reg-recent-docs

Loads the "information on the files and folders recently opened or executed with Windows Explorer by the user” stored in the registry. With the loaded data, you can check information on files and folders opened or executed by the user and whether documents and folders have been executed. You can also use it to identify the user's behavior.

Syntax

reg-recent-docs [zippath=ZIPFILE_PATH] FILE_PATH
Required Parameters
FILE_PATH
Path to the registry file. If you provided the zippath option, input the file path in the ZIP file.
Optional Parameters
zippath=ZIPFILE_PATH
Path to the ZIP file.

Description

After running the reg-recent-files command, the output fields are as follows:

FieldTypeDescription
file_nameStringFile name
file_extStringFile extension
last_writtenDateLast written time
orderIntegerFile order by extension

Usage

  1. Retrieve by providing the file path.

    reg-recent-docs /opt/logpresso/testdata/registry/test/NTUSER.DAT
    
  2. Retrieve when the zippath option is provided.

    reg-recent-docs zippath=/opt/logpresso/testdata/registry.zip registry/test/NTUSER.DAT
    
  3. Sort the order by file extension.

    reg-recent-docs /opt/logpresso/testdata/registry/test/NTUSER.DAT
    | sort file_ext, order