Skip to main content

LnkParse3

Windows Shortcut file (LNK) parser

PRs Welcome PyPI license PyPi Version PyPi Python Versions GitHub last commit

LnkParse3 is a minimalistic python package for forensics of a binary file with LNK extension aka Microsoft Shell Link aka Windows shortcut. It is aimed to dig up as much data as possible and to process even malformed files. It is not able to create or modify files.

Features

  • easy to use
  • CLI tool & package
  • JSON output

Background

This is a fork of lnkfile available here.

Improvements:

  • much more extracted data
  • many bug fixes
  • made to not fail on malformed files

NOTE: master branch history was rewritten and has different commits metadata than the upstream master.

Installation

pip install LnkParse3

Usage

Can be used as a package or as a command line tool. It accepts several arguments, including setting the output format to JSON or a more human-readable form. For all parameters, see the program description below.

usage: lnkparse [-h] [-t] [-j] [-c CP] [-a] FILE

Windows Shortcut file (LNK) parser

positional arguments:
  FILE                  absolute or relative path to the file

optional arguments:
  -h, --help            show this help message and exit
  -t, --target          print target only
  -j, --json            print output in JSON
  -c CP, --codepage CP  set codepage of ASCII strings
  -a, --all             print all extracted data (i.e. offsets and sizes)

CLI tool

$ lnkparse tests/samples/microsoft_example
Windows Shortcut Information:
   Guid: 00021401-0000-0000-C000-000000000046
   Link flags: HasTargetIDList | HasLinkInfo | HasRelativePath | HasWorkingDir | IsUnicode | EnableTargetMetadata - (524443)
   File flags: FILE_ATTRIBUTE_ARCHIVE - (32)
   Creation time: 2008-09-12 20:27:17.101000+00:00
   Accessed time: 2008-09-12 20:27:17.101000+00:00
   Modified time: 2008-09-12 20:27:17.101000+00:00
   File size: 0
   Icon index: 0
   Windowstyle: SW_SHOWNORMAL
   Hotkey: UNSET - UNSET {0x0000}

   ...more data...

   EXTRA:
      DISTRIBUTED LINK TRACKER BLOCK:
         Size: 96
         Length: 88
         Version: 0
         Machine identifier: chris-xps
         Droid volume identifier: 94C77840-FA47-46C7-B356-5C2DC6B6D115
         Droid file identifier: 7BCD46EC-7F22-11DD-9499-00137216874A
         Birth droid volume identifier: 94C77840-FA47-46C7-B356-5C2DC6B6D115
         Birth droid file identifier: 7BCD46EC-7F22-11DD-9499-00137216874A

Python package

>>> import LnkParse3
>>> with open('tests/samples/microsoft_example', 'rb') as indata:
>>> 	lnk = LnkParse3.lnk_file(indata)
>>> 	lnk.print_json()
{
	"data": {
        "relative_path": ".\\a.txt",
        "working_directory": "C:\\test"
    },
    "extra": {
        "DISTRIBUTED_LINK_TRACKER_BLOCK": {
            "birth_droid_file_identifier": "7BCD46EC-7F22-11DD-9499-00137216874A",
            "birth_droid_volume_identifier": "94C77840-FA47-46C7-B356-5C2DC6B6D115",
            "droid_file_identifier": "7BCD46EC-7F22-11DD-9499-00137216874A",
            "droid_volume_identifier": "94C77840-FA47-46C7-B356-5C2DC6B6D115",
            "length": 88,
            "machine_identifier": "chris-xps",
            "size": 96,
            "version": 0
        }
    },
	...more data...
}

Extracted data

List of data in LNK structure and their current status of implementation. For more information about each data, see Microsoft LNK documentation and Shell item format specification.

