SKIP TO CONTENT
USB AND REMOVABLE MEDIA03 / 36

USB Connection Event Logs

Also called Partition Diagnostic 1006, Kernel-PnP events, DriverFrameworks-UserMode, USB event log timestamps.

PLATFORM
Windows
CATEGORY
USB and Removable Media
INDEX
3 of 36
PROVES
4 findings
CANNOT PROVE
5 limits
QUESTIONS
3 answered
WHAT IT IS

Event-log channels that timestamp individual device arrivals and removals, and which — unlike the registry — can record how often a device was connected and how large its volume was.

Where it lives

Microsoft-Windows-Partition/Diagnostic (Event ID 1006), Microsoft-Windows-Kernel-PnP/Configuration, and Microsoft-Windows-DriverFrameworks-UserMode/Operational, under %SystemRoot%\System32\winevt\Logs

Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of usb connection event logs” is neither.

What it records

The Partition/Diagnostic channel writes an Event ID 1006 record when a storage device arrives or departs, capturing the device's vendor and product strings, reported serial, capacity, and on many builds the first sectors of the media including its partition table. Kernel-PnP records device configuration events. The DriverFrameworks-UserMode operational channel recorded connection and disconnection pairs on Windows 7 and is disabled by default on later builds. Each of these is a per-event record with its own timestamp, which is what distinguishes them from the registry's fixed set of values.

What it proves — and what it cannot

These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.

What it proves

FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.

  • Individual, separately timestamped connection and removal events, which is the only Windows source that can support a claim about how often a device was used
  • The reported capacity of the attached volume, useful when a party later produces a different drive and calls it the one at issue
  • Partition-table content captured at connection, which can distinguish two devices reporting identical vendor and product strings
  • That a device was attached during a window in which the registry's overwritten values have since moved on

What it cannot prove

INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.

  • Anything about file transfer. These channels record device arrival, configuration and departure; no filename or byte count appears in them
  • A complete connection history. Event logs are size-capped and roll, so the record reaches back weeks or months on a busy machine and is silent about anything older
  • That the channel was ever recording. The DriverFrameworks-UserMode operational channel is disabled by default on current builds, and channel availability differs across Windows 10 and 11 releases — presence has to be verified rather than assumed
  • Which user was at the keyboard. These are system channels with no per-user attribution
  • That the absence of an event means the device was not connected. Rollover, a disabled channel, and log clearing all produce the same silence

How the finding is attacked

An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.

  • Establishing the log's earliest surviving record and showing that the examiner's frequency claim covers a period the log never held
  • Showing the relevant channel was disabled by default on the build in question, so no inference can be drawn from an empty log
  • Questioning whether an arrival event was generated by a person inserting a device or by a docking station, a reboot, or a virtual machine's device redirection
  • Comparing the reported capacity against the produced device and using a mismatch to argue that the examined device is not the one in evidence

What survives, and for how long

Records live in the .evtx files until the channel reaches its configured maximum size and rolls, which on a workstation typically means weeks to months for these low-volume channels and much less on a busy system. Clearing a log leaves its own record; a wipe and reinstall removes everything.

More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.

Questions counsel ask

Can Windows tell you how many times a USB drive was plugged in?

Only from the event logs, and only as far back as the log reaches. The registry holds a small fixed set of timestamps per device and no counter, so frequency claims have to come from per-event channels such as Partition/Diagnostic. Those channels are size-capped and roll over, so the honest form of the finding states how many connections survived in the log and how far back the log extends.

What is Event ID 1006 in the Partition/Diagnostic log?

It is a storage-device event written when a disk or removable volume is seen, recording the device's vendor and product strings, its reported serial, its capacity, and on many builds the first sectors of the media including the partition table. That combination can distinguish two drives that report identical vendor and product strings, which the enumeration registry keys alone often cannot.

Why is there no USB event log on this machine?

Most often because the channel is disabled by default on that build. The DriverFrameworks-UserMode operational channel was on by default in Windows 7 and is off in later releases, and channel availability otherwise varies across Windows 10 and 11 versions. An empty or missing channel is therefore evidence about configuration, not about whether devices were connected, and the two have to be distinguished before any conclusion is drawn.

Terms used on this page

Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.

No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.

A FINDING ON THIS ARTIFACT

Whether the usb connection event logsevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

  • Can This Artifact Prove That?

    Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.

  • Computer forensics

    The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.

  • The artifact index

    All 36 entries, grouped by what they bear on and filterable by platform.

  • Daubert and digital evidence

    Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.

← BACK TO THE ARTIFACT INDEX

Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.