From ForensicsWiki
Revision as of 16:11, 13 August 2010 by Joachim Metz (Talk | contribs) (External Links)

Jump to: navigation, search

Microsoft Windows Shortcut Files

File Format

  • TODO


  • Three date/time stamps which are a snapshot of the target date/time stamps before it was last opened;
  • The size of the target when it was last accessed;
  • Serial number of the volume where the target was stored;
    • Useful for correlating a USB drive or other removable media (if you can get the volume serial number off it) to a particular user or system.
  • Network volume share name;
  • Read-only, hidden, system, volume label, encryption, sparse, compressed, offline and several other target attributes;
  • MAC address of the host computer (sometimes).

External Links