Backup Extractor Software
A backup file extractor that reads any backup archive, tape or disk image, including virtual disks and forensic containers.
- Veeam VBK without a Veeam server
- Acronis TIB without True Image installed
- NTBackup BKF without NTBackup on Windows 11
- An LTO tape without the original backup application
Version 26.7 | Windows 11, 10, 8.1, 7 and Windows Server | Read only, never writes to the source
34 Format Families
Detected by binary signature, not by file extension
Backup archives15 Tape media and archives18 Virtual disks and images13 Forensic and memory containers10 Filesystems read inside images11Trusted Worldwide Since 2011
Softpedia
UpdateStar
Software Informer
CNET
Uptodown
Open a Backup File When the Software That Made It Is Gone
You have the backup. You cannot open it.
The vendor software is gone
The product was discontinued, the licence expired or the MSP who set it up left. Windows has no built in way to read a .tib, a .vbk or a .bkf. Generic archive tools cannot parse them at all.
You need three files, not everything
Restoring a whole backup set to retrieve a handful of documents is not reasonable when the archive is larger than the disk you have free. A backup file extractor lists the contents first and pulls out only what you tick.
The source must not change
Every read is a read only operation. The archive, the image and the tape are never written to, so the same evidence can be examined again later by someone else and produce exactly the same result.
Why a backup file will not open
A backup is not one thing. It is three layers. Most tools stop at the first or the second.
Swipe the diagram sideways to see all three layers
Windows has no reader for the container. A generic archive tool may unwrap the container but cannot parse the filesystem inside it. Reading all three layers is what turns an unopenable file into a browsable folder tree.
What a Backup File Extractor Does
What a backup file extractor does that a generic archive tool cannot
Identifies the format and the software that wrote it
Load any file and Backup Extractor reports what it is and which application created it, before you extract anything. A .bkf reports as Microsoft Tape Format written by Windows NTBackup or Symantec Backup Exec.
Search inside an unopened archive
Type a file name into the search box and find one item inside an archive that holds thousands, without extracting anything first.
Selective extraction at every level
Tick the whole archive, one folder or a single file. There is no restore everything then delete step, which matters when the archive is larger than your free disk space.
Folder paths and both timestamps preserved
Extracted files keep their original directory structure, their created date and their modified date, to the second.
Full archive metadata on screen
Hostname, backup date, volume label, media label, block size, file mark and archive number are all read from the container and shown in File Details.
Unix ownership and permissions
Owner, group, UID and GID are carried through from TAR, CPIO, PAX and DUMP archives, which matters when the files are going back onto a Linux host.
Full and incremental detected
A backup archive extractor reports whether the file is a full, incremental or differential backup, so you know immediately whether this file alone is enough or whether you need the rest of the chain.
Signature detection, not extension guessing
A file renamed to the wrong extension or given no extension at all is still identified correctly. This also resolves the case where three different formats all use .img.
No other software required
No Veeam server, no Acronis install, no NTBackup binaries downloaded from an unofficial site and no third party imaging software for disk images.
Read only by design
The source file, image or tape is never modified. Everything runs locally on your machine and nothing is uploaded anywhere.
How Backup Extractor Opens a File Nothing Else Reads
Seven steps with Backup Extractor Software, from an unreadable file to your data back on disk
Open a file, a folder or a tape drive
Load a single archive, a folder holding a segmented or multi part set or attach a tape drive and use Detect Drives and Scan Tape.
The format is identified by signature
Backup Extractor names the format and the application that wrote it. A .bkf file reports as Microsoft Tape Format (MTF) written by Windows NTBackup or Backup Exec. You do not need to know what created your file.
The full contents are listed
Every file and folder is counted and displayed before anything is extracted, with sizes and original timestamps.
Browse or search inside the archive
Walk the folder tree or type a file name into the search box to find one item inside an archive holding thousands.
Inspect any item before extracting
File Details shows created and modified timestamps, owner, group, UID and GID, the archive format and the tape block position.
Tick exactly what you need
Check boxes work at every level, from the whole archive down to a single folder or file.
Export the Selection or Export All
Files are written out with their original folder paths and both timestamps intact. Two separate buttons, so there is never any doubt about how much is coming out.
Actual status bar output, nothing rewritten

Supported Backup, Tape and Disk Image Formats
A backup archive extractor is only as good as its format list. Here are 34 families, detected by binary signature so a renamed or extensionless file is still identified correctly. Pick a category to see the extensions and which edition reads them.
