Forensic Mode finds records the log no longer has
Every EVTX block starts with the same eight bytes and is exactly 65,536 bytes long. Forensic Mode uses that structure to walk a file, disk image or entire drive byte by byte, ignoring the file header and finding blocks the normal reader cannot reach. It can recover records left in free space after a log was deleted or rotated, and read a log with a destroyed header. On a test file with its header wiped, it recovered 23,367 events from 316 blocks in about a second and a half. Duplicate blocks are recognised and shown once, so a drive scan does not show the same events three times. In the program, it is in the File menu as 'Deep scan for lost events'.