Skip to content

USBSTOR Forensics: Serials and the 0064–0067 Timestamps

Reading Enum\USBSTOR and Enum\USB in the SYSTEM hive: vendor, product, serial, Windows-generated IDs, ContainerID and the device property timestamps.

Published on 3 min read

TL;DR. SYSTEM\ControlSet00x\Enum\USBSTOR\<Disk&Ven_…&Prod_…&Rev_…>\<serial>&<LUN> identifies each USB mass-storage device. Its Properties\{83da6326-97a6-4088-9453-a1923f573b29} subkey holds four FILETIMEs: 0064 install date, 0065 first install date, 0066 last arrival, 0067 last removal. A serial whose second character is & was made up by Windows.

Anatomy of a USBSTOR entry

Enum\USBSTOR\Disk&Ven_Contoso&Prod_SecureFlash&Rev_1.00\CS1234567890&0
    FriendlyName = Contoso SecureFlash USB Device
    ContainerID  = {5c1e2a7d-8b34-4f0e-9d61-2a7c4e9b0f13}
    Properties\{83da6326-97a6-4088-9453-a1923f573b29}\0064 … 0067
  • The class key encodes vendor, product and revision as reported by the device's SCSI inquiry data; underscores stand for spaces.
  • The instance key is serial & LUN. Remove the trailing &0 to compare with other sources.
  • FriendlyName is what Device Manager shows; ContainerID groups the device nodes that belong to the same physical device (ContainerID).

Read the control set named by Select\Current: other control sets can hold older copies.

Enum\USB: the USB side of the same device

Enum\USB\VID_3F10&PID_4C21\CS1234567890 is the USB device node: vendor and product IDs, the Service (USBSTOR for mass storage, HidUsb for a mouse), and the same ContainerID. For devices with a real serial the instance name matches the USBSTOR serial; for others both sides get different generated IDs and only the ContainerID links them.

Not every Enum\USB entry is storage: hubs, keyboards and mice live there too. Filter on the service or on a link to USBSTOR.

The property timestamps

Windows 8 and later store device properties under the instance key. The four that matter here come from devpkey.h, where they are property IDs 100 to 103 of {83da6326-97a6-4088-9453-a1923f573b29}:

KeyPropertyMeaning
0064DEVPKEY_Device_InstallDateLatest installation of the device
0065DEVPKEY_Device_FirstInstallDateFirst installation on this system
0066DEVPKEY_Device_LastArrivalDateLast time it was connected
0067DEVPKEY_Device_LastRemovalDateLast time it was removed

Each is the default value of its key, typed 0xFFFF0010 (a device property of type FILETIME). Windows 7 used a deeper layout (00000065\00000000, value Data). Some published guides swap 0064 and 0065; the property definitions above are the reference, and tools such as regipy follow them.

Two cautions: these keys only hold the latest arrival and removal, and uninstalling the device from Device Manager deletes them — the next connection starts over. That is why setupapi.dev.log can show an earlier first installation than 0065; see setupapi.dev.log for USB.

Windows-generated serials

When a device reports no serial (or a serial Windows does not consider unique), Windows builds an instance ID such as 7&1f2e3d4c&0. The tell is the & in second position. The ID depends on where the device was plugged in and is meaningless on another computer. Identify such a device by vendor, product, capacity, volume serial number and timing instead. More in Windows-generated serial.

Beyond USBSTOR

  • Enum\SWD\WPDBUSENUM entries (portable-device view of the volume) carry the volume label as FriendlyName.
  • MountedDevices gives the drive letter and volume GUID.
  • The per-user side starts with MountPoints2.

USB Forensics reads all of these and shows each device's timestamps with a chip naming the exact key they came from, next to the event-log records that confirm or contradict them.

Related articles

Every Windows artifact that records a USB stick — registry, setupapi.dev.log, event logs, LNK, Jump Lists, ShellBags — and how to tie them to one device.
A fictional intrusion walked through with USB Forensics: find the stick, confirm when it was connected, attribute the account and list the files copied.
Tie shortcuts, Jump Lists, ShellBags and 4663 events to a physical USB device with volume serial numbers, drive letters and time, and name the user.