#DFIR  

Checkout my write-up on Windows Shellbag parsing, it comes with a tool! http://www.williballenthin.com/forensics/shellbags/index.html #dfir

@williballenthin