LNK Shortcut Files
Also called link files, shortcut files, Recent folder LNK, LinkInfo.
- PLATFORM
- Windows
- CATEGORY
- File and Folder Access
- INDEX
- 5 of 36
- PROVES
- 5 findings
- CANNOT PROVE
- 6 limits
- QUESTIONS
- 4 answered
Shortcut files Windows creates when a document is opened through the shell, retaining the target's full path, its size and timestamps, and often the volume serial number of the drive it lived on.
Where it lives
%AppData%\Microsoft\Windows\Recent\*.lnk; also Office and application recent-item folders, and LNK streams embedded inside jumplists
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of lnk shortcut files” is neither.
What it records
A LNK file's header stores the target file's size and its own set of timestamps as they stood when the shortcut was written. The LinkInfo structure, where populated, records the volume serial number, volume label, drive type and local base path of the media holding the target. Extra data blocks may include distributed link tracking fields carrying a NetBIOS name and a hardware address. Windows maintains one shortcut per target path in the Recent folder and overwrites it, so the shortcut's own creation and modification times approximate first and most recent access to that path.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- That a file at a specific full path was opened through the Windows shell by this user account
- The size the file had at the time of access, which can be compared against a produced copy
- The volume serial number and label of the media holding the file, where LinkInfo is populated — the strongest routine link between a named file and a specific removable device
- Approximate first and most recent access to that path, from the shortcut file's own creation and modification times
- That the file existed, and where, long after both the file and its volume are gone
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- That the file was copied. Opening a document from a network share leaves the same kind of record as opening one staged on a USB drive; the path and volume serial are what distinguish them, not the existence of the shortcut
- How many times the file was accessed. There is one shortcut per target path and it is overwritten, so the record holds two moments and not a count
- That a file was not accessed. Many applications and most portable tools bypass the shell entirely and generate nothing, and the Recent folder is trimmed and cleared
- That the machine named in a distributed link tracking block is the machine where the shortcut was created. Those fields are frequently absent or zeroed, describe the host of the target volume, and are further degraded by virtual adapters and randomised hardware addresses
- That the volume serial identifies one device in the world. Serials are not guaranteed unique and are reassigned when a volume is reformatted
- That the user read the document. The shell records that it was opened, not that anything was displayed for any length of time or understood
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Asking whether LinkInfo was populated at all, since the device attribution collapses without it
- Treating a tracker block hardware address as identification of a home or new-employer machine, which it does not reliably supply
- Noting that a LNK file can be created by opening a file for an innocent reason, and that the artifact records no purpose
- Establishing that the shortcut's timestamps were themselves derived from the target's metadata, which may have been altered before access
- Pointing out that shortcuts can be copied between machines, so a LNK file's presence on a device does not establish that the target was ever on that device
What survives, and for how long
LNK files persist long after the target file and its volume are gone, which is what makes them among the most probative artifacts available. They live in a per-user folder, so an examination scoped to the wrong profile misses them, and Windows trims the Recent folder over time so older entries disappear without ceremony.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
Does a LNK file prove a file was opened?
It proves the path was opened through the Windows shell by that user account, which is close to but not the same as proving the document was read. It does not distinguish opening from copying, does not record how long the file was displayed, and does not record why. Its real strength is elsewhere: the LinkInfo structure often records the volume serial number of the drive the file lived on.
Can a LNK file show a file was on a USB drive?
Often, yes, and it is the usual way that link is made. Where the LinkInfo structure is populated it records the volume serial number and label of the media holding the target file. When that serial matches a volume associated with a device in the USB registry keys, and the shortcut points to a path under a removable drive letter, the record moves from device presence to interaction with named files.
How many times does a LNK file show a document was opened?
It does not show a count. Windows maintains one shortcut per target path in the Recent folder and overwrites it on each access, so the file's own creation time approximates first access and its modification time approximates the most recent one. Everything between those two moments is unrecorded. A claim about frequency of access has to come from a different artifact.
Does the MAC address in a LNK file identify the computer?
No, and this is a common overreach. Distributed link tracking fields can carry a NetBIOS name and a hardware address, but they are frequently absent or zeroed, they describe the machine hosting the target volume rather than reliably identifying where the shortcut was made, and virtual adapters and randomised hardware addresses degrade them further. Treat them as a lead to be corroborated against machine identifiers produced in discovery.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
Jumplists
Per-application recent-file lists stored as compound files containing embedded LNK streams and an ordering list, recording which documents each program opened for a specific user.
Shellbags
Registry entries preserving the name, position in the folder tree, and display settings of folders a user browsed in Explorer — including folders that no longer exist.
RecentDocs and the Open/Save MRU Keys
Per-user registry lists of recently opened documents and of the folders used in Open and Save dialogs, ordered by recency but carrying a timestamp only for the most recent entry.
USBSTOR and USB Device History
The SYSTEM registry records which USB storage devices were attached to a machine, their vendor and product strings, and a small fixed set of first-seen and last-connected timestamps.
$MFT (Master File Table)
The NTFS index of every file and directory on a volume, holding two independent sets of four timestamps per file plus, for small files, the file's entire content.
Whether the lnk shortcut filesevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.