SKIP TO CONTENT
USB AND REMOVABLE MEDIA01 / 36

USBSTOR and USB Device History

Also called USB insertion history, USBSTOR registry key, USB device registry artifacts, removable device history.

PLATFORM
Windows
CATEGORY
USB and Removable Media
INDEX
1 of 36
PROVES
5 findings
CANNOT PROVE
6 limits
QUESTIONS
4 answered
WHAT IT IS

The SYSTEM registry records which USB storage devices were attached to a machine, their vendor and product strings, and a small fixed set of first-seen and last-connected timestamps.

Where it lives

SYSTEM\CurrentControlSet\Enum\USBSTOR and SYSTEM\CurrentControlSet\Enum\USB; device timestamps live under each device's Properties subkey, GUID {83da6326-97a6-4088-9453-a1923f573b29}

Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of usbstor and usb device history” is neither.

What it records

When Windows loads a driver for a USB mass-storage device it writes an enumeration key naming the vendor, product and revision strings the device reported, keyed by a device instance identifier. Under each device's Properties subkey, Windows stores discrete timestamp values — commonly first install, first connection since the key existed, last arrival and last removal — as individual values rather than as an event stream. Values 0066 and 0067 in that property set, which carry last-arrival and last-removal, are present from Windows 8 onward and should not be assumed on older builds.

What it proves — and what it cannot

These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.

What it proves

FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.

  • That a device matching a specific vendor, product and revision string was attached to this machine at least once
  • Approximately when a given device was first installed on the machine, which is the fact that dates the relationship between device and computer
  • The last time that device arrived and was removed, on builds that record those values
  • That several distinct devices were used, and the order in which they first appeared — the basis for identifying a device that appears only in the departure window
  • A device identifier that can be compared against a drive produced in discovery, when the drive reports a real manufacturer serial

What it cannot prove

INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.

  • That any file was copied to or from the device. USBSTOR records driver enumeration, not I/O. There is no byte count, no filename, and no transfer record anywhere in this key
  • How many times the device was connected. The registry holds a handful of timestamp values, not a counter, so a claim about frequency has to come from event-log channels whose coverage is finite
  • That the device instance identifier is a manufacturer serial number. Where its second character is an ampersand, Windows generated the value because the device reported no serial, and such identifiers are not unique across devices
  • Which user was logged on when the device was attached. USBSTOR sits in a machine-wide hive; per-user attribution requires MountPoints2 in the individual user's hive
  • That the drive produced in discovery is the drive in the registry, where the vendor and product strings are generic — thousands of identical devices report identical strings
  • That a device was never used. Keys can be removed by cleanup utilities, by driver uninstallation, and by a user with administrative rights

How the finding is attacked

An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.

  • Reading the instance identifier as a serial number when the ampersand in the second character shows the operating system generated it
  • Treating first-install time as the time of an event, when it records when the driver stack first enumerated that device on this machine and nothing about what happened afterwards
  • Arguing from a single device key to a pattern of use, when the key records no count
  • Offering an innocent explanation the examination never tested — a sanctioned backup drive, a presentation stick, a personal media device the employer tolerated
  • Pointing out that the connection could have been made by anyone with physical access, where no per-user artifact was examined

What survives, and for how long

The enumeration keys persist across reboots and remain after the device is gone, often for the life of the installation, because nothing routinely prunes them. They do not survive a wipe and reinstall, and they can be deleted deliberately by cleanup tools or by an administrator, so absence is weak evidence that a device was never attached.

More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.

Questions counsel ask

Does USB history prove files were copied to a thumb drive?

No. USB registry history records that a device was attached and when the driver stack enumerated it. It contains no filenames, no byte counts, and no record of file transfer of any kind. Showing that material moved requires other artifacts — LNK files or jumplist entries carrying the volume serial number of the removable media, shellbags for folders browsed on it, journal records, or the device itself.

What does the USBSTOR last connected timestamp actually mean?

It records the last time Windows saw that device arrive on the bus, written to a property value under the device's registry key. It is a single overwritten value, not an entry in a history, so it tells you about one moment and nothing about the connections before it. On builds older than Windows 8 the value may not exist at all, and its absence there says nothing about whether the device was used.

Is a USB device instance ID the same as the drive's serial number?

Often, but not always, and the difference matters under oath. Where the device reported a serial number, the instance identifier is usually that serial. Where the second character of the identifier is an ampersand, the device reported no serial and Windows generated the value — those identifiers are not unique, so two different drives can produce the same one. Reports treating every instance identifier as a serial invite correction on cross-examination.

Can you tell which user plugged in the USB device?

Not from USBSTOR, which lives in a machine-wide hive and speaks to the computer rather than to any account. The per-user MountPoints2 key in an individual user's NTUSER.DAT records which volumes that account mounted, which is the artifact that separates a device touching a shared workstation from a particular user's account mounting it. On a machine several people used, that distinction is frequently the whole dispute.

Terms used on this page

Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.

No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.

A FINDING ON THIS ARTIFACT

Whether the usbstor and usb device historyevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

  • Can This Artifact Prove That?

    Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.

  • Computer forensics

    The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.

  • The artifact index

    All 36 entries, grouped by what they bear on and filterable by platform.

  • Daubert and digital evidence

    Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.

← BACK TO THE ARTIFACT INDEX

Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.