Notifications
Clear all

USB insertion date

5 Posts
4 Users
0 Likes
442 Views
(@odiggity)
Posts: 3
New Member
Topic starter
 

Hi, this is my first time posting on here. I have a general question about reading/decoding the USB insertion date that I found for a device.

How do I decode the Uinque Instance ID for a USB device to find out the date the device was installed?

 
Posted : 31/10/2010 12:29 am
Fab4
 Fab4
(@fab4)
Posts: 173
Estimable Member
 

How do I decode the Uinque Instance ID for a USB device to find out the date the device was installed?

You don't decode it. You may find it in clear text in the event log (depending on the OS in question). There should also be a timestamp associated with its original insertion in USBSTOR although there are events that can update this date stamp.

Beforehand however, you should acquire a good level of understanding. May I suggest Windows Forensic Analysis by Harlan Carvey as a starting point….? Or I recall Rob Lee from SANS has published some relevant information.

 
Posted : 01/11/2010 2:32 am
(@odiggity)
Posts: 3
New Member
Topic starter
 

Thank you for the info Fab4, I appreciate it.

 
Posted : 02/11/2010 7:06 am
(@farmerdude)
Posts: 242
Estimable Member
 

Also, review the contents of the often overlooked but sometimes quite telling "setupapi.log" file. There may be useful information regarding USB attached devices therein.

Cheers!

farmerdude

www.onlineforensictraining.com

www.forensicbootcd.com

 
Posted : 05/11/2010 6:23 pm
(@douglasbrush)
Posts: 812
Prominent Member
 

I also like and use quite often NirSoft's USBDeview
http//www.nirsoft.net/utils/usb_devices_view.html

While certainly take some deeper understanding as to how it parses and generates it's results and will not always give you results (i.e. verify with other tools as you would be doing with anything else ) ), it is a good way to get some results in a point and click manner in Windows.

 
Posted : 06/11/2010 1:24 am
Share: