C:\Windows\setupapi.log
http://forensics.sans.org
http://twitter.com/sansforensics
ProfileXPUSBDevices
USBDEVICE1
1.WriteDownVendor,Product,Version SYSTEM\CurrentControlSet\Enum\USBSTOR 2.WriteDownSerialNumbers SYSTEM\CurrentControlSet\Enum\USBSTOR 3.DetermineParentPrefixID SYSTEM\CurrentControlSet\Enum\USBSTOR 4.DetermineDriveLetterDeviceMappedTo SYSTEM\MountedDevices-> Performsearchfor ParentPrefixID 5.WriteDownVolumeGUIDs SYSTEM\MountedDevices-> PerformSearchfor ParentPrefixID 6.FindUserThatUsedTheSpecificUSBDevice NTUSER.DAT\Software\Microsoft\Windows\ CurrentVersion\Explorer\MountPoints2-> SearchforDeviceGUID 7.DetermineLastTimeDeviceConnected SYSTEM\CurrentControlSet\Control\Devic eClasses\{53f56307-b6bf-11d0-94f200a0c91efb8b}-> PerformsearchforS/N 8.DiscoverFirstTimeDeviceConnected C:\Windows\setupapi.log >Performsearch forSerialNumber
USBDEVICE2
1.WriteDownVendor,Product,Version SYSTEM\CurrentControlSet\Enum\USBSTOR 2.WriteDownSerialNumbers SYSTEM\CurrentControlSet\Enum\USBSTOR 3.DetermineParentPrefixID SYSTEM\CurrentControlSet\Enum\USBSTOR 4.DetermineDriveLetterDeviceMappedTo SYSTEM\MountedDevices-> Performsearchfor ParentPrefixID 5.WriteDownVolumeGUIDs SYSTEM\MountedDevices-> PerformSearchfor ParentPrefixID 6.FindUserThatUsedTheSpecificUSBDevice NTUSER.DAT\Software\Microsoft\Windows\ CurrentVersion\Explorer\MountPoints2-> SearchforDeviceGUID 7.DetermineLastTimeDeviceConnected SYSTEM\CurrentControlSet\Control\Devic eClasses\{53f56307-b6bf-11d0-94f200a0c91efb8b}-> PerformsearchforS/N 8.DiscoverFirstTimeDeviceConnected C:\Windows\setupapi.log >Performsearch forSerialNumber
USBDEVICE3
1.WriteDownVendor,Product,Version SYSTEM\CurrentControlSet\Enum\USBSTOR 2.WriteDownSerialNumbers SYSTEM\CurrentControlSet\Enum\USBSTOR 3.DetermineParentPrefixID SYSTEM\CurrentControlSet\Enum\USBSTOR 4.DetermineDriveLetterDeviceMappedTo SYSTEM\MountedDevices-> Performsearchfor ParentPrefixID 5.WriteDownVolumeGUIDs SYSTEM\MountedDevices-> PerformSearchfor ParentPrefixID 6.FindUserThatUsedTheSpecificUSBDevice NTUSER.DAT\Software\Microsoft\Windows\ CurrentVersion\Explorer\MountPoints2-> SearchforDeviceGUID 7.DetermineLastTimeDeviceConnected SYSTEM\CurrentControlSet\Control\Devic eClasses\{53f56307-b6bf-11d0-94f200a0c91efb8b}-> PerformsearchforS/N 8.DiscoverFirstTimeDeviceConnected C:\Windows\setupapi.log >Performsearch forSerialNumber
USBDEVICE4
1.WriteDownVendor,Product,Version SYSTEM\CurrentControlSet\Enum\USBSTOR 2.WriteDownSerialNumbers SYSTEM\CurrentControlSet\Enum\USBSTOR 3.DetermineParentPrefixID SYSTEM\CurrentControlSet\Enum\USBSTOR 4.DetermineDriveLetterDeviceMappedTo SYSTEM\MountedDevices-> Performsearchfor ParentPrefixID 5.WriteDownVolumeGUIDs SYSTEM\MountedDevices-> PerformSearchfor ParentPrefixID 6.FindUserThatUsedTheSpecificUSBDevice NTUSER.DAT\Software\Microsoft\Windows\ CurrentVersion\Explorer\MountPoints2-> SearchforDeviceGUID 7.DetermineLastTimeDeviceConnected SYSTEM\CurrentControlSet\Control\Devic eClasses\{53f56307-b6bf-11d0-94f200a0c91efb8b}-> PerformsearchforS/N 8.DiscoverFirstTimeDeviceConnected C:\Windows\setupapi.log >Performsearch forSerialNumber