Collect USB Artifacts with KAPE, Velociraptor or PowerShell
What to collect for a Windows USB investigation — hives, setupapi.dev.log, event logs, user files — and the exact KAPE, Velociraptor and PowerShell steps.
TL;DR. Collect the SYSTEM and SOFTWARE hives, C:\Windows\INF\setupapi.dev*.log, five event logs (Partition/Diagnostic, Kernel-PnP/Configuration, DriverFrameworks-UserMode/Operational, Security, System) and, for every profile, NTUSER.DAT, UsrClass.dat and the Recent folder. KAPE's USBDetective target or Velociraptor's Windows.Triage.Targets with the same target gets all of it in one run.
The file list
| File | Why |
|---|---|
C:\Windows\System32\config\SYSTEM | USBSTOR, USB, WPDBUSENUM, MountedDevices, property timestamps, time zone |
C:\Windows\System32\config\SOFTWARE | Volume labels (Windows Portable Devices), EMDMgmt, ProfileList |
C:\Windows\INF\setupapi.dev.log (and rotated setupapi.dev.*.log) | First installation of each device |
…\winevt\Logs\Microsoft-Windows-Partition%4Diagnostic.evtx | Event 1006: arrivals, removals, volume boot records |
…\Microsoft-Windows-Kernel-PnP%4Configuration.evtx | Events 400/410/420/430 |
…\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx | Events 2003/2100–2102 (often disabled) |
…\Security.evtx, …\System.evtx | 6416 and 4663 when audited; UserPnp driver installs |
C:\Users\<user>\NTUSER.DAT | MountPoints2 |
C:\Users\<user>\AppData\Local\Microsoft\Windows\UsrClass.dat | ShellBags |
C:\Users\<user>\AppData\Roaming\Microsoft\Windows\Recent\ | Shortcuts and Jump Lists |
Keep the folder layout: the account a user file belongs to is read from its Users\<name>\ path.
KAPE
From an elevated prompt in the KAPE folder:
kape.exe --tsource C: --tdest C:\triage\kape --target USBDetective
USBDetective is a compound target that pulls the setupapi logs, the registry hives (system and user), the event logs, LNK files and Jump Lists, and Amcache. Drop C:\triage\kape (or a ZIP of it) on USB Forensics.
Velociraptor
In current releases, collect Windows.Triage.Targets (from the Velociraptor Triage project) with the USBDetective target — or RegistryHives, EventLogs, USBDevicesLogs and LNKFilesAndJumpLists — from the GUI, a hunt or an offline collector, then download the collection ZIP and drop it as-is. Velociraptor percent-encodes characters such as : in paths; the tool decodes them.
Older releases still ship Windows.KapeFiles.Targets, which takes the same target names as parameters.
No tools: PowerShell on the live host
The site's How to get your data panel has a copy-ready block. It uses:
reg save HKLM\SYSTEMandHKLM\SOFTWAREfor the locked hives,wevtutil eplfor each event log, with the Security log filtered to events 6416 and 4663,reg save HKU\<SID>andHKU\<SID>_Classesfor the hives of logged-on users,robocopyfor every profile'sRecentfolder.
reg save cannot reach users who are not logged on: for them use KAPE, Velociraptor or an image.
Gotchas
- Event logs roll over. A busy Security log may cover days. Collect early and look for older copies in Volume Shadow Copies.
- Time zones. setupapi.dev.log is in local time; collect SYSTEM so it can be converted.
- Dirty hives. Raw copies may have pending writes in
.LOG1/.LOG2. Keep the logs; replay them with a registry tool if the newest changes matter. - Hash first. Hash the collection before analysis and work on copies.
Once collected, the complete map of USB artifacts explains what each file contributes.