Pinned Tweet
The SILENT WITNESS ON YOUR COMPUTER WAITING FOR YOU TO GET INTO TROUBLE.
Most people believe that deleting a folder, clearing recent files, or wiping their history is enough to hide their tracks on a computer. What they don’t realize is that Windows quietly keeps a hidden record of the folders they open, even after those folders are deleted or the drive is removed. These records are called Shellbags, and they are one of the most powerful and incriminating artifacts available to forensic investigators.
Shellbags appear inside two registry hives NTUSER.DAT and USRCLASS.DAT and they store detailed information about a user’s folder-browsing activity. This includes local folders, USB drives, external hard drives, network shares, and even directories that no longer exist. Each time a user opens a folder in Windows Explorer, the system automatically creates or updates a Shellbag entry. These entries contain timestamps, folder paths, the hierarchy of subfolders, the order in which a folder was accessed, and even the specific view settings used by the user. Because of this, Shellbags reconstruct a user’s exact navigation trail long after the person believes the evidence is gone. What makes Shellbags truly dangerous is the fact that they survive actions that users typically rely on to cover their tracks.
Deleting a folder does not delete the Shellbag. Formatting a drive does not delete it. Even privacy tools and cleaners like CCleaner or BleachBit cannot reliably erase Shellbag data, because the information is deeply embedded within registry hives that standard cleaning utilities do not touch. The only way to remove Shellbags is through advanced forensic wiping, and attempting such wiping is, in itself, a sign of suspicious behavior.
Forensic examiners rely heavily on Shellbags because they expose the truth even when a suspect tries to lie.
If a person denies ever accessing a directory, the Shellbags can show when that folder was opened, how many times it was accessed, and whether it was located on an internal drive, an external USB, or a deleted partition. This makes Shellbags extremely valuable in investigations involving insider threats, data theft, fraud, child exploitation, unauthorized data access, and corporate disputes. In many cases, Shellbags become the deciding factor that disproves a suspect’s story. In the screenshot, the highlighted red section shows three important keys inside the registry.
When all of this information is combined, Shellbags become a silent witness that never forgets. They reconstruct a hidden story of user activity that the person cannot deny, overwrite, or talk their way out of. This is why Shellbags remain one of the most feared artifacts for anyone attempting to conceal their actions on a Windows computer. You can delete the folder… but Shellbags still show it existed
Even if you format a drive or delete the directory, Windows has already logged:
1. The folder name
2. Its full path
3. When it was opened
4. How many times it was opened
5. The view settings (icon mode, window size)
6. The order in which folders were browsed
This means forensic investigators can prove someone accessed:
“Secret” directories
Hidden folder structures
USB drives or removable media
Folder paths used for storage of illicit or suspicious
Folder paths used for storage of illicit or suspicious data even if the folders are long gone.
Nana Sei Anyemedu retweeted
My colleague sent me a zip file and after trying to extract it i got to know its password protected💀meaning without the password i can’t extract it, my colleague also didn’t send me the password he just sent the zip and varnished🌚
Nana Sei Anyemedu retweeted
Poland’s Orlen lost $230 MILLION in a failed Venezuelan oil deal, with tens of millions in Tether reportedly being handed to brokers via USB sticks.
Nana Sei Anyemedu retweeted
My colleague @CyberSamuraiDev sent me a protected zip file and before i can access it i need the password but here is the case he didn’t add the password for me so i decided to crack and find the password…
Pretty sure something else is hidden i’d be back
The amount of data that can be recovered from a gaming console is honestly quite alarming. A forensic dump of its HDD can reveal user accounts, browsing activity, messages, network information, saved credentials, gameplay history, timestamps, and other valuable digital evidence. Gaming consoles are not just entertainment devices they can be significant sources of forensic evidence.
Funny enough, I once met someone pursuing a master’s degree in Cybersecurity and Digital Forensics. I asked him which forensic tools they had received practical training on, and he mentioned Autopsy.
But even with Autopsy, the lecturer only assigned it to them as a presentation topic there was no proper hands-on training😂😂.
At that point, I just felt shy on behalf of the institution. How can someone be pursuing a master’s degree in Digital Forensics without practical exposure to the essential tools of the profession? Even the open source ones.
