USBSTOR and USB Device History
Also called USB insertion history, USBSTOR registry key, USB device registry artifacts, removable device history.
- PLATFORM
- Windows
- CATEGORY
- USB and Removable Media
- INDEX
- 1 of 36
- PROVES
- 5 findings
- CANNOT PROVE
- 6 limits
- QUESTIONS
- 4 answered
The SYSTEM registry records which USB storage devices were attached to a machine, their vendor and product strings, and a small fixed set of first-seen and last-connected timestamps.
Where it lives
SYSTEM\CurrentControlSet\Enum\USBSTOR and SYSTEM\CurrentControlSet\Enum\USB; device timestamps live under each device's Properties subkey, GUID {83da6326-97a6-4088-9453-a1923f573b29}
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of usbstor and usb device history” is neither.
What it records
When Windows loads a driver for a USB mass-storage device it writes an enumeration key naming the vendor, product and revision strings the device reported, keyed by a device instance identifier. Under each device's Properties subkey, Windows stores discrete timestamp values — commonly first install, first connection since the key existed, last arrival and last removal — as individual values rather than as an event stream. Values 0066 and 0067 in that property set, which carry last-arrival and last-removal, are present from Windows 8 onward and should not be assumed on older builds.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- That a device matching a specific vendor, product and revision string was attached to this machine at least once
- Approximately when a given device was first installed on the machine, which is the fact that dates the relationship between device and computer
- The last time that device arrived and was removed, on builds that record those values
- That several distinct devices were used, and the order in which they first appeared — the basis for identifying a device that appears only in the departure window
- A device identifier that can be compared against a drive produced in discovery, when the drive reports a real manufacturer serial
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- That any file was copied to or from the device. USBSTOR records driver enumeration, not I/O. There is no byte count, no filename, and no transfer record anywhere in this key
- How many times the device was connected. The registry holds a handful of timestamp values, not a counter, so a claim about frequency has to come from event-log channels whose coverage is finite
- That the device instance identifier is a manufacturer serial number. Where its second character is an ampersand, Windows generated the value because the device reported no serial, and such identifiers are not unique across devices
- Which user was logged on when the device was attached. USBSTOR sits in a machine-wide hive; per-user attribution requires MountPoints2 in the individual user's hive
- That the drive produced in discovery is the drive in the registry, where the vendor and product strings are generic — thousands of identical devices report identical strings
- That a device was never used. Keys can be removed by cleanup utilities, by driver uninstallation, and by a user with administrative rights
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Reading the instance identifier as a serial number when the ampersand in the second character shows the operating system generated it
- Treating first-install time as the time of an event, when it records when the driver stack first enumerated that device on this machine and nothing about what happened afterwards
- Arguing from a single device key to a pattern of use, when the key records no count
- Offering an innocent explanation the examination never tested — a sanctioned backup drive, a presentation stick, a personal media device the employer tolerated
- Pointing out that the connection could have been made by anyone with physical access, where no per-user artifact was examined
What survives, and for how long
The enumeration keys persist across reboots and remain after the device is gone, often for the life of the installation, because nothing routinely prunes them. They do not survive a wipe and reinstall, and they can be deleted deliberately by cleanup tools or by an administrator, so absence is weak evidence that a device was never attached.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
Does USB history prove files were copied to a thumb drive?
No. USB registry history records that a device was attached and when the driver stack enumerated it. It contains no filenames, no byte counts, and no record of file transfer of any kind. Showing that material moved requires other artifacts — LNK files or jumplist entries carrying the volume serial number of the removable media, shellbags for folders browsed on it, journal records, or the device itself.
What does the USBSTOR last connected timestamp actually mean?
It records the last time Windows saw that device arrive on the bus, written to a property value under the device's registry key. It is a single overwritten value, not an entry in a history, so it tells you about one moment and nothing about the connections before it. On builds older than Windows 8 the value may not exist at all, and its absence there says nothing about whether the device was used.
Is a USB device instance ID the same as the drive's serial number?
Often, but not always, and the difference matters under oath. Where the device reported a serial number, the instance identifier is usually that serial. Where the second character of the identifier is an ampersand, the device reported no serial and Windows generated the value — those identifiers are not unique, so two different drives can produce the same one. Reports treating every instance identifier as a serial invite correction on cross-examination.
Can you tell which user plugged in the USB device?
Not from USBSTOR, which lives in a machine-wide hive and speaks to the computer rather than to any account. The per-user MountPoints2 key in an individual user's NTUSER.DAT records which volumes that account mounted, which is the artifact that separates a device touching a shared workstation from a particular user's account mounting it. On a machine several people used, that distinction is frequently the whole dispute.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
MountedDevices and MountPoints2
Two registry locations that map drive letters and volume identifiers to underlying devices — one machine-wide and current-state only, one per-user and the closest thing to user attribution for a mounted volume.
USB Connection Event Logs
Event-log channels that timestamp individual device arrivals and removals, and which — unlike the registry — can record how often a device was connected and how large its volume was.
LNK Shortcut Files
Shortcut files Windows creates when a document is opened through the shell, retaining the target's full path, its size and timestamps, and often the volume serial number of the drive it lived on.
Shellbags
Registry entries preserving the name, position in the folder tree, and display settings of folders a user browsed in Explorer — including folders that no longer exist.
AmCache
A registry hive maintained by the compatibility appraiser recording that binaries were present on the system, with their paths, publishers, sizes and a SHA-1 of the file.
Whether the usbstor and usb device historyevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.