{
    "mode": "man",
    "parameter": "ntfsclone",
    "section": "8",
    "url": "https://www.chedong.com/phpMan.php/man/ntfsclone/8/json",
    "generated": "2026-10-06T11:29:58Z",
    "synopsis": "ntfsclone [OPTIONS] SOURCE\nntfsclone --save-image [OPTIONS] SOURCE\nntfsclone --restore-image [OPTIONS] SOURCE\nntfsclone --metadata [OPTIONS] SOURCE",
    "sections": {
        "NAME": {
            "content": "ntfsclone - Efficiently clone, image, restore or rescue an NTFS\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "ntfsclone [OPTIONS] SOURCE\nntfsclone --save-image [OPTIONS] SOURCE\nntfsclone --restore-image [OPTIONS] SOURCE\nntfsclone --metadata [OPTIONS] SOURCE\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "ntfsclone  will  efficiently clone (copy, save, backup, restore) or rescue an NTFS filesystem\nto a sparse file, image, device (partition) or standard output.   It  works  at  disk  sector\nlevel and copies only the used data. Unused disk space becomes zero (cloning to sparse file),\nencoded  with  control  codes  (saving in special image format), left unchanged (cloning to a\ndisk/partition) or filled with zeros (cloning to standard output).\n\nntfsclone can be useful to make backups, an exact snapshot of an NTFS filesystem and  restore\nit  later  on, or for developers to test NTFS read/write functionality, troubleshoot/investi‐\ngate users' issues using the clone without the risk of destroying the original filesystem.\n\nThe clone, if not using the special image format, is an  exact  copy  of  the  original  NTFS\nfilesystem  from  sector  to  sector  thus it can be also mounted just like the original NTFS\nfilesystem.  For example if you clone to a file and the kernel has loopback device  and  NTFS\nsupport then the file can be mounted as\n\nmount -t ntfs -o loop ntfsclone.img /mnt/ntfsclone\n\n",
            "subsections": [
                {
                    "name": "Windows Cloning",
                    "content": "If  you want to copy, move or restore a system or boot partition to another computer, or to a\ndifferent disk or partition (e.g. hda1->hda2, hda1->hdb1 or to a different disk  sector  off‐\nset) then you will need to take extra care.\n\nUsually,  Windows will not be able to boot, unless you copy, move or restore NTFS to the same\npartition which starts at the same sector on the same type  of  disk  having  the  same  BIOS\nlegacy cylinder setting as the original partition and disk had.\n\nThe ntfsclone utility guarantees to make an exact copy of NTFS but it won't deal with booting\nissues.  This  is  by  design: ntfsclone is a filesystem, not system utility. Its aim is only\nNTFS cloning, not Windows cloning. Hereby ntfsclone can be used as a very fast  and  reliable\nbuild block for Windows cloning but itself it's not enough.\n"
                },
                {
                    "name": "Sparse Files",
                    "content": "A  file  is  sparse if it has unallocated blocks (holes). The reported size of such files are\nalways higher than the disk space consumed by them.  The du command can tell  the  real  disk\nspace  used by a sparse file.  The holes are always read as zeros. All major Linux filesystem\nlike, ext2, ext3, reiserfs, Reiser4, JFS and XFS, supports sparse files but for  example  the\nISO 9600 CD-ROM filesystem doesn't.\n"
                },
                {
                    "name": "Handling Large Sparse Files",
                    "content": "As  of  today  Linux  provides inadequate support for managing (tar, cp, gzip, gunzip, bzip2,\nbunzip2, cat, etc) large sparse files.  The only main Linux filesystem having support for ef‐\nficient sparse file handling is XFS by the XFSIOCGETBMAPX ioctl(2).  However  none  of  the\ncommon  utilities  supports it.  This means when you tar, cp, gzip, bzip2, etc a large sparse\nfile they will always read the entire file, even if you use the \"sparse support\" options.\n\nbzip2(1) compresses large sparse files much better than gzip(1) but  it  does  so  also  much\nslower.  Moreover neither of them handles large sparse files efficiently during uncompression\nfrom disk space usage point of view.\n\nAt present the most efficient way, both speed and  space-wise,  to  compress  and  uncompress\nlarge  sparse  files by common tools would be using tar(1) with the options -S (handle sparse\nfiles \"efficiently\") and -j (filter the archive through bzip2). Although tar still reads  and\nanalyses  the entire file, it doesn't pass on the large data blocks having only zeros to fil‐\nters and it also avoids writing large amount of zeros to the disk needlessly. But  since  tar\ncan't  create  an archive from the standard input, you can't do this in-place by just reading\nntfsclone standard output. Even more sadly, using the -S option  results  serious  data  loss\nsince  the  end  of  2004 and the GNU tar maintainers didn't release fixed versions until the\npresent day.\n"
