Skip to content
Docs
100% client-sideRust + WebAssembly · runs 100% in your browser

Windows Recycle Bin $I Parser

Drop $I and $R files — or a whole $Recycle.Bin folder — below. Everything is parsed and recovered locally in your browser with WebAssembly; no file ever leaves your machine.

  • $I v1 & v2
  • $R pairing
  • KAPE / Velociraptor ZIPs
  • Works offline
Drop $I / $R files or a $Recycle.Bin folderParsed locally. Nothing is uploaded.Browse files

The sample is a synthetic $Recycle.Bin from a fictional intrusion — no real data. Tip: click a deletion time to see what else was deleted within ±1 min.

Supports $I v1 (Vista–8.1) and v2 (Windows 10/11). Each $I is paired with its $R so the deleted file can be recovered under its original name. ZIP collections (KAPE, Velociraptor…) are unpacked in the browser. Deleted folders are recovered as ZIP.

Loading parser…

How to get your data

From a live Windows host to parsed results in about two minutes — nothing to install.

  1. Collect $Recycle.Bin
  2. Drop the folder or ZIP here
  3. Everything stays in your browser

Open PowerShell as Administrator on the host (Windows 10 1803+ or 11). Built-in tools only.

1 · Copy every user’s Recycle Bin from C: (the folder is created for you)

robocopy 'C:\$Recycle.Bin' 'C:\triage\RecycleBin\C\$Recycle.Bin' /E /B /DCOPY:T /R:0 /W:0

2 · Optional — zip it to move it off the host

tar -a -cf C:\triage\RecycleBin.zip -C C:\triage RecycleBin

Then drop the C:\triage\RecycleBin folder or C:\triage\RecycleBin.zip here. $I and $R stay paired in their SID folders, so every item is recoverable.

Gotchas

  • Run elevated. Each SID folder is readable only by its owner: without Administrator, robocopy /B refuses to run and a normal copy only gets your own bin.
  • One bin per volume. Repeat for D:, E:… (see Disk image). Removable USB flash drives bypass the Recycle Bin, so there is nothing to collect there.
  • Collect early. Emptying the bin, Disk Cleanup or Storage Sense (30 days by default when enabled) deletes $I and $R together. Deletion times are UTC.
Why analysts use it

From $Recycle.Bin to evidence in seconds

Everything you need to triage deleted files on a Windows host — without installing anything or uploading a single byte.

  • Pairs $I with $R automatically

    Drop loose files, a SID folder or an entire $Recycle.Bin tree. Every $I record is matched with its $R content by suffix.

  • Preview inside the app

    Images, video, audio, PDF and text render right in the workspace. Everything else opens as a hex dump — scripts are shown as source, never run.

  • Spots renamed files

    Magic bytes are checked against the original extension, so an executable hiding behind .pdf is flagged instantly.

  • Recover under original names

    Restore one file or rebuild the whole original folder tree as a ZIP, with timestamps and a metadata manifest.

  • Hashes & provenance

    SHA-256 for every recovered file, plus Zone.Identifier HostUrl/ReferrerUrl when the file was downloaded from the internet.

  • Timeline-ready CSV

    Export original path, size and ISO-8601 UTC deletion time for your super-timeline or report.

How it works

Three steps, zero setup

  1. 01

    Collect

    Grab $Recycle.Bin from a live host, a KAPE or Velociraptor collection, or a mounted image.

  2. 02

    Drop

    Drag files, folders or ZIPs onto the page. The Rust parser decodes $I v1 and v2 locally.

  3. 03

    Preview & recover

    Browse the full-screen workspace, check hashes, preview content and restore what matters.

Recycle Bin parser — FAQ

What is the $Recycle.Bin folder in Windows?

$Recycle.Bin is the hidden, protected folder at the root of every NTFS volume where Windows (Vista and later) stores deleted files. Inside it, each user has a subfolder named after their SID, containing paired $I metadata files and $R content files.

What is a $I file?

A $I file is the index/metadata record Windows writes when a file is sent to the Recycle Bin. It stores the original full path, the original size in bytes, and the deletion timestamp (a Windows FILETIME). The matching $R file holds the actual content.

Does this tool upload my Recycle Bin files anywhere?

No. Parsing runs entirely in your browser via a Rust parser compiled to WebAssembly. The bytes never leave your machine and there is no upload endpoint — you can disconnect from the network and it still works.

Which Windows versions are supported?

Both $I formats are auto-detected: v1 (Windows Vista, 7, 8, 8.1 — a fixed 544-byte layout) and v2 (Windows 10 and 11 — a variable, length-prefixed layout).

Can I recover the deleted file itself?

Yes, if you also provide the paired $R file. The $I file only holds metadata (original path, size, deletion time); the content lives in the $R file with the same suffix. Drop both — or the whole $Recycle.Bin / SID folder — and the tool pairs them and restores each file under its original name. “Recover all” rebuilds the original folder structure in a ZIP and keeps last-modified times.

Why does the deleted timestamp show UTC?

Windows stores the deletion time as a FILETIME in UTC. The table renders it in your locale while the CSV export keeps a strict ISO-8601 UTC value so timelines stay unambiguous across timezones.

Bring deleted files back into the investigation

Free, open source and private by design.

Open files