Skip to content

USB Device Forensics on Windows: The Complete Map

Every Windows artifact that records a USB stick — registry, setupapi.dev.log, event logs, LNK, Jump Lists, ShellBags — and how to tie them to one device.

Published on 4 min read

TL;DR. No single Windows artifact tells the whole story of a USB stick. The SYSTEM hive names the device and gives four property timestamps; setupapi.dev.log dates its first installation; the event logs date each connection and removal; per-user artifacts (MountPoints2, shortcuts, Jump Lists, ShellBags) show who used it and what was opened on it. The investigator's job is to join them, and the keys that join them are the serial / instance ID, the volume GUID and the volume serial number.

The three questions

A USB investigation almost always asks the same three things:

  1. Which device? Make, model, serial number, and whether that serial is real.
  2. When? First connection, every later connection and removal, and the last one.
  3. Who, and what? Which account mounted it, and which files and folders were opened, written or read on it.

Each question is answered by a different family of artifacts, and each family has its own identifier for the same device. That is why USB analysis feels like stitching.

Which device: the SYSTEM hive

Under ControlSet00x\Enum\USBSTOR Windows keeps one key per mass-storage device class (Disk&Ven_Contoso&Prod_SecureFlash&Rev_1.00) with one subkey per instance (CS1234567890&0). The instance name is the device serial followed by & and a LUN number. See USBSTOR.

Two warnings:

  • If the second character of the serial is & (for example 7&1f2e3d4c&0), the device reported no usable serial and Windows generated the ID. It is unique on this computer only — see Windows-generated serial.
  • Enum\USB\VID_xxxx&PID_yyyy\<serial> holds the USB side (vendor and product IDs). It shares a ContainerID with the USBSTOR entry, which links them even when their instance names differ.

Each instance key also has a Properties\{83da6326-97a6-4088-9453-a1923f573b29} subkey with device property timestamps: 0064 install date, 0065 first install date, 0066 last arrival, 0067 last removal. The USBSTOR article covers them in detail.

MountedDevices maps drive letters and volume GUIDs to devices, and the SOFTWARE hive adds volume labels (Windows Portable Devices) and, on systems where ReadyBoost was evaluated, EMDMgmt entries that pair a device serial with a volume label and volume serial number.

When: setupapi and the event logs

  • C:\Windows\INF\setupapi.dev.log has a section for each device installation. The first section for a device is its first connection to this computer. Its times are in local time — see setupapi.dev.log for USB.
  • Microsoft-Windows-Partition/Diagnostic, event 1006 is logged on disk arrival (with model, serial, partition table and volume boot records) and, according to practitioner research, again with a zero capacity when the disk goes away. It is the richest single source on Windows 10 1703 and later — see Partition/Diagnostic 1006.
  • Kernel-PnP/Configuration 400/410 log device configuration and start; DriverFrameworks-UserMode 2003 / 2100–2102 log UMDF arrival and removal where that channel is enabled; Security 6416 logs "a new external device was recognized" when Audit PNP Activity is on.

Registry timestamps give you the latest arrival and removal; logs give you every one they still hold. When they disagree, the disagreement itself is evidence: a reinstall, rolled-over logs, or a hive copied at another moment.

Who and what: per-user artifacts

The system-wide artifacts never name a user. For that you need each profile:

  • NTUSER.DAT MountPoints2 lists the volume GUIDs mounted in that user's session. Match them with MountedDevices — see MountPoints2.
  • Shortcuts (Recent\*.lnk) and Jump Lists store the target path and the volume's drive type, label and serial number. The serial ties a file to a physical stick even when the drive letter was reused.
  • ShellBags record folders browsed in Explorer, with the drive letter only.
  • Security 4663 on removable storage (when Audit Removable Storage is on) records file reads and writes, with a \Device\HarddiskVolumeN path.

The LNK, Jump Lists and ShellBags article explains how to attribute them.

Joining it all

KeyWhere it appears
Serial / instance IDUSBSTOR, USB, WPDBUSENUM, MountedDevices data, EMDMgmt, setupapi, Kernel-PnP, 6416, 1006 ParentId
Container IDUSB, USBSTOR, SWD\WPDBUSENUM
Volume GUIDMountedDevices, MountPoints2
Volume serial number1006 volume boot record, EMDMgmt, LNK / Jump List VolumeID

USB Forensics does this join in your browser: drop a triage collection and you get one card per device, one timeline, and evidence chips naming the file and key, record or line behind every fact. The collection guide lists what to collect.

Related articles

A fictional intrusion walked through with USB Forensics: find the stick, confirm when it was connected, attribute the account and list the files copied.
Event 1006 in Microsoft-Windows-Partition/Diagnostic logs each USB disk with model, serial and boot records. How to read it and extract the volume serial number.
Reading Enum\USBSTOR and Enum\USB in the SYSTEM hive: vendor, product, serial, Windows-generated IDs, ContainerID and the device property timestamps.