Backup Extractor Software

A backup file extractor that reads any backup archive, tape or disk image, including virtual disks and forensic containers.

  • Veeam VBK without a Veeam server
  • Acronis TIB without True Image installed
  • NTBackup BKF without NTBackup on Windows 11
  • An LTO tape without the original backup application

Version 26.7  |  Windows 11, 10, 8.1, 7 and Windows Server  |  Read only, never writes to the source

Trusted Worldwide Since 2011

softpedia

Softpedia

update star

UpdateStar

software informer

Software Informer

cnet

CNET

uptodown

Uptodown

Open a Backup File When the Software That Made It Is Gone

You have the backup. You cannot open it.

vendor lock in

The vendor software is gone

The product was discontinued, the licence expired or the MSP who set it up left. Windows has no built in way to read a .tib, a .vbk or a .bkf. Generic archive tools cannot parse them at all.

selective extraction

You need three files, not everything

Restoring a whole backup set to retrieve a handful of documents is not reasonable when the archive is larger than the disk you have free. A backup file extractor lists the contents first and pulls out only what you tick.

read only

The source must not change

Every read is a read only operation. The archive, the image and the tape are never written to, so the same evidence can be examined again later by someone else and produce exactly the same result.

Why a backup file will not open

A backup is not one thing. It is three layers. Most tools stop at the first or the second.

Swipe the diagram sideways to see all three layers

The three layers inside a backup file A backup container such as a BKF, VBK, TIB or VHDX holds a filesystem such as NTFS or FAT32, which in turn holds your files. Windows cannot open the container. Generic archive tools stop at the filesystem. Backup Extractor reads all three layers. 1 Backup container .bkf   .vbk   .tib   .vhdx   .e01 2 Filesystem inside it NTFS   FAT32   ext4   HFS Plus 3 Your files documents, databases, mailboxes Windows cannot open this Generic archive tools stop here Backup Extractor reads all three layers

Windows has no reader for the container. A generic archive tool may unwrap the container but cannot parse the filesystem inside it. Reading all three layers is what turns an unopenable file into a browsable folder tree.

What a Backup File Extractor Does

What a backup file extractor does that a generic archive tool cannot

format identification

Identifies the format and the software that wrote it

Load any file and Backup Extractor reports what it is and which application created it, before you extract anything. A .bkf reports as Microsoft Tape Format written by Windows NTBackup or Symantec Backup Exec.

search inside archive

Search inside an unopened archive

Type a file name into the search box and find one item inside an archive that holds thousands, without extracting anything first.

selective extraction

Selective extraction at every level

Tick the whole archive, one folder or a single file. There is no restore everything then delete step, which matters when the archive is larger than your free disk space.

folder paths and timestamps

Folder paths and both timestamps preserved

Extracted files keep their original directory structure, their created date and their modified date, to the second.

archive metadata

Full archive metadata on screen

Hostname, backup date, volume label, media label, block size, file mark and archive number are all read from the container and shown in File Details.

unix ownership

Unix ownership and permissions

Owner, group, UID and GID are carried through from TAR, CPIO, PAX and DUMP archives, which matters when the files are going back onto a Linux host.

full and incremental

Full and incremental detected

A backup archive extractor reports whether the file is a full, incremental or differential backup, so you know immediately whether this file alone is enough or whether you need the rest of the chain.

signature detection

Signature detection, not extension guessing

A file renamed to the wrong extension or given no extension at all is still identified correctly. This also resolves the case where three different formats all use .img.

no other software required

No other software required

No Veeam server, no Acronis install, no NTBackup binaries downloaded from an unofficial site and no third party imaging software for disk images.

read only

Read only by design

The source file, image or tape is never modified. Everything runs locally on your machine and nothing is uploaded anywhere.

How Backup Extractor Opens a File Nothing Else Reads

Seven steps with Backup Extractor Software, from an unreadable file to your data back on disk

Open a file, a folder or a tape drive

Load a single archive, a folder holding a segmented or multi part set or attach a tape drive and use Detect Drives and Scan Tape.

