Shell Bags [In Progress] - nurit-cyber/OperatingSystemForensics GitHub Wiki

Table of Contents

Introduction

Windows Explorer tracks window position, and whenever a folder is browsed to in explorer, a note is recorded and is stored in Shell 'Bags' registry key and an MRU list.

XP - Vista: tracks folder views and icon positions in every folder
Vista+: only keeps desktop icon positions under Shell Bags\ItemPosxx values

Location

XP: NTUSER.DAT Vista+: NTUSER.DAT, USRCLASS.DAT

HKEY_CURRENT_USER\Software\Microsoft\Windows\

Shell\Bags
Shell\BagMRU
ShellNoRoam\Bags
ShellNoRoam\BagMRU
CurrentVersion\Explorer\SteamMRU
CurrentVersion\Explorer\RecentDocs

HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\

Shell\Bags
Shell\BagMRU

\BagMRU

Each folder contains a different set of information for certain drives and locations.

- 0: localhost
- 1: \[IP Address]
- 2: \Hood
- 3: \Win7-1
- 3\0: C$
- 3\0\0: music