USB Exfiltration Investigation: A Worked Example
A fictional intrusion walked through with USB Forensics: find the stick, confirm when it was connected, attribute the account and list the files copied.
TL;DR. This walkthrough uses the site's synthetic sample (fictional host FIN-WKS-07, rogue account svc_backup, 14 September 2026). In about ten minutes the tool shows a new USB stick connected at 10:30 UTC, mounted by svc_backup, used to write payroll and HR files to E:\exfil, and removed at 10:50 — each step backed by several independent sources.
Everything below is fictional: devices, serials and people do not exist.
The question
The incident window is 10:00–10:55 UTC on 2026-09-14: a rogue account was created, tools were staged and data left the host. Did it leave on removable media?
1. Load and check the sources
Dropping the collection (SYSTEM, SOFTWARE, setupapi.dev.log, five event logs, two users' hives, shortcuts and a Jump List) gives three devices. The Sources tab confirms every file parsed and notes that setupapi times were converted from Romance Standard Time using the hive's daylight-saving rules.
2. Set the window
With the time range set to the incident window, one device remains: Contoso SecureFlash, serial CS1234567890. The findings panel raises four items:
- Connected during the selected window.
- Mass-storage device first seen recently — its first install is minutes before the newest evidence.
- Files opened, copied or read on a removable volume — seven file and folder events, three of them writes.
- Device used by an unexpected account —
svc_backupis a service-style name.
3. When was it connected?
The First install entry at 10:30:13.998 UTC merges three setupapi sections (local 12:30, converted), the 0065 FirstInstallDate keys of the USB and USBSTOR nodes and a UserPnp driver install. The Connected entry a second later merges Security 6416, Kernel-PnP 400/410, Partition/Diagnostic 1006 and DriverFrameworks 2003 with the 0066 LastArrivalDate keys. Removal at 10:50:40 merges DriverFrameworks 2100/2102 (surprise removal), 1006 with capacity 0, and the 0067 keys. No source disagrees for this device.
4. Which volume, which account?
The 1006 event's boot record gives an exFAT volume, serial 3C9D-51A2; EMDMgmt pairs the device serial with the label BACKUP and the same serial; MountedDevices gives E: and the volume GUID; svc_backup's MountPoints2 lists that GUID at 10:30:21.
5. What was done on it?
- 10:41:30 — ShellBags:
svc_backupbrowsedE:\exfil(inferred from letter and time). - 10:44:58–10:45:31 — Security 4663:
rclone.exeand Explorer wroteHR\salaries_2026.csv,HR\contracts_2026.zipandPayroll_2026.xlsxon\Device\HarddiskVolume8(inferred: only this device was connected). - 10:46:20 — shortcut + Explorer Jump List:
E:\exfilopened, volume serial 3C9D-51A2 (stated by the sources). - 10:48:02 — shortcut and 4663:
Payroll_2026.xlsxopened in Excel.
6. Context and caveats
Two older devices used by alice stay out of the window but explain the picture: a Fabrikam TravelDrive with two volume serials (reformatted in August) and a Litware card reader with a Windows-generated serial whose setupapi first install predates its registry first install by 48 days — a reinstall, shown as a disagreement rather than hidden.
Inferred rows can be hidden with one checkbox; exports keep a confidence column. See how files are tied to a stick and try the sample on the home page.