Skip to content

devon-gadarowski/SeeShellsv2

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

SeeShells: Windows Shellbag Timeline Display & Parser

GitHub release (latest by date) GitHub All Releases SeeShells License

SeeShells Logo

SeeShells is a configurable Windows desktop application which focuses on extracting specific Registry data known as ShellBags. SeeShells displays this information in a interactive timeline that highlights user events as they were recorded.

The goal of SeeShell is to assist digital forensics investigators in their course of actions and provide more information that can be used as evidence in a court of law.

In addition to the timeline, SeeShells provides exporting:

  • CSV of all ShelBag information parsed.
  • HTML representation of the timeline
  • PDF for formal forensics reporting

SeeShells operates on both running machines (live) and registry hive files (offline).

Requirements

Configuration

JSON configuration files are used within the SeeShells application to provide information about Windows versions and their registry keys. This ensures that if any new discoveries are found in the future regarding ShellBag information, they can easily be updated in the configuration file, and the program can adjust accordingly.

See the Help Section for modifying SeeShells configurations.

Contributors

v1 Developers

v2 Developers

Sponsor

About

The v2 of SeeShells

Resources

License

Stars

Watchers

Forks

Packages

No packages published

Languages

  • C# 83.1%
  • JavaScript 16.3%
  • HTML 0.6%