Eye Describe Anatomy

LNK files: structure, contents and evidential limits

The definitive forensic guide to the Windows shortcut (.lnk) file format — the MS-SHLLINK Shell Link structure used across Windows, and what a shortcut reveals about the file it points to.

What this page covers

  1. Full logical dissection reference
  2. ExtraData block signatures
  3. LinkFlags bitmask (0x14)
  4. Reading the LNK / Jump-List dashboard
  5. What a shortcut supports, and what it does not
  6. Frequently asked questions
Figure 1
Live Byte Selection

Select any field in the map to reveal a deep forensic dive.

The Three Pillars of Windows Artifacts

Windows maintains three distinct artifact types that record file and application access history. All three share a common underlying structure — the Shell Link (LNK) binary format — but they wrap it in different containers and enrich it with different metadata layers:

  • LNK Files (.lnk): Standalone shell shortcut files, one per accessed item. Found in \Recent\.
  • Automatic Destinations: OLE Compound File containers, system-managed, tracking recently and frequently accessed items per application.
  • Custom Destinations: Raw binary files, application-managed or user-driven, tracking pinned and task items.

This page focuses on the core LNK binary payload found inside all three containers.

Full logical dissection reference

Table 1
Offset Size Field Name Forensic Meaning & Value

ExtraData block signatures

Table 2
SignatureBlock NameSignificance
0xA0000003TrackerDataBlockContains Machine NetBIOS, MAC Address, & Droid GUIDs.
0xA0000009PropertyStoreBlockSerialized metadata (Author, Last_Author, Title, EXIF).
0xA0000001EnvironmentVarBlockTarget paths using variables like %APPDATA%.
0xA0000006DarwinDataBlockWindows Installer (MSI) application component ID.
0xA000000BKnownFolderBlockSystem folder GUID (e.g. Startup, Downloads).
0xA0000002ConsoleDataBlockCommand prompt styling; reveals hidden 1x1 shell execution.
0xA0000008ShimDataBlockApplied Compatibility Shims (.sdb) - possible persistence.

LinkFlags bitmask (0x14)

Table 3
MaskFlagForensic Result
0x0001HasTargetIDListEnables the IDList section containing Shell breadcrumbs & MFT references.
0x0002HasLinkInfoEnables LinkInfo section containing Volume Serial Numbers & Local Paths.
0x0020HasArgumentsEnables StringData containing command-line arguments (critical for malware).
0x0080IsUnicodeIndicates StringData blocks are UTF-16LE encoded.

Reading the LNK / Jump-List dashboard

The Charts button on the LNK and Jump-List table tabs opens one dashboard over all three "a user opened this" artifacts — LNK shortcuts, Automatic jump lists, and Custom jump lists — read from LnkDB.db. Every record is the same shape: a target that was opened, when (its Standard-Info times), by which application, and from which volume. One rule holds everywhere: source = colour.

Sources
SourceWhat it recordsColour
LNK shortcutA .lnk file — a target path, its MAC times, volume serial/label, and tracker/MFT identityblue
Automatic jump listThe per-application DestList — what an app opened, in access order (AppID)green
Custom jump listApplication-pinned / task items (.customDestinations-ms)purple

The two regions

Left — three source activity strips (a cell per day, source = colour) over the target last-access history; click a day for the drill-down: opens-by-hour (stacked by source), by application, top directories, top file types, and an event list (time · source · app · target · volume). Right — the overview: totals, an Insights card, a Volumes (device history) card, and the most-used applications, directories and file types.

Insights & device history

Click for detail

Click a day to fill the drill-down. Click a target (a row in the opens list) for its full profile: which sources recorded it (an LNK and a jump list can both point at the same file), its Access / Create / Modify times, the volume + serial it lived on, and — from a richer LNK — its MFT entry, tracker MAC and command-line arguments. Two header filters apply to everything: a search box, a source and a volume selector, and a date dropdown.

From reading to doing

Stop hex-diving — let Crow-Eye parse every LNK

You've just dissected a Shell Link byte by byte. Crow-Eye does this across the whole evidence set automatically — recovering target paths, the three MAC timestamps, the tracker block's machine ID & NIC MAC address, and the full Shell IDList — and lays them on a timeline.

Download Crow-Eye

What a shortcut supports, and what it does not

A LNK file is the richest single-file artifact Windows writes about a user's contact with a document, and that richness is why it is routinely asked to prove more than it can. Three claims it does not carry:

The timestamps inside belong to the target, not to the opening

The created, modified and accessed times stored in a shortcut are the target file's times, copied at the moment the shortcut was last written. They describe the document, not the act of opening it. The time the user opened something is the shortcut's own MAC times on disk — the LNK file in Recent\ — and those are the ones a timeline should plot.

It records that a target was opened, not who opened it or with what

A shortcut in a user's Recent folder ties the activity to that profile and no further. It does not name the application that opened the file, and it does not distinguish a person double-clicking a document from a script, an installer or a preview handler touching it. For the application, the answer is the Jump List and its AppID; for the person, it is a logon session beside the timestamp.

A LNK for a file that no longer exists is normal, not suspicious

Shortcuts outlive their targets by design — that is what makes them valuable against a removable drive or a deleted document. A path pointing at nothing proves the target was reachable once, at that path, with that volume serial. It does not prove deletion, and it does not prove the file was ever on the local disk.

What it is genuinely good for: the target's identity across machines and media. A shortcut carries the volume serial number, the volume label and, where a tracker block survives, the machine ID and a NIC MAC address of the system that created it. That is a statement about where the file came from which no timestamp provides, and it is what lets a document be followed onto a USB stick, across a share, or back to a machine that is not the one being examined.

Frequently asked questions

What does a Windows LNK file reveal in an investigation?

The full path of the target, the target's created, modified and accessed times as they were when the shortcut was written, the volume serial number, and often a tracker block holding the machine ID and a NIC MAC address of the system where it was created.

Where are LNK files found on Windows?

Automatically created shortcuts live in the user's Recent folder under AppData. Others sit on the Desktop, in the Start Menu, and anywhere a user or installer placed them, so both automatic and deliberate shortcuts are worth collecting.

Does a LNK file prove a document was opened?

A shortcut in the Recent folder is good evidence the target was opened through the shell, and it preserves the target's timestamps at that moment even if the file has since been deleted or moved. It does not by itself say who opened it or from which application.

Can a LNK file point at a file that no longer exists?

Yes, and that is one of its most useful properties. The shortcut retains the target's path, size and timestamps after the target is gone, which makes LNK files a common source of evidence for removed or external-media files.