SKIP TO CONTENT
USB AND REMOVABLE MEDIA02 / 36

MountedDevices and MountPoints2

Also called registry MountedDevices, MountPoints2, drive letter assignment registry, volume GUID mapping.

PLATFORM
Windows
CATEGORY
USB and Removable Media
INDEX
2 of 36
PROVES
4 findings
CANNOT PROVE
5 limits
QUESTIONS
3 answered
WHAT IT IS

Two registry locations that map drive letters and volume identifiers to underlying devices — one machine-wide and current-state only, one per-user and the closest thing to user attribution for a mounted volume.

Where it lives

SYSTEM\MountedDevices (machine-wide) and, per user, NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2

Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of mounteddevices and mountpoints2” is neither.

What it records

MountedDevices holds one value per drive letter and per volume identifier, whose binary data identifies the underlying device: a device instance path for removable media, or a disk signature and partition offset for fixed disks. It records the present mapping, overwritten as letters are reassigned, not a history of mappings. MountPoints2 sits in each user's own hive and contains a subkey for each volume that account mounted, named by volume GUID, by drive letter, or by UNC path for a network share; the subkey's last-write time is the timestamp examiners use.

What it proves — and what it cannot

These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.

What it proves

FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.

  • Which physical or removable device a given drive letter currently refers to, so that a path recorded elsewhere as E:\ can be resolved to a device
  • That a particular user account, and not merely the machine, mounted a specific volume — the per-user attribution USBSTOR cannot supply
  • That an account connected to a named network share, where a ##server#share subkey is present under MountPoints2
  • A last-write timestamp for each MountPoints2 subkey, giving a rough date for that account's interaction with the volume

What it cannot prove

INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.

  • The historical mapping of any drive letter. MountedDevices is a snapshot of the current state; letters are recycled to later devices, so a mapping recorded today may not be the mapping in force on the date at issue
  • That anything was read from or written to the mounted volume. Mounting is not access, and neither key records file activity
  • That a MountPoints2 subkey's last-write time is the time of the mount. The key is rewritten for reasons other than a fresh mount, so the timestamp bounds rather than fixes the event
  • Which user mounted a volume, from MountedDevices alone — it is machine-wide and account-blind
  • That an absent MountPoints2 entry means the account never used the volume. The key is routinely cleared by cleanup utilities and by roaming-profile behaviour

How the finding is attacked

An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.

  • Reading a current drive-letter mapping backwards onto an earlier date without establishing which device held the letter then
  • Presenting a MountPoints2 last-write time as the moment of connection rather than as an upper bound
  • Pointing out that a volume GUID subkey persists after the device is gone, so its presence dates nothing on its own
  • Noting that on a shared or kiosk machine the same profile may have been used by more than one person

What survives, and for how long

Both persist across reboots. MountedDevices survives only as a current-state snapshot, so historical mappings are lost as letters are reassigned. MountPoints2 subkeys accumulate in the user hive and can remain long after the volume is gone, but they are among the first things cleanup utilities remove.

More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.

Questions counsel ask

What does the MountedDevices registry key show?

It maps each drive letter and volume identifier to the device behind it — a device instance path for removable media, a disk signature and partition offset for a fixed disk. It records the current state only. Drive letters are handed out again to later devices, so a mapping read from an image is a snapshot that has to be dated against something else before it can be used to resolve a path recorded on an earlier date.

How do you show which user account connected a USB drive?

Through MountPoints2, in that user's own registry hive, which records the volumes that account mounted. The machine-wide USBSTOR keys establish that a device touched the computer; MountPoints2 is what connects the mount to an account. It still names an account rather than a person, so attribution to a human requires corroboration from outside the machine — badge records, video, or an admission.

Does MountPoints2 record network drives?

Yes. Alongside volume GUID and drive-letter subkeys, MountPoints2 contains subkeys named for UNC paths, recording that the account connected to a named server and share. That makes it useful in matters where the question is whether a user reached a file server they were not supposed to reach. It records the connection, not what was opened on the share.

Terms used on this page

Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.

No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.

A FINDING ON THIS ARTIFACT

Whether the mounteddevices and mountpoints2evidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

  • Can This Artifact Prove That?

    Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.

  • Computer forensics

    The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.

  • The artifact index

    All 36 entries, grouped by what they bear on and filterable by platform.

  • Daubert and digital evidence

    Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.

← BACK TO THE ARTIFACT INDEX

Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.