Windows Recycle Bin $I Parser
Drop $I and $R files — or a whole $Recycle.Bin folder — below. Everything is parsed and recovered locally in your browser with WebAssembly; no file ever leaves your machine.
- $I v1 & v2
- $R pairing
- KAPE / Velociraptor ZIPs
- Works offline
The sample is a synthetic $Recycle.Bin from a fictional intrusion — no real data. Tip: click a deletion time to see what else was deleted within ±1 min.
Supports $I v1 (Vista–8.1) and v2 (Windows 10/11). Each $I is paired with its $R so the deleted file can be recovered under its original name. ZIP collections (KAPE, Velociraptor…) are unpacked in the browser. Deleted folders are recovered as ZIP.
Loading parser…
How to get your data
From a live Windows host to parsed results in about two minutes — nothing to install.
- Collect $Recycle.Bin
- Drop the folder or ZIP here
- Everything stays in your browser
Open PowerShell as Administrator on the host (Windows 10 1803+ or 11). Built-in tools only.
1 · Copy every user’s Recycle Bin from C: (the folder is created for you)
robocopy 'C:\$Recycle.Bin' 'C:\triage\RecycleBin\C\$Recycle.Bin' /E /B /DCOPY:T /R:0 /W:02 · Optional — zip it to move it off the host
tar -a -cf C:\triage\RecycleBin.zip -C C:\triage RecycleBinThen drop the C:\triage\RecycleBin folder or C:\triage\RecycleBin.zip here. $I and $R stay paired in their SID folders, so every item is recoverable.
KAPE · RecycleBin target (collects $I + $R), run as Administrator from the KAPE folder
.\kape.exe --tsource C: --tdest C:\triage\kape --target RecycleBinDrop the whole C:\triage\kape folder here — or zip it first, ZIPs are unpacked in your browser.
Velociraptor
Collect the Windows.Triage.Targets artifact (Velociraptor Triage project; formerly Windows.KapeFiles.Targets) with the RecycleBin target, then drop the downloaded collection ZIP as-is. Not Windows.Forensics.RecycleBin: it parses $I on the endpoint and only uploads $R content renamed after the original file, so there is nothing left to pair.
FTK Imager (E01, raw, VHDX…)
File → Add Evidence Item → Image File, expand the partition to [root], right-click $Recycle.Bin → Export Files…, then drop the exported folder. FTK’s .FileSlack files are ignored automatically.
Another volume, or an image mounted read-only (e.g. Arsenal Image Mounter) — replace E: with its drive letter in both paths
robocopy 'E:\$Recycle.Bin' 'C:\triage\RecycleBin\E\$Recycle.Bin' /E /B /DCOPY:T /R:0 /W:0Linux / SIFT · image already mounted read-only at /mnt/windows
mkdir -p ~/triage && cp -r '/mnt/windows/$Recycle.Bin' ~/triage/- $I metadata · Windows Vista – 11, one subfolder per user SID
C:\$Recycle.Bin\<SID>\$I* - $R content · same 6-character suffix as its $I (a folder if a directory was deleted)
C:\$Recycle.Bin\<SID>\$R* - Every other fixed volume has its own bin (D:, E:, external hard drives…)
<Drive>:\$Recycle.Bin\<SID>\ - Map a SID folder to its user account · SOFTWARE hive
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList - Windows XP / 2003 · single INFO2 index (C:\RECYCLED on FAT) — not parsed by this tool
C:\RECYCLER\<SID>\INFO2
Drop them together: the $I (metadata) and $R (content) halves are paired by folder and suffix, so drop the whole $Recycle.Bin, a SID folder, or a ZIP of either. $I alone still gives names, paths and deletion times.
Gotchas
- Run elevated. Each SID folder is readable only by its owner: without Administrator,
robocopy /Brefuses to run and a normal copy only gets your own bin. - One bin per volume. Repeat for D:, E:… (see Disk image). Removable USB flash drives bypass the Recycle Bin, so there is nothing to collect there.
- Collect early. Emptying the bin, Disk Cleanup or Storage Sense (30 days by default when enabled) deletes $I and $R together. Deletion times are UTC.
From $Recycle.Bin to evidence in seconds
Everything you need to triage deleted files on a Windows host — without installing anything or uploading a single byte.
Pairs $I with $R automatically
Drop loose files, a SID folder or an entire $Recycle.Bin tree. Every $I record is matched with its $R content by suffix.
Preview inside the app
Images, video, audio, PDF and text render right in the workspace. Everything else opens as a hex dump — scripts are shown as source, never run.
Spots renamed files
Magic bytes are checked against the original extension, so an executable hiding behind .pdf is flagged instantly.
Recover under original names
Restore one file or rebuild the whole original folder tree as a ZIP, with timestamps and a metadata manifest.
Hashes & provenance
SHA-256 for every recovered file, plus Zone.Identifier HostUrl/ReferrerUrl when the file was downloaded from the internet.
Timeline-ready CSV
Export original path, size and ISO-8601 UTC deletion time for your super-timeline or report.
Three steps, zero setup
- 01
Collect
Grab $Recycle.Bin from a live host, a KAPE or Velociraptor collection, or a mounted image.
- 02
Drop
Drag files, folders or ZIPs onto the page. The Rust parser decodes $I v1 and v2 locally.
- 03
Preview & recover
Browse the full-screen workspace, check hashes, preview content and restore what matters.
Related tools
- MFT ParserThe $R file keeps its MFT entry until the bin is emptied, with timestamps to check against the $I record.
- USN ParserThe journal records the rename into $Recycle.Bin and the final delete when the bin is emptied.
- LNK ParserLNK files often still point to a file's original path after it was sent to the bin.
Recycle Bin parser — FAQ
What is the $Recycle.Bin folder in Windows?
$Recycle.Bin is the hidden, protected folder at the root of every NTFS volume where Windows (Vista and later) stores deleted files. Inside it, each user has a subfolder named after their SID, containing paired $I metadata files and $R content files.
What is a $I file?
A $I file is the index/metadata record Windows writes when a file is sent to the Recycle Bin. It stores the original full path, the original size in bytes, and the deletion timestamp (a Windows FILETIME). The matching $R file holds the actual content.
Does this tool upload my Recycle Bin files anywhere?
No. Parsing runs entirely in your browser via a Rust parser compiled to WebAssembly. The bytes never leave your machine and there is no upload endpoint — you can disconnect from the network and it still works.
Which Windows versions are supported?
Both $I formats are auto-detected: v1 (Windows Vista, 7, 8, 8.1 — a fixed 544-byte layout) and v2 (Windows 10 and 11 — a variable, length-prefixed layout).
Can I recover the deleted file itself?
Yes, if you also provide the paired $R file. The $I file only holds metadata (original path, size, deletion time); the content lives in the $R file with the same suffix. Drop both — or the whole $Recycle.Bin / SID folder — and the tool pairs them and restores each file under its original name. “Recover all” rebuilds the original folder structure in a ZIP and keeps last-modified times.
Why does the deleted timestamp show UTC?
Windows stores the deletion time as a FILETIME in UTC. The table renders it in your locale while the CSV export keeps a strict ISO-8601 UTC value so timelines stay unambiguous across timezones.
Bring deleted files back into the investigation
Free, open source and private by design.
Open files