SKIP TO CONTENT
FILE AND FOLDER ACCESS04 / 36

Shellbags

Also called shell bags, BagMRU, Explorer folder view registry.

PLATFORM
Windows
CATEGORY
File and Folder Access
INDEX
4 of 36
PROVES
5 findings
CANNOT PROVE
5 limits
QUESTIONS
4 answered
WHAT IT IS

Registry entries preserving the name, position in the folder tree, and display settings of folders a user browsed in Explorer — including folders that no longer exist.

Where it lives

USRCLASS.DAT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU and \Bags; NTUSER.DAT\Software\Microsoft\Windows\Shell\BagMRU and \Bags

Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of shellbags” is neither.

What it records

When Explorer displays a folder it stores the window's view settings, keyed to a shell item that describes the folder itself. The BagMRU hierarchy mirrors the folder tree the user traversed, so the structure of a removable or network volume can be reconstructed from it long after the volume is gone. Each shell item may carry embedded date values describing the folder, distinct from the registry key's own last-write time. Since Windows Vista most of this data lives in USRCLASS.DAT rather than NTUSER.DAT.

What it proves — and what it cannot

These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.

What it proves

FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.

  • That a user account browsed a folder with a given name, at a given position in a tree, under a given drive letter
  • The structure of a volume that was never produced — the standard way to reconstruct the directory layout of a departed external drive
  • That folders existed which no longer appear anywhere on the disk, because the entry survives deletion of the folder
  • A per-user record, since the hives are per-account, which is stronger attribution than any machine-wide device key
  • Where recorded, the volume label of the drive node, which can be compared against other artifacts

What it cannot prove

INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.

  • That the folder was on any particular physical device. Shellbags carry no volume serial number — that is a LinkInfo field found in LNK files and jumplist streams — so on their own they cannot attribute a folder tree to a device
  • That any file inside the folder was opened, read, or copied. The record is of a folder being displayed, nothing more
  • That the user intended anything. An employee who opened a folder looking for a personal file leaves an entry indistinguishable from one who opened it to select everything and drag it
  • The moment of browsing, from the shell item's embedded dates. Those values describe the folder, not the act of viewing it, and their semantics vary by Windows version and by which of the folder's own dates the item recorded
  • That a folder was not browsed. Explorer is only one way to reach a directory; command-line tools, third-party file managers, and most applications' own dialogs create nothing here

How the finding is attacked

An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.

  • Asking which timestamp the examiner relied on — the key's last-write time or the shell item's embedded value — and what event each reflects. An examiner who states a shellbag timestamp as a bare fact invites the correction
  • Pointing out the missing volume serial number and asking how the folder tree was tied to the device in evidence
  • Showing that automated processes, backup software, and shell enumeration can create entries without a person browsing anything
  • Arguing that the reconstructed tree is a superset or subset of what actually existed on the volume at any single moment, since entries accumulate across sessions

What survives, and for how long

Shellbags persist in the user's hives across reboots and long after the folder and its volume are gone, which is precisely what makes them valuable. They are per-user, so an examination scoped to the wrong profile finds nothing; they are removed by profile deletion, hive corruption, and cleanup utilities.

More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.

Questions counsel ask

What do shellbags prove?

Shellbags prove that a user account browsed a folder with a particular name, at a particular place in a folder tree, using Windows Explorer. Because the entry survives deletion of the folder and of the volume holding it, they are the standard way to reconstruct the directory structure of an external drive that was never produced. They do not show that any file inside the folder was opened or copied.

Do shellbags prove a USB drive was used?

Not on their own. Shellbags record no volume serial number, so a shellbag entry for a folder under drive E: cannot be tied to a specific physical device by itself. Device attribution comes from correlating the entry with LNK files or jumplist streams, whose LinkInfo structure does carry the volume serial, with the USB registry keys, and with the timeline of which device held which drive letter when.

Can shellbags be created without the user opening the folder?

Yes, and this is the most productive line of attack on a shellbag finding. Entries can be produced by shell enumeration and by automated processes that traverse a directory tree, not only by a person clicking through folders in a window. An examiner who treats every entry as a deliberate act of browsing has assumed something the artifact does not record.

What do shellbag timestamps mean?

There are two kinds and they mean different things. The registry key's last-write time reflects when the entry was updated. The shell item's embedded date values describe the folder itself, and which of the folder's own dates they capture varies by Windows version. Neither is straightforwardly the moment a user looked at the folder, and a report that states a shellbag timestamp without saying which value it is has skipped the hard part.

Terms used on this page

Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.

No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.

A FINDING ON THIS ARTIFACT

Whether the shellbagsevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

  • Can This Artifact Prove That?

    Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.

  • Computer forensics

    The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.

  • The artifact index

    All 36 entries, grouped by what they bear on and filterable by platform.

  • Daubert and digital evidence

    Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.

← BACK TO THE ARTIFACT INDEX

Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.