IT Forensics – Windows
Forensic analysis of Windows USB artefacts – Tracing connected devices
Windows stores a great deal of information about connected USB devices. This includes, amongst other things, registry entries, device identifiers, time-stamps and other metadata. These artefacts can provide important clues as to which USB-Sticks, external hard drives or other storage media have been used on a system.
As part of a professional IT forensic investigation, USB artefacts are never analysed in isolation. Only by correlating them with the Windows Registry, event logs, LNK files, ShellBags, jump lists and other digital traces is it possible to carry out a reliable technical assessment.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.
Our services
We analyse registry entries, device identifiers, timestamps and other USB-related artefacts. The results are correlated with additional Windows artefacts and fully documented.
Typical areas of application
This is how the analysis works
Once a forensic image has been created, all relevant USB artefacts are analysed. The results are then cross-referenced with other digital evidence and assessed from a technical perspective.
Why are USB artefacts important?
USB artefacts can provide clues about connected devices and their use. However, their significance only becomes apparent following a comprehensive analysis of all relevant digital traces relating to the case in question.
Frequently Asked Questions
🔗 Related topics
LanCologne – Windows Forensics in Cologne
Do you need a professional analysis of Windows USB artefacts or other Windows artefacts? LanCologne can assist you with the forensic-grade preservation of digital evidence and the objective analysis of complex Windows systems.
Related to this topic
- Forensic analysis of Windows user profiles – tracing user activities
- Forensic analysis of Windows AppData – analysing application and user data
- Forensic analysis of Windows temporary files – Temporary artefacts as digital evidence
- In-depth forensic analysis of the Windows Recycle Bin (.Bin) – tracing deletion processes