Skip to content

USB forensics · guides

Blog

Guides to USB device forensics on Windows: registry keys, event logs, setupapi and user artifacts.

A fictional intrusion walked through with USB Forensics: find the stick, confirm when it was connected, attribute the account and list the files copied.
Tie shortcuts, Jump Lists, ShellBags and 4663 events to a physical USB device with volume serial numbers, drive letters and time, and name the user.
How to read setupapi.dev.log device install sections, convert their local times to UTC, and compare them with the registry's first install date.
Event 1006 in Microsoft-Windows-Partition/Diagnostic logs each USB disk with model, serial and boot records. How to read it and extract the volume serial number.
Reading Enum\USBSTOR and Enum\USB in the SYSTEM hive: vendor, product, serial, Windows-generated IDs, ContainerID and the device property timestamps.
What to collect for a Windows USB investigation — hives, setupapi.dev.log, event logs, user files — and the exact KAPE, Velociraptor and PowerShell steps.
Every Windows artifact that records a USB stick — registry, setupapi.dev.log, event logs, LNK, Jump Lists, ShellBags — and how to tie them to one device.