Introduction
Windows Explorer, known as File Explorer in modern versions of Microsoft Windows, is the graphical file management application that allows users to browse, access, copy, move, and manage files and folders stored on a computer.
Since its introduction in Windows 95, Windows Explorer has been a core component of the Windows operating system, providing users with an intuitive interface for interacting with the file system.
From a digital forensics perspective, Windows Explorer generates a significant amount of metadata and historical information that can provide investigators with valuable insights into user activity.
These artefacts can reveal which files were accessed, when folders were opened, what removable devices were connected, and even the locations recently visited by a user.
Such evidence is frequently examined during criminal investigations, corporate inquiries, and civil litigation.
History of Windows Explorer
Windows Explorer first appeared in Windows 95 as a replacement for the earlier File Manager application used in previous Windows versions. Over time, Microsoft expanded its capabilities by introducing features such as:
- Integrated desktop navigation
- Quick Access and Favorites
- Search functionality
- Libraries and network browsing
- File previews and metadata viewing
- Cloud storage integration
Modern versions of Windows, including Windows 10 and Windows 11, continue to rely on File Explorer as the primary method for managing files and folders.
Importance in Digital Forensics
Windows Explorer records numerous traces of user interaction with files and folders. These artefacts can help answer key forensic questions:
- Which files were accessed?
- Which folders were opened?
- When were files viewed?
- Were external devices connected?
- Did the user attempt to conceal activity?
- What documents were recently used?
Even when files have been deleted, Windows Explorer artefacts may remain and provide evidence of prior activity.
Key Windows Explorer Forensic Artefacts
1. ShellBags
ShellBags are among the most valuable Windows Explorer artefacts.
Purpose:
- Store folder view preferences
- Record directories viewed by a user
- Persist even after folders have been deleted
Location:
- NTUSER.DAT
- USRCLASS.DAT
Forensic Value:
- Identifies folders accessed by a user
- Reveals deleted directories
- Demonstrates knowledge of file locations
- Shows access to external drives and network shares
ShellBags can provide a historical map of a user’s navigation activity.
2. Recent Files
Windows maintains a list of recently opened files.
Location:
- %APPDATA%\Microsoft\Windows\Recent
Forensic Value:
- Identifies documents accessed by the user
- Provides timestamps for file usage
- Creates shortcuts to recently opened files
These shortcut files (.lnk) often survive even when the original file has been deleted.
3. Jump Lists
Jump Lists were introduced in Windows 7 to provide quick access to recently used files.
Location:
- %APPDATA%\Microsoft\Windows\Recent\AutomaticDestinations
- %APPDATA%\Microsoft\Windows\Recent\CustomDestinations
Forensic Value:
- Lists recently accessed files
- Shows application usage
- Records file paths and timestamps
- Demonstrates user interaction with documents
Jump Lists can reveal extensive evidence regarding document activity.
4. Shortcut Files (LNK Files)
Windows automatically creates shortcut files when documents are opened.
Location:
- Recent Folder
- Desktop
- User-created locations
Forensic Value:
- Original file path
- Volume serial number
- Device information
- Access timestamps
- Network locations
LNK files frequently provide evidence of files that no longer exist.
5. Quick Access
Quick Access stores frequently and recently accessed locations.
Location:
- AutomaticDestinations
Forensic Value:
- Frequently accessed folders
- Recently viewed directories
- User preferences and habits
This artefact can help establish normal user behaviour patterns.
6. Windows Search Database
The Windows Search service indexes files to improve search performance.
Location:
- ProgramData\Microsoft\Search\Data
Forensic Value:
- Indexed file names
- Document metadata
- Historical file references
- Potential remnants of deleted files
Investigators often examine the search database for evidence of user activity.
7. Registry MRU Lists
MRU (Most Recently Used) entries record recently accessed files, folders, and commands.
Common Registry Keys:
- OpenSavePidlMRU
- LastVisitedPidlMRU
- RecentDocs
- RunMRU
Forensic Value:
- Recently opened documents
- Recently accessed folders
- Executed commands
- Application usage
MRU artefacts can help establish a timeline of user actions.
8. Thumbnail Cache
Windows generates thumbnail previews for images, videos, and documents.
Location:
- %LOCALAPPDATA%\Microsoft\Windows\Explorer
Files include:
- thumbcache_*.db
Forensic Value:
- Evidence of viewed images
- Evidence of deleted files
- Visual confirmation of file contents
Thumbnail caches often remain after the original files have been deleted.
9. Prefetch Files
Although not exclusive to Windows Explorer, Prefetch records application execution.
Location:
- C:\Windows\Prefetch
Forensic Value:
- Program execution evidence
- Last execution times
- Execution counts
- Associated files and libraries
Prefetch data can corroborate file access activity.
10. USB and External Device Artefacts
Windows Explorer records interactions with removable media.
Relevant Artefacts:
- USBSTOR Registry Keys
- MountPoints2
- ShellBags
- LNK Files
- Jump Lists
Forensic Value:
- Device connection history
- Device serial numbers
- First and last connection times
- Files accessed from removable media
These artefacts are particularly useful in data theft investigations.
Timeline Reconstruction
One of the primary goals of digital forensics is reconstructing a user’s activity timeline. Windows Explorer artefacts contribute significantly by providing:
Artefact Information Provided
ShellBags Folder access history
LNK Files Opened file information
Jump Lists Recent file usage
RecentDocs Recently opened documents
Thumbnail Cache Viewed media files
Search Database Indexed content
Prefetch Program execution history
Combining these sources allows investigators to establish a detailed chronology of user actions.
Limitations
While Windows Explorer artefacts are valuable, investigators should consider several limitations:
- Artefacts can be partially overwritten.
- Some entries may persist long after actual use.
- System cleaning utilities may remove artefacts.
- Multiple users may access the same device.
- Timestamps can be altered under certain circumstances.
Forensic findings should therefore be corroborated using multiple evidence sources.
Conclusion
Windows Explorer is a rich source of digital forensic evidence.
Through artefacts such as ShellBags, Jump Lists, LNK files, MRU entries, thumbnail caches, and search databases, investigators can reconstruct user behaviour, identify accessed files and folders, and establish timelines of activity.
These artefacts often persist even after files have been deleted, making them invaluable in criminal investigations, corporate inquiries, incident response engagements, and civil litigation.
Understanding the location, structure, and interpretation of Windows Explorer artefacts remains a fundamental skill for digital forensic practitioners.
About Athena Forensics
For information on our computer forensic expert services or if you require any advice or assistance please contact a member of our team on 0330 123 4448 or via email on enquiries@athenaforensics.co.uk, further details are available on our contact us page.
Our client’s confidentiality is of the utmost importance. All correspondence is treated with discretion, from initial contact to conclusion of the matter.
We are fully aware of the significance and importance of the information that they encounter and we have been accredited to ISO 9001 for 14 years.
Our premises along with our security procedures have been inspected and approved by law enforcement agencies and we do not disclose personal information to other companies or suppliers.
Our team are all security cleared and we offer non-disclosure agreements if required.
Our premises along with our security procedures have been inspected and approved by law enforcement agencies.
Athena Forensics do not disclose personal information to other companies or suppliers.