Unrar Command to View Archive Host OS

When inspecting a RAR archive, determining the operating system used to create it provides valuable technical and forensic details. The unrar utility does not reveal this information in standard listing mode, but appending the technical modifier t to the list commands allows you to view detailed metadata. This guide explains how to use the lt and vt commands in unrar to inspect the host OS of the archive creator.

The Technical Information Switch: lt and vt

To view the creator's host operating system, use the technical list command lt (list technical information) or vt (verbosely list technical information).

In the unrar command syntax, the standard l and v commands list files in a concise tabular format. Adding the t parameter instructs unrar to display an extended multi-line block of technical metadata for each file inside the archive, which includes the Host OS entry.

How to Run the Command

Open your terminal or command prompt and run the following command:

unrar lt archive_name.rar

Alternatively, you can use the verbose variant:

unrar vt archive_name.rar

Understanding the Output

Executing either command prints detailed parameters for every item contained in the archive. Within each entry's metadata block, look for the Host OS line:

Details: RAR 5

Name: document.txt
Type: File
Target size: 1024
Packed size: 450
Ratio: 43%
mtime: 2023-10-15 14:22:10
Attributes: -rw-r--r--
Host OS: Unix
Compression: RAR 5.0(v50) -m3 -md=32M

Common values displayed under the Host OS field include:

  • Windows: The archive was compressed on a Microsoft Windows environment.
  • Unix: The archive was compressed on Linux, macOS, BSD, or another Unix-like system.
  • MS-DOS or OS/2: Found on legacy archives created on older platforms.