Jump List Examinati...
 
Notifications
Clear all

Jump List Examination

12 Posts
8 Users
0 Reactions
5,510 Views
(@chitapett)
Estimable Member
Joined: 18 years ago
Posts: 76
Topic starter  

Thanks for the contribution guys/gals!



   
ReplyQuote
EricZimmerman
(@ericzimmerman)
Estimable Member
Joined: 13 years ago
Posts: 222
 

I think you are trying to find evidence about copying a document to usb device from jumplist if jumplisted file exist in acquired hard drive and jumplist indicate it as openned from usb drive yes you can say it you sould also look at link files to verify

jumplists are just collections of lnk files. if you have an automatic destination jump list there is a bit more info available over stuff from a custom jump list.

if you want to read about the inner workings of jump lists and get some more free tools for jump lists, start here

https://binaryforay.blogspot.com/2016/02/jump-lists-in-depth-understand-format.html

this is a nice jump list gui i am working on too if you want to try it

https://t.co/PSYUVk8wC1

another thing to consider is looking at the full path to the document based on the jump list, then look at the shell bags via shell bags explorer to see what the parent directory(ies) look like for the document in question. you can then start drilling down into file system artifacts and volume serial numbers using the data in the relevant lnk file (and also creation date, droid birth info, etc). along with mft info from the lnk information and shell bag stuff.

lots to look at! =)



   
ReplyQuote
Page 2 / 2
Share: