BigHugger
sk Skill · mukul975

analyzing-windows-shellbag-artifacts

Analyze Windows Shellbag (BagMRU) registry artifacts with SBECmd and Shellbags Explorer to reconstruct folder browsing activity and prove user interaction with directories, including removable media and network shares, even after the folders are deleted. Use when reconstructing a user's folder access history or proving access to a since-removed directory in DFIR work.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
powershellbagmrunetwork-sharesPythondfirfolder-accessuser-activityshellbags-explorersbecmdwindows-registryremovable-mediashellbags
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python