Windows Shell Link forensics
Windows LNK Parser & Viewer
Open a Windows .lnk shortcut and inspect its metadata — target path, arguments, timestamps and more.
Files are parsed entirely in your browser with WebAssembly and are never uploaded.
Drop .lnk files, a folder or a ZIP collection
KAPE and Velociraptor ZIPs welcome. Everything stays on this device.
Sample: synthetic shortcuts from a fictional intrusion (host FIN-WKS-07) — no real data. Tip: open “Time range” and pick “Last hour” to zoom on the incident.
- .lnk shortcuts
- ZIP collections (KAPE, Velociraptor)
- Whole folders
How to get your .lnk files
Never collected shortcuts before? One command gathers every .lnk on a Windows machine into a ZIP you can drop here.
- Collect with one command
- Drop the ZIP or folder here
- Nothing leaves your browser
Before you start: Windows 10 (1803+), 11 or Server 2019+. Open Command Prompt or PowerShell with Run as administrator.
Copies every .lnk from all user profiles and the shared Start Menu with their timestamps and folder layout, then zips the result.
robocopy C:\Users C:\triage\lnk\Users *.lnk /S /B /XJ /R:0 /W:0 /NFL /NDL
robocopy "C:\ProgramData\Microsoft\Windows\Start Menu" "C:\triage\lnk\ProgramData\Microsoft\Windows\Start Menu" *.lnk /S /B /XJ /R:0 /W:0 /NFL /NDL
tar -a -cf C:\triage\lnk.zip -C C:\triage lnkDrop C:\triage\lnk.zip here (or the C:\triage\lnk folder). The folder layout is kept, so each shortcut is filed by user and location.
KAPE: LnkFilesAndJumpLists target (elevated prompt, in the KAPE folder)
kape.exe --tsource C: --tdest C:\triage\kape --target LnkFilesAndJumpListsDrop the C:\triage\kape folder. The jump lists it also collects are listed as skipped, with a link to the Jump List parser. Need Startup, Start Menu or taskbar shortcuts too? Check the target's paths, or use the quickest command, which takes every .lnk under C:\Users.
Velociraptor: Windows.Triage.Targets artifact (Velociraptor Triage project) with LNKFilesAndJumpLists
From the server GUI (New collection) or an offline collector (Server Artifacts → Build offline collector), select that artifact, tick the LNKFilesAndJumpLists target, then drop the collection ZIP as is: Velociraptor's uploads/auto/C%3A/… paths are decoded.
Older Velociraptor releases: formerly Windows.KapeFiles.Targets, from the command line
velociraptor.exe artifacts collect Windows.KapeFiles.Targets --args LnkFilesAndJumpLists=Y --output C:\triage\lnk-velociraptor.zipDrop the output ZIP as is.
Windows: mount the E01 or raw image read-only (FTK Imager › File › Image Mounting, or Arsenal Image Mounter), then run against its drive letter
robocopy E:\Users C:\triage\lnk\Users *.lnk /S /B /XJ /R:0 /W:0 /NFL /NDL
robocopy "E:\ProgramData\Microsoft\Windows\Start Menu" "C:\triage\lnk\ProgramData\Microsoft\Windows\Start Menu" *.lnk /S /B /XJ /R:0 /W:0 /NFL /NDL
tar -a -cf C:\triage\lnk.zip -C C:\triage lnkReplace E: with the letter of the mounted Windows partition, then drop C:\triage\lnk.zip.
Linux / macOS: Windows partition mounted read-only at /mnt/windows
cd /mnt/windows && find Users ProgramData/Microsoft/Windows -iname '*.lnk' | zip ~/lnk.zip -@Drop ~/lnk.zip. XP images keep profiles under Documents and Settings: put that folder in the find command instead of Users ProgramData/….
Plain files, not locked: every location is under C:\Users\<user>\ or C:\ProgramData\. AppData is hidden: paste the path into the Explorer address bar.
- Recent itemsVista+
%APPDATA%\Microsoft\Windows\Recent\ - Office recent
%APPDATA%\Microsoft\Office\Recent\ - Desktop (user)
%USERPROFILE%\Desktop\ - Startup (user)
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ - Startup (all users)
%ProgramData%\Microsoft\Windows\Start Menu\Programs\StartUp\ - Pinned taskbarWin 7+
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\ - Recent itemsXP
C:\Documents and Settings\<user>\Recent\
Drop them together, as a whole folder or a ZIP, and keep the Users\<user>\… layout: that is how each shortcut gets its user and location.
