{
  "id": 11120838,
  "title": "How I Recovered Deleted SQL Server Rows Without Ever Enabling CDC or Audit",
  "url": "https://urgent.news/2026/10/01/how-i-recovered-deleted-sql-server-rows-without-ever-enabling-cdc-or",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-01T06:03:54.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/caiderek/how-i-recovered-deleted-sql-server-rows-without-ever-enabling-cdc-or-audit-d84"
  },
  "original_language": "en",
  "account": "The article recounts how the author developed LogCarver, a tool to recover deleted SQL Server rows without enabling Change Data Capture, Change Tracking, or Audit. Most recovery tools assume these features were enabled beforehand, but in small and mid-sized businesses, this is rarely the case. SQL Server's transaction log already records every change, but the fn_dblog function that reads it is rarely used and its row image byte layout isn't published. The author reverse-engineered the format from actual output, byte by byte, leading to the creation of LogCarver. Two bugs were discovered after releasing the tool: one affecting Heap tables and another caused by extra indexes. Debugging the issue required connecting to a live database and examining fn_dblog's raw output. The fix involved querying sys.indexes for the table's storage structure and building the exact AllocUnitName from that, instead of guessing string patterns. All three bugs were only found by testing on actual SQL Server instances, not by relying on documentation or intuition. The current limitations of LogCarver include handling specific data types and TRUNCATE TABLE operations.",
  "summary": "Most data-recovery tools assume you turned on Change Data Capture, Change Tracking, or Audit before the incident happened. In the real world — small and mid-sized companies running their own SQL Server — almost nobody does that. By the time someone notices bad data, it's already too late to turn those features on retroactively. SQL Server's transaction log already records every change. The…",
  "key_points": [
    "Author created LogCarver to recover deleted SQL Server rows without CDC, Change Tracking, or Audit.",
    "Reverse-engineered fndblog function format from actual output, byte by byte.",
    "Discovered two bugs after release; fixed by querying sys.indexes for storage structure."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}