USB Device Forensics on Windows: The Complete Map
Every Windows artifact that records a USB stick — registry, setupapi.dev.log, event logs, LNK, Jump Lists, ShellBags — and how to tie them to one device.
TL;DR. No single Windows artifact tells the whole story of a USB stick. The SYSTEM hive names the device and gives four property timestamps; setupapi.dev.log dates its first installation; the event logs date each connection and removal; per-user artifacts (MountPoints2, shortcuts, Jump Lists, ShellBags) show who used it and what was opened on it. The investigator's job is to join them, and the keys that join them are the serial / instance ID, the volume GUID and the volume serial number.
The three questions
A USB investigation almost always asks the same three things:
- Which device? Make, model, serial number, and whether that serial is real.
- When? First connection, every later connection and removal, and the last one.
- Who, and what? Which account mounted it, and which files and folders were opened, written or read on it.
Each question is answered by a different family of artifacts, and each family has its own identifier for the same device. That is why USB analysis feels like stitching.
Which device: the SYSTEM hive
Under ControlSet00x\Enum\USBSTOR Windows keeps one key per mass-storage device class (Disk&Ven_Contoso&Prod_SecureFlash&Rev_1.00) with one subkey per instance (CS1234567890&0). The instance name is the device serial followed by & and a LUN number. See USBSTOR.
Two warnings:
- If the second character of the serial is
&(for example7&1f2e3d4c&0), the device reported no usable serial and Windows generated the ID. It is unique on this computer only — see Windows-generated serial. Enum\USB\VID_xxxx&PID_yyyy\<serial>holds the USB side (vendor and product IDs). It shares a ContainerID with the USBSTOR entry, which links them even when their instance names differ.
Each instance key also has a Properties\{83da6326-97a6-4088-9453-a1923f573b29} subkey with device property timestamps: 0064 install date, 0065 first install date, 0066 last arrival, 0067 last removal. The USBSTOR article covers them in detail.
MountedDevices maps drive letters and volume GUIDs to devices, and the SOFTWARE hive adds volume labels (Windows Portable Devices) and, on systems where ReadyBoost was evaluated, EMDMgmt entries that pair a device serial with a volume label and volume serial number.
When: setupapi and the event logs
C:\Windows\INF\setupapi.dev.loghas a section for each device installation. The first section for a device is its first connection to this computer. Its times are in local time — see setupapi.dev.log for USB.- Microsoft-Windows-Partition/Diagnostic, event 1006 is logged on disk arrival (with model, serial, partition table and volume boot records) and, according to practitioner research, again with a zero capacity when the disk goes away. It is the richest single source on Windows 10 1703 and later — see Partition/Diagnostic 1006.
- Kernel-PnP/Configuration 400/410 log device configuration and start; DriverFrameworks-UserMode 2003 / 2100–2102 log UMDF arrival and removal where that channel is enabled; Security 6416 logs "a new external device was recognized" when Audit PNP Activity is on.
Registry timestamps give you the latest arrival and removal; logs give you every one they still hold. When they disagree, the disagreement itself is evidence: a reinstall, rolled-over logs, or a hive copied at another moment.
Who and what: per-user artifacts
The system-wide artifacts never name a user. For that you need each profile:
- NTUSER.DAT
MountPoints2lists the volume GUIDs mounted in that user's session. Match them withMountedDevices— see MountPoints2. - Shortcuts (
Recent\*.lnk) and Jump Lists store the target path and the volume's drive type, label and serial number. The serial ties a file to a physical stick even when the drive letter was reused. - ShellBags record folders browsed in Explorer, with the drive letter only.
- Security 4663 on removable storage (when Audit Removable Storage is on) records file reads and writes, with a
\Device\HarddiskVolumeNpath.
The LNK, Jump Lists and ShellBags article explains how to attribute them.
Joining it all
| Key | Where it appears |
|---|---|
| Serial / instance ID | USBSTOR, USB, WPDBUSENUM, MountedDevices data, EMDMgmt, setupapi, Kernel-PnP, 6416, 1006 ParentId |
| Container ID | USB, USBSTOR, SWD\WPDBUSENUM |
| Volume GUID | MountedDevices, MountPoints2 |
| Volume serial number | 1006 volume boot record, EMDMgmt, LNK / Jump List VolumeID |
USB Forensics does this join in your browser: drop a triage collection and you get one card per device, one timeline, and evidence chips naming the file and key, record or line behind every fact. The collection guide lists what to collect.