The definitive forensic guide to the Windows shortcut (.lnk) file format — the MS-SHLLINK Shell Link structure used across Windows, and what a shortcut reveals about the file it points to.
Select any field in the map to reveal a deep forensic dive.
Windows maintains three distinct artifact types that record file and application access history. All three share a common underlying structure — the Shell Link (LNK) binary format — but they wrap it in different containers and enrich it with different metadata layers:
\Recent\.This page focuses on the core LNK binary payload found inside all three containers.
| Offset | Size | Field Name | Forensic Meaning & Value |
|---|
| Signature | Block Name | Significance |
|---|---|---|
| 0xA0000003 | TrackerDataBlock | Contains Machine NetBIOS, MAC Address, & Droid GUIDs. |
| 0xA0000009 | PropertyStoreBlock | Serialized metadata (Author, Last_Author, Title, EXIF). |
| 0xA0000001 | EnvironmentVarBlock | Target paths using variables like %APPDATA%. |
| 0xA0000006 | DarwinDataBlock | Windows Installer (MSI) application component ID. |
| 0xA000000B | KnownFolderBlock | System folder GUID (e.g. Startup, Downloads). |
| 0xA0000002 | ConsoleDataBlock | Command prompt styling; reveals hidden 1x1 shell execution. |
| 0xA0000008 | ShimDataBlock | Applied Compatibility Shims (.sdb) - possible persistence. |
| Mask | Flag | Forensic Result |
|---|---|---|
| 0x0001 | HasTargetIDList | Enables the IDList section containing Shell breadcrumbs & MFT references. |
| 0x0002 | HasLinkInfo | Enables LinkInfo section containing Volume Serial Numbers & Local Paths. |
| 0x0020 | HasArguments | Enables StringData containing command-line arguments (critical for malware). |
| 0x0080 | IsUnicode | Indicates StringData blocks are UTF-16LE encoded. |
The Charts button on the LNK and Jump-List table tabs opens one
dashboard over all three "a user opened this" artifacts — LNK shortcuts,
Automatic jump lists, and Custom jump lists — read from LnkDB.db.
Every record is the same shape: a target that was opened, when (its Standard-Info times), by which
application, and from which volume. One rule holds everywhere: source = colour.
| Source | What it records | Colour |
|---|---|---|
| LNK shortcut | A .lnk file — a target path, its MAC times, volume serial/label, and tracker/MFT identity | blue |
| Automatic jump list | The per-application DestList — what an app opened, in access order (AppID) | green |
| Custom jump list | Application-pinned / task items (.customDestinations-ms) | purple |
Left — three source activity strips (a cell per day, source = colour) over the target last-access history; click a day for the drill-down: opens-by-hour (stacked by source), by application, top directories, top file types, and an event list (time · source · app · target · volume). Right — the overview: totals, an Insights card, a Volumes (device history) card, and the most-used applications, directories and file types.
Drive_Type
is removable or remote (or that carry a network share) — the portable-media / exfiltration angle.Click a day to fill the drill-down. Click a target (a row in the opens list) for its full profile: which sources recorded it (an LNK and a jump list can both point at the same file), its Access / Create / Modify times, the volume + serial it lived on, and — from a richer LNK — its MFT entry, tracker MAC and command-line arguments. Two header filters apply to everything: a search box, a source and a volume selector, and a date dropdown.
You've just dissected a Shell Link byte by byte. Crow-Eye does this across the whole evidence set automatically — recovering target paths, the three MAC timestamps, the tracker block's machine ID & NIC MAC address, and the full Shell IDList — and lays them on a timeline.
Download Crow-EyeA LNK file is the richest single-file artifact Windows writes about a user's contact with a document, and that richness is why it is routinely asked to prove more than it can. Three claims it does not carry:
The created, modified and accessed times stored in a shortcut are the
target file's times, copied at the moment the shortcut was last written. They
describe the document, not the act of opening it. The time the user opened something is the
shortcut's own MAC times on disk — the LNK file in
Recent\ — and those are the ones a timeline should plot.
A shortcut in a user's Recent folder ties the activity to that profile and
no further. It does not name the application that opened the file, and it does not
distinguish a person double-clicking a document from a script, an installer or a preview
handler touching it. For the application, the answer is the Jump List and its AppID; for the
person, it is a logon session beside the timestamp.
Shortcuts outlive their targets by design — that is what makes them valuable against a removable drive or a deleted document. A path pointing at nothing proves the target was reachable once, at that path, with that volume serial. It does not prove deletion, and it does not prove the file was ever on the local disk.
What it is genuinely good for: the target's identity across machines and media. A shortcut carries the volume serial number, the volume label and, where a tracker block survives, the machine ID and a NIC MAC address of the system that created it. That is a statement about where the file came from which no timestamp provides, and it is what lets a document be followed onto a USB stick, across a share, or back to a machine that is not the one being examined.
The full path of the target, the target's created, modified and accessed times as they were when the shortcut was written, the volume serial number, and often a tracker block holding the machine ID and a NIC MAC address of the system where it was created.
Automatically created shortcuts live in the user's Recent folder under AppData. Others sit on the Desktop, in the Start Menu, and anywhere a user or installer placed them, so both automatic and deliberate shortcuts are worth collecting.
A shortcut in the Recent folder is good evidence the target was opened through the shell, and it preserves the target's timestamps at that moment even if the file has since been deleted or moved. It does not by itself say who opened it or from which application.
Yes, and that is one of its most useful properties. The shortcut retains the target's path, size and timestamps after the target is gone, which makes LNK files a common source of evidence for removed or external-media files.