What is the “User MRU” Windows forensic artifact?

Windows keeps a family of “Most Recently Used” lists inside each user’s registry hive (NTUSER.DAT), recording actions the user performed personally and interactively. These include RunMRU (commands typed into the Run dialog), TypedPaths (addresses typed directly into the Explorer address bar), OpenSavePIDsMRU and LastVisitedPIDsMRU (files and folders chosen through open/save dialogs), and RecentDocs (recently opened documents). Each entry is ordered and timestamped, forming a compact record of what the user deliberately chose to do.

For a DFIR investigator, MRU data carries a unique evidentiary weight: it separates human intent from background process noise. A program touching a file proves execution; a user typing the path to a sensitive share, or manually selecting a file in a save dialog, proves knowledge and intent. Because these lists are written by Explorer itself — the shell the user actually interacted with — they are difficult to plausibly deny and frequently survive attempts to cover tracks.


Enterprise Forensic Applications

User MRU analysis shines in insider threat and HR investigations, where intent is everything. During Insider Risk & HR Investigations, TensorGuard correlates MRU entries with staging and exfiltration artifacts to show not merely that sensitive data moved, but that a specific person navigated to it on purpose — typed the path, ran the command, chose the file. In compromise investigations, RunMRU entries frequently preserve the exact moment an attacker went hands-on-keyboard, capturing commands and paths that no automated tooling would ever produce.


Collecting, Decoding, and Viewing “User MRU” with TensorGuard

  1. Create a TensorGuard account and sign in to the TensorGuard console at https://app.tensorguard.com.
  2. Select “Case Manager”, then the plus button to create a case. This will contain your enrolled devices, their reports, and any manually submitted collections.
  3. Linked inside the case menu, download the TensorGuard Forensic Collector and run it on your target system.
  4. In the console, click the plus button for “New Enrollment”, copy the enrollment key, and paste it into the TensorGuard Forensic Collector on your target device.
  5. Now that you have a device enrolled, select the device(s), and click “Send Signal”. Answer the questions regarding what you want to look for in the analysis, any alerting on positive findings, and if the collection and analysis should be recurring.
  6. Once the report is generated, you’ll have User MRU delivered in the browser, alongside an executive summary and timeline of findings.

Get Started

TensorGuard™ is a trademark of TensorGuard Inc. All other trademarks are the property of their respective owners. The information provided on this website is for educational and informational purposes only and does not constitute legal, forensic, or professional advice. Due to the complexities of Digital Forensics and potential legal implications, you should always consult with qualified legal counsel or a certified digital forensics expert before taking action based on findings.

User MRU Forensic Integration Logo

User MRU

Windows

The registry’s “Most Recently Used” lists — Run dialog commands, typed Explorer paths, and recently opened files — direct evidence of deliberate, interactive user action.

Start with a Compromise Assessment.

One flat fee, fully credited toward a subscription. We conduct a complete, AI-driven Compromise Assessment across your critical systems — with evidence-linked findings your team can validate in minutes.

TensorGuard Automated DFIR Platform Dashboard