Skip to content

Glossary

USBSTOR

The SYSTEM hive key Enum\USBSTOR, where Windows keeps one entry per USB mass-storage device with vendor, product, revision and serial.

ControlSet00x\Enum\USBSTOR holds one class key per device model (Disk&Ven_Contoso&Prod_SecureFlash&Rev_1.00) and one instance key per device (CS1234567890&0: the serial, &, and a logical unit number). Values include FriendlyName and ContainerID, and the Properties subkey holds the device property timestamps.

It answers which storage devices were connected, not who used them. See USBSTOR forensics.