Skip to content

Windows Shell Link forensics

Windows LNK Parser & Viewer

Open a Windows .lnk shortcut and inspect its metadata — target path, arguments, timestamps and more.

Files are parsed entirely in your browser with WebAssembly and are never uploaded.

Drop .lnk files, a folder or a ZIP collection

KAPE and Velociraptor ZIPs welcome. Everything stays on this device.

Sample: synthetic shortcuts from a fictional intrusion (host FIN-WKS-07) — no real data. Tip: open “Time range” and pick “Last hour” to zoom on the incident.

  • .lnk shortcuts
  • ZIP collections (KAPE, Velociraptor)
  • Whole folders

How to get your .lnk files

Never collected shortcuts before? One command gathers every .lnk on a Windows machine into a ZIP you can drop here.

  1. Collect with one command
  2. Drop the ZIP or folder here
  3. Nothing leaves your browser

Before you start: Windows 10 (1803+), 11 or Server 2019+. Open Command Prompt or PowerShell with Run as administrator.

Copies every .lnk from all user profiles and the shared Start Menu with their timestamps and folder layout, then zips the result.

robocopy C:\Users C:\triage\lnk\Users *.lnk /S /B /XJ /R:0 /W:0 /NFL /NDL
robocopy "C:\ProgramData\Microsoft\Windows\Start Menu" "C:\triage\lnk\ProgramData\Microsoft\Windows\Start Menu" *.lnk /S /B /XJ /R:0 /W:0 /NFL /NDL
tar -a -cf C:\triage\lnk.zip -C C:\triage lnk

Drop C:\triage\lnk.zip here (or the C:\triage\lnk folder). The folder layout is kept, so each shortcut is filed by user and location.

Gotchas

  • Run as administrator: without it robocopy /B stops with an access error, and other users' profiles are unreadable anyway.
  • Collect before you look around, and never double-click a collected .lnk: opening files on the machine writes new Recent entries, and opening a shortcut runs its target.
  • Target MAC times are read from inside the link (UTC). The .lnk file's own created/modified times live in the file system: robocopy keeps them, a ZIP keeps only the modified time. Collect $MFT if you need them all.

Every field an investigator needs

  • Target path
  • Arguments
  • Working directory
  • Target MAC times
  • Volume & network share
  • Link flags
  • File attributes
  • Extra data blocks

Built for triage

From one shortcut to a whole user profile

Drop a single .lnk to read it, or a full triage collection to review every shortcut a user touched — Recent items, Desktop, Start Menu, Startup and the taskbar.

  • Triage collections in one drop

    ZIPs from KAPE or Velociraptor and whole folders are unpacked in the browser; every .lnk inside is found and filed by location and user.

  • Full-screen workspace

    After the first file the results take over the screen: a sortable, filterable table with resizable and pinnable columns next to the decoded detail.

  • Sessions that survive a reload

    Your analysis is auto-saved in this browser. Name it, reopen it tomorrow, rename or delete it — nothing ever leaves the device.

  • Suspicious shortcuts stand out

    Arguments that launch PowerShell, cmd, mshta or remote URLs, and targets in Temp or AppData, are flagged so malicious .lnk files surface first.

  • Honest about what it skipped

    Files that are not Shell Links get a reason — jump list, empty file, wrong magic bytes, truncated header — instead of a silent failure.

  • Private by construction

    Parsing runs locally in Rust compiled to WebAssembly. No upload, no server, no account: safe for live incident-response evidence.

How it works

  1. 01

    Drop

    A .lnk file, a folder or a ZIP collection. Several at once is fine.

  2. 02

    Decode

    Each shortcut is parsed in your browser with WebAssembly, with live progress for large collections.

  3. 03

    Investigate

    Sort, filter and pin columns, open any shortcut's full structure, then export CSV or JSON.

Where to find .lnk files

Shortcuts Windows creates for you (Recent, Office, taskbar) plus user-made ones (Desktop, Start Menu, Startup). Paths are per user unless noted.

  • Recent itemsVista+%APPDATA%\Microsoft\Windows\Recent\
  • Office recent%APPDATA%\Microsoft\Office\Recent\
  • Desktop (user)%USERPROFILE%\Desktop\
  • Desktop (all users)C:\Users\Public\Desktop\
  • Start Menu (user)%APPDATA%\Microsoft\Windows\Start Menu\Programs\
  • Start Menu (all users)%ProgramData%\Microsoft\Windows\Start Menu\Programs\
  • Startup (user)%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\
  • Startup (all users)%ProgramData%\Microsoft\Windows\Start Menu\Programs\StartUp\
  • Pinned taskbarWin 7+%APPDATA%\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\
  • Recent itemsXPC:\Documents and Settings\<user>\Recent\

How to get them

Read the LNK forensics guide →

LNK Parser is a free online tool to open and read Windows .lnk shortcut files. Drop a file above to view its target path, command-line arguments, working directory, timestamps and link flags. Everything runs locally with WebAssembly — your file never leaves your device, which makes it safe for forensics and incident response.

Artifacts that answer the next question in the same case.

LNK file guides

Blog
Opening a Windows .lnk file usually runs its target, not the shortcut itself. Here is how to inspect the .lnk's actual binary contents safely, in your browser, with PowerShell, or with a hex viewer.
A field guide to the artifacts inside Windows shortcuts — NetBIOS name, droid GUID, target FILETIMEs, volume serials — and how DFIR teams use them.
Why .lnk shortcut files are an attacker's preferred delivery vector, from Stuxnet's CVE-2010-2568 to today's ISO+LNK phishing campaigns, and how to spot a malicious one before it runs.

Frequently asked questions

How do I open a .lnk file?

Drag a Windows .lnk shortcut onto the parser above, or click to browse for one. It decodes the file in your browser and shows the target path, arguments, working directory and timestamps. Nothing is uploaded.

Is it safe to open an .lnk file here?

Yes. The file is parsed entirely on your device with WebAssembly and never leaves your browser, so even a malicious shortcut is only inspected, never executed.

What information does a .lnk shortcut contain?

A Shell Link stores the target path, command-line arguments, working directory, icon location, creation/access/write timestamps, link flags and volume or network information — all of which this parser decodes.

Follow the bearing to the target

Drop a shortcut and see exactly what it pointed to, when, and with which arguments.

Open a .lnk file