Then I asked on Kali Linux, he said he was going to pay someone to setup for him because they were given links to download VMware or virtual box plus the kali. But he’s not the only one with such experience; I’ve come across some people who do these same programmes and Charley kali Linux sef they don’t even know what it is and those who know sef nothing better.
Some training institutions or universities in Ghana charge between GHS 15,000 and GHS 29,000 for MSc Cybersecurity or MSc Information Security programmes, yet many lack properly equipped cybersecurity laboratories and some have no practical labs or centers at all.
When institutions collect such substantial fees without investing in the infrastructure required for practical training, students may graduate with impressive certificates but limited real-world competence.
In many African corporate environments, competence and hard work alone may not be enough to get you to the top. You should know how to FANFOOL😂.
Office politics, excessive flattery and pleasing the right people often carry more weight than genuine performance. Unfortunately, only a few people rise purely on merit; for many others, success seems to require mastering the art of pretence and bootlicking.
Nana Sei Anyemedu retweeted
Can @wode_maya go to the USA and set up a whole school with market and build houses for USA teachers?
Sometimes we need to be very critical about certain things o...
We are going to HOST the BIGGEST DFIR CTF Challenge in the whole of West Africa early next year God willing💪🏻
I am waiting for that tech content creator to post “How to hack WhatsApp in 5 mins”.
I have search TikTok saaaa I no dey find anyone😂😂
Nana Sei Anyemedu retweeted
Only 6 days to go!
The 7th batch of our Digital Forensics and Investigations (DFI) class begins soon.
Register now through our website and enjoy a 30% discount.
Link: hivesecurityconsult.com/chec…
Choose the 70% payment.
Please note:
The training is hybrid, and classes are held only on weekends from 4:00 p.m. to 6:00 p.m.
Secure your spot today!
“You are making the government unpopular“😂😂
This gyimi kasa I hear some keep ooo😂😂
Nana Sei Anyemedu retweeted
Replying to @RedHatPentester
Person wey teach us dey ask how we dey do am ey 😂😭
But my students are good ooo. Eiiii Charley how you and Philip @mrphilghana dey do am😂😂🙏🏾
I demonstrated layered steganography technique in Kali Linux.
A password protected 𝒔𝒆𝒄𝒓𝒆𝒕.𝒕𝒙𝒕 was hidden inside cat.jpg. Then cat.jpg was hidden inside GOATS.jpg, leaving a single, ordinary JPG as the only visible file after the originals were deleted.
Here's what makes it interesting
GOATS.jpg functioned completely normally, even while carrying another image. The hidden cat.jpg also functioned normally after extraction. The recovered secret.txt opened normally as well.
Three working files, two layers of hidden data, one carrier image. A file behaving normally is not evidence that it's clean. Sometimes the evidence is hiding inside the evidence.
Nana Sei Anyemedu retweeted
Replying to @RedHatPentester
Hybrid forensics training with a real discount window is rare. Hands-on beats another slide deck every time.
ACTIVE DIRECTORY HACKING
BloodHound Never Lies: Exposing Hidden Routes to Domain Admin
Attackers don't break in; they log in. And more often than not, they follow a path that was hiding in plain sight all along.
In this session, we're diving deep into how adversaries use BloodHound to map hidden routes to Domain Admin, the relationships, permissions, and misconfigurations that quietly hand over the keys to your environment. More importantly, we'll look at how defenders can find and close these paths before an attacker does.
Whether you're on the red team mapping attack paths, the blue team hardening Active Directory, or somewhere in between, this one's for you.
Saturday, September 26, 2026
8:00 PM – 9:00 PM (GMT)
Join here: lnkd.in/d8iWW9tV
#BloodHound #ActiveDirectory #CyberSecurity #RedTeam #BlueTeam #DomainAdmin #PrivilegeEscalation #HiveConsult
Nana Sei Anyemedu retweeted
Replying to @RedHatPentester
If the politicians do it today, what will they do tomorrow. You gerrit? 🤣🤣🤣🤣
Only 6 days to go!
The 7th batch of our Digital Forensics and Investigations (DFI) class begins soon.
Register now through our website and enjoy a 30% discount.
Link: hivesecurityconsult.com/chec…
Choose the 70% payment.
Please note:
The training is hybrid, and classes are held only on weekends from 4:00 p.m. to 6:00 p.m.
Secure your spot today!