ShellBag Forensics

Поділитися
Вставка
  • Опубліковано 31 гру 2017
  • As a continuation of the "Introduction to Windows Forensics" series, this video introduces ShellBags. Have you ever customized the folder view settings within any folder in Windows Explorer? This could be anything from changing the sort order, to changing the view type from icons, to list view, to detail view, changing what columns are visible, or even changing the size of the window. If so, when you’ve returned to that folder at a later date, you’ve probably seen that the customizations remained. That information is stored within “ShellBags”.
    Why do we care about folder view settings, and how could this possibly be of forensic interest? Watch this video and find out!
    ** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. **
    Introduction to Windows Forensics:
    • Introduction to Window...
    ShellBags Forensics: Addressing a Misconception:
    www.4n6k.com/2013/12/shellbags...
    Forensic Analysis of Windows ShellBags:
    www.magnetforensics.com/compu...
    Windows ShellBag Parser:
    www.tzworks.net/prototype_pag...
    shellbags.py:
    github.com/williballenthin/sh...
    ShellBags Explorer:
    ericzimmerman.github.io/
    Internet Evidence Finder (IEF):
    www.magnetforensics.com/magne...
    #Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics

КОМЕНТАРІ • 23

  • @bernhardstosik4625
    @bernhardstosik4625 4 роки тому +2

    14:07

  • @scottsabo9070
    @scottsabo9070 6 років тому +3

    I really enjoyed this video. Thanks for sharing. I wish I had more time in the day to watch all of your videos and develop my forensic skills.

  • @matthewgrady1579
    @matthewgrady1579 6 років тому +4

    Great video! Good explanations and examples given. Keep it up. This is great content!

  • @moretwocome21
    @moretwocome21 5 років тому +1

    @13Cubed the command line freak! Another great video sir! Thank you! Theae are helping me prepare for my interviews!

  • @mcfawknuts
    @mcfawknuts 3 роки тому +2

    Great content. Thank you for this.

  • @johnnyguitar4391

    great video introducing shell bags

  • @JaKeizBrick33
    @JaKeizBrick33 3 роки тому +1

    Your channel is amazing.

  • @ellis6067
    @ellis6067 5 років тому +2

    Well done! I sense some Rob Lee knowledge influence :)

  • @SecureTheWorld
    @SecureTheWorld 5 років тому

    Excellent video. Thanks a lot.

  • @decimator8278
    @decimator8278 3 роки тому +1

    This vid was so helpful!

  • @davidmacfarlane8228
    @davidmacfarlane8228 3 роки тому +4

    I've been slowly working through the 13cubed archive and this is excellent!! I've read a couple of times (including on Magnet Forensics blog) that Shellbags are located within HKCR when clearly you are showing them within HKCU here... I'm confused!! 🤔

  • @lucyboi3968
    @lucyboi3968 Рік тому

    @13cubed Regarding the shellbag explorer demo, how long will the USB data be stored in that shellbag? Will it not be overwritten over time?

  • @SecureTheWorld
    @SecureTheWorld 5 років тому

    could you please share the software you use to prepare and edit your videos ! thanks a lot for the awesome tutorial as usual!

  • @othmanb4222
    @othmanb4222 3 роки тому

    Hello. I liked the content a lot however I'm not a native english speaker and I'm still looking for an exact definition of a shell bag. Is a shell bag:

  • @ahmedmohsen3046
    @ahmedmohsen3046 2 роки тому +1

    What if I create new windows or upgrade current window version are shellbags will be exist for old windows

  • @arthifrox
    @arthifrox 4 роки тому +1

    please consider about font size of presentation.