Series
USB forensics fundamentals
5 posts in this series. Read them in order or jump to any one.
- USB Device Forensics on Windows: The Complete Map
Every Windows artifact that records a USB stick — registry, setupapi.dev.log, event logs, LNK, Jump Lists, ShellBags — and how to tie them to one device.
- Collect USB Artifacts with KAPE, Velociraptor or PowerShell
What to collect for a Windows USB investigation — hives, setupapi.dev.log, event logs, user files — and the exact KAPE, Velociraptor and PowerShell steps.
- USBSTOR Forensics: Serials and the 0064–0067 Timestamps
Reading Enum\USBSTOR and Enum\USB in the SYSTEM hive: vendor, product, serial, Windows-generated IDs, ContainerID and the device property timestamps.
- Partition/Diagnostic 1006: USB Arrivals and Volume Serials
Event 1006 in Microsoft-Windows-Partition/Diagnostic logs each USB disk with model, serial and boot records. How to read it and extract the volume serial number.
- setupapi.dev.log: When a USB Device Was First Connected
How to read setupapi.dev.log device install sections, convert their local times to UTC, and compare them with the registry's first install date.