Skip to content

Partition/Diagnostic 1006: USB Arrivals and Volume Serials

Event 1006 in Microsoft-Windows-Partition/Diagnostic logs each USB disk with model, serial and boot records. How to read it and extract the volume serial number.

Published on 3 min read

TL;DR. On Windows 10 1703+, every disk arrival writes event 1006 to Microsoft-Windows-Partition/Diagnostic with the manufacturer, model, serial, capacity, parent device ID, partition table, MBR and volume boot records. The boot record gives the volume serial number (VSN) — the value shortcuts and Jump Lists store — so 1006 is the bridge between a physical device and the files opened on it.

What the event contains

The interesting EventData fields:

FieldUse
Manufacturer, Model, Revision, SerialNumberWhat the storage stack reports (can differ from USBSTOR's descriptor serial)
ParentIdThe USB device instance, e.g. USB\VID_3F10&PID_4C21\CS1234567890 — ties the event to Enum\USB
BusType7 for USB (12 SD, 13 MMC); other buses are internal disks
CapacityBytes; practitioners report 0 on removal
PartitionStyle, PartitionTable, MbrMBR/GPT layout; the MBR disk signature also appears in MountedDevices
Vbr0…Vbr3Volume boot record of each partition, as binary

The exact field list varies across Windows builds, so read fields by name rather than by position.

Volume serial number from the VBR

The volume serial number sits at a fixed offset of the boot sector, depending on the file system (check the OEM name at offset 3 first):

File systemIdentifySerial offsetSize
NTFSOEM NTFS 0x488 bytes (Windows shows the low 4)
exFATOEM EXFAT 0x644 bytes
FAT32FAT32 at 0x520x434 bytes
FAT12/16FAT1x at 0x360x274 bytes

Read the four bytes little-endian and print them as XXXX-XXXX. A stick formatted as exFAT with bytes A2 51 9D 3C at 0x64 has serial 3C9D-51A2 — exactly what a shortcut to a file on it records in its VolumeID. See volume serial number.

Formatting creates a new serial. If one device shows two serials across its 1006 events, it was reformatted between them: files opened under each serial belong to the same physical stick.

Arrivals, removals and gaps

Pair arrivals (capacity > 0) with the next zero-capacity event to get connection windows. Then compare with the registry: 0066 (last arrival) should match the newest arrival in the log. If the registry is newer and no event matches, the log rolled over or was cleared; if the log is newer, the hive may have been copied earlier. Both situations are worth writing down, not smoothing over.

Limits

  • Windows 10 1703+ only; older systems need setupapi.dev.log, Kernel-PnP and DriverFrameworks events.
  • The log has a size limit and rolls over.
  • The 1006 SerialNumber is the storage serial, which can differ from the USB serial in USBSTOR; ParentId is the reliable link.

USB Forensics decodes each 1006 record, extracts the file system and VSN from every VBR, and links them to the device and to the shortcuts that mention the same VSN — each fact with a chip pointing to the record number. More context in the complete USB artifact map.

Related articles

Every Windows artifact that records a USB stick — registry, setupapi.dev.log, event logs, LNK, Jump Lists, ShellBags — and how to tie them to one device.
A fictional intrusion walked through with USB Forensics: find the stick, confirm when it was connected, attribute the account and list the files copied.
Tie shortcuts, Jump Lists, ShellBags and 4663 events to a physical USB device with volume serial numbers, drive letters and time, and name the user.