Shell Bags [In Progress] - nurit-cyber/OperatingSystemForensics GitHub Wiki
Table of Contents
Introduction
Windows Explorer tracks window position, and whenever a folder is browsed to in explorer, a note is recorded and is stored in Shell 'Bags' registry key and an MRU list.
XP - Vista: tracks folder views and icon positions in every folder
Vista+: only keeps desktop icon positions under Shell Bags\ItemPosxx values
Location
XP: NTUSER.DAT Vista+: NTUSER.DAT, USRCLASS.DAT
HKEY_CURRENT_USER\Software\Microsoft\Windows\
Shell\Bags
Shell\BagMRU
ShellNoRoam\Bags
ShellNoRoam\BagMRU
CurrentVersion\Explorer\SteamMRU
CurrentVersion\Explorer\RecentDocs
HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\
Shell\Bags
Shell\BagMRU
\BagMRU
Each folder contains a different set of information for certain drives and locations.
- 0: localhost
- 1: \[IP Address]
- 2: \Hood
- 3: \Win7-1
- 3\0: C$
- 3\0\0: music