LNK与跳转列表分析

原名:analyzing-lnk-file-and-jump-list-artifacts

使用 LECmd 分析 Windows LNK 快捷方式文件和 Jump List 记录。

分类
学习研究
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
0
收藏
0
发布
2026-08-18
更新
2026-08-18
TRACE 评分
3.4 / 5

内容概览

Windows LNK (shortcut) files and Jump Lists are critical forensic artifacts that provide evidence of file access, program execution, and user behavior. LNK files are created automatically when a user opens a file through Windows Explorer or the Open/Save dialog, storing metadata about the target file including its original path, timestamps, volume serial number, NetBIOS name, and MAC address of the host system. Jump Lists, introduced in Windows 7, extend this by maintaining per-application lists of recently and frequently accessed files. These artifacts persist even after the target files are deleted, making them invaluable for establishing that a user accessed specific files at specific times. - When investigating security incidents that require analyzing lnk file and jump list artifacts - When building detection rules or threat hunting queries for this domain - When SOC analysts need s…

查看 SKILL 详情