There are many weird and wonderful registry entries that I have yet to know about that could contain useful forensics information. One of the most recent that Iāve learnt about are theĀ shellbagĀ entries. These keys are stored in the usersĀ ntuser.datĀ file, and store the viewing settings for users folders ā e.g. the size, position and icon of … Continue reading Windows Shellbags Forensics