ShellBags Deleted Folders: Proving a Folder Existed
Use ShellBags to show a deleted or renamed folder existed: read its path, embedded times and MFT entry and sequence, then confirm with the $MFT and USN.
Use ShellBags to show a deleted or renamed folder existed: read its path, embedded times and MFT entry and sequence, then confirm with the $MFT and USN.
A fictional case, step by step: ShellBags show a service account browsing a ZIP toolkit, a finance share and a USB drive. What they prove, and what they do not.
Four user-activity artifacts compared: what ShellBags, LNK files, Jump Lists and RecentDocs each record, what they prove, their timestamps and blind spots.
Key LastWrite, MRUListEx-derived last interacted, and embedded FAT times: what each ShellBags timestamp proves, with a worked example and the common traps.