                },
                {
                    "name": "The Special Image Format",
                    "content": "It's also possible, actually it's recommended, to save an NTFS filesystem to a special  image\nformat.   Instead of representing unallocated blocks as holes, they are encoded using control\ncodes. Thus, the image saves space without requiring sparse file support. The image format is\nideal for streaming filesystem images over the network and similar, and can be used as a  re‐\nplacement  for  Ghost  or Partition Image if it is combined with other tools. The downside is\nthat you can't mount the image directly, you need to restore it first.\n\nTo save an image using the special image format, use the -s or the  --save-image  option.  To\nrestore  an image, use the -r or the --restore-image option. Note that you can restore images\nfrom standard input by using '-' as the SOURCE file.\n"
                },
                {
                    "name": "Metadata-only Cloning",
                    "content": "One of the features of ntfsclone is that, it can also save only the NTFS metadata  using  the\noption  -m or --metadata and the clone still will be mountable. In this case all non-metadata\nfile content will be lost and reading them back will result always zeros.\n\nThe metadata-only image can be compressed very well, usually to not more  than  1-8  MB  thus\nit's easy to transfer for investigation, troubleshooting.\n\nIn  this  mode  of ntfsclone, NONE of the user's data is saved, including the resident user's\ndata embedded into metadata. All is filled with zeros.  Moreover  all  the  file  timestamps,\ndeleted  and unused spaces inside the metadata are filled with zeros. Thus this mode is inap‐\npropriate for example for forensic analyses.  This mode may be combined with --save-image  to\ncreate a special image format file instead of a sparse file.\n\nPlease  note, filenames are not wiped out. They might contain sensitive information, so think\ntwice before sending such an image to anybody.\n"
                }
            ]
        },
        "OPTIONS": {
            "content": "Below is a summary of all the options that ntfsclone accepts.  Nearly all  options  have  two\nequivalent names.  The short name is preceded by - and the long name is preceded by -- .  Any\nsingle  letter  options,  that don't take an argument, can be combined into a single command,\ne.g.  -fv is equivalent to -f -v .  Long named options can be abbreviated to any unique  pre‐\nfix of their name.\n",
            "subsections": [
                {
                    "name": "-o --output",
                    "content": "Clone  NTFS  to the non-existent FILE.  If FILE is '-' then clone to the standard out‐\nput. This option cannot be used for creating a partition, use --overwrite for  an  ex‐\nisting partition.\n",
                    "flag": "-o",
                    "long": "--output"
                },
                {
                    "name": "-O --overwrite",
                    "content": "Clone NTFS to FILE, which can be an existing partition or a regular file which will be\noverwritten if it exists.\n",
                    "flag": "-O",
                    "long": "--overwrite"
                },
                {
                    "name": "-s --save-image",
                    "content": "Save  to the special image format. This is the most efficient way space and speed-wise\nif imaging is done to the standard output, e.g. for image compression,  encryption  or\nstreaming through a network.\n",
                    "flag": "-s",
                    "long": "--save-image"
                },
                {
                    "name": "-r --restore-image",
                    "content": "Restore  from  the special image format specified by SOURCE argument. If the SOURCE is\n'-' then the image is read from the standard input.\n",
                    "flag": "-r",
                    "long": "--restore-image"
                },
                {
                    "name": "-n --no-action",
                    "content": "Test the consistency of a saved image by simulating its restoring without writing any‐\nthing. The NTFS data contained in the image is not tested.  The option --restore-image\nmust also be present, and the options --output and --overwrite must be omitted.\n",
                    "flag": "-n",
                    "long": "--no-action"