Worth collecting alongside: $MFT records each .lnk file's own created/modified times for your timeline, and jump lists (Recent\AutomaticDestinations, Recent\CustomDestinations) embed LNK streams: use the Jump List parser
Gotchas
- Run as administrator: without it
robocopy /Bstops with an access error, and other users' profiles are unreadable anyway. - Collect before you look around, and never double-click a collected .lnk: opening files on the machine writes new Recent entries, and opening a shortcut runs its target.
- Target MAC times are read from inside the link (UTC). The .lnk file's own created/modified times live in the file system: robocopy keeps them, a ZIP keeps only the modified time. Collect
$MFTif you need them all.
Every field an investigator needs
- Target path
- Arguments
- Working directory
- Target MAC times
- Volume & network share
- Link flags
- File attributes
- Extra data blocks
Built for triage
From one shortcut to a whole user profile
Drop a single .lnk to read it, or a full triage collection to review every shortcut a user touched — Recent items, Desktop, Start Menu, Startup and the taskbar.
Triage collections in one drop
ZIPs from KAPE or Velociraptor and whole folders are unpacked in the browser; every .lnk inside is found and filed by location and user.
Full-screen workspace
After the first file the results take over the screen: a sortable, filterable table with resizable and pinnable columns next to the decoded detail.
Sessions that survive a reload
Your analysis is auto-saved in this browser. Name it, reopen it tomorrow, rename or delete it — nothing ever leaves the device.
Suspicious shortcuts stand out
Arguments that launch PowerShell, cmd, mshta or remote URLs, and targets in Temp or AppData, are flagged so malicious .lnk files surface first.
Honest about what it skipped
Files that are not Shell Links get a reason — jump list, empty file, wrong magic bytes, truncated header — instead of a silent failure.
Private by construction
Parsing runs locally in Rust compiled to WebAssembly. No upload, no server, no account: safe for live incident-response evidence.
How it works
- 01
Drop
A .lnk file, a folder or a ZIP collection. Several at once is fine.
- 02
Decode
Each shortcut is parsed in your browser with WebAssembly, with live progress for large collections.
- 03
Investigate
Sort, filter and pin columns, open any shortcut's full structure, then export CSV or JSON.
Where to find .lnk files
Shortcuts Windows creates for you (Recent, Office, taskbar) plus user-made ones (Desktop, Start Menu, Startup). Paths are per user unless noted.
- Recent itemsVista+
%APPDATA%\Microsoft\Windows\Recent\ - Office recent
%APPDATA%\Microsoft\Office\Recent\ - Desktop (user)
%USERPROFILE%\Desktop\ - Desktop (all users)
C:\Users\Public\Desktop\ - Start Menu (user)
%APPDATA%\Microsoft\Windows\Start Menu\Programs\ - Start Menu (all users)
%ProgramData%\Microsoft\Windows\Start Menu\Programs\ - Startup (user)
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ - Startup (all users)
%ProgramData%\Microsoft\Windows\Start Menu\Programs\StartUp\ - Pinned taskbarWin 7+
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\ - Recent itemsXP
C:\Documents and Settings\<user>\Recent\
How to get them
- Step-by-step collection commands (robocopy, KAPE, Velociraptor, disk image)
Recent\AutomaticDestinationsandRecent\CustomDestinationshold jump lists with embedded LNK streams, not standalone .lnk files: use the Jumplist parser
LNK Parser is a free online tool to open and read Windows .lnk shortcut files. Drop a file above to view its target path, command-line arguments, working directory, timestamps and link flags. Everything runs locally with WebAssembly — your file never leaves your device, which makes it safe for forensics and incident response.
Related tools
Artifacts that answer the next question in the same case.
LNK file guides
BlogFrequently asked questions
How do I open a .lnk file?
Drag a Windows .lnk shortcut onto the parser above, or click to browse for one. It decodes the file in your browser and shows the target path, arguments, working directory and timestamps. Nothing is uploaded.
Is it safe to open an .lnk file here?
Yes. The file is parsed entirely on your device with WebAssembly and never leaves your browser, so even a malicious shortcut is only inspected, never executed.
What information does a .lnk shortcut contain?
A Shell Link stores the target path, command-line arguments, working directory, icon location, creation/access/write timestamps, link flags and volume or network information — all of which this parser decodes.
Follow the bearing to the target
Drop a shortcut and see exactly what it pointed to, when, and with which arguments.
Open a .lnk file