Backup software
Proprietary archives written by backup applications. A backup file extractor reports a .bkf as Microsoft Tape Format from Windows NTBackup or Symantec Veritas Backup Exec, a .vbk is a Veeam backup chain file, a .tib is an Acronis True Image image. Windows cannot open any of them and generic archive tools cannot parse them.
BKFNTBackup, Symantec Backup Exec
TIBAcronis True Image
VBKVeeam
VSTOREVeeam NAS
ADIAOMEI Backupper
DBIHasleo
MRIMGXMacrium Reflect X
SPFShadowProtect
PBDEaseUS Todo
DLISTDuplicati
VOLBacula, Bareos
VHDZUrBackup
AMANDAAmanda Backup
WIMWindows Imaging
FFSFreeFileSync
Edition coverage
| Product | Extensions | Vendor | Std$49 | Pro$99 | Forensic$199 |
|---|---|---|---|---|---|
| Windows Backup, NTBackup and Symantec Backup Exec | .bkf | Microsoft, Symantec, Veritas | |||
| Acronis True Image | .tib .tibx | Acronis | |||
| Veeam Backup and Replication | .vbk .vib .vrb .vbm .vsb | Veeam | |||
| Veeam NAS and File Share Backup | .vstore .vsource | Veeam | |||
| AOMEI Backupper | .adi .afi | AOMEI | |||
| Hasleo Backup Suite | .dbi | Hasleo | |||
| Macrium Reflect X | .mrimgx .mrbakx | Macrium | |||
| StorageCraft ShadowProtect | .spf .spi | StorageCraft | |||
| EaseUS Todo Backup | .pbd | EaseUS | |||
| Duplicati Backup | .dlist.zip | Duplicati | |||
| Bacula and Bareos Volume | .vol .bacula | Bacula, Bareos | |||
| UrBackup Image | .vhdz .raw | UrBackup | |||
| Amanda Backup | .amanda | AMANDA | |||
| Windows Imaging Format | .wim .esd | Microsoft | |||
| FreeFileSync | .ffs_gui .ffs_batch .ffs_real .ffs_db | FreeFileSync |
Tape media and archives
Sequential formats written to tape or to tape image files. LTO, DLT, DAT and AIT are the media. MTF, TAR, CPIO, PAX and DUMP are the formats written onto them. Without the original catalogue the backup software cannot find anything, even though the data is intact.
LTOUltrium media
DLTDigital Linear Tape
SDLTSuper DLT
DATDigital Audio Tape
DDSDigital Data Storage
AITAdvanced Intelligent Tape
LTFSTape filesystem
MTFMicrosoft Tape Format
AWSHercules tape
HETHercules tape
TARUNIX archive
TAR.GZCompressed TAR
CPIOUNIX archive
PAXPOSIX archive
DUMPBSD, UFS, ext
ZIPStandard archive
DEBDebian package
RPMRed Hat package
Edition coverage
Physical tape media, LTO, DLT, SDLT, DAT, DDS and AIT, is read through the tape drive and requires the Professional edition.
| Format | Extensions | Notes | Std$49 | Pro$99 | Forensic$199 |
|---|---|---|---|---|---|
| Virtual Tape, AWSTAPE and HET | .aws .het | Hercules virtual tape volumes | |||
| UNIX TAR | .tar | Plain uncompressed archives | |||
| Compressed TAR | .tar.gz .tgz .tar.xz .tar.zst | Decompressed on the fly | |||
| UNIX CPIO | .cpio | Binary, old ASCII, SVR4 and CRC variants | |||
| POSIX PAX | .pax | Extended header records read | |||
| DUMP and restore | .dump | BSD, Solaris UFS and Linux ext | |||
| ZIP archive | .zip | Standard and compressed entries | |||
| Linux packages | .deb .rpm | Payload extracted with paths intact |
Virtual disks and images
Whole disk containers. A .vhdx is a Windows system image or Hyper-V disk, a .vmdk is VMware, a .dd or .img is a bit for bit sector copy. The partitions and filesystems inside them have to be parsed before any file can be read.
