From ForensicsWiki
Revision as of 16:22, 13 August 2010 by Joachim Metz (Talk | contribs) (Metadata)

Jump to: navigation, search

Microsoft Windows Shortcut Files

File Format

  • TODO


  • MAC date and timestamps which are a snapshot of the target date and timestamps before it was last opened;
  • The Shell Item list of the target;
  • The size of the target when it was last accessed;
  • Serial number of the volume where the target was stored;
    • Useful for correlating a USB drive or other removable media (if you can get the volume serial number off it) to a particular user or system.
  • Network volume share name;
  • Read-only, hidden, system, volume label, encryption, sparse, compressed, offline and several other target attributes;
  • MAC address of the host computer (sometimes).

External Links