<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>USB Forensics — Blog</title>
    <link>https://www.usbforensics.com/de/blog</link>
    <description>Latest from Blog</description>
    <language>de</language>
    <lastBuildDate>Tue, 29 Sep 2026 14:11:32 GMT</lastBuildDate>
    <atom:link href="https://www.usbforensics.com/de/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>USB-Exfiltration untersuchen: ein durchgespieltes Beispiel</title>
      <link>https://www.usbforensics.com/de/blog/usb-exfiltration-investigation-walkthrough</link>
      <guid isPermaLink="true">https://www.usbforensics.com/de/blog/usb-exfiltration-investigation-walkthrough</guid>
      <description>Ein fiktiver Einbruch, analysiert mit USB Forensics: den Stick finden, das Anschließen datieren, das Konto zuordnen und kopierte Dateien auflisten.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Welche Dateien kamen vom USB-Stick? LNK und Jump Lists</title>
      <link>https://www.usbforensics.com/de/blog/link-files-to-usb-lnk-jumplists-shellbags</link>
      <guid isPermaLink="true">https://www.usbforensics.com/de/blog/link-files-to-usb-lnk-jumplists-shellbags</guid>
      <description>Verknüpfungen, Jump Lists, ShellBags und 4663-Ereignisse über Volume-Seriennummer, Laufwerksbuchstabe und Zeit einem USB-Gerät und Benutzer zuordnen.</description>
      <author>Florian Amette</author>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>setupapi.dev.log: Erstes Anschließen eines USB-Geräts</title>
      <link>https://www.usbforensics.com/de/blog/setupapi-dev-log-usb-first-install</link>
      <guid isPermaLink="true">https://www.usbforensics.com/de/blog/setupapi-dev-log-usb-first-install</guid>
      <description>Installationsabschnitte in setupapi.dev.log lesen, ihre Ortszeiten nach UTC umrechnen und mit dem Erstinstallationsdatum der Registry vergleichen.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Partition/Diagnostic 1006: USB-Geräte und Volume-Serials</title>
      <link>https://www.usbforensics.com/de/blog/partition-diagnostic-1006-volume-serial</link>
      <guid isPermaLink="true">https://www.usbforensics.com/de/blog/partition-diagnostic-1006-volume-serial</guid>
      <description>Ereignis 1006 in Microsoft-Windows-Partition/Diagnostic erfasst USB-Datenträger mit Modell, Seriennummer und Bootsektoren. So lesen Sie es aus.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>USBSTOR-Forensik: Seriennummern und Zeitstempel 0064–0067</title>
      <link>https://www.usbforensics.com/de/blog/usbstor-registry-key-forensics</link>
      <guid isPermaLink="true">https://www.usbforensics.com/de/blog/usbstor-registry-key-forensics</guid>
      <description>Enum\USBSTOR und Enum\USB im SYSTEM-Hive lesen: Hersteller, Produkt, Seriennummer, von Windows erzeugte IDs, ContainerID und Eigenschafts-Zeitstempel.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>USB-Artefakte mit KAPE, Velociraptor oder PowerShell sichern</title>
      <link>https://www.usbforensics.com/de/blog/collect-usb-artifacts-kape-velociraptor</link>
      <guid isPermaLink="true">https://www.usbforensics.com/de/blog/collect-usb-artifacts-kape-velociraptor</guid>
      <description>Was für eine USB-Untersuchung unter Windows zu sichern ist — Hives, setupapi.dev.log, Ereignisprotokolle, Benutzerdateien — und die genauen Schritte.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>USB-Geräteforensik unter Windows: die vollständige Übersicht</title>
      <link>https://www.usbforensics.com/de/blog/usb-device-forensics-windows-guide</link>
      <guid isPermaLink="true">https://www.usbforensics.com/de/blog/usb-device-forensics-windows-guide</guid>
      <description>Alle Windows-Artefakte, die einen USB-Stick erfassen — Registry, setupapi.dev.log, Ereignisprotokolle, LNK, Jump Lists, ShellBags — und ihre Zuordnung.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>