码迷,mamicode.com
首页 > 其他好文 > 详细

How to find missing USB Records?

时间:2017-10-25 16:40:05      阅读:154      评论:0      收藏:0      [点我收藏+]

标签:dig   too   file   actual   conf   png   following   rand   iss   

In my previously article "EnCase missed some USB activities in the evidence files", I mentioned about that EnCase could  only "see" few USB records. Actually not only EnCase may not see all USB records, some other forensic tools got the same problems.

 

What else could help us to find the missing USB Records? Take Windows 10 for example, we could take a look at the event log file named "Microsoft-Windows-Kernel-PnP%4Configuration.evtx" as below. You could know the brand, model and serial number and the timestamp etc.

技术分享

 

 

Actually there is more than one USB device that suspect used as below. It‘s Seagate BUP_BK, but what‘s wrong with the serial number? All the digit is zero? That‘s not gonna happen,right?

技术分享

 

Don‘t worry~ Just take a look at the following record and you will see its actual serial number.

技术分享

 

 

How to find missing USB Records?

标签:dig   too   file   actual   conf   png   following   rand   iss   

原文地址:http://www.cnblogs.com/pieces0310/p/7729327.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!