Inspect Raw Archive Structure Using 7-Zip
This guide demonstrates how to inspect the internal, low-level
structure of archives using 7-Zip's built-in command-line diagnostic
features. By leveraging specific switches such as -slt,
-t#, and verbose logging, you can bypass high-level file
views to examine internal block headers, compression streams, physical
offsets, and nested parser data for forensics or data recovery.
Enable Technical Listing
Mode (-slt)
The default listing command (7z l archive.zip) only
shows standard metadata such as filenames, dates, and compressed sizes.
To view the internal structural properties of an archive, use the
-slt (Show Technical Information) switch:
7z l -slt archive.7zThis switch outputs comprehensive diagnostic details for the container itself and each individual block, including:
- Path and Physical Size: Location on disk and total byte span.
- Headers Size: The space allocated strictly for header metadata.
- Method: The exact compression and filter algorithms (e.g., LZMA2:24, BCJ, AES-256).
- Characteristics: Structural flags denoting multi-threading blocks, solid blocks, or header encryption.
- Offset: Physical byte offsets where streams begin within the container.
Inspect Parser
Chains with Diagnostic Mode (-t#)
7-Zip normally detects archive wrappers automatically (such as
extracting a .tar.gz down to its final payload). When
diagnosing corrupted files, split volumes, or non-standard containers,
you can use the -t# switch to disable automatic container
resolution and enter the diagnostic parser mode.
Run the listing command targeting the # parser:
7z l -t# container.binThis mode treats the file as a raw container, allowing you to:
- Identify embedded payload signatures that regular extraction ignores.
- View nested streams numbered sequentially (e.g.,
0,1,[PAD]), showing unparsed raw components. - Determine if an archive contains trailing unallocated data, overlay data, or mismatched header lengths.
To inspect a specific sub-stream identified by the diagnostic parser, reference its index directly:
7z l -t# -slt container.binIncrease Log
Verbosity with Diagnostic Output (-bb3)
To observe how 7-Zip processes internal chunks and block boundaries
in real-time, combine standard commands with the -bb (Set
Output Log Level) parameter set to level 3:
7z t -bb3 archive.zipWhen running an integrity test (t), level 3 output
prints detailed line-by-line operational states. It displays stream
openings, unpack sizes per chunk, CRC verifications for individual
headers, and failure points without extracting data to disk.
Combined Command for Deep Inspection
For deep forensic analysis or corrupted archive triage, combine these switches to isolate the raw structure into a clean, parseable text output:
7z l -slt -t# -ba archive.iso > structure_dump.txt-slt: Generates raw key-value structural data.-t#: Forces the low-level raw parser.-ba: Suppresses standard console headers and banner text, leaving strictly archive data.