Skip to content

Collect USB Artifacts with KAPE, Velociraptor or PowerShell

What to collect for a Windows USB investigation — hives, setupapi.dev.log, event logs, user files — and the exact KAPE, Velociraptor and PowerShell steps.

Published on 3 min read

TL;DR. Collect the SYSTEM and SOFTWARE hives, C:\Windows\INF\setupapi.dev*.log, five event logs (Partition/Diagnostic, Kernel-PnP/Configuration, DriverFrameworks-UserMode/Operational, Security, System) and, for every profile, NTUSER.DAT, UsrClass.dat and the Recent folder. KAPE's USBDetective target or Velociraptor's Windows.Triage.Targets with the same target gets all of it in one run.

The file list

FileWhy
C:\Windows\System32\config\SYSTEMUSBSTOR, USB, WPDBUSENUM, MountedDevices, property timestamps, time zone
C:\Windows\System32\config\SOFTWAREVolume labels (Windows Portable Devices), EMDMgmt, ProfileList
C:\Windows\INF\setupapi.dev.log (and rotated setupapi.dev.*.log)First installation of each device
…\winevt\Logs\Microsoft-Windows-Partition%4Diagnostic.evtxEvent 1006: arrivals, removals, volume boot records
…\Microsoft-Windows-Kernel-PnP%4Configuration.evtxEvents 400/410/420/430
…\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtxEvents 2003/2100–2102 (often disabled)
…\Security.evtx, …\System.evtx6416 and 4663 when audited; UserPnp driver installs
C:\Users\<user>\NTUSER.DATMountPoints2
C:\Users\<user>\AppData\Local\Microsoft\Windows\UsrClass.datShellBags
C:\Users\<user>\AppData\Roaming\Microsoft\Windows\Recent\Shortcuts and Jump Lists

Keep the folder layout: the account a user file belongs to is read from its Users\<name>\ path.

KAPE

From an elevated prompt in the KAPE folder:

kape.exe --tsource C: --tdest C:\triage\kape --target USBDetective

USBDetective is a compound target that pulls the setupapi logs, the registry hives (system and user), the event logs, LNK files and Jump Lists, and Amcache. Drop C:\triage\kape (or a ZIP of it) on USB Forensics.

Velociraptor

In current releases, collect Windows.Triage.Targets (from the Velociraptor Triage project) with the USBDetective target — or RegistryHives, EventLogs, USBDevicesLogs and LNKFilesAndJumpLists — from the GUI, a hunt or an offline collector, then download the collection ZIP and drop it as-is. Velociraptor percent-encodes characters such as : in paths; the tool decodes them.

Older releases still ship Windows.KapeFiles.Targets, which takes the same target names as parameters.

No tools: PowerShell on the live host

The site's How to get your data panel has a copy-ready block. It uses:

  • reg save HKLM\SYSTEM and HKLM\SOFTWARE for the locked hives,
  • wevtutil epl for each event log, with the Security log filtered to events 6416 and 4663,
  • reg save HKU\<SID> and HKU\<SID>_Classes for the hives of logged-on users,
  • robocopy for every profile's Recent folder.

reg save cannot reach users who are not logged on: for them use KAPE, Velociraptor or an image.

Gotchas

  • Event logs roll over. A busy Security log may cover days. Collect early and look for older copies in Volume Shadow Copies.
  • Time zones. setupapi.dev.log is in local time; collect SYSTEM so it can be converted.
  • Dirty hives. Raw copies may have pending writes in .LOG1/.LOG2. Keep the logs; replay them with a registry tool if the newest changes matter.
  • Hash first. Hash the collection before analysis and work on copies.

Once collected, the complete map of USB artifacts explains what each file contributes.

Related articles

A fictional intrusion walked through with USB Forensics: find the stick, confirm when it was connected, attribute the account and list the files copied.
Tie shortcuts, Jump Lists, ShellBags and 4663 events to a physical USB device with volume serial numbers, drive letters and time, and name the user.
How to read setupapi.dev.log device install sections, convert their local times to UTC, and compare them with the registry's first install date.