Inspect Raw Archive Structure Using 7-Zip

This guide demonstrates how to inspect the internal, low-level structure of archives using 7-Zip's built-in command-line diagnostic features. By leveraging specific switches such as -slt, -t#, and verbose logging, you can bypass high-level file views to examine internal block headers, compression streams, physical offsets, and nested parser data for forensics or data recovery.

Enable Technical Listing Mode (-slt)

The default listing command (7z l archive.zip) only shows standard metadata such as filenames, dates, and compressed sizes. To view the internal structural properties of an archive, use the -slt (Show Technical Information) switch:

7z l -slt archive.7z

This switch outputs comprehensive diagnostic details for the container itself and each individual block, including:

  • Path and Physical Size: Location on disk and total byte span.
  • Headers Size: The space allocated strictly for header metadata.
  • Method: The exact compression and filter algorithms (e.g., LZMA2:24, BCJ, AES-256).
  • Characteristics: Structural flags denoting multi-threading blocks, solid blocks, or header encryption.
  • Offset: Physical byte offsets where streams begin within the container.

Inspect Parser Chains with Diagnostic Mode (-t#)

7-Zip normally detects archive wrappers automatically (such as extracting a .tar.gz down to its final payload). When diagnosing corrupted files, split volumes, or non-standard containers, you can use the -t# switch to disable automatic container resolution and enter the diagnostic parser mode.

Run the listing command targeting the # parser:

7z l -t# container.bin

This mode treats the file as a raw container, allowing you to:

  1. Identify embedded payload signatures that regular extraction ignores.
  2. View nested streams numbered sequentially (e.g., 0, 1, [PAD]), showing unparsed raw components.
  3. Determine if an archive contains trailing unallocated data, overlay data, or mismatched header lengths.

To inspect a specific sub-stream identified by the diagnostic parser, reference its index directly:

7z l -t# -slt container.bin

Increase Log Verbosity with Diagnostic Output (-bb3)

To observe how 7-Zip processes internal chunks and block boundaries in real-time, combine standard commands with the -bb (Set Output Log Level) parameter set to level 3:

7z t -bb3 archive.zip

When running an integrity test (t), level 3 output prints detailed line-by-line operational states. It displays stream openings, unpack sizes per chunk, CRC verifications for individual headers, and failure points without extracting data to disk.

Combined Command for Deep Inspection

For deep forensic analysis or corrupted archive triage, combine these switches to isolate the raw structure into a clean, parseable text output:

7z l -slt -t# -ba archive.iso > structure_dump.txt
  • -slt: Generates raw key-value structural data.
  • -t#: Forces the low-level raw parser.
  • -ba: Suppresses standard console headers and banner text, leaving strictly archive data.