Shell Item Artifact Attributes
“Recent Docs” Shortcut Files (.lnk)
Location
Windows 10 Recent Doc changes
LeCMD.exe and lp.exe
- LNK file analysis and parsing be
LNK File Data Structure
Win 7 - Win 10 JumpLists
Automatic Destinations
Location
- C:\Users(Profile)\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations
Custom Destinations
Location
- C:\Users(Profile)\AppData\Roaming\Microsoft\Windows\Recent\CustomeDestinations
AppIDs
Shellbags
Tracking Folder/Directory Usage Win 7-10
Location
- Explorer = USERCLASS.DAT\Local setting\Software\Microsoft\Windows\Shell\ Bags OR BagMRU - Desktop - NTUSER.DAT\Software\Microsoft\Windows\Shell\Bags OR BagMRU
Shellbags - Based on Windows Explorer
- Example: Setting the window size, changing file viewing option, looking at thumbnails, sorting options
Parsing Win7 - Win10 Shellbags / What do Shellbags consist of
Shellbags Analysis Key items
Purpose of USB Device Forensics
Removable Device Info
User Information & Activity w/ USB Device
30 days of activity stored in Registry - USB & USBSTOR Keys
Mass Storage Device (MSC)
*** USB Device Types
Picture Transfer Protocol (PTP)
*** USB Device Types
Examples
- Cameras (images/videos), scanners, printers, smartphone, & tablets
Media Transfer Protocol (MTP)
*** USB Device Types
Examples
- MP3 players, cameras, smartphones, & tablets
Evidence of File Opening (USB)
Location
- C:\Users(Username)\AppData\Local\Tamp\WPDNSE{GUID}
WPDNSE Folder - MTP Devices Win7/8
Location
- C:\Users(Username)\AppData\Local\Tamp\WPDNSE{FolderGUID}
USBSTOR - MSC Devices (Removable)
Location
- SYSTEM\CuurentControlSet\Enum\USBSTOR
MSC, PTP, and MTP USB Enumeration
Locations
- SYSTEM\CuurentControlSet\Enum\USB
Discover Volume name for MSC, MTP, PTP
Locations
- SOFTWARE\Microsoft\Windows portable Devices\Devices
Find User that used USB
Locations
- NTUSER.DAT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints
MSC USB Device times to track