Inspection

Archives

The Archives module opens ZIP, 7z, TAR, CAB, ISO and installers and shows their contents without extracting anything. It computes the hashes of single entries without writing them to disk, compares the declared CRC with the recomputed one and says what the system's archive manager keeps quiet: why an archive won't open, which name is really written, when the dates don't add up.

What it does

What the Archives module does

Hashes without extracting

MD5, SHA-1 and SHA-256 of an entry, computed by decompressing it in memory: the content is never written to disk. You document a suspicious archive without materialising it.

Declared vs recomputed CRC

Entry by entry, the CRC-32 recorded in the archive is compared with the recomputed one: the container's internal integrity, with the same logic as the acquisition hash of an E01 image.

Every date, with its source

A ZIP carries the DOS time (2-second resolution, local time with no time zone) and often also the NTFS or Unix extra fields in UTC. Probatio shows both and flags when they disagree.

The name as a byte sequence

UTF-8, CP437 and CP850 readings side by side, the raw bytes in hex and the state of bit 11, which declares whether the name is UTF-8. Probatio doesn't pick a single reading for you.

“Will Windows Explorer open this archive?”

A diagnosis with measured, not guessed, thresholds: from 260 characters in an entry name Explorer rejects the archive; between 257 and 259 it opens it empty, with no error at all. Plus unsupported methods, AES-256, reserved characters, undeclared UTF-8 and symbolic links, with the real error codes.

Split and nested archives

Byte-split sets (.7z.001, .zip.001…) open as if they were whole, starting from any piece and without rebuilding them on disk; a missing piece is named. An archive inside an archive can be browsed up to three levels deep.

Nothing disappears silently

Whatever is not extracted — a name the system rejects, an out-of-range compression ratio, a path escaping the destination — appears in a list, with the reason next to each entry. An encrypted entry is called encrypted, not dismissed as a broken archive.

Isolated parsing

Zip slip, reserved device names, NTFS alternate streams and decompression bombs, including non-recursive ones, are caught. Reading happens in a separate subprocess with time limits; on macOS also without network and without the ability to start other programs.

PDF report

Landscape report with the hash of the examined archive, the list of entries, the findings and the compatibility diagnosis.

Step by step

How it works

  1. Drop an archive: the format is recognised from its bytes, not its extension.
  2. Browse the column tree (size, compression, dates) and select an entry for hashes, CRC, dates, name readings, preview and YARA.
  3. Extract only what you need, files or folders: next to the archive, at the same level or in a folder of your choice. The final path is shown before extracting.
  4. Generate the PDF report.
FAQ

Frequently asked questions

Why does Windows say “the compressed folder is invalid” on a valid archive?
File Explorer has its own limits: it rejects entry names of 260 characters or more, handles no method other than Stored and Deflate nor AES encryption, and between 257 and 259 characters shows the archive empty without errors. The Archives module tells which of these cases applies, entry by entry.
Can I hash a file inside a ZIP without extracting it?
Yes: the entry is decompressed in memory and its MD5, SHA-1 and SHA-256 are computed without writing it to disk. For very large entries it is better to extract it and use the Hash module.
Does it open RAR files?
No, for licensing rather than technical reasons: the only available implementation derives from the UnRAR source, with a licence incompatible with Probatio. The file is recognised and the app says so explicitly, instead of making it look corrupted.
Does extracting an archive alter the evidence?
The archive is not modified, but materialising thousands of files changes the disk and puts potentially hostile content on the filesystem. That is why Probatio lets you document content and hashes without extracting, and extract only the entries you need.