USBSTOR Forensics: Serials and the 0064–0067 Timestamps
Reading Enum\USBSTOR and Enum\USB in the SYSTEM hive: vendor, product, serial, Windows-generated IDs, ContainerID and the device property timestamps.
TL;DR. SYSTEM\ControlSet00x\Enum\USBSTOR\<Disk&Ven_…&Prod_…&Rev_…>\<serial>&<LUN> identifies each USB mass-storage device. Its Properties\{83da6326-97a6-4088-9453-a1923f573b29} subkey holds four FILETIMEs: 0064 install date, 0065 first install date, 0066 last arrival, 0067 last removal. A serial whose second character is & was made up by Windows.
Anatomy of a USBSTOR entry
Enum\USBSTOR\Disk&Ven_Contoso&Prod_SecureFlash&Rev_1.00\CS1234567890&0
FriendlyName = Contoso SecureFlash USB Device
ContainerID = {5c1e2a7d-8b34-4f0e-9d61-2a7c4e9b0f13}
Properties\{83da6326-97a6-4088-9453-a1923f573b29}\0064 … 0067
- The class key encodes vendor, product and revision as reported by the device's SCSI inquiry data; underscores stand for spaces.
- The instance key is serial
&LUN. Remove the trailing&0to compare with other sources. - FriendlyName is what Device Manager shows; ContainerID groups the device nodes that belong to the same physical device (ContainerID).
Read the control set named by Select\Current: other control sets can hold older copies.
Enum\USB: the USB side of the same device
Enum\USB\VID_3F10&PID_4C21\CS1234567890 is the USB device node: vendor and product IDs, the Service (USBSTOR for mass storage, HidUsb for a mouse), and the same ContainerID. For devices with a real serial the instance name matches the USBSTOR serial; for others both sides get different generated IDs and only the ContainerID links them.
Not every Enum\USB entry is storage: hubs, keyboards and mice live there too. Filter on the service or on a link to USBSTOR.
The property timestamps
Windows 8 and later store device properties under the instance key. The four that matter here come from devpkey.h, where they are property IDs 100 to 103 of {83da6326-97a6-4088-9453-a1923f573b29}:
| Key | Property | Meaning |
|---|---|---|
0064 | DEVPKEY_Device_InstallDate | Latest installation of the device |
0065 | DEVPKEY_Device_FirstInstallDate | First installation on this system |
0066 | DEVPKEY_Device_LastArrivalDate | Last time it was connected |
0067 | DEVPKEY_Device_LastRemovalDate | Last time it was removed |
Each is the default value of its key, typed 0xFFFF0010 (a device property of type FILETIME). Windows 7 used a deeper layout (00000065\00000000, value Data). Some published guides swap 0064 and 0065; the property definitions above are the reference, and tools such as regipy follow them.
Two cautions: these keys only hold the latest arrival and removal, and uninstalling the device from Device Manager deletes them — the next connection starts over. That is why setupapi.dev.log can show an earlier first installation than 0065; see setupapi.dev.log for USB.
Windows-generated serials
When a device reports no serial (or a serial Windows does not consider unique), Windows builds an instance ID such as 7&1f2e3d4c&0. The tell is the & in second position. The ID depends on where the device was plugged in and is meaningless on another computer. Identify such a device by vendor, product, capacity, volume serial number and timing instead. More in Windows-generated serial.
Beyond USBSTOR
- Enum\SWD\WPDBUSENUM entries (portable-device view of the volume) carry the volume label as FriendlyName.
- MountedDevices gives the drive letter and volume GUID.
- The per-user side starts with MountPoints2.
USB Forensics reads all of these and shows each device's timestamps with a chip naming the exact key they came from, next to the event-log records that confirm or contradict them.