reg-opensave-files

Loads the "information on the files recently opened or saved with the Windows Explorer public dialog box" stored in the registry and information on the files that you opened or saved through web browsers and applications. You can see files recently opened or saved by the user with the data you loaded.

Syntax

reg-opensave-files [zippath=ZIPFILE_PATH] FILE_PATH
Required Parameters
FILE_PATH
Path to the registry file. If you provided the zippath option, input the file path in the ZIP file.
Optional Parameters
zippath=ZIPFILE_PATH
Path to the ZIP file.

Description

After running the reg-opensave-files command, the output fields are as follows:

FieldTypeDescription
file_pathStringFile path
file_extStringFile extension
file_sizeStringFile volume
access_atDateLast access time
created_atDateCreation time
modified_atDateLast modification time
mft_entry_indexBinaryMFT entry index
ntfs_seqIntegerNTFS sequnce
last_writtenDateLast written time
orderIntegerFile order by extension

Usage

  1. Retrieve by providing the file path.

    reg-opensave-files /opt/logpresso/testdata/registry/test/NTUSER.DAT
    
  2. Retrieve when the zippath option is provided.

    reg-opensave-files zippath=/opt/logpresso/testdata/registry.zip registry/test/NTUSER.DAT
    
  3. Sort the order by file extension.

    reg-opensave-files /opt/logpresso/testdata/registry/test/NTUSER.DAT
    | sort file_ext, order