MountedDevices and MountPoints2
Also called registry MountedDevices, MountPoints2, drive letter assignment registry, volume GUID mapping.
- PLATFORM
- Windows
- CATEGORY
- USB and Removable Media
- INDEX
- 2 of 36
- PROVES
- 4 findings
- CANNOT PROVE
- 5 limits
- QUESTIONS
- 3 answered
Two registry locations that map drive letters and volume identifiers to underlying devices — one machine-wide and current-state only, one per-user and the closest thing to user attribution for a mounted volume.
Where it lives
SYSTEM\MountedDevices (machine-wide) and, per user, NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of mounteddevices and mountpoints2” is neither.
What it records
MountedDevices holds one value per drive letter and per volume identifier, whose binary data identifies the underlying device: a device instance path for removable media, or a disk signature and partition offset for fixed disks. It records the present mapping, overwritten as letters are reassigned, not a history of mappings. MountPoints2 sits in each user's own hive and contains a subkey for each volume that account mounted, named by volume GUID, by drive letter, or by UNC path for a network share; the subkey's last-write time is the timestamp examiners use.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- Which physical or removable device a given drive letter currently refers to, so that a path recorded elsewhere as E:\ can be resolved to a device
- That a particular user account, and not merely the machine, mounted a specific volume — the per-user attribution USBSTOR cannot supply
- That an account connected to a named network share, where a ##server#share subkey is present under MountPoints2
- A last-write timestamp for each MountPoints2 subkey, giving a rough date for that account's interaction with the volume
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- The historical mapping of any drive letter. MountedDevices is a snapshot of the current state; letters are recycled to later devices, so a mapping recorded today may not be the mapping in force on the date at issue
- That anything was read from or written to the mounted volume. Mounting is not access, and neither key records file activity
- That a MountPoints2 subkey's last-write time is the time of the mount. The key is rewritten for reasons other than a fresh mount, so the timestamp bounds rather than fixes the event
- Which user mounted a volume, from MountedDevices alone — it is machine-wide and account-blind
- That an absent MountPoints2 entry means the account never used the volume. The key is routinely cleared by cleanup utilities and by roaming-profile behaviour
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Reading a current drive-letter mapping backwards onto an earlier date without establishing which device held the letter then
- Presenting a MountPoints2 last-write time as the moment of connection rather than as an upper bound
- Pointing out that a volume GUID subkey persists after the device is gone, so its presence dates nothing on its own
- Noting that on a shared or kiosk machine the same profile may have been used by more than one person
What survives, and for how long
Both persist across reboots. MountedDevices survives only as a current-state snapshot, so historical mappings are lost as letters are reassigned. MountPoints2 subkeys accumulate in the user hive and can remain long after the volume is gone, but they are among the first things cleanup utilities remove.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
What does the MountedDevices registry key show?
It maps each drive letter and volume identifier to the device behind it — a device instance path for removable media, a disk signature and partition offset for a fixed disk. It records the current state only. Drive letters are handed out again to later devices, so a mapping read from an image is a snapshot that has to be dated against something else before it can be used to resolve a path recorded on an earlier date.
How do you show which user account connected a USB drive?
Through MountPoints2, in that user's own registry hive, which records the volumes that account mounted. The machine-wide USBSTOR keys establish that a device touched the computer; MountPoints2 is what connects the mount to an account. It still names an account rather than a person, so attribution to a human requires corroboration from outside the machine — badge records, video, or an admission.
Does MountPoints2 record network drives?
Yes. Alongside volume GUID and drive-letter subkeys, MountPoints2 contains subkeys named for UNC paths, recording that the account connected to a named server and share. That makes it useful in matters where the question is whether a user reached a file server they were not supposed to reach. It records the connection, not what was opened on the share.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
USBSTOR and USB Device History
The SYSTEM registry records which USB storage devices were attached to a machine, their vendor and product strings, and a small fixed set of first-seen and last-connected timestamps.
USB Connection Event Logs
Event-log channels that timestamp individual device arrivals and removals, and which — unlike the registry — can record how often a device was connected and how large its volume was.
Shellbags
Registry entries preserving the name, position in the folder tree, and display settings of folders a user browsed in Explorer — including folders that no longer exist.
LNK Shortcut Files
Shortcut files Windows creates when a document is opened through the shell, retaining the target's full path, its size and timestamps, and often the volume serial number of the drive it lived on.
Whether the mounteddevices and mountpoints2evidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.