Shell items, More than Meets the Eye

  • Monday, 16 May 2016 1:00PM EDT (16 May 2016 17:00 UTC)
  • Speaker: David Cowen

It's time to revisit everyone's favorite windows forensic resources; shell items. Whether you like to look at them as lnk files, jumplists, shell bags or registry entries they are everywhere. In recent years and in recent versions of Windows we keep finding more data within shell items we can use to make even more correlations and find more evidence! Tune in to see new research, tools and analysis you can use to take your case farther today.

Digital Forensics & Incident Response Summit
Austin, TX

Summit Dates: June 23-24
Training Course Dates: June 25-30
DFIR NetWars: June 27-28
Register at

SANS Annual DFIR Summit is the only event of its kind that gathers the most influential group of experts, the highest quality of training & the greatest opportunities to network with others in the field of Digital Forensics & Incident Response, all in one place! Attend the DFIR Summit and gain the investigative skills you need and the ones you never knew you needed.