                },
                {
                    "name": "--rescue",
                    "content": "Ignore disk read errors so disks having bad sectors, e.g. dying disks, can be  rescued\nthe  most efficiently way, with minimal stress on them. Ntfsclone works at the lowest,\nsector level in this mode too thus more data can be rescued.  The contents of the  un‐\nreadable  sectors  are  filled  by character '?' and the beginning of such sectors are\nmarked by \"BadSectoR\\0\".\n",
                    "long": "--rescue"
                },
                {
                    "name": "-m --metadata",
                    "content": "Clone ONLY METADATA (for NTFS experts). Only cloning to a (sparse)  file  is  allowed,\nunless  used the option --save-image is also used.  You can't metadata-only clone to a\ndevice.\n",
                    "flag": "-m",
                    "long": "--metadata"
                },
                {
                    "name": "--ignore-fs-check",
                    "content": "Ignore the result of the filesystem consistency check. This option is  allowed  to  be\nused  only  with  the  --metadata  option, for the safety of user's data. The clusters\nwhich cause the inconsistency are saved too.\n",
                    "long": "--ignore-fs-check"
                },
                {
                    "name": "-t --preserve-timestamps",
                    "content": "Do not wipe the timestamps, to be used only with the --metadata option.\n",
                    "flag": "-t",
                    "long": "--preserve-timestamps"
                },
                {
                    "name": "--full-logfile",
                    "content": "Include the Windows log file in the copy. This is only useful for extracting metadata,\nsaving or cloning a file system which was not properly unmounted from Windows.\n\n--new-serial, or\n",
                    "long": "--full-logfile"
                },
                {
                    "name": "--new-half-serial",
                    "content": "Set a new random serial number to the clone. The serial number is a 64 bit number used\nto identify the device during the mounting process, so it has to be changed to  enable\nthe original file system and the clone to be mounted at the same time on the same com‐\nputer.\n\nThe option --new-half-serial only changes the upper part of the serial number, keeping\nthe lower part which is used by Windows unchanged.\n\nThe  options  --new-serial  and --new-half-serial can only be used when cloning a file\nsystem of restoring from an image.\n\nThe serial number is not the volume UUID used by Windows to locate  files  which  have\nbeen moved to another volume.\n\n",
                    "long": "--new-half-serial"
                },
                {
                    "name": "-f --force",
                    "content": "Forces ntfsclone to proceed if the filesystem is marked \"dirty\" for consistency check.\n",
                    "flag": "-f",
                    "long": "--force"
                },
                {
                    "name": "-q --quiet",
                    "content": "Do not display any progress-bars during operation.\n",
                    "flag": "-q",
                    "long": "--quiet"
                },
                {
                    "name": "-h --help",
                    "content": "Show a list of options with a brief description of each one.\n",
                    "flag": "-h",
                    "long": "--help"
                }
            ]
        },
        "EXIT CODES": {
            "content": "The exit code is 0 on success, non-zero otherwise.\n",
            "subsections": []
        },
        "EXAMPLES": {
            "content": "Clone NTFS on /dev/hda1 to /dev/hdc1:\n\nntfsclone --overwrite /dev/hdc1 /dev/hda1\n\nSave an NTFS to a file in the special image format:\n\nntfsclone --save-image --output backup.img /dev/hda1\n\nRestore an NTFS from a special image file to its original partition:\n\nntfsclone --restore-image --overwrite /dev/hda1 backup.img\n\nSave an NTFS into a compressed image file:\n\nntfsclone --save-image -o - /dev/hda1 | gzip -c > backup.img.gz\n\nRestore an NTFS volume from a compressed image file:\n\ngunzip -c backup.img.gz | \\\nntfsclone --restore-image --overwrite /dev/hda1 -\n\nBackup  an NTFS volume to a remote host, using ssh. Please note, that ssh may ask for a pass‐\nword!\n\nntfsclone --save-image --output - /dev/hda1 | \\\ngzip -c | ssh host 'cat > backup.img.gz'\n\nRestore an NTFS volume from a remote host via ssh. Please note, that ssh may ask for a  pass‐\nword!