How to Determine US...
 
Notifications
Clear all

How to Determine USB Key User

3 Posts
2 Users
0 Likes
252 Views
(@jrwhite6)
Posts: 6
Active Member
Topic starter
 

Greetings,

I have more "New Computer Examiner" questions and so far this has been the place to get answers. Please bear with me.

I am conducting my first exam of a USB Thumbdrive and have downloaded and made use of Mr. Lee's awesome guide (https://blogs.sans.org/computer-forensics/files/2009/09/USBKEY-Guide.pdf) and have been mostly successful figuring this all out on my own. HOWEVER… I can't figure out who the "user" is associated with the Device GUID in the MountPoints2. I have the registry information, and located the Device GUID, but have no idea what/where the "user" information is.

Can someone point me in the right direction?

Thanks!
Jeff

 
Posted : 08/05/2013 8:14 pm
keydet89
(@keydet89)
Posts: 3568
Famed Member
 

Jeff,

I am conducting my first exam of a USB Thumbdrive and have downloaded and made use of Mr. Lee's awesome guide (https://blogs.sans.org/computer-forensics/files/2009/09/USBKEY-Guide.pdf) and have been mostly successful figuring this all out on my own. HOWEVER… I can't figure out who the "user" is associated with the Device GUID in the MountPoints2. I have the registry information, and located the Device GUID, but have no idea what/where the "user" information is.

You already have it. The user is whichever profile you extracted the NTUSER.DAT (where the MountPoints2 key is located) from.

 
Posted : 08/05/2013 10:41 pm
(@jrwhite6)
Posts: 6
Active Member
Topic starter
 

Thank You Sir.
Now that you mention it… it DOES make sense.
Have a good one!
Jeff

 
Posted : 08/05/2013 11:39 pm
Share: