LZNT1 Decompress

Decode LZNT1-compressed blobs from Windows RtlCompressBuffer — NTFS files, registry hives, hibernation pages, and malware configs. Paste hex or Base64 and recover the original bytes. Runs entirely in your browser, no server, no sign-up.

Decompressed output

What this tool does

LZNT1 Decompress decodes a blob compressed with Windows' built-in LZNT1 algorithm — the format emitted by RtlCompressBuffer / RtlDecompressBuffer when called with COMPRESSION_FORMAT_LZNT1. Paste the compressed bytes as hex or Base64, pick how you want the recovered data shown (hex, plain UTF-8 text, or Base64), and the original bytes appear instantly. Everything runs locally in your browser — the blob never leaves your machine.

Where LZNT1 shows up

LZNT1 is the legacy compression scheme baked into Windows, so it turns up constantly in systems and security work:

How LZNT1 works

An LZNT1 stream is a sequence of chunks. Each chunk begins with a 16-bit little-endian header: the top bit flags whether the chunk body is compressed (otherwise it is stored verbatim), and the low 12 bits hold the body length minus one. A compressed body is split into flag groups — one flag byte followed by up to eight tokens. Each bit of the flag byte (least-significant first) marks the matching token as either a single literal byte or a 16-bit back-reference. The split between a back-reference's length and displacement fields shifts as the window fills, which is what makes LZNT1 trickier to decode than a plain LZ77 stream. This tool implements that wire format directly, so it needs no Windows API and works on any platform.

Tips

FAQ

What input formats are accepted?

Hex (the default) or Base64. Hex is forgiving — whitespace, line breaks, and an optional 0x prefix are ignored, and case doesn't matter. Base64 works with or without = padding. Output can be hex, UTF-8 text, or Base64.

Why do I get a "truncated LZNT1 stream/chunk" error?

The chunk header declares how many body bytes follow; if fewer remain (or a back-reference token is missing its second byte), the blob was cut short. Usually you copied only part of the buffer — grab the entire compressed region and try again.

Can it decompress LZNT1 data that Windows stored uncompressed?

Yes. RtlCompressBuffer emits verbatim (stored) chunks when compression wouldn't help; the chunk header's top bit marks those, and the tool copies them through unchanged. A stream mixing compressed and stored chunks decodes correctly.

Does this handle Xpress or Xpress Huffman blobs?

No — only COMPRESSION_FORMAT_LZNT1. Newer Windows features (Win10 memory compression, some hibernation formats) use LZ77/Xpress or Xpress Huffman, which are different wire formats; an LZNT1 decoder will error on them.

Is my blob uploaded anywhere?

No — decoding is pure Rust compiled to WebAssembly and runs entirely in the page, which matters when the blob comes from a sensitive forensic image or malware sample.

Developer & Automation Access

Run it from the terminal

Same engine as this page, headless — via the gizza CLI:

gizza tool lznt1-decompress "Paste the compressed blob as hex (e.g. 03b0 0041 4243) or Base64"

New to the CLI? Get gizza →

Open it by URL

Pre-fill and auto-run this tool with query parameters — the names match the API/CLI:

https://gizza.ai/tools/lznt1-decompress/?data=Paste%20the%20compressed%20blob%20as%20hex%20%28e.g.%2003b0%200041%204243%29%20or%20Base64&input_encoding=hex&output_encoding=hex

Machine-readable descriptor: tool.json — title + parameters JSON Schema for agents.