Notifications
Clear all

USB Logs

6 Posts
5 Users
0 Reactions
474 Views
(@paulo111)
Eminent Member
Joined: 17 years ago
Posts: 36
Topic starter  

Are there any tools that can determine the date and time a USB drive was pluggged in a specific Win XP machine? Or am I asking for the impossible? I trawled the archives and most said its a no-go but thought I would check?


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Actually, this has been addressed multiple times right here on this forum.

The book, "Windows Forensic Analysis", covers this in detail…


   
ReplyQuote
(@benclelland)
Eminent Member
Joined: 19 years ago
Posts: 21
 

This might be of use to you - http//www.nirsoft.net/utils/usb_devices_view.html


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Bencle,

Quick question…at the page you linked to, it says the following

"Specifies the date/time that the device was installed. In most cases, this date/time value represents the time that you first plugged the device to the USB port. However, be aware that in some circumstances this value may be wrong. "

There's no specification as to when or under what conditions these times may be wrong…so why are so many people recommending the tool? I'm just curious….


   
ReplyQuote
Fab4
 Fab4
(@fab4)
Estimable Member
Joined: 18 years ago
Posts: 173
 

I recommend RegRipper.

As Harlan covers most eloquently in his aforementioned book, you can ascertain the timestamp associated with the time the USB was first inserted and, by following the evidence trail, the time it was last inserted.


   
ReplyQuote
(@seth_h)
New Member
Joined: 16 years ago
Posts: 4
 

I may be wrong but i believe the date it uses is the Creation part of the MAC time for the registry key. And may be liable to inconsistancies.


   
ReplyQuote
Share: