Skip to content

USB Exfiltration Investigation: A Worked Example

A fictional intrusion walked through with USB Forensics: find the stick, confirm when it was connected, attribute the account and list the files copied.

Published on 3 min read

TL;DR. This walkthrough uses the site's synthetic sample (fictional host FIN-WKS-07, rogue account svc_backup, 14 September 2026). In about ten minutes the tool shows a new USB stick connected at 10:30 UTC, mounted by svc_backup, used to write payroll and HR files to E:\exfil, and removed at 10:50 — each step backed by several independent sources.

Everything below is fictional: devices, serials and people do not exist.

The question

The incident window is 10:00–10:55 UTC on 2026-09-14: a rogue account was created, tools were staged and data left the host. Did it leave on removable media?

1. Load and check the sources

Dropping the collection (SYSTEM, SOFTWARE, setupapi.dev.log, five event logs, two users' hives, shortcuts and a Jump List) gives three devices. The Sources tab confirms every file parsed and notes that setupapi times were converted from Romance Standard Time using the hive's daylight-saving rules.

2. Set the window

With the time range set to the incident window, one device remains: Contoso SecureFlash, serial CS1234567890. The findings panel raises four items:

  • Connected during the selected window.
  • Mass-storage device first seen recently — its first install is minutes before the newest evidence.
  • Files opened, copied or read on a removable volume — seven file and folder events, three of them writes.
  • Device used by an unexpected account — svc_backup is a service-style name.

3. When was it connected?

The First install entry at 10:30:13.998 UTC merges three setupapi sections (local 12:30, converted), the 0065 FirstInstallDate keys of the USB and USBSTOR nodes and a UserPnp driver install. The Connected entry a second later merges Security 6416, Kernel-PnP 400/410, Partition/Diagnostic 1006 and DriverFrameworks 2003 with the 0066 LastArrivalDate keys. Removal at 10:50:40 merges DriverFrameworks 2100/2102 (surprise removal), 1006 with capacity 0, and the 0067 keys. No source disagrees for this device.

4. Which volume, which account?

The 1006 event's boot record gives an exFAT volume, serial 3C9D-51A2; EMDMgmt pairs the device serial with the label BACKUP and the same serial; MountedDevices gives E: and the volume GUID; svc_backup's MountPoints2 lists that GUID at 10:30:21.

5. What was done on it?

  • 10:41:30 — ShellBags: svc_backup browsed E:\exfil (inferred from letter and time).
  • 10:44:58–10:45:31 — Security 4663: rclone.exe and Explorer wrote HR\salaries_2026.csv, HR\contracts_2026.zip and Payroll_2026.xlsx on \Device\HarddiskVolume8 (inferred: only this device was connected).
  • 10:46:20 — shortcut + Explorer Jump List: E:\exfil opened, volume serial 3C9D-51A2 (stated by the sources).
  • 10:48:02 — shortcut and 4663: Payroll_2026.xlsx opened in Excel.

6. Context and caveats

Two older devices used by alice stay out of the window but explain the picture: a Fabrikam TravelDrive with two volume serials (reformatted in August) and a Litware card reader with a Windows-generated serial whose setupapi first install predates its registry first install by 48 days — a reinstall, shown as a disagreement rather than hidden.

Inferred rows can be hidden with one checkbox; exports keep a confidence column. See how files are tied to a stick and try the sample on the home page.

Related articles

Every Windows artifact that records a USB stick — registry, setupapi.dev.log, event logs, LNK, Jump Lists, ShellBags — and how to tie them to one device.
Tie shortcuts, Jump Lists, ShellBags and 4663 events to a physical USB device with volume serial numbers, drive letters and time, and name the user.
How to read setupapi.dev.log device install sections, convert their local times to UTC, and compare them with the registry's first install date.