\n\nssh host 'cat backup.img.gz' | gunzip -c | \\\nntfsclone --restore-image --overwrite /dev/hda1 -\n\nStream an image file from a web server and restore it to a partition:\n\nwget -qO - http://server/backup.img | \\\nntfsclone --restore-image --overwrite /dev/hda1 -\n\nClone an NTFS volume to a non-existent file:\n\nntfsclone --output ntfs-clone.img /dev/hda1\n\nPack  NTFS  metadata for NTFS experts. Please note that bzip2 runs very long but results usu‐\nally at least 10 times smaller archives than gzip on a sparse file.\n\nntfsclone --metadata --output ntfsmeta.img /dev/hda1\nbzip2 ntfsmeta.img\n\nOr, outputting to a compressed image :\nntfsclone -mst --output - /dev/hda1 | bzip2 > ntfsmeta.bz2\n\nUnpacking NTFS metadata into a sparse file:\n\nbunzip2 -c ntfsmeta.img.bz2 | \\\ncp --sparse=always /proc/self/fd/0 ntfsmeta.img\n\n",
            "subsections": []
        },
        "KNOWN ISSUES": {
            "content": "There are no known problems with ntfsclone.  If you think  you  have  found  a  problem  then\nplease send an email describing it to the development team: ntfs-3g-devel@lists.sf.net\n\nSometimes  it  might appear ntfsclone froze if the clone is on ReiserFS and even CTRL-C won't\nstop it. This is not a bug in ntfsclone, however it's due to ReiserFS being extremely ineffi‐\ncient creating large sparse files and not handling signals during this operation. This  Reis‐\nerFS problem was improved in kernel 2.4.22.  XFS, JFS and ext3 don't have this problem.\n",
            "subsections": []
        },
        "AUTHORS": {
            "content": "ntfsclone  was  written  by Szabolcs Szakacsits with contributions from Per Olofsson (special\nimage format support) and Anton Altaparmakov.  It was ported to ntfs-3g by Erik  Larsson  and\nJean-Pierre Andre.\n",
            "subsections": []
        },
        "AVAILABILITY": {
            "content": "ntfsclone is part of the ntfs-3g package and is available at:\nhttps://github.com/tuxera/ntfs-3g/wiki/\n",
            "subsections": []
        },
        "SEE ALSO": {
            "content": "ntfsresize(8) ntfsprogs(8) xfscopy(8) debugreiserfs(8) e2image(8)\n\nntfs-3g 2022.10.3                           February 2013                               NTFSCLONE(8)",
            "subsections": []
        }
    },
    "summary": "ntfsclone - Efficiently clone, image, restore or rescue an NTFS",
    "flags": [
        {
            "flag": "-o",
            "long": "--output",
            "arg": null,
            "description": "Clone NTFS to the non-existent FILE. If FILE is '-' then clone to the standard out‐ put. This option cannot be used for creating a partition, use --overwrite for an ex‐ isting partition."
        },
        {
            "flag": "-O",
            "long": "--overwrite",
            "arg": null,
            "description": "Clone NTFS to FILE, which can be an existing partition or a regular file which will be overwritten if it exists."
        },
        {
            "flag": "-s",
            "long": "--save-image",
            "arg": null,
            "description": "Save to the special image format. This is the most efficient way space and speed-wise if imaging is done to the standard output, e.g. for image compression, encryption or streaming through a network."
        },
        {
            "flag": "-r",
            "long": "--restore-image",
            "arg": null,
            "description": "Restore from the special image format specified by SOURCE argument. If the SOURCE is '-' then the image is read from the standard input."
        },
        {
            "flag": "-n",
            "long": "--no-action",
            "arg": null,
            "description": "Test the consistency of a saved image by simulating its restoring without writing any‐ thing. The NTFS data contained in the image is not tested. The option --restore-image must also be present, and the options --output and --overwrite must be omitted."
        },
        {
            "flag": "",
            "long": "--rescue",
            "arg": null,
            "description": "Ignore disk read errors so disks having bad sectors, e.g. dying disks, can be rescued the most efficiently way, with minimal stress on them. Ntfsclone works at the lowest, sector level in this mode too thus more data can be rescued. The contents of the un‐ readable sectors are filled by character '?' and the beginning of such sectors are marked by \"BadSectoR\\0\"."
        },
        {
            "flag": "-m",
            "long": "--metadata",
            "arg": null,
            "description": "Clone ONLY METADATA (for NTFS experts). Only cloning to a (sparse) file is allowed, unless used the option --save-image is also used. You can't metadata-only clone to a device."
