Partition/Diagnostic 1006: USB Arrivals and Volume Serials
Event 1006 in Microsoft-Windows-Partition/Diagnostic logs each USB disk with model, serial and boot records. How to read it and extract the volume serial number.
TL;DR. On Windows 10 1703+, every disk arrival writes event 1006 to Microsoft-Windows-Partition/Diagnostic with the manufacturer, model, serial, capacity, parent device ID, partition table, MBR and volume boot records. The boot record gives the volume serial number (VSN) — the value shortcuts and Jump Lists store — so 1006 is the bridge between a physical device and the files opened on it.
What the event contains
The interesting EventData fields:
| Field | Use |
|---|---|
Manufacturer, Model, Revision, SerialNumber | What the storage stack reports (can differ from USBSTOR's descriptor serial) |
ParentId | The USB device instance, e.g. USB\VID_3F10&PID_4C21\CS1234567890 — ties the event to Enum\USB |
BusType | 7 for USB (12 SD, 13 MMC); other buses are internal disks |
Capacity | Bytes; practitioners report 0 on removal |
PartitionStyle, PartitionTable, Mbr | MBR/GPT layout; the MBR disk signature also appears in MountedDevices |
Vbr0…Vbr3 | Volume boot record of each partition, as binary |
The exact field list varies across Windows builds, so read fields by name rather than by position.
Volume serial number from the VBR
The volume serial number sits at a fixed offset of the boot sector, depending on the file system (check the OEM name at offset 3 first):
| File system | Identify | Serial offset | Size |
|---|---|---|---|
| NTFS | OEM NTFS | 0x48 | 8 bytes (Windows shows the low 4) |
| exFAT | OEM EXFAT | 0x64 | 4 bytes |
| FAT32 | FAT32 at 0x52 | 0x43 | 4 bytes |
| FAT12/16 | FAT1x at 0x36 | 0x27 | 4 bytes |
Read the four bytes little-endian and print them as XXXX-XXXX. A stick formatted as exFAT with bytes A2 51 9D 3C at 0x64 has serial 3C9D-51A2 — exactly what a shortcut to a file on it records in its VolumeID. See volume serial number.
Formatting creates a new serial. If one device shows two serials across its 1006 events, it was reformatted between them: files opened under each serial belong to the same physical stick.
Arrivals, removals and gaps
Pair arrivals (capacity > 0) with the next zero-capacity event to get connection windows. Then compare with the registry: 0066 (last arrival) should match the newest arrival in the log. If the registry is newer and no event matches, the log rolled over or was cleared; if the log is newer, the hive may have been copied earlier. Both situations are worth writing down, not smoothing over.
Limits
- Windows 10 1703+ only; older systems need setupapi.dev.log, Kernel-PnP and DriverFrameworks events.
- The log has a size limit and rolls over.
- The 1006
SerialNumberis the storage serial, which can differ from the USB serial in USBSTOR;ParentIdis the reliable link.
USB Forensics decodes each 1006 record, extracts the file system and VSN from every VBR, and links them to the device and to the shortcuts that mention the same VSN — each fact with a chip pointing to the record number. More context in the complete USB artifact map.