The format is identified by signature

Backup Extractor names the format and the application that wrote it. A .bkf file reports as Microsoft Tape Format (MTF) written by Windows NTBackup or Backup Exec. You do not need to know what created your file.

The full contents are listed

Every file and folder is counted and displayed before anything is extracted, with sizes and original timestamps.

Browse or search inside the archive

Walk the folder tree or type a file name into the search box to find one item inside an archive holding thousands.

Inspect any item before extracting

File Details shows created and modified timestamps, owner, group, UID and GID, the archive format and the tape block position.

Tick exactly what you need

Check boxes work at every level, from the whole archive down to a single folder or file.

Export the Selection or Export All

Files are written out with their original folder paths and both timestamps intact. Two separate buttons, so there is never any doubt about how much is coming out.

Actual status bar output, nothing rewritten

Loaded 202 entries from my.bkf (Microsoft Tape Format (MTF)) - 188 files, 14 directories, 58.4 MB total

BitRecover Backup Extractor identifying my.bkf as Microsoft Tape Format written by Windows NTBackup or Symantec Backup Exec

Supported Backup, Tape and Disk Image Formats

A backup archive extractor is only as good as its format list. Here are 34 families, detected by binary signature so a renamed or extensionless file is still identified correctly. Pick a category to see the extensions and which edition reads them.

included partly, see the row not in that edition | Std Standard Pro Professional, most popular Forensic full DFIR set Compare editions
Scroll horizontally to view categories
Format Categories
34 Format Families

Backup software

Proprietary archives written by backup applications. A backup file extractor reports a .bkf as Microsoft Tape Format from Windows NTBackup or Symantec Veritas Backup Exec, a .vbk is a Veeam backup chain file, a .tib is an Acronis True Image image. Windows cannot open any of them and generic archive tools cannot parse them.

BKF

BKFNTBackup, Symantec Backup Exec

TIB

TIBAcronis True Image

VBK

VBKVeeam

VSTORE

VSTOREVeeam NAS

ADI

ADIAOMEI Backupper

DBI

DBIHasleo

MRIMGX

MRIMGXMacrium Reflect X

SPF

SPFShadowProtect

PBD

PBDEaseUS Todo

DLIST

DLISTDuplicati

VOL

VOLBacula, Bareos

VHDZ

VHDZUrBackup

AMANDA

AMANDAAmanda Backup

WIM

WIMWindows Imaging

FFS

FFSFreeFileSync

Edition coverage

Product Extensions Vendor Std$49 Pro$99 Forensic$199
Windows Backup, NTBackup and Symantec Backup Exec.bkfMicrosoft, Symantec, Veritas
Acronis True Image.tib .tibxAcronis
Veeam Backup and Replication.vbk .vib .vrb .vbm .vsbVeeam
Veeam NAS and File Share Backup.vstore .vsourceVeeam
AOMEI Backupper.adi .afiAOMEI
Hasleo Backup Suite.dbiHasleo
Macrium Reflect X.mrimgx .mrbakxMacrium
StorageCraft ShadowProtect.spf .spiStorageCraft
EaseUS Todo Backup.pbdEaseUS
Duplicati Backup.dlist.zipDuplicati
Bacula and Bareos Volume.vol .baculaBacula, Bareos
UrBackup Image.vhdz .rawUrBackup
Amanda Backup.amandaAMANDA
Windows Imaging Format.wim .esdMicrosoft
FreeFileSync.ffs_gui .ffs_batch .ffs_real .ffs_dbFreeFileSync

Tape media and archives

Sequential formats written to tape or to tape image files. LTO, DLT, DAT and AIT are the media. MTF, TAR, CPIO, PAX and DUMP are the formats written onto them. Without the original catalogue the backup software cannot find anything, even though the data is intact.

