Once in a while, I’ll stumble on a question online (or get an email) from a person wondering “Who the heck is leeholm16?”
If you’re reading this post, you’re likely one of them :)
I never know exactly what situation leads people to ask the question, but they’ve invariably started using a forensic parsing tool against Windows PowerShell.lnk or Windows PowerShell (x86).lnk. For example, here is the forensic analysis of the LNK file included in a SANS408 course. It comes from lp.exe by TZWorks.






