reg-opensave-files
Loads the "information on the files recently opened or saved with the Windows Explorer common dialog box" stored in the registry file and information on the files you opened or saved through web browsers and applications. Using this command, you can see files recently opened or saved by the user.
Syntax
reg-opensave-files [zipcharset=CHARSET] [zippath=ZIPFILE_PATH] FILE_PATH
Required Parameter
FILE_PATH
- Path to the registry file. Using a wildcard (
*
) in the file name, you can retrieve all files containing a specific string pattern in the file name (e.g.:\data\registry\*.DAT
). If you provided thezippath
option, input the DAT file path in the ZIP file.
Optional Parameter
zipcharset=CHARSET
- Character set to be used to decode the ZIP entry name and comment that are not encoded by UTF-8 encoding. Use the preferred MIME name or aliases registered in the following document: http://www.iana.org/assignments/character-sets/character-sets.xhtml
zippath=ZIPFILE_PATH
- Path to the ZIP file
Description
The output fields are as follows:
Field | Type | Description |
---|---|---|
file_path | String | File path |
file_ext | String | File extension |
file_size | String | File volume |
access_at | Date | Last access time |
created_at | Date | Creation time |
modified_at | Date | Last modification time |
mft_entry_index | Binary | MFT entry index |
ntfs_seq | Integer | NTFS sequence |
last_written | Date | Last written time |
order | Integer | File order by extension |
Usage
-
Retrieve information by providing the file path.
reg-opensave-files D:\data\registry\NTUSER.DAT
-
Retrieve information when the
zippath
option is provided.reg-opensave-files zippath=D:\data\registry.zip registry\NTUSER.DAT
-
Sort the
order
field by file extension.reg-opensave-files D:\data\registry\NTUSER.DAT | sort file_ext, order