The exploitation of Windows hibernation files to “look back in time” and uncover compelling evidence is crucial to digital forensics practitioners. Hibernation Recon not only supports active memory reconstruction from Windows XP, Vista, 7, 8/8.1, and 10 hibernation files, but also extracts massive volumes of information from the multiple types (and levels) of slack space that often exist within them. Additional features of Hibernation Recon include the automatic recovery of valuable NTFS metadata and parallel processing of multiple hibernation files. Digital forensics practitioners cannot afford to analyze electronic evidence without extracting maximum value from Windows hibernation files.


If Hibernation Recon is run without a license, it will run in “Free Mode” and provide core functionality. If Hibernation Recon is licensed, it will run in “Professional Mode” with full functionality enabled. More information can be found in Arsenal Recon’s FAQ.


Active Memory


Reconstruction of active memory from Windows XP, Vista, 7, 8/8.1, and 10 hibernation files


Hibernation Slack


Only tool that properly supports extraction of multiple types and levels of hibernation slack


NTFS Metadata


Automatic recovery of valuable NTFS metadata



  • Windows XP, Vista, 7, 8/8.1, and 10 hibernation file support
  • Active memory reconstruction
  • Identification and extraction of multiple levels of slack space
  • Brute force decompression of partially overwritten slack
  • Segregation of extracted slack based on particular hibernation
  • Proper handling of legacy hibernation data found in modern hibernation files
  • NTFS metadata recovery with human-friendly decoding
  • Parallel processing of multiple hibernation files


  • HIBERNATION RECON requires Microsoft Windows 8 or later.