
Windows link file (shortcuts) examiner
A forensic tool for Windows link file examinations (i.e. Windows shortcuts)
'lifer' is a Windows or *nix command-line tool inspired by the whitepaper 'The Meaning of Link Files in Forensic Examinations' by Harry Parsonage and available here. It started life as a lightweight tool that I wrote in order to extract certain information from link files to assist in enquiries I was making whilst working as a computer forensic analyst. Now I am retired but I am looking to expand it's usefulness and publish it so that others can benefit.
The information extracted is in accordance with the Microsoft Open Specification Document 'MS-SHLLNK' which can be found online here. At the time of writing most parts of specification version 4.0 are implemented. I do hope to implement the parsing of unopened jump list files in the future.
Details of the files to be found in the Test directory and how to use them is given in the '.\Test\Tests.txt' file. What follows is a brief outline...
Once you have installed the tool, open a command-line shell (e.g. bash or Powershell) and from the './lifer/src' directory type:
lifer -s ./Test/Test1.lnk
This should give the output:
LINK FILE -------------- .\Test\Test1.lnk
{**OPERATING SYSTEM (stat) DATA**}
Last Accessed: 2017-04-18 20:28:19 (UTC)
Last Modified: 2017-04-18 20:28:19 (UTC)
Last Changed: 2017-04-18 20:28:19 (UTC)
{**LINK FILE EMBEDDED DATA**}
{S_2.1 - ShellLinkHeader}
Attributes: 0x00000020 FILE_ATTRIBUTE_ARCHIVE
Creation Time: 2008-09-12 20:27:17 (UTC)
Access Time: 2008-09-12 20:27:17 (UTC)
Write Time: 2008-09-12 20:27:17 (UTC)
Target Size: 0 bytes
{S_2.3 - LinkInfo}
{S_2.3.1 - LinkInfo - VolumeID}
Drive Type: DRIVE_FIXED
Drive Serial No: 307A8A81
Volume Label: [EMPTY]
Local Base Path: C:\test\a.txt
{S_2.4 - StringData}
{S_2.4 - StringData - RELATIVE_PATH}
Relative Path: .\a.txt
{S_2.4 - StringData - WORKING_DIR}
Working Dir: C:\test
{S_2.5 - ExtraData}
{S_2.5.10 - ExtraData - TrackerDataBlock}
MachineID: chris-xps
Droid1: {94C77840-FA47-46C7-B356-5C2DC6B6D115}
Droid2: {7BCD46EC-7F22-11DD-9499-00137216874A}
UUID Sequence: 153
UUID Time: 2008-09-10 10:23:17 (UTC)
UUID Node (MAC): 00:13:72:16:87:4A
NOTE: The section above titled '{OPERATING SYSTEM (stat) DATA}' will have different dates as these will depend on the dates you installed and accessed that link file on your own system. The embedded data will be the same however.
A more fulsome output (including more accurate timestamps) can be obtained by omitting the '-s' option.
The most detail about a link file can be gleaned by using the '-i' option which will print known details about any idlist objects too. This option is not compatible with the '-s' option.
All the link files in a directory (folder) can be parsed by just passing the name of the directory:
lifer ./src/Test/WinXP
(for brevity the output has not been shown).
The most useful output for a number of link files can be created by sending the output as a tab (or comma) separated list to a file that can then be imported into a spreadsheet for analysis at your leisure. This can be achieved like this:
lifer -o tsv ./src/Test/WinXP > WinXP.tsv
or
lifer -so tsv ./src/Test/WinXP > WinXP.tsv
for a file that has some of the superfluous and uninteresting data redacted.
Strings within link files can sometimes contain commas. Because this causes a conflict with the field separator any commas within strings have been replaced with semi-colons (i.e. ',' replaced with ';'). This is only true for the '-o csv' option and not the default '-o txt' or the '-o tsv' and '-o xml' options.
Visit the Releases Page and choose the appropriate executable file for your machine from the latest release and download it. Rename the executable to 'lifer' (or 'lifer.exe' for windows). Ensure it has the correct attributes to run as an executable file and either place it in a folder containing the link files you want to examine or add the location to your PATH variable and you'll be good to go.
The first thing to do is to ensure you have git installed on your machine/device; in a command-line shell, change to your desired project root directory and issue the command:
git clone https://github.com/Paul-Tew/lifer.git
A new directory named 'lifer' will be created.
(This may work for Mac installations but I don't have the kind of money needed to test it out for sure...) Because this tool is pretty basic, the dependencies are minimal, ensure you have the 'gcc' compiler and the relevant 'libc' development libraries installed, that's all. Start a command-line terminal and navigate to the ./lifer/src directory. Issue the command:
gcc -Wall ./lifer.c ./liblife/liblife.c ./libbin2hex/libbin2hex.c -o lifer
Provided no warnings or errors appeared, you should now have an executable file 'lifer' sitting in the directory, you might want to check this by issuing the command:
ls -la
If all is OK then you can test that lifer works by testing it out on the file specified in the Microsoft document which I included as part of the git repository you cloned and should be sitting in the ./Test/ directory. You can do this by issuing the command:
./lifer ./Test/Test.lnk
You can also test that lifer works on a bunch of link files sitting in a directory by issuing the command:
./lifer ./Test/WinXP/
Install the tool onto the OS by issuing the command:
sudo install ./lifer /usr/bin/
This will enable you to use lifer anywhere on your system without specifying the directory prefix (e.g. lifer ./Test/Test.lnk rather than ./lifer ./Test/Test.lnk)