Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

have shellbag events provide the full shell item path #48

Closed
gregfreemyer opened this issue Nov 25, 2014 · 2 comments
Closed

have shellbag events provide the full shell item path #48

gregfreemyer opened this issue Nov 25, 2014 · 2 comments
Assignees
Labels
enhancement New or improved functionality

Comments

@gregfreemyer
Copy link

I have looked at the output of psort.py on a image of mine for shell bag activity.

The activity shows up, but there is not any folder information in the output file. If I use ShellBagExplorer I do have folder info in some of the active shell bags so it is not a case of no data being available.

== details
I'm calling log2timeline / psort as:

/log2timeline.py -d --logfile plaso-debug.log --workers 4 --offset 411648 cu01c1.plasodb /mnt/imageCU01/ewf1

psort -z EST5EDT -w $dir.plaso.converted cu01c1.plasodb

I'm searching through the *.converted file.

@joachimmetz
Copy link
Member

Proposed notation:

<Root> Path

E.g.

<My Computer> C:\Documents and Settings\Administrator

@joachimmetz joachimmetz changed the title log2timeline shellbag events should provide the directory path if available have shellbag events provide the full shell item path Mar 17, 2015
@joachimmetz
Copy link
Member

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New or improved functionality
Projects
None yet
Development

No branches or pull requests

2 participants