USB activity monito...
 
Notifications
Clear all

USB activity monitoring

6 Posts
6 Users
0 Reactions
1,440 Views
Agent47
(@agent47)
Eminent Member
Joined: 12 years ago
Posts: 32
Topic starter   [#15902]

Is there any method or tool witch allowed to monitor activity on USB? With activity I mean if you can by any chance see if was file (pdf, jpeg, doc, etc, …) on USB copy or open.



   
Quote
Bunnysniper
(@bunnysniper)
Reputable Member
Joined: 14 years ago
Posts: 259
 

Is there any method or tool witch allowed to monitor activity on USB? With activity I mean if you can by any chance see if was file (pdf, jpeg, doc, etc, …) on USB copy or open.

ShellBags! MFT! LNK! Memory Dumps! Hyberfil! Pagefile! So many options here….!



   
ReplyQuote
Mreza
(@mreza)
Trusted Member
Joined: 11 years ago
Posts: 85
 

Is there any method or tool witch allowed to monitor activity on USB? With activity I mean if you can by any chance see if was file (pdf, jpeg, doc, etc, …) on USB copy or open.

A few examples

http//cyberforensicator.com/2017/09/10/the-hitchhikers-guide-to-usb-forensics/

https://youtu.be/HtQ6AxE_dT0



   
ReplyQuote
AmNe5iA
(@amne5ia)
Estimable Member
Joined: 10 years ago
Posts: 175
 

http//desowin.org/usbpcap/



   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 19 years ago
Posts: 5133
 

Is there any method or tool witch allowed to monitor activity on USB? With activity I mean if you can by any chance see if was file (pdf, jpeg, doc, etc, …) on USB copy or open.

Just to clear your question (that has already been read and thus answered differently) are you asking about
1) "monitor" PAST activity (i.e. interpreting logs and artifacts created by default and standard OS, which is what Bunnysniper and Mreza referenced)
2) "monitor" CURRENT activity (i.e. recording what goes through the USB bus which is what AmNe5iA referenced)

jaclaz



   
ReplyQuote
(@cmontiel05)
New Member
Joined: 7 years ago
Posts: 3
 

Hello Agent47,

Unsure if you've already found your solution but can tell you that W4 by Vound can provide you the information you're requesting.

W4 has a nice feature called "Links". For example, you can see your document and all of the other artifacts linked to it such as usb drives, user accounts, etc.

Thanks

CM



   
ReplyQuote
Share: