MultiDrive CLI reference (mdcli)

Updated

mdcli.exe runs drive backup, clone, erase, and restore without the GUI app. The installer adds the MultiDrive folder to PATH.
The portable ZIP does not: run mdcli from that folder with admin privileges. You can also open the app, click the gear menu, and choose Launch CLI.

mdcli <command> --help prints the flags for the command. The tables below list every supported command and its flags. You can also read a walkthrough with screenshots: backup, clone, erase, and restore from the command prompt.

list

mdcli list shows the list of drives on your system with their assigned Short IDs.

d1 is the boot drive. Further IDs (d2, d3, …) are the other disks. Commands also accept the System ID from that list. MultiDrive cannot overwrite the boot drive, but you can use it as a source for backup or clone.

mdcli list
Connected drives

Short ID   Drive                             Size     Boot   Serial Number      Partitions   System ID
───────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
d1         KINGSTON SNV3S1000G               932 GB    +     50026B763180E4E8   C:           SCSI\DISK&VEN_NVME&PROD_KINGSTON_SNV3S10\7&14A3EDCF&0&000000
d2         KXG50ZNV256G NVMe TOSHIBA 256GB   238 GB          384C52LZK13P                    SCSI\DISK&VEN_REALTEK&PROD_RTL9210B-CG\9&13515C40&0&000000
d3         Samsung SSD 970 EVO Plus 250GB    233 GB          S4EUNC0N206725Y    D: E:        SCSI\DISK&VEN_NVME&PROD_SAMSUNG_SSD_970\5&2B04FDD7&0&000000
d4         SanDisk pSSD                      119 GB          00f3176b3          F:           USBSTOR\DISK&VEN_SANDISK&PROD_EXTREME_PRO&REV_0\1531367961F3&0

backup

Writes a drive, or part of it, to a RAW, ZIP, or ZSTD file. Syntax: mdcli backup [source] [target] [options]

OptionDefaultDescription
-y, --yesSkips prompts by automatically confirming with 'yes' to all questions
-b, --byte_offset <BYTE_OFFSET>0The starting byte offset on the source drive
-c, --byte_count <BYTE_COUNT>How many bytes to back up
-z, --zipCompress a target backup file to ZIP format on-the-fly (compression level: 2)
-a, --zstdCompress a target backup file to ZSTD format on-the-fly (compression level: 1)
-p, --split <SPLIT_SIZE>0Divide a target backup file by <SPLIT_SIZE> into partial file segments
-q, --hash <HASH_TYPE>NoneHash to calculate for the integrity check: MD5, SHA1, SHA256, or SHA512
-s, --source <SOURCE>Source drive, instead of the positional argument
-t, --target <TARGET>Target file, instead of the positional argument
-u, --share-user <SHARE_USER>Username for network share authentication
-w, --share-pass <SHARE_PASS>Password for network share authentication

Published examples use the suffixes M, G, and T (500M, 2G, 1T).

# Back up Drive #1 to a RAW file
mdcli backup d1 E:\backups\backup.raw

# Back up Drive #1 to a ZIP file and verify it with SHA256
mdcli backup d1 E:\backups\backup.zip --hash sha256

# Back up Drive #2 to a ZIP file, naming source and target with flags
mdcli backup -s d2 -t E:\backups\backup.zip --zip

# Back up the Samsung SSD by its System ID instead of its Short ID
mdcli backup "SCSI\DISK&VEN_NVME&PROD_SAMSUNG_SSD_970\5&2B04FDD7&0&000000" E:\backups\samsung.raw

# Back up 10 GB of Drive #1 from offset 1 MB, as a ZIP split into 2 GB files
mdcli backup d1 E:\backups\backup.zip -b 1M -c 10G --zip --split 2G

# Back up Drive #2 to a network share as ZSTD (Zstandard compression)
mdcli backup -s d2 -t "\\nas\share\backup.zst" --zstd --share-user DOMAIN\user --share-pass <password>

Scheduling: automated backup with Task Scheduler.

clone

Clones one drive to another. Partial cloning is supported.

Syntax: mdcli clone [source] [target] [options]

OptionDefaultDescription
-y, --yesSkips prompts by automatically confirming with 'yes' to all questions
-b, --byte_offset <BYTE_OFFSET>0The starting byte offset for both the source and target drives
-c, --byte_count <BYTE_COUNT>How many bytes to clone
-q, --hash <HASH_TYPE>NoneHash to calculate for the integrity check: MD5, SHA1, SHA256, or SHA512
-m, --mountMount the target drive's partitions in Windows when the task finishes
-s, --source <SOURCE>Source drive, instead of the positional argument
-t, --target <TARGET>Target drive, instead of the positional argument
# Clone Drive #1 to Drive #3
mdcli clone d1 d3

