Developer Builds Tool to Recover Deleted SQL Server Rows Without Prior Audit Setup
A developer created LogCarver, an open-source tool that recovers deleted or modified SQL Server rows by reading the database's built-in transaction log via the undocumented fn_dblog function, requiring no prior configuration such as Change Data Capture or Audit. The tool reconstructs full INSERT, UPDATE, and DELETE histories and generates reviewable Undo and Replay SQL statements. During real-world testing, two significant bugs were uncovered: Heap table operations were silently excluded due to an incomplete context filter, and tables with extra indexes broke the internal record-matching logic. Both issues were fixed by querying SQL Server's sys.indexes for exact storage metadata rather than relying on pattern guessing, and the fixes were validated across SQL Server 2016, 2019, and 2022. LogCarver is MIT-licensed and publicly available on GitHub, though support for data types like decimal and money, as well as TRUNCATE TABLE handling, remains a work in progress.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in