ZIP discovery in binary data
Find Embedded ZIP Files in Firmware and Binary Images
Useful ZIP data does not always arrive as a .zip file. Firmware images, disk images and proprietary binary containers can carry ZIP records at non-zero offsets. DotFix ZIP Forensics scans the input for those records and turns readable results into a browsable file tree.
When a forensic ZIP scan is useful
Firmware and update packages
Look for embedded ZIP records in a .bin image or another device-specific container, even when there is no ordinary ZIP filename.
Disk images and raw dumps
Search a binary input for ZIP structures instead of assuming that a standard archive directory is present at the beginning of the file.
Damaged containers
Continue scanning after unrelated or corrupt bytes to find later readable ZIP entries.
Unknown extensions
Investigate a file by its internal structure rather than trusting a missing or misleading extension.
From an unfamiliar image to readable content
- Open the firmware or binary image or cd/dvd image in the DotFix Zip Forensics.
- The software will automatically run a forensic scan to detect ZIP entries throughout the input file.
- Browse the reconstructed tree and review the available filenames and metadata.
- Preview supported configuration files, logs, code, documents or images in the application.
- Search the discovered content and extract only the items needed for your analysis with a licensed edition.

What this scan does and does not claim
The forensic scanner looks for ZIP structures and helps investigate the ZIP content it can read. It is not a general firmware unpacker, file-system parser or decryption tool. A scan cannot reveal data that is absent, strongly encrypted without the known password, or stored in an unsupported non-ZIP container.
Known-password access: Supported ZipCrypto and WinZip AES ZIP entries can be opened when you supply the correct password. The software does not guess or crack unknown passwords.
See the method in context
The version 26.5 investigation walkthrough shows a BZip2-compressed configuration recovered from a firmware image. The version 26 technical overview describes forensic scan mode and automatic format detection. After a scan, the same preview and content-search workflow helps identify useful files without bulk extraction. For a broader tour of firmware and archive scenarios, see ZIP Forensics in practice.
Check whether your image contains ZIP data
The free trial can scan, browse, search and preview discovered content. Saving and extraction are disabled until you choose a license.