Skip to content

registry · setupapi · evtx · LNK

USB device history, stitched together for you

Drop a Windows triage collection. USBSTOR, MountedDevices, setupapi.dev.log, Partition/Diagnostic 1006, Kernel-PnP, LNK, Jump Lists and ShellBags become one timeline per device — with the source of every fact and the places where sources disagree. Parsed in your browser with WebAssembly; nothing is uploaded.

Drop a triage collection, a ZIP or single files

SYSTEM and SOFTWARE hives, setupapi.dev.log, event logs (Partition/Diagnostic, Kernel-PnP, DriverFrameworks, Security, System), NTUSER.DAT / UsrClass.dat, LNK files and Jump Lists. KAPE and Velociraptor layouts work as-is; unrelated files are skipped.

The sample is a synthetic collection from a fictional workstation: a USB stick plugged in by a rogue account during an intrusion, plus two older devices.

Parsed in your browser — nothing is uploaded

How to get your data

Full acquisition guide

USB history is spread over the SYSTEM and SOFTWARE hives, setupapi.dev.log, a few event logs and each user's hive and Recent folder. Collect them together: every source you add confirms or corrects the others.

  1. Collect with one admin command, KAPE or Velociraptor
  2. Drop the folder or the ZIP here
  3. Parsed locally — nothing leaves the browser

On the live host, open PowerShell with “Run as administrator” and paste this block. reg save exports the locked hives; wevtutil exports the event logs (Security filtered to 6416 and 4663); the user hives of logged-on accounts and every profile's Recent folder are copied too.

PowerShell · Admin
$t = 'C:\triage'; New-Item -ItemType Directory -Force $t | Out-Null
reg save HKLM\SYSTEM "$t\SYSTEM" /y; reg save HKLM\SOFTWARE "$t\SOFTWARE" /y
Copy-Item C:\Windows\INF\setupapi.dev*.log $t
'Microsoft-Windows-Partition/Diagnostic','Microsoft-Windows-Kernel-PnP/Configuration','Microsoft-Windows-DriverFrameworks-UserMode/Operational','System' |
  ForEach-Object { wevtutil epl $_ "$t\$($_ -replace '/','%4').evtx" /ow:true }
wevtutil epl Security "$t\Security.evtx" "/q:*[System[(EventID=6416 or EventID=4663)]]" /ow:true
Get-ChildItem Registry::HKEY_USERS | Where-Object PSChildName -match '^S-1-5-21-[\d-]+$' | ForEach-Object {
  reg save "HKU\$($_.PSChildName)" "$t\NTUSER_$($_.PSChildName).DAT" /y
  reg save "HKU\$($_.PSChildName)_Classes" "$t\UsrClass_$($_.PSChildName).dat" /y }
Get-ChildItem C:\Users -Directory | ForEach-Object {
  robocopy "$($_.FullName)\AppData\Roaming\Microsoft\Windows\Recent" "$t\Users\$($_.Name)\AppData\Roaming\Microsoft\Windows\Recent" /S /XJ /R:0 /W:0 /NP /NFL /NDL | Out-Null }

Everything lands in C:\triage. Drop that folder on the page.

Or zip it first to move it off the host (Windows 10 1803+ ships tar):

PowerShell / cmd
tar -a -c -f C:\usb-triage.zip -C C:\ triage

Gotchas

  • Copying SYSTEM or NTUSER.DAT with Explorer fails or gives a file full of zeros while Windows runs: use reg save, KAPE or a raw-copy tool.
  • setupapi.dev.log is in local time. Add the SYSTEM hive so the times are converted; otherwise they are shown as if they were UTC.
  • Event logs roll over: a busy Security.evtx may only cover days. Collect early and keep older .evtx copies from backups or Volume Shadow Copies.
  • reg save only reaches the hives of logged-on users; for everyone else use KAPE / Velociraptor or copy NTUSER.DAT from an image.

What this tool reconstructs

Windows records a removable device in a dozen places, none of them complete. The SYSTEM hive knows the device (USBSTOR, USB, WPDBUSENUM), its drive letter and volume GUID (MountedDevices) and four property timestamps: first install, last install, last arrival and last removal. setupapi.dev.log dates the first installation. The event logs date every connection and removal, and Partition/Diagnostic 1006 even carries the volume boot record, hence the volume serial number. Each user's hive, shortcuts, Jump Lists and ShellBags show who mounted the volume and what was opened on it.

