Windows Shellbags Forensics

There are many weird and wonderful registry entries that I have yet to know about that could contain useful forensics information. One of the most recent that I’ve learnt about are theĀ shellbagĀ entries. These keys are stored in the usersĀ ntuser.datĀ file, and store the viewing settings for users folders – e.g. the size, position and icon of … Continue reading Windows Shellbags Forensics