ShellBag Forensics
Вставка
- Опубліковано 31 гру 2017
- As a continuation of the "Introduction to Windows Forensics" series, this video introduces ShellBags. Have you ever customized the folder view settings within any folder in Windows Explorer? This could be anything from changing the sort order, to changing the view type from icons, to list view, to detail view, changing what columns are visible, or even changing the size of the window. If so, when you’ve returned to that folder at a later date, you’ve probably seen that the customizations remained. That information is stored within “ShellBags”.
Why do we care about folder view settings, and how could this possibly be of forensic interest? Watch this video and find out!
** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. **
Introduction to Windows Forensics:
• Introduction to Window...
ShellBags Forensics: Addressing a Misconception:
www.4n6k.com/2013/12/shellbags...
Forensic Analysis of Windows ShellBags:
www.magnetforensics.com/compu...
Windows ShellBag Parser:
www.tzworks.net/prototype_pag...
shellbags.py:
github.com/williballenthin/sh...
ShellBags Explorer:
ericzimmerman.github.io/
Internet Evidence Finder (IEF):
www.magnetforensics.com/magne...
#Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics
14:07
I really enjoyed this video. Thanks for sharing. I wish I had more time in the day to watch all of your videos and develop my forensic skills.
Great video! Good explanations and examples given. Keep it up. This is great content!
@13Cubed the command line freak! Another great video sir! Thank you! Theae are helping me prepare for my interviews!
Great content. Thank you for this.
great video introducing shell bags
Your channel is amazing.
Well done! I sense some Rob Lee knowledge influence :)
Excellent video. Thanks a lot.
This vid was so helpful!
I've been slowly working through the 13cubed archive and this is excellent!! I've read a couple of times (including on Magnet Forensics blog) that Shellbags are located within HKCR when clearly you are showing them within HKCU here... I'm confused!! 🤔
@13cubed Regarding the shellbag explorer demo, how long will the USB data be stored in that shellbag? Will it not be overwritten over time?
could you please share the software you use to prepare and edit your videos ! thanks a lot for the awesome tutorial as usual!
Hello. I liked the content a lot however I'm not a native english speaker and I'm still looking for an exact definition of a shell bag. Is a shell bag:
What if I create new windows or upgrade current window version are shellbags will be exist for old windows
please consider about font size of presentation.