Shellbag Forensics
As a continuation of the "Introduction to Windows Forensics" series, this video introduces Shellbags. Have you ever customized the folder view settings within any folder in Windows Explorer? This could be anything from changing the sort order, to changing the view type from icons, to list view, to detail view, changing what columns are visible, or even changing the size of the window. If so, when you’ve returned to that folder at a later date, you’ve probably seen that the customizations remained. That information is stored within “Shellbags”.
Why do we care about folder view settings, and how could this possibly be of forensic interest? Watch this video and find out!
*** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. ***
Introduction to Windows Forensics:
https://www.youtube.com/watch?v=VYROU-ZwZX8
Shellbags Forensics: Addressing a Misconception:
http://www.4n6k.com/2013/12/shellbags-forensics-addressing.html
Forensic Analysis of Windows Shellbags:
https://www.magnetforensics.com/computer-forensics/forensic-analysis-of-windows-shellbags/
Windows ShellBag Parser:
https://www.tzworks.net/prototype_page.php?proto_id=14
Shellbags.py:
https://github.com/williballenthin/shellbags
ShellBags Explorer:
https://ericzimmerman.github.io/
Internet Evidence Finder (IEF):
https://www.magnetforensics.com/magnet-ief/
#Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics
Видео Shellbag Forensics канала 13Cubed
Why do we care about folder view settings, and how could this possibly be of forensic interest? Watch this video and find out!
*** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. ***
Introduction to Windows Forensics:
https://www.youtube.com/watch?v=VYROU-ZwZX8
Shellbags Forensics: Addressing a Misconception:
http://www.4n6k.com/2013/12/shellbags-forensics-addressing.html
Forensic Analysis of Windows Shellbags:
https://www.magnetforensics.com/computer-forensics/forensic-analysis-of-windows-shellbags/
Windows ShellBag Parser:
https://www.tzworks.net/prototype_page.php?proto_id=14
Shellbags.py:
https://github.com/williballenthin/shellbags
ShellBags Explorer:
https://ericzimmerman.github.io/
Internet Evidence Finder (IEF):
https://www.magnetforensics.com/magnet-ief/
#Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics
Видео Shellbag Forensics канала 13Cubed
Показать
Комментарии отсутствуют
Информация о видео
Другие видео канала
![LNK Files and Jump Lists](https://i.ytimg.com/vi/wu4-nREmzGM/default.jpg)
![Introduction to Windows Forensics](https://i.ytimg.com/vi/VYROU-ZwZX8/default.jpg)
![Email Header Analysis and Forensic Investigation](https://i.ytimg.com/vi/nK5QpGSBR8c/default.jpg)
![Windows SRUM Forensics](https://i.ytimg.com/vi/Uw8n4_o-ETM/default.jpg)
![](https://i.ytimg.com/vi/bKeqfR8RCTM/default.jpg)
![Digital Forensics Incident Response (DFIR) Training - Artifact Triage](https://i.ytimg.com/vi/RTtKXBLLGS0/default.jpg)
![KAPE + EZ Tools and Beyond - OSDFCon 2019 - Eric Zimmerman](https://i.ytimg.com/vi/ZCj7cbWwUOs/default.jpg)
![Episode 21: “Quick Win” files #4 - Shellbags-Part 1](https://i.ytimg.com/vi/86tzZWcQH60/default.jpg)
![Disk Imaging for Digital Forensics](https://i.ytimg.com/vi/eoscb7b-4FE/default.jpg)
![COMPUTER SCIENCE വിദ്യാർത്ഥികൾക്കുള്ള ഉപരിപഠന ചോയിസുകളും നേട്ടങ്ങളും](https://i.ytimg.com/vi/YOsP5sOSnpM/default.jpg)
![Digital Forensic Memory Analysis - Volatility](https://i.ytimg.com/vi/Cs0Gc3GtfZY/default.jpg)
![Prefetch Deep Dive](https://i.ytimg.com/vi/f4RAtR_3zcs/default.jpg)
![Digital Forensics | Davin Teo | TEDxHongKongSalon](https://i.ytimg.com/vi/Pf-JnQfAEew/default.jpg)
![DFIR in 120 seconds - Prefetch](https://i.ytimg.com/vi/LA3M3aor6Mo/default.jpg)
![](https://i.ytimg.com/vi/xvgngqHtGV8/default.jpg)
![NTFS Journal Forensics](https://i.ytimg.com/vi/1mwiShxREm8/default.jpg)
![RDP Cache Forensics](https://i.ytimg.com/vi/NnEOk5-Dstw/default.jpg)
![Computer Forensic Examinations 10 - Shellbags](https://i.ytimg.com/vi/lZlLj02FG18/default.jpg)
![Introduction to Memory Forensics](https://i.ytimg.com/vi/1PAGcPJFwbE/default.jpg)
![RDP Event Log Forensics](https://i.ytimg.com/vi/myzG11BP3Sk/default.jpg)