New Jump List Parse...
 
Notifications
Clear all

New Jump List Parser just released

3 Posts
3 Users
0 Reactions
855 Views
tzworks
(@tzworks)
Active Member
Joined: 14 years ago
Posts: 5
Topic starter  

We just posted a new tool for 'Jump List' parsing at TZWorks LLC at http//tzworks.net/prototype_page.php?proto_id=20. The tool is call 'jmp' and there are binary versions that run on Windows, Linux and Mac OS-X.
If you haven't seen the forensic artifacts produced by parsing Jump Lists on Win7 and beyond, download the tool and take a look at the output it produces. This tool is command line based and is geared for outputting data in a parsable CSV format. Since this is a first release, it is still considered to be prototype software.
All constructive comments for improvement to the tool are solicited.


   
Quote
(@sam305754)
Eminent Member
Joined: 14 years ago
Posts: 44
 

Hello,

I tried the jmp and it is a great tool. it gives plenty of results to investigate the automatic and customs destinations in a simple manner. However could you provide us with some clarifications on the different columns we get?
I am newbie in this field and want some clarifications on informations seen.
MRU/MFU Time; File modified time,…Target…
For an automatic file the "file mdate"and "file cdate" are the same for all the streams within this file?
To be accurate I want to know if I can ascertain the last real acces to a word document ?
Thank you


   
ReplyQuote
(@ssenyl)
Eminent Member
Joined: 17 years ago
Posts: 25
 

Sam,

I have done a lot of work on the topic of Jump Lists and have posted an article here

Analysis of Windows 7 Jump Lists

Please feel free to PM me for more information

Regards


   
ReplyQuote
Share: