RAID and server data recovery in Hamilton
For Hamilton, complex storage incidents require the hardware set and its configuration to stay together. The aim is to reconstruct a coherent data state before trying to restore a service.
- Case intake Gather the storage details, failure chronology, prior actions, encryption information and priority files.
- Technical diagnosis Determine the physical and logical risks and select an acquisition approach suited to the medium.
- Source protection Use protected images where possible to rebuild arrays, volumes and file structures outside the source.
- Result validation Test representative priority data, describe incomplete results and prepare readable files on healthy storage.
Preserve the set before replacing a member
A second warning during a rebuild can leave several plausible but incompatible states. Bay position, serial number, event time and controller messages should be recorded before disks are moved.
Each readable member is acquired independently so reconstruction does not depend on the array writing new parity.
For New Zealand NAS and server cases, bay order, controller messages, encryption and service dependencies are recorded before members are moved.
A camera card or USB drive with missing files
Stop recording and writing before the device recycles space that may still hold the data.
SD, microSD and USB media used for cameras, drones, audio recorders and field equipment may appear unformatted, empty or intermittently connected.
Keep the adaptor and note the device, recording mode, file type and approximate session. Stable media is best captured as a complete image before repair or file reconstruction, while a heating or disconnecting device should not be subjected to repeated reader tests.
- Remove the media from use and engage its write-protect tab if available.
- Do not format it or save recovered files back onto it.
- Record the camera or recorder model and the relevant capture period.
What to preserve with the device
Keep the original enclosure, power supply and adapters with an external drive. For NAS, RAID or recorders, label every disk by bay and retain configuration screens and alert logs.
Do not initialise a replacement disk, accept a repair prompt or save recovered files back to the source. Those actions can overwrite metadata needed for reconstruction.
Where stable reading remains possible, sectors are copied with limited retries to protected working storage; reconstruction proceeds away from the original medium.
A surveillance recorder missing the required footage
Recorder disks, channel metadata and the local clock all contribute to a usable video result.
An NVR may lose access after disk errors, a reset or accidental setup, while continuous recording can progressively overwrite an older incident.
Preserve the recorder model and bay order and note the camera, displayed time zone and exact period sought. Any recovered sequence should be tested for playback, continuity and correct channel and time, with gaps reported rather than concealed in a total file size.
- Stop recording before the target period leaves the retention window.
- Photograph the disk order, camera labels and displayed date and time.
- Set the smallest practical incident window for each relevant channel.
Validate content, not just directory names
Documents, photographs, archives and video containers require representative opening tests. Expected date ranges and folder relationships help expose incomplete files that still carry plausible names.
The handover identifies usable, partial and missing material without turning detection into a recovery guarantee.
Folder structure, dates and chosen formats are compared with the brief so damaged content, missing periods and unavailable keys remain explicit.
The stages of a defensible data recovery
A very slow drive should remain powered off during regional or inter-island transport.
Unstable heads and unreadable sectors can worsen each time a normal backup retries.
Document the first delay and any power event, then capture responsive areas with bounded retries. Analyse volume structures and essential folders on the image.
Clicking, scraping, or recurring recalibration means power should remain off. Mechanical stability needs evaluation before another region of the disk is read.
- Stop a copy if the computer freezes or the drive repeatedly disconnects
- Record SMART warnings and the location of observed read errors
- Do not run a surface scan or repair tool that writes to the drive
- Open priority samples and describe every material limit.
A practical brief for the diagnostic assessment
A virtual disk is inseparable from its descriptors, extents, snapshots, and datastore allocation.
Replacement VMs and snapshot consolidation may consume blocks or metadata needed by the missing guest.
Preserve configuration first, rebuild dependencies on copies, and test essential guest files or databases. A boot screen alone is not sufficient validation.
Record datastore extents, hypervisor version, and snapshot parent identifiers. One incorrect dependency can present an older guest while hiding the latest application state.
- Do not create a new VM or datastore on the affected storage
- Preserve configuration files, descriptors and snapshot names
- List critical guest data and the last known working state
- For arrays: bay order, alerts and encryption.
- Maker, model, capacity and connection.
- Precise warning, noise or detection behaviour.
Data recovery laboratory — Hard Drive Recovery in an ISO 5 Clean Room
For a case sent from Hamilton, the diagnostic assessment first identifies the storage technology and the affected layer. That evidence selects the suitable mechanical, electronic, logical or system-level laboratory process.
If controller access has failed, flash packages may be read directly. Scrambling, interleaving, error correction and block mapping are reconstructed through electronic and logical work, without exposing hard-drive platters.
Stop new writes after deletion or formatting
For Hamilton, synchronisation, indexing, updates and normal use are stopped because new writes can replace surviving content or metadata. File-system type, event time, encryption and tools already used are documented before reconstruction on an image.
The source is not repaired in place. A sector-level or device-appropriate acquisition is created where condition permits, and every read limitation remains logged for later reconstruction.
File systems, containers, arrays or application layers are analysed on a separate working copy. This prevents an incorrect assumption from changing the only available source.
The result is checked by opening priority documents, media, archives or application data and comparing them with known dates and structures.
FAQ
Frequently asked questions
Is one cable change safe on an external drive?
Only when there is no abnormal noise, smell, heat or history of impact. Stop if detection remains unstable.
Why image a drive before repairing its file system?
An image preserves readable sectors and lets logical work proceed without writing repairs to the only source.
Why might a recovered video file have no playable ending?
A recording may not have been finalised before failure, or later writes may have replaced part of it. Container repair and content recovery are separate checks.
Does exporting other footage help test a damaged NVR?
It also keeps the recorder writing and reading. When overwrite risk or disk instability exists, preserve the target window before attempting routine exports. Note channels, clock offset and the recorder's export format.
Should an extremely slow hard drive be copied with a normal backup program?
No. Uncontrolled retries can worsen the condition. A limited, logged sector image provides a safer basis for recovery work.
Should an orphaned virtual disk be attached directly to a new VM?
Not from the original storage. Mounting can write metadata; secure dependencies and a read-only image before testing an attachment. Map datastore extents and snapshot parents before attachment.
Diagnostic assessment
Unsure about a storage device or fault?
Datastrophe assesses the risk before any recovery attempt and points you towards the safest next step.