tyanque Posted December 3, 2009 Share Posted December 3, 2009 How do you find out what USB devices have been plugged in, the devices activity, the difference between one of the same USB key, and what changes on the system when it is plugged in? (All in a windows box, with no additional tools). Thanks Quote Link to comment Share on other sites More sharing options...
lopez1364 Posted December 3, 2009 Share Posted December 3, 2009 Watch a video from season 5 when Chris Gerling talks about recognizing USB devices. Quote Link to comment Share on other sites More sharing options...
digip Posted December 3, 2009 Share Posted December 3, 2009 jaclaz Jul 4 2006, 01:23 PM You can scan the registry. All devices connected once should have an entry. They should be in: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USB but check also in HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\USB Mass storage devices will have additional entries in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR jaclaz - http://www.msfn.org/board/lofiversion/inde...gen/t77698.html Quote Link to comment Share on other sites More sharing options...
catchyanow Posted December 10, 2009 Share Posted December 10, 2009 Start - my computer lol Quote Link to comment Share on other sites More sharing options...
operat0r_001 Posted December 10, 2009 Share Posted December 10, 2009 random psycho babble * not sure but something about flash media over say 8gigs is 'different' maybe <8 is flash and >8 is 'removal disk' I just have had issues with boot/etc with larger flash drives * as far as USB forensics for windows I use HandyRecovery.exe GetDataBack for NTFS portable.exe GetDataBack for FAT portable.exe (PhotoRec - CGSecurity) * also look into dd_rhelp but normally flash works or does not so its more a matter of what tools to aim at it then reading from it with IDE/SATA you can buy PCI cards that can read at a lower level * for more info pop it in a *nix box and google the device is picksup to answer your Q: lookinto WMI you can monitor and query event logs etc anything ... you could http://www.google.com/search?q=GPO+%22usb+flash%22 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.