壳袋遗踪解析
原名:analyzing-windows-shellbag-artifacts
使用 SBECmd 分析 Windows Shellbag (BagMRU) 注册表工件。
- 分类
- 学习研究
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 0
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-20
- TRACE 评分
- 3.6 / 5
内容概览
Shellbags are Windows registry artifacts that track how users interact with folders through Windows Explorer, storing view settings such as icon size, window position, sort order, and view mode. From a forensic perspective, Shellbags provide definitive evidence of folder access -- even folders that no longer exist on the system. When a user browses to a folder via Windows Explorer, the Open/Save dialog, or the Control Panel, a Shellbag entry is created or updated in the user's registry hive. These entries persist after folder deletion, drive disconnection, and even across user profile resets, making them invaluable for proving that a user navigated to specific directories on local drives, USB devices, network shares, or zip archives. - When investigating security incidents that require analyzing windows shellbag artifacts - When building detection rules or threat hunting queries for this…