
educationJan 30, 202613:45pending
Course 21 - Digital Forensics: Windows Shellbags | Episode 1: Windows Shellbags: Forensic Fundamentals and Deep Dive Analysis
About this episode
In this lesson, you’ll learn about:
You can listen and download our episodes for free on more than 10 different platforms:
https://linktr.ee/cybercode_academy
- What Windows Shellbags Are and Why They Matter
- How shellbags are registry-based artifacts created by Windows Explorer to store folder view preferences.
- Why they are a powerful source of user activity evidence, even when files or folders no longer exist.
- How Shellbags Are Created and Updated
- The specific user actions that trigger shellbag updates, such as resizing windows or changing icon views.
- Why even casual folder browsing can leave long-lasting forensic traces.
- Forensic Value of Shellbags
- How shellbags persist even after folders are deleted or external/network drives are removed.
- How they enable user attribution, allowing investigators to determine which user accessed which path and when.
- Registry Locations and Data Sources
- The role of NTUSER.DAT and USRCLASS.DAT in storing shellbag data.
- The importance of the BagMRU registry key for tracking hierarchical folder navigation.
- Manual Reconstruction and Validation
- How investigators can manually “walk” BagMRU subkeys to reconstruct exact directory paths.
- Using hex and Unicode analysis to identify drive letters and folder names.
- Why manual validation is essential for evidence verification and expert testimony, even when automated tools are used.
You can listen and download our episodes for free on more than 10 different platforms:
https://linktr.ee/cybercode_academy
Get every episode summarized
Each time CyberCode Academy publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from CyberCode Academy

Course 42 - Mobile Malware Analysis Fundamentals | Episode 13: Designing and Arc...
CyberCode Academy
Sep 9, 202617:34pending

Course 42 - Mobile Malware Analysis Fundamentals | Episode 12: Dynamic Analysis...
CyberCode Academy
Sep 8, 202628:08completed

Course 42 - Mobile Malware Analysis Fundamentals | Episode 11: Dynamic Analysis...
CyberCode Academy
Sep 7, 202624:15completed

Course 42 - Mobile Malware Analysis Fundamentals | Episode 10: The Essentials of...
CyberCode Academy
Sep 6, 202623:12completed