LTO

LTOUltrium media

DLT

DLTDigital Linear Tape

SDLT

SDLTSuper DLT

DAT

DATDigital Audio Tape

DDS

DDSDigital Data Storage

AIT

AITAdvanced Intelligent Tape

LTFS

LTFSTape filesystem

MTF

MTFMicrosoft Tape Format

AWS

AWSHercules tape

HET

HETHercules tape

TAR

TARUNIX archive

TAR.GZ

TAR.GZCompressed TAR

CPIO

CPIOUNIX archive

PAX

PAXPOSIX archive

DUMP

DUMPBSD, UFS, ext

ZIP

ZIPStandard archive

DEB

DEBDebian package

RPM

RPMRed Hat package

Edition coverage

Physical tape media, LTO, DLT, SDLT, DAT, DDS and AIT, is read through the tape drive and requires the Professional edition.

Format Extensions Notes Std$49 Pro$99 Forensic$199
Virtual Tape, AWSTAPE and HET.aws .hetHercules virtual tape volumes
UNIX TAR.tarPlain uncompressed archives
Compressed TAR.tar.gz .tgz .tar.xz .tar.zstDecompressed on the fly
UNIX CPIO.cpioBinary, old ASCII, SVR4 and CRC variants
POSIX PAX.paxExtended header records read
DUMP and restore.dumpBSD, Solaris UFS and Linux ext
ZIP archive.zipStandard and compressed entries
Linux packages.deb .rpmPayload extracted with paths intact

Virtual disks and images

Whole disk containers. A .vhdx is a Windows system image or Hyper-V disk, a .vmdk is VMware, a .dd or .img is a bit for bit sector copy. The partitions and filesystems inside them have to be parsed before any file can be read.

VHD

VHDHyper-V, Virtual PC

VHDX

VHDXHyper-V

VDI

VDIVirtualBox

VMDK

VMDKVMware

QCOW2

QCOW2QEMU, KVM

DD

DDRaw sector image

IMG

IMGRaw sector image

BIN

BINRaw sector image

RAW

RAWRaw sector image

PTCL

PTCLPartclone, Clonezilla

DMG

DMGApple Disk Image

ISO

ISOOptical disc

UDF

UDFOptical disc

Edition coverage

Format Extensions Platform Std$49 Pro$99 Forensic$199
Virtual disk.vhd .vhdx .vdi .vmdk .qcow2Hyper-V, VirtualBox, VMware, QEMU and KVM
Raw disk image.dd .img .bin .rawBit for bit sector images. Standard reads FAT filesystems inside them, NTFS and ext need Professional
Partclone and Clonezilla.ptcl .imgUsed only allocated blocks
Apple Disk Image.dmgUDIF with zlib compression
Optical disc image.iso .udfISO 9660 with Rock Ridge and Joliet

Forensic and memory

Evidence containers that wrap a disk or memory image with metadata and hashes. E01 is EnCase, AD1 is FTK Imager, AFF4 is the open standard. LiME and AVML hold Linux memory captures.

E01

E01EnCase evidence

EX01

EX01EnCase EWF2

S01

S01SMART evidence

L01

L01EnCase logical

LX01

LX01EnCase logical

AD1

AD1FTK Imager

AFF

AFFAdvanced Forensic Format

AFF4

AFF4AFF4 container

LIME

LIMELinux memory

AVML

AVMLLinux memory

Edition coverage

Format Extensions Notes Std$49 Pro$99 Forensic$199
EnCase Evidence File.e01 .ex01 .s01EWF version 1 and version 2, plus SMART
EnCase Logical Evidence.l01 .lx01Logical file collections
FTK Imager AD1.ad1Multi segment sets supported
Advanced Forensic Format.affAFFLIBv3 pages with zlib
AFF4 container.aff4Physical and logical, Map layout
Linux memory capture.lime .avmlReconstructed into a flat memory image

Filesystems read inside

Not file types you pick. When an image is opened its partitions are detected and these filesystems are parsed directly, which is what turns a raw container into a browsable folder tree.

NTFS

NTFSMFT parsing

exFAT

exFATFAT chain

FAT32

FAT32Long file names

FAT16

FAT16Long file names

FAT12

FAT12Long file names

ext4

ext4Inode parsing

ext3

ext3Inode parsing

ext2

ext2Inode parsing

HFS+

HFS+Apple catalog

ISO9660

ISO9660Rock Ridge, Joliet

UDF

UDFOptical volumes

Edition coverage

These are not selectable file types. When a disk image or virtual disk is opened, its partitions are detected and these filesystems are parsed directly.

