Shellbags
Also called shell bags, BagMRU, Explorer folder view registry.
- PLATFORM
- Windows
- CATEGORY
- File and Folder Access
- INDEX
- 4 of 36
- PROVES
- 5 findings
- CANNOT PROVE
- 5 limits
- QUESTIONS
- 4 answered
Registry entries preserving the name, position in the folder tree, and display settings of folders a user browsed in Explorer — including folders that no longer exist.
Where it lives
USRCLASS.DAT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU and \Bags; NTUSER.DAT\Software\Microsoft\Windows\Shell\BagMRU and \Bags
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of shellbags” is neither.
What it records
When Explorer displays a folder it stores the window's view settings, keyed to a shell item that describes the folder itself. The BagMRU hierarchy mirrors the folder tree the user traversed, so the structure of a removable or network volume can be reconstructed from it long after the volume is gone. Each shell item may carry embedded date values describing the folder, distinct from the registry key's own last-write time. Since Windows Vista most of this data lives in USRCLASS.DAT rather than NTUSER.DAT.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- That a user account browsed a folder with a given name, at a given position in a tree, under a given drive letter
- The structure of a volume that was never produced — the standard way to reconstruct the directory layout of a departed external drive
- That folders existed which no longer appear anywhere on the disk, because the entry survives deletion of the folder
- A per-user record, since the hives are per-account, which is stronger attribution than any machine-wide device key
- Where recorded, the volume label of the drive node, which can be compared against other artifacts
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- That the folder was on any particular physical device. Shellbags carry no volume serial number — that is a LinkInfo field found in LNK files and jumplist streams — so on their own they cannot attribute a folder tree to a device
- That any file inside the folder was opened, read, or copied. The record is of a folder being displayed, nothing more
- That the user intended anything. An employee who opened a folder looking for a personal file leaves an entry indistinguishable from one who opened it to select everything and drag it
- The moment of browsing, from the shell item's embedded dates. Those values describe the folder, not the act of viewing it, and their semantics vary by Windows version and by which of the folder's own dates the item recorded
- That a folder was not browsed. Explorer is only one way to reach a directory; command-line tools, third-party file managers, and most applications' own dialogs create nothing here
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Asking which timestamp the examiner relied on — the key's last-write time or the shell item's embedded value — and what event each reflects. An examiner who states a shellbag timestamp as a bare fact invites the correction
- Pointing out the missing volume serial number and asking how the folder tree was tied to the device in evidence
- Showing that automated processes, backup software, and shell enumeration can create entries without a person browsing anything
- Arguing that the reconstructed tree is a superset or subset of what actually existed on the volume at any single moment, since entries accumulate across sessions
What survives, and for how long
Shellbags persist in the user's hives across reboots and long after the folder and its volume are gone, which is precisely what makes them valuable. They are per-user, so an examination scoped to the wrong profile finds nothing; they are removed by profile deletion, hive corruption, and cleanup utilities.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
What do shellbags prove?
Shellbags prove that a user account browsed a folder with a particular name, at a particular place in a folder tree, using Windows Explorer. Because the entry survives deletion of the folder and of the volume holding it, they are the standard way to reconstruct the directory structure of an external drive that was never produced. They do not show that any file inside the folder was opened or copied.
Do shellbags prove a USB drive was used?
Not on their own. Shellbags record no volume serial number, so a shellbag entry for a folder under drive E: cannot be tied to a specific physical device by itself. Device attribution comes from correlating the entry with LNK files or jumplist streams, whose LinkInfo structure does carry the volume serial, with the USB registry keys, and with the timeline of which device held which drive letter when.
Can shellbags be created without the user opening the folder?
Yes, and this is the most productive line of attack on a shellbag finding. Entries can be produced by shell enumeration and by automated processes that traverse a directory tree, not only by a person clicking through folders in a window. An examiner who treats every entry as a deliberate act of browsing has assumed something the artifact does not record.
What do shellbag timestamps mean?
There are two kinds and they mean different things. The registry key's last-write time reflects when the entry was updated. The shell item's embedded date values describe the folder itself, and which of the folder's own dates they capture varies by Windows version. Neither is straightforwardly the moment a user looked at the folder, and a report that states a shellbag timestamp without saying which value it is has skipped the hard part.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
LNK Shortcut Files
Shortcut files Windows creates when a document is opened through the shell, retaining the target's full path, its size and timestamps, and often the volume serial number of the drive it lived on.
Jumplists
Per-application recent-file lists stored as compound files containing embedded LNK streams and an ordering list, recording which documents each program opened for a specific user.
USBSTOR and USB Device History
The SYSTEM registry records which USB storage devices were attached to a machine, their vendor and product strings, and a small fixed set of first-seen and last-connected timestamps.
MountedDevices and MountPoints2
Two registry locations that map drive letters and volume identifiers to underlying devices — one machine-wide and current-state only, one per-user and the closest thing to user attribution for a mounted volume.
RecentDocs and the Open/Save MRU Keys
Per-user registry lists of recently opened documents and of the folders used in Open and Save dialogs, ordered by recency but carrying a timestamp only for the most recent entry.
Whether the shellbagsevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.