<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>USB Forensics — Blog</title>
    <link>https://www.usbforensics.com/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Tue, 29 Sep 2026 12:44:22 GMT</lastBuildDate>
    <atom:link href="https://www.usbforensics.com/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>USB Exfiltration Investigation: A Worked Example</title>
      <link>https://www.usbforensics.com/en/blog/usb-exfiltration-investigation-walkthrough</link>
      <guid isPermaLink="true">https://www.usbforensics.com/en/blog/usb-exfiltration-investigation-walkthrough</guid>
      <description>A fictional intrusion walked through with USB Forensics: find the stick, confirm when it was connected, attribute the account and list the files copied.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Which Files Were Opened From a USB Stick? LNK, Jump Lists</title>
      <link>https://www.usbforensics.com/en/blog/link-files-to-usb-lnk-jumplists-shellbags</link>
      <guid isPermaLink="true">https://www.usbforensics.com/en/blog/link-files-to-usb-lnk-jumplists-shellbags</guid>
      <description>Tie shortcuts, Jump Lists, ShellBags and 4663 events to a physical USB device with volume serial numbers, drive letters and time, and name the user.</description>
      <author>Florian Amette</author>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>setupapi.dev.log: When a USB Device Was First Connected</title>
      <link>https://www.usbforensics.com/en/blog/setupapi-dev-log-usb-first-install</link>
      <guid isPermaLink="true">https://www.usbforensics.com/en/blog/setupapi-dev-log-usb-first-install</guid>
      <description>How to read setupapi.dev.log device install sections, convert their local times to UTC, and compare them with the registry&apos;s first install date.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Partition/Diagnostic 1006: USB Arrivals and Volume Serials</title>
      <link>https://www.usbforensics.com/en/blog/partition-diagnostic-1006-volume-serial</link>
      <guid isPermaLink="true">https://www.usbforensics.com/en/blog/partition-diagnostic-1006-volume-serial</guid>
      <description>Event 1006 in Microsoft-Windows-Partition/Diagnostic logs each USB disk with model, serial and boot records. How to read it and extract the volume serial number.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>USBSTOR Forensics: Serials and the 0064–0067 Timestamps</title>
      <link>https://www.usbforensics.com/en/blog/usbstor-registry-key-forensics</link>
      <guid isPermaLink="true">https://www.usbforensics.com/en/blog/usbstor-registry-key-forensics</guid>
      <description>Reading Enum\USBSTOR and Enum\USB in the SYSTEM hive: vendor, product, serial, Windows-generated IDs, ContainerID and the device property timestamps.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Collect USB Artifacts with KAPE, Velociraptor or PowerShell</title>
      <link>https://www.usbforensics.com/en/blog/collect-usb-artifacts-kape-velociraptor</link>
      <guid isPermaLink="true">https://www.usbforensics.com/en/blog/collect-usb-artifacts-kape-velociraptor</guid>
      <description>What to collect for a Windows USB investigation — hives, setupapi.dev.log, event logs, user files — and the exact KAPE, Velociraptor and PowerShell steps.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>USB Device Forensics on Windows: The Complete Map</title>
      <link>https://www.usbforensics.com/en/blog/usb-device-forensics-windows-guide</link>
      <guid isPermaLink="true">https://www.usbforensics.com/en/blog/usb-device-forensics-windows-guide</guid>
      <description>Every Windows artifact that records a USB stick — registry, setupapi.dev.log, event logs, LNK, Jump Lists, ShellBags — and how to tie them to one device.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>