IT Forensics – Windows

Forensic analysis of Windows USB artefacts – Tracing connected devices

Windows stores a great deal of information about connected USB devices. This includes, amongst other things, registry entries, device identifiers, time-stamps and other metadata. These artefacts can provide important clues as to which USB-Sticks, external hard drives or other storage media have been used on a system.

Enquire without obligation

As part of a professional IT forensic investigation, USB artefacts are never analysed in isolation. Only by correlating them with the Windows Registry, event logs, LNK files, ShellBags, jump lists and other digital traces is it possible to carry out a reliable technical assessment.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.

Our services

We analyse registry entries, device identifiers, timestamps and other USB-related artefacts. The results are correlated with additional Windows artefacts and fully documented.

Typical areas of application

Data theft
Analysis of external storage media
Incident Response
Investigation into allegations of manipulation
Employment law proceedings
Expert reports for the courts

This is how the analysis works

Once a forensic image has been created, all relevant USB artefacts are analysed. The results are then cross-referenced with other digital evidence and assessed from a technical perspective.

Why are USB artefacts important?

USB artefacts can provide clues about connected devices and their use. However, their significance only becomes apparent following a comprehensive analysis of all relevant digital traces relating to the case in question.

Frequently Asked Questions

What sort of information might USB artefacts contain?+
Depending on the data available, this may include, amongst other things, device identifiers, connection details and timestamps.
Is the original system being examined?+
No. Only a forensic copy or forensic image is analysed.
Can USB devices that have been removed be detected?+
Depending on the artefacts available, it may be possible to trace previous device connections.
Are USB artefacts alone sufficient for an expert report?+
No. They are always analysed alongside other Windows artefacts.

LanCologne – Windows Forensics in Cologne

Do you need a professional analysis of Windows USB artefacts or other Windows artefacts? LanCologne can assist you with the forensic-grade preservation of digital evidence and the objective analysis of complex Windows systems.

Get in touch now