Call us — 01223 655015
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Trust, Practice & Honest Limits · Names Are a Separate Question

File Names Live in the Filesystem, Not in the Files, So They Are Recovered Separately

Her enquiry asks about the outcome rather than the process, and it is the right question. A network storage drive that corrupted, where a previous recovery returned "just numbers" so she "didn't have a clue what was what" across a terabyte of material — and she wants to know whether names can be returned this time. The answer is knowable in advance, and it depends on something quite specific rather than on effort or price.

MediaHard drive from a network storage unit, approximately 1TB occupied — prior recovery returning content without original names or folder structure
Reported situationNetwork storage drive suffering corruption · prior recovery performed by another provider · content returned without original file names · content returned without folder structure · approximately 1TB of material rendered unidentifiable · recovery with original naming sought
Fault classPrior recovery performed by signature carving without filesystem structures — naming absent by method rather than by omission; structural reconstruction feasibility to be established
Equipment usedNaming feasibility established at assessment before any figure was quoted · drive imaged write-blocked at the block level before any interpretation · filesystem structures located and interpreted with their duplicate copies in preference to carving · directory tree reconstructed and matched against carved content where structures were partial · deliverable arrangement confirmed with the owner in advance

The decode: where names come from, and how to know in advance

Why names are not in the files: they are in the index. A file's content carries no record of what it is called — the name and its position in a folder are held in the filesystem's own structures.

What follows from that: the two are recovered by different means. Content can be found by recognising the shape of a file, and names cannot be found that way at all.

Why her previous recovery returned numbers: it carved. Where the filesystem cannot be read, content is located by scanning for recognisable file openings, and each one is given a sequential name because nothing else is available.

Why that is a method rather than a shortcoming: it is the fallback. A provider unable to read the structures did the only thing left, and the numbered output is what that produces.

What determines whether names can be returned: whether the structures survive. If the filesystem's records can be read or reconstructed, the tree comes back with names, folders and dates intact.

Why that is often possible even after apparent corruption: filesystems keep duplicates. Copies of the key records sit elsewhere on the volume and frequently survive damage to the primary ones.

Why a network storage drive adds a step: the format is the appliance's own. Its filesystem is not one a desktop system implements, and a provider treating it as a plain disc may find no structures to read — which alone can explain a numbered result.

Why that is a hopeful reading of her situation: the structures may never have been attempted. Content carved from an appliance volume, without interpreting the appliance's own format, is exactly what produces a terabyte of numbers.

Why the question is answerable before committing: the assessment establishes it. Whether the directory tree can be reconstructed is determined from the image, and can be stated before any figure is agreed.

What is worth agreeing in advance either way: the shape of the delivery. Where names are only partly recoverable, sorting by type and date makes a large recovery usable rather than merely complete.

On the bench

Naming feasibility was established at assessment before any figure was quoted — file content carrying no record of its own name, which is held with folder position in the filesystem's structures, so carving by recognised file openings can only assign sequential names. Recoverable naming therefore depends on whether those structures survive or can be rebuilt from duplicate copies. Appliance volumes use formats desktop systems do not implement. Structures were interpreted in preference to carving.

The outcome

Naming feasibility established before any figure was quoted, structures interpreted in preference to carving, and the delivery arrangement confirmed in advance. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: names live in the filesystem, not in the files. Numbers mean the structures were not read — and on an appliance drive, they may simply never have been attempted.

Asking whether names and folders come back

Ask before agreeing to anything, because it's answerable at assessment rather than afterwards. Names aren't stored in files — they live in the filesystem's own records alongside folder position, so content found by recognising file shapes can only be numbered sequentially. Whether names return depends on those records surviving or being rebuildable from their duplicate copies. If the drive came from a network appliance, its format isn't one desktop systems read, which alone can explain a numbered result.

Last recovery came back as numbered files?
Ask about naming first — call Cambridge Data Recovery on 01223 655015; feasibility established at assessment, structures interpreted in preference to carving, delivery arrangement agreed in advance.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.