Rock YouTube channel with real views, likes and subscribers
Get Free YouTube Subscribers, Views and Likes

ShellBag Forensics

Follow
13Cubed

As a continuation of the "Introduction to Windows Forensics" series, this video introduces ShellBags. Have you ever customized the folder view settings within any folder in Windows Explorer? This could be anything from changing the sort order, to changing the view type from icons, to list view, to detail view, changing what columns are visible, or even changing the size of the window. If so, when you’ve returned to that folder at a later date, you’ve probably seen that the customizations remained. That information is stored within “ShellBags”.

Why do we care about folder view settings, and how could this possibly be of forensic interest? Watch this video and find out!

** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. **

Introduction to Windows Forensics:
   • Introduction to Windows Forensics  

ShellBags Forensics: Addressing a Misconception:
http://www.4n6k.com/2013/12/shellbags...

Forensic Analysis of Windows ShellBags:
https://www.magnetforensics.com/compu...

Windows ShellBag Parser:
https://www.tzworks.net/prototype_pag...

shellbags.py:
https://github.com/williballenthin/sh...

ShellBags Explorer:
https://ericzimmerman.github.io/

Internet Evidence Finder (IEF):
https://www.magnetforensics.com/magne...

#Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics

posted by fortejarnt