ShellBags Deleted Folders: Proving a Folder Existed
Use ShellBags to show a deleted or renamed folder existed: read its path, embedded times and MFT entry and sequence, then confirm with the $MFT and USN.
Use ShellBags to show a deleted or renamed folder existed: read its path, embedded times and MFT entry and sequence, then confirm with the $MFT and USN.
How ShellBags record browsing inside ZIP files and other archives in Explorer, what the compressed folder items contain, and how to interpret archive paths.
Four user-activity artifacts compared: what ShellBags, LNK files, Jump Lists and RecentDocs each record, what they prove, their timestamps and blind spots.
Step-by-step: parse UsrClass.dat and NTUSER.DAT in your browser, read the tree and timeline, triage flagged folders, export CSV or JSON. Nothing uploaded.
What ShellBags are, where Windows stores them, what BagMRU and shell items prove, how to read their timestamps and where the artifact misleads analysts.