Proprietary sequential binary format analysis of the customDestinations-ms Jump List — user-pinned items and application-defined tasks, and what a pinned entry reveals in a forensic investigation.
Select any field in the map to reveal a deep forensic dive.
Custom Jump Lists (.customDestinations-ms) use a proprietary binary format
rather than the OLE Compound File format used by Automatic Destinations. They are essentially a sequential
concatenation of Windows Shortcut (LNK) files packaged with a simple framing layer.
Binary Layout: There is no DestList stream, no OLE directory, and no structured index. The
parser scans the raw bytes linearly, looking for Category Headers followed by the 20-byte LNK Magic Signature,
until it hits the final 0xBABFFBAB footer.
Forensic Value: Because they lack a DestList, forensic timelines rely entirely on the payload inside the embedded LNK entries. These entries provide massive value: MAC timestamps, MFT Entry/Sequence numbers (IDList), Volume Serial Numbers & Drive Types (Link Info), Command-Line arguments (String Data), and Tracker NetBIOS/MAC data (ExtraData blocks). Explained in full: the DestList stream
| Offset | Size | Field Name | Forensic Meaning & Value |
|---|
| Identifier | Category Name | Meaning |
|---|---|---|
| 0x00000000 | Custom Category | App-supplied category. A 2-byte name length and UTF-16LE category name follow (e.g. "Pinned", a project name, "Tasks"), then a 4-byte LNK entry count and the LNK payloads. |
| 0x00000001 | Known Category | Built-in Windows category. A 4-byte KnownCategoryType sub-value follows: 1 = Frequent, 2 = Recent, 3 = Tasks. No name; the OS renders a localised title. |
| 0x00000002 | Tasks Category (legacy) | Older shape kept for back-compat. Skips the name fields — a 4-byte LNK entry count follows directly, then the LNK payloads. |
LNK Magic Signature (20
Bytes):4C 00 00 00 01 14 02 00 00 00 00 00 C0 00 00 00 00 00 00 46
Because
LNK entries lack explicit length prefixes, tools scan for this exact sequence to carve out shortcuts.
Footer (0xBABFFBAB):
Stored as AB FB BF BA in little-endian. Marks the
absolute end of the list. If missing, the file was truncated or the system crashed.
The Application Identity (AppID) is not explicitly stored inside the Custom Destinations binary format.
Instead, the filename itself is the hex representation of the AppID (e.g.,
1b4dd67f29cb1962.customDestinations-ms). Explained in full: the AppID hash
| AppID Hash | Target Application |
|---|---|
| 1b4dd67f29cb1962 | Windows Explorer |
| f01b4d95cf55d32a | Command Prompt (cmd.exe) |
| 5d696d521ea23821 | Google Chrome |
The Charts button on the LNK and Jump-List tabs opens the opened-files dashboard — LNK shortcuts, automatic and custom jump lists on one timeline, with a per-target profile and a volume/device-history trail. Documented in Reading the LNK / Jump-List dashboard.
Crow-Eye extracts pinned and custom destinations and decodes their embedded LNK metadata, turning Custom Jump Lists into clear evidence of deliberate, user-driven file access.
Download Crow-EyeA Custom Jump List is written by the application rather than by Windows, which makes it the closest thing on disk to a statement of what a user deliberately chose to keep. That is also the source of its three limits:
A pinned entry records that someone chose to keep this item on the application's list. It carries no time of use and no count of uses. A file can be pinned and never opened again, and a file can be opened a hundred times and never pinned — those are different acts, and only the first one is what a custom list stores.
Windows does not maintain this file; the program does, through the shell API, and it writes what its developers chose to write. Tasks, categories and entries differ between applications and between versions of the same application. An empty or missing custom list says the program did not write one, which is not evidence about the user at all.
Each entry is a LNK stream, and the timestamps inside it are the target file's, captured when the stream was written. They are not when the item was pinned and not when it was last used. The nearest thing to a time of action is the custom list file's own modification time on disk, which moves whenever the application rewrites the list for any reason.
What it is genuinely good for: intent. Where an Automatic list is a passive record of what passed through an application, a Custom list is a record of what a person decided was worth keeping in front of them — and because the application writes it, it can hold targets that never appeared in the shell's own recent list at all, including network paths and items from removable media that have long since been disconnected.
Automatic Jump Lists are maintained by Windows as a user opens files. Custom Jump Lists are written by the application itself and hold pinned entries and application-defined tasks, so they reflect deliberate user choices and program design rather than passive recent-file history.
In the user's Recent folder under AppData, in the CustomDestinations subfolder, named by AppID with a customDestinations-ms extension.
Pinning is an intentional act. A pinned file or location shows the user considered it worth keeping to hand, which carries different weight from a file that merely appeared in a recent list once.
Largely yes - the entries are LNK-format blocks concatenated with a footer, so the same target paths, timestamps and volume details a shortcut carries are recoverable from them.