Observed arrival · 2026-09-28
ShellBags Parser: browser-based Windows forensics
A browser-based viewer for examining Windows ShellBags from registry hives, folders, or ZIP collections.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- DFIR analysts triaging Windows user activity
- Worth noticing
- Its fictional sample includes an E:\exfil timestamp with a control to inspect activity within five minutes on either side.
Field notes
The page walks through collecting both registry hives and their .LOG1/.LOG2 files, noting that Windows locks them while running. It gives a PowerShell shadow-copy command, a KAPE target, and Velociraptor collection guidance; the drop zone accepts a folder or ZIP while preserving per-user folder layout. A fictional sample includes an E:\exfil timestamp with a control to inspect activity within five minutes.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central
One card from the complete issue