption, VSS harvesting and AI triage into a single tool — giving you the best chance of getting your files back.
Core engine
Each layer activates automatically when the previous one can't fully recover your data.
While the system is still running, many ransomware strains keep their AES or ChaCha20 keys in memory. PocketRescue scans live RAM to capture them before they disappear.
MemScannerA built-in SQLite database of known ransomware families, YARA rules and their encryption weaknesses. When a match is found, the corresponding decryptor is applied automatically.
SignatureDBRansomware often fails to fully delete Volume Shadow Copies. PocketRescue reads raw sectors via DeviceIoControl to harvest VSS remnants and carve files from unallocated space.
DiskCarverWhen no signature matches, an ONNX-based ML model analyzes entropy patterns, file headers and extension changes to predict the ransomware family and suggest a recovery path.
RansomClassifierWorkflow
No technical knowledge required. PocketRescue guides you through every step.
Launch PocketRescue with administrator rights. Raw disk and memory access require elevated privileges.
Choose the affected volume or physical drive. PocketRescue auto-detects NTFS partitions and their size.
All four recovery layers run in sequence — RAM scan, signature match, VSS harvest, disk carving. Progress is shown in real time.
Recovered files are placed in a quarantine folder. An HTML/PDF report lists every file with its SHA-256 hash and recovery status.
Signature database
Coverage grows with every release. Community contributions welcome.
| Family | Encrypted extension | Encryption | Decryptor |
|---|---|---|---|
| WannaCry | .WNCRY |
AES-128 + RSA-2048 | Full recovery |
| LockBit 2.0 | .lockbit |
AES-256 + RSA-2048 | Partial |
| Dharma / Crysis | .dharma |
AES-256 | Full recovery |
| STOP / Djvu | .djvu |
Salsa20 | Offline key only |
| Conti v2 | .CONTI |
AES-256 | Full recovery |
| REvil / Sodinokibi | .sodinokibi |
Salsa20 + EC | v2.2 only |
| Ryuk | .RYK |
AES-256 + RSA | Partial |
| BlackCat (ALPHV) | .alphv |
AES-256 + ChaCha20 | Detection only |
Download
Free to use. No installation required. No data leaves your machine.
Download PocketRescue