Shellbags record how users interact with folders in Explorer, including view settings, and they persist after a folder is deleted or a drive is disconnected. The skill explains where the data lives: BagMRU and Bags keys inside `NTUSER.DAT` and `UsrClass.dat`, with BagMRU holding a numbered tree of Shell Items that encode type, short and long names, timestamps and NTFS MFT references.
Analysis uses the EZ Tools command-line SBECmd and Shellbags Explorer to reconstruct folder access history, including removable media and network shares, for digital forensics and incident response work. Helper scripts (`scripts/agent.py`, `scripts/process.py`), a report template and reference files on workflows, standards and an API come with it. Listed prerequisites are familiarity with forensics concepts, a lab environment, Python 3.8 or newer, and proper authorization for any testing.