  • ShellLinkHeader [lnk_header.py]
  • LinkTargetIDList [lnk_targets.py]
    • RootFolder [root_folder.py] (incomplete)
    • CommonPlacesFolder [common_places_folder.py]
    • CompressedFolder [compressed_folder.py]
    • ControlPanel [control_panel.py]
    • Internet [internet.py]
    • MyComputer [my_computer.py]
    • NetworkLocation [network_location.py]
    • Printers [printers.py]
    • ShellFSFolder [shell_fs_folder.py] (incomplete)
    • UsersFilesFolder [users_files_folder.py]
  • LinkInfo [lnk_info.py]
    • Local [local.py]
    • Network [network.py]
  • StringData [string_data.py]
  • ExtraData [extra_data.py]
    • ConsoleDataBlock [console.py]
    • ConsoleFEDataBlock [code_page.py]
    • DarwinDataBlock [darwin.py]
    • EnvironmentVariableDataBlock [environment.py]
    • IconEnvironmentDataBlock [icon.py]
    • KnownFolderDataBlock [known_folder.py]
    • PropertyStoreDataBlock [metadata.py] (incomplete)
    • ShimDataBlock [shim_layer.py]
    • SpecialFolderDataBlock [special_folder.py]
    • TrackerDataBlock [distributed_tracker.py]
    • VistaAndAboveIDListDataBlock [shell_item.py]
    • Unknown (undefined) block [unknown.py]
    • TerminalBlock [terminal.py]

Contributing

Any contribution is welcome. There are still several uncovered parts of LNK Structure. Just fork the project and open a new PR.

Tests

To run tests without installing any dependencies, just run:

python -m unittest discover tests

If you want to use pytest, install it via pip and run:

pytest tests

Also, to see code coverage in HTML output, run:

pytest --cov=LnkParse3 tests --cov-fail-under=80 --cov-report=html --no-cov-on-fail

Code

Make sure to run ruff auto-formatter and linter before opening a PR. It will keep the code in good shape.

Also, it would be nice to try to make meaningful commit messages and atomic commits.

Authors and acknowledgment

Many thanks to the project's founder @silascutler as well as to @ernix for such a good job refactoring and improving the code.

Related projects

Here is a list of other available LNK parsers:

  • pylnk3 - console application and package in Python 3
  • lnk-parse - console application in Perl
  • pylnker - console application and package in Python 2, based on lnk-parse
  • liblnk - robust C library with Python 2/3 bindings

License

Distributed under the MIT License. See LICENSE for more information.

Contact

matusjas.work@gmail.com

Source - https://github.com/Matmaus/LnkParse3

Metadata

Release files for LnkParse3 1.6.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for LnkParse3 1.6.0
File Size Uploaded
lnkparse3-1.6.0.tar.gz 35.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for LnkParse3 1.6.0
File Interpreter ABI Platform
lnkparse3-1.6.0-py3-none-any.whl Python 3 none any Details

Total release size: 88.2 kB

Release files / lnkparse3-1.6.0.tar.gz

Download URL lnkparse3-1.6.0.tar.gz
Size 35.6 kB
Tags Source
SHA-256 checksum
How to use checksums
519e6af6193b3d1802e1ec118a531ee3ca5a39d31137b507c0f19a0d437bd8ba
BLAKE2b-256 checksum
How to use checksums
47080ab4666bcc6ce5aa43642cc6c75e1718417911952c0667d6c19eec0fbcd5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.25

Release files / lnkparse3-1.6.0-py3-none-any.whl

Download URL lnkparse3-1.6.0-py3-none-any.whl
Size 52.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7b3b1289e99992a4d3901d80ac9ab87fa8de854b2bffe5c4011453b093038b50
BLAKE2b-256 checksum
How to use checksums
477f3998a1902e88b556679118cdc052fd87ee180b8782c925585e77a176371a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.25

Release history Release notifications | RSS feed

This release

1.6.0 This release

2 release files

1.5.3

2 release files

1.5.2

2 release files

1.5.1

2 release files

1.5.0

2 release files

1.4.0

2 release files

1.3.3

2 release files

1.3.2

2 release files

1.3.1

2 release files

1.3.0

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.0

1 release file

0.3.3

1 release file

0.3.2

1 release file

0.3.1

1 release file

0.3.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page