        },
        {
            "flag": "",
            "long": "--ignore-fs-check",
            "arg": null,
            "description": "Ignore the result of the filesystem consistency check. This option is allowed to be used only with the --metadata option, for the safety of user's data. The clusters which cause the inconsistency are saved too."
        },
        {
            "flag": "-t",
            "long": "--preserve-timestamps",
            "arg": null,
            "description": "Do not wipe the timestamps, to be used only with the --metadata option."
        },
        {
            "flag": "",
            "long": "--full-logfile",
            "arg": null,
            "description": "Include the Windows log file in the copy. This is only useful for extracting metadata, saving or cloning a file system which was not properly unmounted from Windows. --new-serial, or"
        },
        {
            "flag": "",
            "long": "--new-half-serial",
            "arg": null,
            "description": "Set a new random serial number to the clone. The serial number is a 64 bit number used to identify the device during the mounting process, so it has to be changed to enable the original file system and the clone to be mounted at the same time on the same com‐ puter. The option --new-half-serial only changes the upper part of the serial number, keeping the lower part which is used by Windows unchanged. The options --new-serial and --new-half-serial can only be used when cloning a file system of restoring from an image. The serial number is not the volume UUID used by Windows to locate files which have been moved to another volume."
        },
        {
            "flag": "-f",
            "long": "--force",
            "arg": null,
            "description": "Forces ntfsclone to proceed if the filesystem is marked \"dirty\" for consistency check."
        },
        {
            "flag": "-q",
            "long": "--quiet",
            "arg": null,
            "description": "Do not display any progress-bars during operation."
        },
        {
            "flag": "-h",
            "long": "--help",
            "arg": null,
            "description": "Show a list of options with a brief description of each one."
        }
    ],
    "examples": [
        "Clone NTFS on /dev/hda1 to /dev/hdc1:",
        "ntfsclone --overwrite /dev/hdc1 /dev/hda1",
        "Save an NTFS to a file in the special image format:",
        "ntfsclone --save-image --output backup.img /dev/hda1",
        "Restore an NTFS from a special image file to its original partition:",
        "ntfsclone --restore-image --overwrite /dev/hda1 backup.img",
        "Save an NTFS into a compressed image file:",
        "ntfsclone --save-image -o - /dev/hda1 | gzip -c > backup.img.gz",
        "Restore an NTFS volume from a compressed image file:",
        "gunzip -c backup.img.gz | \\",
        "ntfsclone --restore-image --overwrite /dev/hda1 -",
        "Backup  an NTFS volume to a remote host, using ssh. Please note, that ssh may ask for a pass‐",
        "word!",
        "ntfsclone --save-image --output - /dev/hda1 | \\",
        "gzip -c | ssh host 'cat > backup.img.gz'",
        "Restore an NTFS volume from a remote host via ssh. Please note, that ssh may ask for a  pass‐",
        "word!",
        "ssh host 'cat backup.img.gz' | gunzip -c | \\",
        "ntfsclone --restore-image --overwrite /dev/hda1 -",
        "Stream an image file from a web server and restore it to a partition:",
        "wget -qO - http://server/backup.img | \\",
        "ntfsclone --restore-image --overwrite /dev/hda1 -",
        "Clone an NTFS volume to a non-existent file:",
        "ntfsclone --output ntfs-clone.img /dev/hda1",
        "Pack  NTFS  metadata for NTFS experts. Please note that bzip2 runs very long but results usu‐",
        "ally at least 10 times smaller archives than gzip on a sparse file.",
        "ntfsclone --metadata --output ntfsmeta.img /dev/hda1",
        "bzip2 ntfsmeta.img",
        "Or, outputting to a compressed image :",
        "ntfsclone -mst --output - /dev/hda1 | bzip2 > ntfsmeta.bz2",
        "Unpacking NTFS metadata into a sparse file:",
        "bunzip2 -c ntfsmeta.img.bz2 | \\",
        "cp --sparse=always /proc/self/fd/0 ntfsmeta.img"
    ],
    "see_also": [
        {
            "name": "ntfsresize",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/ntfsresize/8/json"
        },
        {
            "name": "ntfsprogs",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/ntfsprogs/8/json"
        },
        {
            "name": "xfscopy",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/xfscopy/8/json"
        },
        {
            "name": "debugreiserfs",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/debugreiserfs/8/json"
        },
        {
            "name": "e2image",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/e2image/8/json"
        }
    ]
}