Filesystem Support detail Std$49 Pro$99 Forensic$199
FAT12, FAT16, FAT32Cluster count based sizing, long file names, deleted entries
NTFSMFT parsing, resident and non resident data, USA fixup
exFATDirectory and FAT chain traversal
ext2, ext3, ext4Inode and directory parsing
HFS PlusApple catalog B-tree parsing
ISO 9660Rock Ridge and Joliet extensions
UDFUniversal Disk Format optical volumes

Tape Media, LTO, LTFS, DLT, DAT and AIT

Tape data recovery usually fails for one reason. The tape is fine, but the catalogue that told the backup software where everything sits is gone.

Reads the tape, not the catalogue
Attach a supported tape drive, then use Detect Drives to find it
Scan Tape reads the raw tape stream from the media itself
The format written on the tape is identified by its binary signature
The complete file list is rebuilt from the tape, with no catalogue needed

Rewind, Eject and Stop sit on the toolbar, so the whole job is done without the original backup application.

Media and formats covered
LTO Ultrium generations, including tapes written by HP, IBM, Quantum, Sony or Fujifilm drives you no longer own
DLT, SDLT, DAT, DDS, AIT, S-AIT, QIC, VXA and Travan legacy media
Microsoft Tape Format written by NTBackup, Symantec Backup Exec and Veritas NetBackup
Hercules virtual tape volumes in AWSTAPE and HET
TAR, CPIO, PAX and DUMP streams written straight to tape

LTO 2LTO 3LTO 4LTO 5LTO 6LTO 7LTO 8LTO 9

Block sizeReported for every entry
File mark positionWhere the entry sits on tape
Archive numberWhich archive set it came from

The physical layout of the tape stays visible throughout, so you always know where a file came from.

Deleted Files Inside a Backup or Image

Deleted files are reconstructed during the same pass that lists the live ones, so nothing has to be scanned twice.

  • FAT12, FAT16 and FAT32. Freed directory slots are rebuilt and the data is carved contiguously from the start cluster, because the FAT chain is cleared on delete.
  • NTFS. Unallocated MFT records are parsed exactly like live records. Resident file data is recovered inline and non resident data from the first data run.
  • Recoverability rating. Every recovered item is flagged as full, partial or overwritten, so the confidence of each carve is visible before you export it.

Deleted file recovery is available in the Forensic edition only.

Browsing a folder inside a backup archive with tick boxes for selective extraction

Four Situations Backup Extractor Was Built For

The departed MSP

The departed MSP

MSPs and IT teams

A client hands over a repository written by a backup product nobody on the current team licenses. The files are intact but unreadable. Backup Extractor Software names the format and pulls the data out without buying a licence.

The defunct vendor

The defunct vendor

Home and business users

The backup product was discontinued years ago and the installer no longer runs on a supported version of Windows. The archive format itself has not changed, so a backup file extractor can still parse it directly.

The tape stack with no catalogue

The tape stack with no catalogue

Archive and storage teams

A shelf of tapes, no job records and no server anywhere. Scan the tape, let the format be identified from the media itself and rebuild the whole file list without the original backup application.

Evidence inside a backup

Evidence inside a backup

DFIR and eDiscovery

The material under examination is not on a disk image, it is inside a backup archive. Standard forensic tooling stops at the container. This reads both and preserves the metadata, keeping the chain of custody intact.

How a Backup Archive Extractor Compares with the Free Tools

Several free tools do part of a backup file extractor job well. Here is exactly what each one covers and where it stops.

