File: <SYSTEMDRIVE>:\Users\<USERNAME>\NTUSER.dat

Registry key:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery

Overview

Introduced in Windows 7, and not present in Windows Server operating systems, the WordWheelQuery registry key tracks the keywords searched in the Windows Explorer search box, potentially resulting in files or folders access.

Information of interest

Each term / keywords entered is stored in a dedicated value under the Explorer\WordWheelQuery key (as a unicode string).

The values are ordered in temporal order, in a Most recently used (MRU) list, with the most recently entered term having the position of 0.

The last write timestamp of the key indicates the timestamp of the most recently entered term.

References



View on GitHub