VHDHyper-V, Virtual PC
VHDXHyper-V
VDIVirtualBox
VMDKVMware
QCOW2QEMU, KVM
DDRaw sector image
IMGRaw sector image
BINRaw sector image
RAWRaw sector image
PTCLPartclone, Clonezilla
DMGApple Disk Image
ISOOptical disc
UDFOptical disc
Edition coverage
| Format | Extensions | Platform | Std$49 | Pro$99 | Forensic$199 |
|---|---|---|---|---|---|
| Virtual disk | .vhd .vhdx .vdi .vmdk .qcow2 | Hyper-V, VirtualBox, VMware, QEMU and KVM | |||
| Raw disk image | .dd .img .bin .raw | Bit for bit sector images. Standard reads FAT filesystems inside them, NTFS and ext need Professional | |||
| Partclone and Clonezilla | .ptcl .img | Used only allocated blocks | |||
| Apple Disk Image | .dmg | UDIF with zlib compression | |||
| Optical disc image | .iso .udf | ISO 9660 with Rock Ridge and Joliet |
Forensic and memory
Evidence containers that wrap a disk or memory image with metadata and hashes. E01 is EnCase, AD1 is FTK Imager, AFF4 is the open standard. LiME and AVML hold Linux memory captures.
E01EnCase evidence
EX01EnCase EWF2
S01SMART evidence
L01EnCase logical
LX01EnCase logical
AD1FTK Imager
AFFAdvanced Forensic Format
AFF4AFF4 container
LIMELinux memory
AVMLLinux memory
Edition coverage
| Format | Extensions | Notes | Std$49 | Pro$99 | Forensic$199 |
|---|---|---|---|---|---|
| EnCase Evidence File | .e01 .ex01 .s01 | EWF version 1 and version 2, plus SMART | |||
| EnCase Logical Evidence | .l01 .lx01 | Logical file collections | |||
| FTK Imager AD1 | .ad1 | Multi segment sets supported | |||
| Advanced Forensic Format | .aff | AFFLIBv3 pages with zlib | |||
| AFF4 container | .aff4 | Physical and logical, Map layout | |||
| Linux memory capture | .lime .avml | Reconstructed into a flat memory image |
Filesystems read inside
Not file types you pick. When an image is opened its partitions are detected and these filesystems are parsed directly, which is what turns a raw container into a browsable folder tree.
NTFSMFT parsing
exFATFAT chain
FAT32Long file names
FAT16Long file names
FAT12Long file names
ext4Inode parsing
ext3Inode parsing
ext2Inode parsing
HFS+Apple catalog
ISO9660Rock Ridge, Joliet
UDFOptical volumes
Edition coverage
These are not selectable file types. When a disk image or virtual disk is opened, its partitions are detected and these filesystems are parsed directly.
| Filesystem | Support detail | Std$49 | Pro$99 | Forensic$199 |
|---|---|---|---|---|
| FAT12, FAT16, FAT32 | Cluster count based sizing, long file names, deleted entries | |||
| NTFS | MFT parsing, resident and non resident data, USA fixup | |||
| exFAT | Directory and FAT chain traversal | |||
| ext2, ext3, ext4 | Inode and directory parsing | |||
| HFS Plus | Apple catalog B-tree parsing | |||
| ISO 9660 | Rock Ridge and Joliet extensions | |||
| UDF | Universal Disk Format optical volumes |
Tape Media, LTO, LTFS, DLT, DAT and AIT
Tape data recovery usually fails for one reason. The tape is fine, but the catalogue that told the backup software where everything sits is gone.
Rewind, Eject and Stop sit on the toolbar, so the whole job is done without the original backup application.
LTO 2LTO 3LTO 4LTO 5LTO 6LTO 7LTO 8LTO 9
The physical layout of the tape stays visible throughout, so you always know where a file came from.
Deleted Files Inside a Backup or Image
Deleted files are reconstructed during the same pass that lists the live ones, so nothing has to be scanned twice.
- FAT12, FAT16 and FAT32. Freed directory slots are rebuilt and the data is carved contiguously from the start cluster, because the FAT chain is cleared on delete.
- NTFS. Unallocated MFT records are parsed exactly like live records. Resident file data is recovered inline and non resident data from the first data run.
- Recoverability rating. Every recovered item is flagged as full, partial or overwritten, so the confidence of each carve is visible before you export it.
Deleted file recovery is available in the Forensic edition only.

Four Situations Backup Extractor Was Built For
The departed MSP
MSPs and IT teams
A client hands over a repository written by a backup product nobody on the current team licenses. The files are intact but unreadable. Backup Extractor Software names the format and pulls the data out without buying a licence.
The defunct vendor
Home and business users
The backup product was discontinued years ago and the installer no longer runs on a supported version of Windows. The archive format itself has not changed, so a backup file extractor can still parse it directly.
The tape stack with no catalogue
Archive and storage teams
A shelf of tapes, no job records and no server anywhere. Scan the tape, let the format be identified from the media itself and rebuild the whole file list without the original backup application.
