> For the complete documentation index, see [llms.txt](https://nk0.gitbook.io/dfir/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://nk0.gitbook.io/dfir/windows/forensics/evidence-of-execution/jumplists.md).

# JumpLists

Shows which files certain applications interacted with. Useful for tracking TA behavior.

{% embed url="<https://forensafe.com/blogs/jumplist.html>" %}

File Location:

* C:\\%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent
* C:\Users\USERNAME\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations
* C:\Users\USERNAME\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations

### Parse Data

{% code overflow="wrap" %}

```
JLECmd.exe -d F:\Tools\Investigation\jplists\ --csv F:\Tools\Investigation\JumpOutput.csv
```

{% endcode %}

* Shows MRU positions and how many entries are in Jump List.
* C and M timestamp data is included.

<figure><img src="https://3278866189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fu4e057u3LTRKJEHFetwE%2Fuploads%2FE3pTPqxeV736jbpDyYuR%2Fimage.png?alt=media&amp;token=7a20da1b-6b8f-49ca-b539-360b44985ca6" alt=""><figcaption></figcaption></figure>

### Considerations

<figure><img src="https://3278866189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fu4e057u3LTRKJEHFetwE%2Fuploads%2FlDWxT1hltUC4a9Pt3SdE%2Fimage.png?alt=media&amp;token=bc4ef111-2f3b-4d8e-b901-901c3bd4b9e1" alt=""><figcaption></figcaption></figure>

* Jump Lists show most recently opened file with an application. (They are just lnk files).
* AutomaticDestination are recents.

<figure><img src="https://3278866189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fu4e057u3LTRKJEHFetwE%2Fuploads%2F1PEJzlVhuHNndGOg3HRt%2Fimage.png?alt=media&amp;token=98f24ee7-662d-4a3f-9859-b63f09efee4b" alt=""><figcaption></figcaption></figure>

* Pinned files are stored in a CustomDestination Jump List

<figure><img src="https://3278866189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fu4e057u3LTRKJEHFetwE%2Fuploads%2FsiqYav4uW70YCqYW5Y4B%2Fimage.png?alt=media&amp;token=9a2c2833-9813-4716-b175-8d0942a2105a" alt=""><figcaption></figcaption></figure>

* Each file in Jump Lists will contain an App ID (Application Identifier) that will show what application stored the lnk file.

<figure><img src="https://3278866189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fu4e057u3LTRKJEHFetwE%2Fuploads%2FIZZatUDLbaXQ2D5bUGBm%2Fimage.png?alt=media&amp;token=ce9881a9-e89e-452d-9dc2-02506a56dc3e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3278866189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fu4e057u3LTRKJEHFetwE%2Fuploads%2F1cMo1L4mH4jUsR7qMnMt%2Fimage.png?alt=media&amp;token=e521be1c-bd15-4f05-9a16-94bdc97f9545" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3278866189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fu4e057u3LTRKJEHFetwE%2Fuploads%2FtQvcsxQGsBwdK5qpyfID%2Fimage.png?alt=media&amp;token=47ff1261-17d2-49f0-8824-18246cd88680" alt=""><figcaption></figcaption></figure>

### Gotchas:

* Unlike automatic jump lists, custom jump lists aren't always created at the time of application creation.
* Be careful about using LNK target timestamps, they often refer to the application timestamps rather than the opened document.
* Jump lists can persist after the uninstallation of an app.

### Anti-Forensics

* Delete Folders.
