Skip to content

Which Files Were Opened From a USB Stick? LNK, Jump Lists

Tie shortcuts, Jump Lists, ShellBags and 4663 events to a physical USB device with volume serial numbers, drive letters and time, and name the user.

Published on 3 min read

TL;DR. Per-user artifacts answer who and what. Shortcuts and Jump Lists store the target's volume serial number, label and drive type — the serial ties them to one physical device. ShellBags and Security 4663 only know a drive letter or a \Device\HarddiskVolumeN, so they can only be tied to a device by time and letter, and should be labelled inferred. MountPoints2 names the users who mounted the volume.

Shortcuts (.lnk)

When a user opens a file, Explorer updates a shortcut in %APPDATA%\Microsoft\Windows\Recent. Its LinkInfo block contains a VolumeID:

plus the LocalBasePath (E:\exfil\Payroll_2026.xlsx) and the target's created, modified and accessed times at the moment the shortcut was written.

Match the serial with the one decoded from the device's boot record in Partition/Diagnostic 1006, or with EMDMgmt. If they match, the file was on that device — even if a different stick later received the same drive letter.

The shortcut file's own modified time is the best "last opened" time. It only survives if the collection preserved file times: KAPE and robocopy do, some copies do not.

Jump Lists

AutomaticDestinations\<AppID>.automaticDestinations-ms files hold a DestList (one entry per item with a last access time) and one embedded shortcut per entry. They add two things to loose shortcuts: a reliable per-item access time, and the application (the AppID, e.g. f01b4d95cf55d32a for Explorer). The embedded shortcut carries the same VolumeID fields.

ShellBags

UsrClass.dat (and older NTUSER.DAT) BagMRU keys record folders browsed in Explorer: My Computer → E:\ → exfil. The path starts with a drive letter only. To tie E:\exfil to a device, look for the device that had letter E: and was connected when the BagMRU key was last written. If two devices used E: at different times, the time decides; if both were connected, do not guess.

Security 4663

With Audit Removable Storage enabled, file access on removable media produces 4663 events with the account, process, access mask (0x2 WriteData, 0x1 ReadData) and a path such as \Device\HarddiskVolume8\exfil\Payroll_2026.xlsx. The volume number is not stable across connections, so attribute a volume number to a device only if every access happened while that device, and no other, was connected.

MountPoints2

Each NTUSER.DAT has Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{volume GUID} for volumes mounted in that user's session. Match the GUID with MountedDevices to get the device (MountPoints2). The key's LastWrite time approximates the last mount by that user.

In practice

USB Forensics links shortcuts and Jump Lists by serial (stated by the source), ShellBags by drive letter and time, and 4663 by volume number and time (inferred), and shows the difference on every row. The exfiltration walkthrough shows all of them in one case.

Related articles

A fictional intrusion walked through with USB Forensics: find the stick, confirm when it was connected, attribute the account and list the files copied.
How to read setupapi.dev.log device install sections, convert their local times to UTC, and compare them with the registry's first install date.
Event 1006 in Microsoft-Windows-Partition/Diagnostic logs each USB disk with model, serial and boot records. How to read it and extract the volume serial number.