Loads the "information on the files and folders recently opened or executed with Windows Explorer by the user” stored in the registry. With the loaded data, you can check information on files and folders opened or executed by the user and whether documents and folders have been executed. You can also use it to identify the user's behavior.
- Path to the registry file. If you provided the
zippathoption, input the file path in the ZIP file.
- Path to the ZIP file.
After running the
reg-recent-files command, the output fields are as follows:
|last_written||Date||Last written time|
|order||Integer||File order by extension|
Retrieve by providing the file path.
Retrieve when the
zippathoption is provided.
reg-recent-docs zippath=/opt/logpresso/testdata/registry.zip registry/test/NTUSER.DAT
orderby file extension.
reg-recent-docs /opt/logpresso/testdata/registry/test/NTUSER.DAT | sort file_ext, order