LicenseApache License 2.0
Programming languagePython
AuthorWilli Ballenthin
Latest release0.5.5 []

Typically this tool will be used to gather information from a compromised system or to track traces from a system to find evidence. Shellbags can provide some insight on browsed directories on the system via Explorer on Microsoft Windows systems.

The shellbags script is provided the path to a raw Windows Registry hive (NTUSER.DAT). It is then parsed on the system of the forensic specialist.

shellbags is commonly used for digital forensics. Target users for this tool are forensic specialists and pentesters.

The review and analysis of this project resulted in the following remarks for this security tool:


  • + The source code of this software is available

Shellbags is under development by Willi Ballenthin.


Shellbags is known to work on Linux and Microsoft Windows.