Tool Backup
archives
Tape
media
What it does well Where it stops
FTK Imager
Free
Mounts and exports from E01, Ex01, AD1 and raw images and browses NTFS, FAT, exFAT, HFS Plus and extNo backup archive formats and no tape. It cannot open a VBK, a TIB, a BKF or an LTFS volume
Veeam Extract Utility
Free
Extracts VBK, VIB and VRB without a Veeam serverVeeam only. It produces raw disk files that still need a second tool to read the filesystem inside
NTBackup on modern Windows
Free
Restores legacy BKF filesWorks on a healthy file. The official Microsoft utility targets Server 2008 and the cab extraction route needs three loose system files. Neither handles a damaged archive well
OSFMount
Free
Mounts E01 and raw images as logical volumesLogical mounting only, no write support and no backup formats
Arsenal Image Mounter
Free tier
Full physical disk mounting for E01, Ex01 and rawNo backup formats and advanced capability sits behind the paid tier
7-Zip
Free
Opens TAR, ZIP, DEB and RPM and sometimes VMDK or VDINo proprietary backup formats, no filesystem parsing and no deleted file recovery
Windows Disk Management
Built in
Attach VHD mounts a VHD or VHDX from a Windows Server Backup or wbadmin job as a drive letterThose two formats only. It cannot touch BKF, VBK, TIB, tape or any forensic container
DISM
Built in
Services and mounts WIM and ESD images from the command lineMicrosoft imaging formats only. It is a command line tool with no browsing or search
BitRecover Backup Extractor
Free demo
All of these container families in one interface, plus tape media, plus deleted FAT and NTFS reconstruction with a recoverability rating in the Forensic editionNot an imaging or write blocking tool. Some proprietary internals are detected and reported rather than extracted

full support   one vendor or format only   not supported

Which Backup Extractor Edition Do You Need

Backup Extractor Software is a one time purchase with a perpetual licence, a free demo and a 30 day money back guarantee on every edition

Standard

$49

One time, up to 2 PCs, personal use


Home users and small businesses restoring their own files

  • TAR, CPIO, PAX, DUMP, ZIP, DEB and RPM
  • Windows Backup BKF and virtual tape
  • AOMEI, Hasleo, EaseUS and Macrium Reflect X
  • Raw disk images and FAT filesystems

Buy Standard $49

30 day money back    Instant delivery    Perpetual licence

Forensic

$199

One time, up to 10 PCs, commercial use


DFIR analysts, investigators and eDiscovery teams

  • Everything in Professional
  • EnCase E01, Ex01, L01, Lx01 and SMART s01
  • FTK Imager AD1, AFF and AFF4 containers
  • LiME and AVML memory captures
  • Deleted file recovery with a recoverability rating

Buy Forensic $199

30 day money back    Instant delivery    Perpetual licence

Not sure yet? Try the Free Demo

Volume, site and unlimited machine licensing is available on request. Comparable read only recovery and forensic image tools range from roughly $99 to $499. Full acquisition suites cost considerably more.

System Requirements, Licence and Updates

Software
Version
26.7
Windows
Windows 11, Windows 10, Windows 8.1, Windows 8, Windows 7
Windows Server
Server 2022, Server 2019, Server 2016, Server 2012, Server 2008
Memory
4 GB RAM
Install size
100 MB
Extraction space
Size of what you extract
Licence
Purchase
One time
Validity
Never expires
Updates and support
12 months included
After 12 months
Software keeps working
Machines
2 to 10 by edition
Volume licensing
On request
Demo and refund
Free demo
Preview only, no export
Identify a format
Yes, before purchase
List contents
Yes, before purchase
Money back
30 days
Delivery
Instant, by email
Processing
Local, nothing uploaded

Backup Extractor Questions, Answered

Everything you need to know about BitRecover Backup Extractor

Yes, provided a drive can read the media. Backup Extractor reads the raw tape stream and parses the format written on it, so the original application is not needed. Use Detect Drives to find the tape device, then Scan Tape to build the file list from the media itself.

LTO Ultrium generations, plus DLT, SDLT, DAT, DDS, AIT, S-AIT, QIC, VXA and Travan media. Tape written in Microsoft Tape Format by NTBackup, Symantec Backup Exec or Veritas NetBackup is read directly, as are TAR, CPIO, PAX and DUMP streams written straight to tape and Hercules virtual tape volumes in AWSTAPE and HET.

In most cases the tape is readable and the catalogue is missing. Backup Extractor does not depend on the catalogue. It identifies the format written on the media by signature and rebuilds the file list from the tape, so a lost or corrupt catalogue no longer blocks the restore.

