analyzing-windows-shellbag-artifacts
CommunityReconstruct folder access history from Shellbags.
Data & Analytics#dfir#windows-registry#user-activity#shellbags#sbecmd#shellbags-explorer#folder-access
AuthorAxxxxxxaaann
Version1.0.0
Installs0
System Documentation
What problem does it solve?
Shellbag registry artifacts capture user folder navigation and view settings, enabling investigators to reconstruct directory access history even after items have been deleted or moved.
Core Features & Use Cases
- Parse BagMRU and Bags entries from NTUSER.DAT and UsrClass.dat to reconstruct folder access histories.
- Identify access to network shares and removable media to correlate with incidents.
- Integrate SBECmd outputs with ShellBags Explorer timelines for evidence-based investigations.
Quick Start
Run SBECmd to export shellbag data from the target hives, then analyze the CSV to generate a folder-access timeline.
Dependency Matrix
Required Modules
Registryregipy
Components
scriptsreferencesassets
💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: analyzing-windows-shellbag-artifacts Download link: https://github.com/Axxxxxxaaann/KAIRI-Skills/archive/main.zip#analyzing-windows-shellbag-artifacts Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.