USB Forensics reads all of them in your browser and ties them together per physical device — by serial / instance ID, then volume GUID, then volume serial number — into a device card and one timeline. Every fact carries evidence chips naming the file and the key, record or line it came from, and where sources disagree the tool says so instead of picking one silently.

Artifacts read

  • SYSTEM: Enum\USBSTOR (vendor, product, revision, serial, FriendlyName, ContainerID and the Properties\{83da6326-97a6-4088-9453-a1923f573b29} timestamps 0064 install date, 0065 first install date, 0066 last arrival, 0067 last removal), Enum\USB (VID/PID), Enum\SWD\WPDBUSENUM, MountedDevices, TimeZoneInformation.
  • SOFTWARE: Microsoft\Windows Portable Devices\Devices (volume labels), Windows NT\CurrentVersion\EMDMgmt (label + volume serial), ProfileList (SID → account).
  • C:\Windows\INF\setupapi.dev.log: device installation sections, converted from local time with the SYSTEM time zone.
  • Event logs: Partition/Diagnostic 1006, Kernel-PnP/Configuration 400/410/420/430, DriverFrameworks-UserMode 2003/2100/2101/2102, Security 6416 and 4663, System UserPnp 20001/20003.
  • Per user: NTUSER.DAT MountPoints2, UsrClass.dat ShellBags, Recent\*.lnk, AutomaticDestinations / CustomDestinations Jump Lists.

What it answers

  • Which USB storage devices were ever connected, with make, model, serial (and whether Windows made the serial up).
  • When each one was first installed, and every connection and removal that any source still records.
  • Which drive letters, volume labels and volume serial numbers it had over time, and which accounts mounted it.
  • Which files and folders were opened, written or read on it, and by whom.
  • Findings for triage: a device connected during the incident window, a storage device first seen recently, files copied to or opened from removable media, a device used by an unexpected account.

Limits

  • Registry transaction logs (.LOG1/.LOG2) are not replayed: a dirty hive is flagged, and the newest changes may be missing.
  • Only the current control set is read. Deleted keys and slack space are not recovered.
  • setupapi.dev.log is converted with the SYSTEM time-zone rules; year-specific Dynamic DST rules are not applied, and the Windows XP setupapi.log format is not supported.
  • ShellBags and Security 4663 do not name the device: they are tied to it by drive letter or volume number and time overlap, and marked “inferred”.
  • Loose shortcut files are dated by their last-modified time from the collection; if the copy did not preserve it, rely on the Jump List and the target times shown in the evidence.
  • The engine has been validated on synthetic data and hand-built edge cases; compare with established tools before relying on it in court.

How to collect

  • Quickest: the elevated PowerShell block above (reg save + wevtutil + robocopy) — or KAPE's USBDetective target.
  • Velociraptor: Windows.Triage.Targets with the USBDetective target, then drop the collection ZIP as-is.
  • Disk images: mount read-only and copy the listed files keeping their paths, or drop an FTK Imager export.

FAQ

Are my files uploaded?

No. The parser is Rust compiled to WebAssembly and runs in a Web Worker inside your browser tab. Files are read locally and nothing is sent anywhere.

Why does a serial number contain “&”?

When the second character of a USBSTOR instance ID is “&”, the device reported no usable serial and Windows generated one (for example 7&1f2e3d4c&0). It is unique only on that computer and is not the device's real serial, so match such a device by vendor, product, volume serial number and times.

Which timestamp tells me when a USB stick was plugged in?

Several: the SYSTEM hive's 0066 “last arrival” property gives the latest one, Partition/Diagnostic 1006 and Kernel-PnP events give each connection, setupapi.dev.log and 0065 (FirstInstallDate) give the first. The tool merges them into one connection entry and shows each source as a chip.

How are shortcuts tied to a USB stick?

A shortcut stores the volume serial number of the drive its target was on. The tool reads the same serial from the volume boot record logged in Partition/Diagnostic 1006 and from EMDMgmt, which links the shortcut to the physical device even when drive letters were reused.

What if the sources disagree?

The disagreement is shown on the device card with both values and their sources: for example setupapi and the registry giving different first-install dates after a reinstall, or a registry last-arrival time with no matching event-log record because the logs rolled over.

A fictional intrusion walked through with USB Forensics: find the stick, confirm when it was connected, attribute the account and list the files copied.
Tie shortcuts, Jump Lists, ShellBags and 4663 events to a physical USB device with volume serial numbers, drive letters and time, and name the user.
How to read setupapi.dev.log device install sections, convert their local times to UTC, and compare them with the registry's first install date.