Yes. NTBackup was removed after Windows XP and Windows Server 2003, so Windows 11 has no built in way to open a .bkf. Microsoft does publish a free NTBackup Restore Utility for Windows Server 2008 that many people install on Windows 11. Other guides tell you to extract ntbackup.exe, ntmsapi.dll and vssapi.dll from nt5backup.cab yourself. Both routes work for a healthy file and both are fiddly. Backup Extractor opens a .bkf directly and reports it as Microsoft Tape Format written by Windows NTBackup or Symantec Backup Exec.

Yes. TIB and TIBX are proprietary formats, but the container structure can be parsed directly, so the contents can be listed and extracted without Acronis True Image installed. This is a read only operation and the .tib file itself is never modified. There is a fuller walkthrough on the TIB file extractor page.

Yes. Veeam publishes a free extract utility of its own, which produces raw disk files that then need a second tool to read the filesystem inside them. Backup Extractor goes one step further and parses that filesystem for you, so you can browse the folder tree and pull out individual files in a single pass. VBK, VIB, VRB, VBM and VSB are all supported. There is a fuller walkthrough on the VBK file extractor page.

Load it and the tool will tell you. Backup Extractor identifies the format by its binary signature rather than by its file extension, then names both the format and the application that wrote it. A file with the wrong extension or no extension at all is still identified correctly.

No. Backup Extractor is a read and extract tool, not an imaging or write blocking product. It reads evidence containers that already exist rather than acquiring new ones and it is priced accordingly. If you need to acquire an image, use a dedicated acquisition tool and then open the result here.

No. All access is read only and the source file, image or tape is never written to. Processing happens locally on your own machine and nothing is uploaded to any server.

Deleted file recovery for FAT and NTFS is available in the Forensic edition only. The Standard and Professional editions list and extract live files but do not reconstruct deleted directory entries or unallocated MFT records.

Yes. Extracted files keep their original folder paths and both their created and modified timestamps. For TAR, CPIO, PAX and DUMP archives the owner, group, UID and GID are read and displayed as well, which matters when the data is going back onto a Linux host.

It identifies them but it does not decrypt them. An encrypted container such as an ADCRYPT protected FTK AD1 is detected and reported so you know what you are holding. The same applies to backup archives whose internals are encrypted by the original product. If you have the original key or password, decrypt with the vendor tool first and then open the result here.

Because a backup file extractor lists the contents before anything is written out, you only need free disk space for the files you actually tick, not for the whole archive. That is the point of selective extraction when the backup is larger than the disk you have free. Very large archives take longer to scan, so run the free demo on your own file first to see how it behaves.

Backup Extractor is a read and extract tool, not a repair tool. It reads healthy archives and will recover what it can from a partly damaged one, but it does not rebuild corrupt structures. If the file is corrupt, BitRecover BKF Repair Wizard and Tape Recovery Wizard are built for that job. Try the free demo first, since it will list the contents if the archive is readable.

The backup extractor demo opens your file, identifies the format, lists every file and folder inside and lets you inspect the metadata. Export is the one thing it does not do. Activating a licence unlocks extraction in the same build, so you can confirm your archive is readable and see exactly what is in it before you pay anything.

Yes. Every edition is a one time purchase and the licence never expires. Updates and technical support are included for twelve months from the date of purchase. A 30 day money back guarantee applies as set out in the refund policy.

Extract Files from Backup Archives You Cannot Open

Download the free backup extractor demo and extract files from backup archives that have been blocking you. If the format is identified and the contents are listed, the full version will extract them.

Free Demo Download Purchase Now

Identifies the format and the software that wrote it
Lists every file and folder inside, before you pay
Read only, your source file is never touched
30 day money back on every edition

Version 26.7  ·  Windows 11, 10, 8.1, 7 and Windows Server  ·  One time purchase, perpetual licence

Backup Extractor Software is built by BitRecover, who have shipped data recovery and migration tools since 2011. Format coverage on this page reflects version 26.7.

Related BitRecover Software


Live Chat