Skip to content

Series

USB forensics fundamentals

5 posts in this series. Read them in order or jump to any one.

  1. USB Device Forensics on Windows: The Complete Map

    Every Windows artifact that records a USB stick — registry, setupapi.dev.log, event logs, LNK, Jump Lists, ShellBags — and how to tie them to one device.

  2. Collect USB Artifacts with KAPE, Velociraptor or PowerShell

    What to collect for a Windows USB investigation — hives, setupapi.dev.log, event logs, user files — and the exact KAPE, Velociraptor and PowerShell steps.

  3. USBSTOR Forensics: Serials and the 0064–0067 Timestamps

    Reading Enum\USBSTOR and Enum\USB in the SYSTEM hive: vendor, product, serial, Windows-generated IDs, ContainerID and the device property timestamps.

  4. Partition/Diagnostic 1006: USB Arrivals and Volume Serials

    Event 1006 in Microsoft-Windows-Partition/Diagnostic logs each USB disk with model, serial and boot records. How to read it and extract the volume serial number.

  5. setupapi.dev.log: When a USB Device Was First Connected

    How to read setupapi.dev.log device install sections, convert their local times to UTC, and compare them with the registry's first install date.

All posts in this series

Every Windows artifact that records a USB stick — registry, setupapi.dev.log, event logs, LNK, Jump Lists, ShellBags — and how to tie them to one device.
What to collect for a Windows USB investigation — hives, setupapi.dev.log, event logs, user files — and the exact KAPE, Velociraptor and PowerShell steps.
Reading Enum\USBSTOR and Enum\USB in the SYSTEM hive: vendor, product, serial, Windows-generated IDs, ContainerID and the device property timestamps.
Event 1006 in Microsoft-Windows-Partition/Diagnostic logs each USB disk with model, serial and boot records. How to read it and extract the volume serial number.
How to read setupapi.dev.log device install sections, convert their local times to UTC, and compare them with the registry's first install date.