Sitemap
All pages on the site.
Home
Blog
- USB Exfiltration Investigation: A Worked Example
- Which Files Were Opened From a USB Stick? LNK, Jump Lists
- setupapi.dev.log: When a USB Device Was First Connected
- Partition/Diagnostic 1006: USB Arrivals and Volume Serials
- USBSTOR Forensics: Serials and the 0064–0067 Timestamps
- Collect USB Artifacts with KAPE, Velociraptor or PowerShell
- USB Device Forensics on Windows: The Complete Map