Evidence inside a backup
DFIR and eDiscovery
The material under examination is not on a disk image, it is inside a backup archive. Standard forensic tooling stops at the container. This reads both and preserves the metadata, keeping the chain of custody intact.
How a Backup Archive Extractor Compares with the Free Tools
Several free tools do part of a backup file extractor job well. Here is exactly what each one covers and where it stops.
| Tool | Backup archives |
Tape media |
What it does well | Where it stops |
|---|---|---|---|---|
| FTK Imager Free | Mounts and exports from E01, Ex01, AD1 and raw images and browses NTFS, FAT, exFAT, HFS Plus and ext | No backup archive formats and no tape. It cannot open a VBK, a TIB, a BKF or an LTFS volume | ||
| Veeam Extract Utility Free | Extracts VBK, VIB and VRB without a Veeam server | Veeam only. It produces raw disk files that still need a second tool to read the filesystem inside | ||
| NTBackup on modern Windows Free | Restores legacy BKF files | Works on a healthy file. The official Microsoft utility targets Server 2008 and the cab extraction route needs three loose system files. Neither handles a damaged archive well | ||
| OSFMount Free | Mounts E01 and raw images as logical volumes | Logical mounting only, no write support and no backup formats | ||
| Arsenal Image Mounter Free tier | Full physical disk mounting for E01, Ex01 and raw | No backup formats and advanced capability sits behind the paid tier | ||
| 7-Zip Free | Opens TAR, ZIP, DEB and RPM and sometimes VMDK or VDI | No proprietary backup formats, no filesystem parsing and no deleted file recovery | ||
| Windows Disk Management Built in | Attach VHD mounts a VHD or VHDX from a Windows Server Backup or wbadmin job as a drive letter | Those two formats only. It cannot touch BKF, VBK, TIB, tape or any forensic container | ||
| DISM Built in | Services and mounts WIM and ESD images from the command line | Microsoft imaging formats only. It is a command line tool with no browsing or search | ||
| BitRecover Backup Extractor Free demo | All of these container families in one interface, plus tape media, plus deleted FAT and NTFS reconstruction with a recoverability rating in the Forensic edition | Not an imaging or write blocking tool. Some proprietary internals are detected and reported rather than extracted |
full support one vendor or format only not supported
Which Backup Extractor Edition Do You Need
Backup Extractor Software is a one time purchase with a perpetual licence, a free demo and a 30 day money back guarantee on every edition
Standard
$49
One time, up to 2 PCs, personal use
Home users and small businesses restoring their own files
- TAR, CPIO, PAX, DUMP, ZIP, DEB and RPM
- Windows Backup BKF and virtual tape
- AOMEI, Hasleo, EaseUS and Macrium Reflect X
- Raw disk images and FAT filesystems
Professional
$99
One time, up to 10 PCs, commercial use
IT admins, MSPs and migration teams
- Everything in Standard
- Veeam, Acronis, ShadowProtect, Duplicati, Bacula and UrBackup
- Tape drives, LTO, DLT, DAT and LTFS volumes
- Virtual disks, optical images and DMG
- NTFS, exFAT, ext and HFS Plus filesystems
Forensic
$199
One time, up to 10 PCs, commercial use
DFIR analysts, investigators and eDiscovery teams
- Everything in Professional
- EnCase E01, Ex01, L01, Lx01 and SMART s01
- FTK Imager AD1, AFF and AFF4 containers
- LiME and AVML memory captures
- Deleted file recovery with a recoverability rating
Not sure yet? Try the Free Demo
Volume, site and unlimited machine licensing is available on request. Comparable read only recovery and forensic image tools range from roughly $99 to $499. Full acquisition suites cost considerably more.
System Requirements, Licence and Updates
- Version
- 26.7
- Windows
- Windows 11, Windows 10, Windows 8.1, Windows 8, Windows 7
- Windows Server
- Server 2022, Server 2019, Server 2016, Server 2012, Server 2008
- Memory
- 4 GB RAM
- Install size
- 100 MB
- Extraction space
- Size of what you extract
- Purchase
- One time
- Validity
- Never expires
- Updates and support
- 12 months included
- After 12 months
- Software keeps working
- Machines
- 2 to 10 by edition
- Volume licensing
- On request
- Free demo
- Preview only, no export
- Identify a format
- Yes, before purchase
- List contents
- Yes, before purchase
- Money back
- 30 days
- Delivery
- Instant, by email
- Processing
- Local, nothing uploaded
Backup Extractor Questions, Answered
Everything you need to know about BitRecover Backup Extractor
Yes, provided a drive can read the media. Backup Extractor reads the raw tape stream and parses the format written on it, so the original application is not needed. Use Detect Drives to find the tape device, then Scan Tape to build the file list from the media itself.
