ShellBag Forensics

Поделиться
HTML-код
  • Опубликовано: 4 фев 2025
  • As a continuation of the "Introduction to Windows Forensics" series, this video introduces ShellBags. Have you ever customized the folder view settings within any folder in Windows Explorer? This could be anything from changing the sort order, to changing the view type from icons, to list view, to detail view, changing what columns are visible, or even changing the size of the window. If so, when you’ve returned to that folder at a later date, you’ve probably seen that the customizations remained. That information is stored within “ShellBags”.
    Why do we care about folder view settings, and how could this possibly be of forensic interest? Watch this video and find out!
    ** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. **
    Introduction to Windows Forensics:
    • Introduction to Window...
    ShellBags Forensics: Addressing a Misconception:
    www.4n6k.com/20...
    Forensic Analysis of Windows ShellBags:
    www.magnetfore...
    Windows ShellBag Parser:
    www.tzworks.ne...
    shellbags.py:
    github.com/wil...
    ShellBags Explorer:
    ericzimmerman....
    Internet Evidence Finder (IEF):
    www.magnetfore...
    #Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics

Комментарии • 26

  • @scottsabo9070
    @scottsabo9070 6 лет назад +3

    I really enjoyed this video. Thanks for sharing. I wish I had more time in the day to watch all of your videos and develop my forensic skills.

  • @bernhardstosik4625
    @bernhardstosik4625 4 года назад +2

    14:07 minutes full of learnings - thanks, great.

  • @moretwocome21
    @moretwocome21 6 лет назад +1

    @13Cubed the command line freak! Another great video sir! Thank you! Theae are helping me prepare for my interviews!

  • @matthewgrady1579
    @matthewgrady1579 7 лет назад +4

    Great video! Good explanations and examples given. Keep it up. This is great content!

  • @johnnyguitar4391
    @johnnyguitar4391 Год назад

    great video introducing shell bags

  • @ellis6067
    @ellis6067 6 лет назад +2

    Well done! I sense some Rob Lee knowledge influence :)

  • @davidmacfarlane8228
    @davidmacfarlane8228 4 года назад +4

    I've been slowly working through the 13cubed archive and this is excellent!! I've read a couple of times (including on Magnet Forensics blog) that Shellbags are located within HKCR when clearly you are showing them within HKCU here... I'm confused!! 🤔

    • @13Cubed
      @13Cubed  4 года назад

      This article will help: www.lifewire.com/hkey-classes-root-2625899
      Quoting from it: "However, because the HKEY_CLASSES_ROOT hive is actually combined data found in both the HKEY_LOCAL_MACHINE hive (HKEY_LOCAL_MACHINE\Software\Classes) and the HKEY_CURRENT_USER hive (HKEY_CURRENT_USER\Software\Classes), it also contains user-specific information as well. Even though that's the case, the HKEY_CLASSES_ROOT is still able to be browsed by any and all users."
      So, UsrClass.dat (one of the locations containing Shellbags [in addition to NTUSER.DAT]) plugs in to HKCU\Software\Classes, and HKCU\Software\Classes is part of HKCR.

    • @davidmacfarlane8228
      @davidmacfarlane8228 4 года назад

      Thanks again, that's really helpful. One other thing I wanted to know was whether it was possible to use Shellbag Explorer to examine a disk image? I tried to load offline hives from artefacts extracted from FTK imager but with no success.

  • @JaKeizBrick33
    @JaKeizBrick33 4 года назад +1

    Your channel is amazing.

  • @decimator8278
    @decimator8278 4 года назад +1

    This vid was so helpful!

  • @lucyboi3968
    @lucyboi3968 2 года назад

    @13cubed Regarding the shellbag explorer demo, how long will the USB data be stored in that shellbag? Will it not be overwritten over time?

    • @13Cubed
      @13Cubed  2 года назад

      They can be removed by privacy cleaners, or manually, but otherwise those bag entries are persistent and do not expire or become overwritten.

  • @ahmedmohsen3046
    @ahmedmohsen3046 2 года назад +1

    What if I create new windows or upgrade current window version are shellbags will be exist for old windows

    • @13Cubed
      @13Cubed  2 года назад +1

      They should still persist after the upgrade/feature update, but the timestamps may be affected. See this: df-stream.com/2019/10/shellbags-windows-10-feature-updates/

  • @othmanb4222
    @othmanb4222 3 года назад

    Hello. I liked the content a lot however I'm not a native english speaker and I'm still looking for an exact definition of a shell bag. Is a shell bag:
    1 - a subkey.
    2 - The values stored in a subkey.
    3 - A subkey and its values.
    4 - A subkey, its values and its children keys?
    That would help me a lot.

  • @lollychan666
    @lollychan666 4 месяца назад

    how to disable shellbags recording logs?

  • @SecureTheWorld
    @SecureTheWorld 6 лет назад

    Excellent video. Thanks a lot.

  • @arthifrox
    @arthifrox 4 года назад +1

    please consider about font size of presentation.

    • @13Cubed
      @13Cubed  4 года назад

      All later videos have much easier to read fonts. This was recorded quite a while ago.

  • @SecureTheWorld
    @SecureTheWorld 5 лет назад

    could you please share the software you use to prepare and edit your videos ! thanks a lot for the awesome tutorial as usual!

    • @13Cubed
      @13Cubed  5 лет назад

      Thanks - ScreenFlow and Final Cut Pro X

    • @SecureTheWorld
      @SecureTheWorld 5 лет назад +1

      13Cubed i really appreciate your efforts you do and making this knowledge easily accessible to others!

  • @thextomxriddlex
    @thextomxriddlex 6 месяцев назад

    Lmao that introduction 😂

  • @quaidoralious4181
    @quaidoralious4181 4 месяца назад

    I know a few shellbags