Taking instructions now — the first conversation is freeExhibits posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
FDRForensic Data Recovery 0800 6890668 Price my job
FDR / What the evidence can show / Files opened from removable media

Jump lists · LNK files · shellbags · removable volume · files opened · volume serial

Files opened from removable media. Open a file from a USB drive, and Windows leaves three separate records of it, each of which outlives the drive.

Knowing that a USB device was connected is useful; knowing which files were opened from it is the evidence. When a file or folder is opened from a removable drive, Windows leaves records in three places at once: jump lists, which record the files recently opened by each application; shortcut (LNK) files, which Windows creates automatically for opened files and which record the file's path and the volume it was on; and shellbags, which record the folders that were browsed, including folders on a drive that is no longer attached. Each of these ties to the removable volume's own serial number, so an examiner can show that a particular file was opened from a particular device, at a particular time, under a particular user account. And because these records survive the files and the device being removed, they often show that folders bearing a company's own client or project names existed on a removable drive, even when the drive is long gone.

Owner-only, authority requiredFree first conversationStandard report £800 + VATWe say what it cannot prove

Rather talk it through? An engineer answers the bench line
0800 6890668

Before anything else: stop using the device, and do not let anyone have a look at it. Every time a computer is switched on and used, the very artefacts an examination relies on, the timeline, the recently-opened lists, the deleted-file space, are overwritten a little more. Do not reinstall, do not run recovery software, do not let IT open it to check, and keep it powered off. Preserve it as it is, record who has held it, and send it with the authority documents we ask for. If proceedings are contemplated, the duty to preserve evidence has already begun.

Three records, and what they show together.

Jump lists are the lists of recently-opened files you see when you right-click an application on the taskbar, and they are stored on disk, recording the files each application opened, with their paths and times. When a path points to a removable volume, the jump list shows that file was opened from that drive.

Shortcut (LNK) files are created automatically by Windows whenever a file is opened, and each records the target file's path, its size and dates, and crucially the serial of the volume it was on. A LNK file pointing to a removable volume's serial is a record that the file was opened from that specific device.

Shellbags record the folders a user browsed in Windows Explorer, including the view settings, and they persist for folders that no longer exist, including folders on a removable drive that has since been removed. Shellbags can therefore show that folders, often bearing recognisable names, a company's client, pricing or project folders, existed on a removable volume and were browsed, even when the drive itself is long gone. Together, the three artefacts show which files were opened from which device, and when.

What it records, and what it means.

Describe your situation →
What is recorded Where it comes from What it shows, and does not
Files opened from a removable driveJump lists and LNK files, by volume serialThat a file was opened from the device; not that it was copied
Folders browsed on a removable driveShellbagsThat the folders existed and were browsed; not their full contents
The volume the file was onThe volume serial in the LNK and shellbagWhich device, tied to the USB history; not who opened it
When the file was openedThe access times in the artefactsWhat was done with the file afterwards

From the exhibit arriving to the report.

Work we have closed →
01

The first conversation, and the authority check Free

Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.

FreeOwner-only; authority established firstThe honest answer about what is possible
02

Imaging behind a write blocker, and the hashes

When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.

Bit-for-bit, behind a write blockerMD5 and SHA-256, verifiedThe original never altered
03

The examination, on the image

The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.

Scoped to your questionsConfirmed in a second toolPrivate material filtered out
04

The report

The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.

Factual, tool-generated, self-containedChain-of-custody and case-log reports5–10 working days

From the bench

  • Preserve the computer promptly; these artefacts can roll over with heavy daily use, unlike the longer-lived USB registry record.
  • Give us the folder names that matter; shellbags matching your own client or project folders are telling.
  • Keep any recovered removable device; its volume serial ties directly to these records.

Shellbags persist for folders that no longer exist, so they can show that named folders existed on a removable drive that has since been removed.

What helps, and what harms.

Do this much first

  • Stop using the device and keep it powered off
  • Preserve it as it is; record who has held it
  • Gather your proof of ownership or authority
  • Tell us the questions you need answered

What sets us back

  • Letting IT or anyone open it to have a look
  • Reinstalling, wiping or running recovery software
  • Carrying on using the device
  • Assuming artefacts prove who was at the keyboard
We examine devices only for the people and organisations with lawful authority over them. Before any work begins we ask for proof that the device is yours, or documented authority to have it examined: proof of ownership, a director's or HR letter for a company device with the lawful basis, a solicitor's instruction, a court order, or an executor's grant. It is a condition of the work, not a formality, and it is what keeps the examination on the right side of the Computer Misuse Act 1990. We will not access another adult's device or accounts without their consent or a court order, we will not install monitoring software or bypass anyone's security, and we do not undertake covert surveillance. A device with no proof of authority is returned unexamined.

Questions answered before you instruct.

Can you show which files were taken on a USB stick?

We can show which files and folders were opened from a removable volume, from jump lists, shortcut files and shellbags tied to the device's serial, with the times. Windows does not log the copy itself, so this is evidence that the files were opened from the device, not a copy log; in practice it is often what matters, and we are clear about the distinction.

The USB drive is gone. Can you still tell what was on it?

Often, to a degree. Shellbags can show that folders, sometimes with recognisable names, existed on the removable volume and were browsed, and LNK files and jump lists can show individual files that were opened from it, even after the drive itself has gone. It is a partial picture, but frequently a revealing one.

How do you know it was that specific device?

Each volume has its own serial, recorded in the LNK files and shellbags, and it ties to the device's serial in the USB history. That lets us connect the files opened to a specific device rather than to removable media in general.

Does this prove the files were used or sent on?

No. It shows the files were opened from the device, under a user account, at particular times. What happened to them afterwards, whether they were copied, used or sent, is not shown by these artefacts, though other evidence, cloud or email, may bear on it.

What does it cost?

This evidence is part of the standard forensic report, £800 + VAT for a one-disk system. The first conversation is free.

The record is on the device; preserve it first.

The first conversation is free. Tell us the situation and who owns the device, and we will tell you what the evidence can show, what it cannot, and whether we can take it on. Until then, stop using the device and preserve it as it is.

0800 6890668