# Same clone, with source and target passed as flags
mdcli clone -s d1 -t d3

# Clone 100 GB from Drive #3, starting at 500 MB, onto Drive #4, then mount it
mdcli clone d3 d4 -b 500M -c 100G --mount

# Clone 1 TB from Drive #3, starting at 120 GB, onto Drive #4, and calculate SHA1
mdcli clone -s d3 -t d4 -b 120G -c 1T --hash SHA1

# Clone the Samsung SSD onto the Kingston SSD, using their System IDs instead of their Short IDs
mdcli clone "SCSI\DISK&VEN_NVME&PROD_SAMSUNG_SSD_970\5&2B04FDD7&0&000000" "SCSI\DISK&VEN_REALTEK&PROD_RTL9210B-CG\9&13515C40&0&000000

erase

One overwrite pass. Default pattern is 00.

Syntax: mdcli erase [target] [options]

OptionDefaultDescription
-y, --yesSkips prompts by automatically confirming with 'yes' to all questions
-b, --byte_offset <BYTE_OFFSET>0The starting byte offset on the target drive
-c, --byte_count <BYTE_COUNT>How many target bytes to erase
-p, --pattern <PATTERN>00HEX byte pattern to write
-m, --mountMount the target drive's partitions in Windows when the task finishes
-t, --target <TARGET>Target drive, instead of the positional argument
-f, --format <FILESYSTEM>After a full-disk erase, format as exFAT or NTFS. Ignored if --byte_offset or --byte_count is set
# Erase Drive #3 with the FF byte pattern
mdcli erase -t d3 --pattern FF

# Erase 30 GB of Drive #3 from offset 1 GB with the 9A7B pattern
mdcli erase d3 -p 9A7B -b 1G -c 30G

# Erase the Samsung SSD by its System ID instead of its Short ID
mdcli erase "SCSI\DISK&VEN_NVME&PROD_SAMSUNG_SSD_970\5&2B04FDD7&0&000000" --pattern FF

See the erase command used in a script: how to automatically wipe drives.

restore

Restores a RAW, ZIP, or ZST file to a drive, or to part of one.

Syntax: mdcli restore [source] [target] [options]

Automatically finds and ingests split RAW/ZIP files with the following extensions:

  • zip.001, zip.002 ... zip.999, zip.1000, zip.1001...
  • zip, z01, z02 ... z99, z100, z101...
  • raw.001, raw.002 ... raw.999, raw.1000, raw.1001
OptionDefaultDescription
-y, --yesSkips prompts by automatically confirming with 'yes' to all questions
-b, --byte_offset <BYTE_OFFSET>0The starting byte offset of the target drive, to which the restore task will start writing the source file
-c, --byte_count <BYTE_COUNT>The number of bytes of the target drive to overwrite
-s, --source <SOURCE>Alternative way to specify a backup file to restore
-t, --target <TARGET>Alternative way to specify a drive to which bytes from the source file are written
-z, --zipDecompress bytes from the source ZIP file on-the-fly
-a, --zstdDecompress bytes from the source ZSTD file on-the-fly
-q, --hash <HASH_TYPE>NoneHash to calculate for the integrity check: MD5, SHA1, SHA256, or SHA512
-m, --mountMount the target drive's partitions in Windows when the task finishes
-u, --share-user <SHARE_USER>Username for network share authentication
-w, --share-pass <SHARE_PASS>Password for network share authentication
# Restore a RAW backup to Drive #3
mdcli restore E:\folder\backup.raw d3

# Restore a ZIP backup to Drive #3, starting at offset 1 GB
mdcli restore E:\folder\backup.zip d3 -b 1G

# Restore a ZST backup to Drive #3
mdcli restore E:\folder\backup.zst d3

# Restore 1 TB of a ZIP backup to Drive #3 from offset 1 GB, and calculate SHA512
mdcli restore -s E:\folder\backup.zip -t d3 -b 1G -c 1T -q sha512

# Restore a RAW backup to Drive #3 and mount it when finished
mdcli restore -s E:\folder\backup.raw -t d3 --mount

# Restore a ZIP backup from a network share
mdcli restore "\10.0.0.3\my dir\backup.zip" d3 --share-user corp\operator --share-pass P@ssw0rd!

# Restore a ZIP backup file onto the Samsung SSD, addressed by its System ID instead of its Short ID
mdcli restore E:\folder\backup.zip "SCSI\DISK&VEN_NVME&PROD_SAMSUNG_SSD_970\5&2B04FDD7&0&000000"

GUI restore: restore a drive from backup.

Author

Vitaliy Mokosiy, CTO at Atola Technology

Vitaliy Mokosiy

CTO at Atola Technology

18 years of building software and hardware systems for HDDs/SSDs and file systems. Expert in data recovery and digital forensics.
Leads engineering at Atola Technology, whose forensic imagers are used by DFIR labs across the globe.