LTO Ultrium generations, plus DLT, SDLT, DAT, DDS, AIT, S-AIT, QIC, VXA and Travan media. Tape written in Microsoft Tape Format by NTBackup, Symantec Backup Exec or Veritas NetBackup is read directly, as are TAR, CPIO, PAX and DUMP streams written straight to tape and Hercules virtual tape volumes in AWSTAPE and HET.
In most cases the tape is readable and the catalogue is missing. Backup Extractor does not depend on the catalogue. It identifies the format written on the media by signature and rebuilds the file list from the tape, so a lost or corrupt catalogue no longer blocks the restore.
Yes. NTBackup was removed after Windows XP and Windows Server 2003, so Windows 11 has no built in way to open a .bkf. Microsoft does publish a free NTBackup Restore Utility for Windows Server 2008 that many people install on Windows 11. Other guides tell you to extract ntbackup.exe, ntmsapi.dll and vssapi.dll from nt5backup.cab yourself. Both routes work for a healthy file and both are fiddly. Backup Extractor opens a .bkf directly and reports it as Microsoft Tape Format written by Windows NTBackup or Symantec Backup Exec.
Yes. TIB and TIBX are proprietary formats, but the container structure can be parsed directly, so the contents can be listed and extracted without Acronis True Image installed. This is a read only operation and the .tib file itself is never modified. There is a fuller walkthrough on the TIB file extractor page.
Yes. Veeam publishes a free extract utility of its own, which produces raw disk files that then need a second tool to read the filesystem inside them. Backup Extractor goes one step further and parses that filesystem for you, so you can browse the folder tree and pull out individual files in a single pass. VBK, VIB, VRB, VBM and VSB are all supported. There is a fuller walkthrough on the VBK file extractor page.
Load it and the tool will tell you. Backup Extractor identifies the format by its binary signature rather than by its file extension, then names both the format and the application that wrote it. A file with the wrong extension or no extension at all is still identified correctly.
No. Backup Extractor is a read and extract tool, not an imaging or write blocking product. It reads evidence containers that already exist rather than acquiring new ones and it is priced accordingly. If you need to acquire an image, use a dedicated acquisition tool and then open the result here.
No. All access is read only and the source file, image or tape is never written to. Processing happens locally on your own machine and nothing is uploaded to any server.
Deleted file recovery for FAT and NTFS is available in the Forensic edition only. The Standard and Professional editions list and extract live files but do not reconstruct deleted directory entries or unallocated MFT records.
Yes. Extracted files keep their original folder paths and both their created and modified timestamps. For TAR, CPIO, PAX and DUMP archives the owner, group, UID and GID are read and displayed as well, which matters when the data is going back onto a Linux host.
It identifies them but it does not decrypt them. An encrypted container such as an ADCRYPT protected FTK AD1 is detected and reported so you know what you are holding. The same applies to backup archives whose internals are encrypted by the original product. If you have the original key or password, decrypt with the vendor tool first and then open the result here.
Because a backup file extractor lists the contents before anything is written out, you only need free disk space for the files you actually tick, not for the whole archive. That is the point of selective extraction when the backup is larger than the disk you have free. Very large archives take longer to scan, so run the free demo on your own file first to see how it behaves.
Backup Extractor is a read and extract tool, not a repair tool. It reads healthy archives and will recover what it can from a partly damaged one, but it does not rebuild corrupt structures. If the file is corrupt, BitRecover BKF Repair Wizard and Tape Recovery Wizard are built for that job. Try the free demo first, since it will list the contents if the archive is readable.
The backup extractor demo opens your file, identifies the format, lists every file and folder inside and lets you inspect the metadata. Export is the one thing it does not do. Activating a licence unlocks extraction in the same build, so you can confirm your archive is readable and see exactly what is in it before you pay anything.
Yes. Every edition is a one time purchase and the licence never expires. Updates and technical support are included for twelve months from the date of purchase. A 30 day money back guarantee applies as set out in the refund policy.
Extract Files from Backup Archives You Cannot Open
Download the free backup extractor demo and extract files from backup archives that have been blocking you. If the format is identified and the contents are listed, the full version will extract them.
Version 26.7 · Windows 11, 10, 8.1, 7 and Windows Server · One time purchase, perpetual licence
Backup Extractor Software is built by BitRecover, who have shipped data recovery and migration tools since 2011. Format coverage on this page reflects version 26.7.