<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>USB Forensics — Blog</title>
    <link>https://www.usbforensics.com/fr/blog</link>
    <description>Latest from Blog</description>
    <language>fr</language>
    <lastBuildDate>Tue, 29 Sep 2026 14:11:32 GMT</lastBuildDate>
    <atom:link href="https://www.usbforensics.com/fr/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Enquête sur une exfiltration USB : un cas concret</title>
      <link>https://www.usbforensics.com/fr/blog/usb-exfiltration-investigation-walkthrough</link>
      <guid isPermaLink="true">https://www.usbforensics.com/fr/blog/usb-exfiltration-investigation-walkthrough</guid>
      <description>Une intrusion fictive analysée avec USB Forensics : trouver la clé, confirmer quand elle a été branchée, attribuer le compte et lister les fichiers copiés.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Fichiers ouverts depuis une clé USB : LNK et Jump Lists</title>
      <link>https://www.usbforensics.com/fr/blog/link-files-to-usb-lnk-jumplists-shellbags</link>
      <guid isPermaLink="true">https://www.usbforensics.com/fr/blog/link-files-to-usb-lnk-jumplists-shellbags</guid>
      <description>Relier raccourcis, Jump Lists, ShellBags et événements 4663 à une clé USB par numéro de série de volume, lettre de lecteur et heure, et nommer l’utilisateur.</description>
      <author>Florian Amette</author>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>setupapi.dev.log : dater la première connexion USB</title>
      <link>https://www.usbforensics.com/fr/blog/setupapi-dev-log-usb-first-install</link>
      <guid isPermaLink="true">https://www.usbforensics.com/fr/blog/setupapi-dev-log-usb-first-install</guid>
      <description>Lire les sections d’installation de setupapi.dev.log, convertir leur heure locale en UTC et les comparer à la date de première installation du registre.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Partition/Diagnostic 1006 : arrivées USB et numéros de série</title>
      <link>https://www.usbforensics.com/fr/blog/partition-diagnostic-1006-volume-serial</link>
      <guid isPermaLink="true">https://www.usbforensics.com/fr/blog/partition-diagnostic-1006-volume-serial</guid>
      <description>L’événement 1006 de Partition/Diagnostic journalise chaque disque USB avec modèle, numéro de série et secteurs d’amorçage. Le lire et en extraire le VSN.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>USBSTOR : numéros de série et horodatages 0064–0067</title>
      <link>https://www.usbforensics.com/fr/blog/usbstor-registry-key-forensics</link>
      <guid isPermaLink="true">https://www.usbforensics.com/fr/blog/usbstor-registry-key-forensics</guid>
      <description>Lire Enum\USBSTOR et Enum\USB dans la ruche SYSTEM : fabricant, produit, numéro de série, ID générés, ContainerID et horodatages des propriétés.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Collecte USB avec KAPE, Velociraptor ou PowerShell</title>
      <link>https://www.usbforensics.com/fr/blog/collect-usb-artifacts-kape-velociraptor</link>
      <guid isPermaLink="true">https://www.usbforensics.com/fr/blog/collect-usb-artifacts-kape-velociraptor</guid>
      <description>Quoi collecter pour une investigation USB sous Windows — ruches, setupapi.dev.log, journaux d’événements, fichiers utilisateur — et les étapes exactes.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Analyse forensique USB sous Windows : la carte complète</title>
      <link>https://www.usbforensics.com/fr/blog/usb-device-forensics-windows-guide</link>
      <guid isPermaLink="true">https://www.usbforensics.com/fr/blog/usb-device-forensics-windows-guide</guid>
      <description>Chaque artefact Windows qui trace une clé USB — registre, setupapi.dev.log, journaux d’événements, LNK, Jump Lists, ShellBags — et comment les relier.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>