Windows LNK文件工件分析

原名:analyzing-windows-lnk-files-for-artifacts

解析 Windows LNK 快捷方式文件,提取目标路径和 MAC 时间戳。

分类
开发提效
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
2
收藏
0
发布
2026-08-18
更新
2026-08-20
TRACE 评分
4.2 / 5

内容概览

- When reconstructing user file access history from Windows shortcut files - For tracking accessed files, network shares, and removable media - During investigations to prove a user opened specific documents - When correlating file access with other timeline artifacts - For identifying accessed paths on remote systems or USB devices - Access to LNK files from forensic image (Recent, Desktop, Quick Launch) - LECmd (Eric Zimmerman), python-lnk, or LnkParser for analysis - Understanding of LNK file structure (Shell Link Binary format) - Knowledge of LNK file locations on Windows systems - Forensic workstation with analysis tools installed Concept Description --------- ------------- Shell Link (.lnk) Windows shortcut file format containing target path, timestamps, and metadata Target timestamps Creation, modification, and access times of the file the shortcut points to Volume serial number U…

查看 SKILL 详情