<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ShellBags Parser — Blog</title>
    <link>https://www.shellbagsparser.com/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Sun, 27 Sep 2026 20:44:01 GMT</lastBuildDate>
    <atom:link href="https://www.shellbagsparser.com/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>ShellBags Explorer Alternatives: SBECmd, RegRipper &amp; More</title>
      <link>https://www.shellbagsparser.com/en/blog/shellbags-explorer-alternatives</link>
      <guid isPermaLink="true">https://www.shellbagsparser.com/en/blog/shellbags-explorer-alternatives</guid>
      <description>A fair comparison of ShellBags tools: ShellBags Explorer, SBECmd, RegRipper, Velociraptor, shellbags.py, Volatility and a browser parser. Strengths, gaps.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>ShellBags Limitations and Anti-Forensics: What to Watch</title>
      <link>https://www.shellbagsparser.com/en/blog/shellbags-anti-forensics-limitations</link>
      <guid isPermaLink="true">https://www.shellbagsparser.com/en/blog/shellbags-anti-forensics-limitations</guid>
      <description>What ShellBags cannot prove, what never creates them, how cleaners like PrivaZer or CCleaner remove them, and the traces deletion and tampering leave.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>ShellBags Deleted Folders: Proving a Folder Existed</title>
      <link>https://www.shellbagsparser.com/en/blog/shellbags-deleted-folders</link>
      <guid isPermaLink="true">https://www.shellbagsparser.com/en/blog/shellbags-deleted-folders</guid>
      <description>Use ShellBags to show a deleted or renamed folder existed: read its path, embedded times and MFT entry and sequence, then confirm with the $MFT and USN.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>ShellBags and ZIP Files: Proving Archive Browsing</title>
      <link>https://www.shellbagsparser.com/en/blog/shellbags-zip-archives</link>
      <guid isPermaLink="true">https://www.shellbagsparser.com/en/blog/shellbags-zip-archives</guid>
      <description>How ShellBags record browsing inside ZIP files and other archives in Explorer, what the compressed folder items contain, and how to interpret archive paths.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>ShellBags USB Forensics: A Worked Investigation Example</title>
      <link>https://www.shellbagsparser.com/en/blog/shellbags-usb-network-share-investigation</link>
      <guid isPermaLink="true">https://www.shellbagsparser.com/en/blog/shellbags-usb-network-share-investigation</guid>
      <description>A fictional case, step by step: ShellBags show a service account browsing a ZIP toolkit, a finance share and a USB drive. What they prove, and what they do not.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>ShellBags on Windows 11, 10, 7 and XP: What Changed</title>
      <link>https://www.shellbagsparser.com/en/blog/shellbags-windows-versions</link>
      <guid isPermaLink="true">https://www.shellbagsparser.com/en/blog/shellbags-windows-versions</guid>
      <description>How ShellBags differ across Windows XP, Vista, 7, 8.1, 10 and 11: hive locations, extension block versions, new root folders and native archive support.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>ShellBags vs LNK Files, Jump Lists and RecentDocs</title>
      <link>https://www.shellbagsparser.com/en/blog/shellbags-vs-lnk-jump-lists-recentdocs</link>
      <guid isPermaLink="true">https://www.shellbagsparser.com/en/blog/shellbags-vs-lnk-jump-lists-recentdocs</guid>
      <description>Four user-activity artifacts compared: what ShellBags, LNK files, Jump Lists and RecentDocs each record, what they prove, their timestamps and blind spots.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Shell Item Format Explained: Inside a ShellBag Entry</title>
      <link>https://www.shellbagsparser.com/en/blog/shell-item-format-explained</link>
      <guid isPermaLink="true">https://www.shellbagsparser.com/en/blog/shell-item-format-explained</guid>
      <description>Byte-level walkthrough of the shell items stored in BagMRU values: class types, file entry items, the 0xBEEF0004 block, MFT references and network items.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>ShellBags Timestamps Explained: What Each Time Means</title>
      <link>https://www.shellbagsparser.com/en/blog/shellbags-timestamps-explained</link>
      <guid isPermaLink="true">https://www.shellbagsparser.com/en/blog/shellbags-timestamps-explained</guid>
      <description>Key LastWrite, MRUListEx-derived last interacted, and embedded FAT times: what each ShellBags timestamp proves, with a worked example and the common traps.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to Analyze ShellBags Online With a Browser Parser</title>
      <link>https://www.shellbagsparser.com/en/blog/analyze-shellbags-online</link>
      <guid isPermaLink="true">https://www.shellbagsparser.com/en/blog/analyze-shellbags-online</guid>
      <description>Step-by-step: parse UsrClass.dat and NTUSER.DAT in your browser, read the tree and timeline, triage flagged folders, export CSV or JSON. Nothing uploaded.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Where Are ShellBags Stored? Locations and Collection</title>
      <link>https://www.shellbagsparser.com/en/blog/where-are-shellbags-stored</link>
      <guid isPermaLink="true">https://www.shellbagsparser.com/en/blog/where-are-shellbags-stored</guid>
      <description>ShellBags registry locations in UsrClass.dat and NTUSER.DAT for Windows XP to 11, plus how to collect locked hives with their transaction logs, per user.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>ShellBags Forensics: The Complete Guide for Investigators</title>
      <link>https://www.shellbagsparser.com/en/blog/shellbags-forensics-guide</link>
      <guid isPermaLink="true">https://www.shellbagsparser.com/en/blog/shellbags-forensics-guide</guid>
      <description>What ShellBags are, where Windows stores them, what BagMRU and shell items prove, how to read their timestamps and where the artifact misleads analysts.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>