USB Device & External Storage - DFIR Workflow & Cheatsheet
Quick Reference: Investigation Priority Matrix
Priority
Artifact
Key Questions Answered
Persistence
OS Version
Investigation Workflow
Phase 1: USB Device Identification (Critical Priority)
1.1 Primary USB Device Enumeration
1.2 Connection Timestamps (First, Last, Removal)
Phase 2: Device-to-User Attribution (High Priority)
2.1 User MountPoints2 (Per-User USB Access)
Step 1: Get Device Volume GUID from MountedDevices
Step 2: Match Volume GUID in User's MountPoints2
Phase 3: Drive Letter & Volume Identification (Medium Priority)
3.1 Last Drive Letter Assignment
Phase 4: Volume Serial Number (VSN) Analysis
4.1 Volume Serial Number Extraction
Phase 5: File Access Evidence (Critical Priority)
5.1 LNK (Shortcut) Files Analysis
Phase 6: System Context (Supporting Priority)
6.1 Operating System Version
6.2 Computer Name
6.3 System Last Shutdown Time
6.4 System Boot & Autostart Programs
Phase 7: Event Log Correlation (Supporting Priority)
7.1 System Event Log
7.2 Security Event Log
7.3 Partition/Diagnostic Event Log (Already Covered)
Phase 8: Cloud Sync & OneDrive (Modern Systems)
Advanced Investigation Techniques
Complete USB Device Timeline Reconstruction
USB Device Identification Cheat Sheet
LNK File to USB Device Mapping
Cross-Artifact Correlation Matrix
Artifact
Provides
Links To
Time Precision
Investigation Checklists
Initial USB Triage Checklist
USB Device Enumeration
Timestamp Extraction
Drive Letter & Volume Analysis
User Attribution
File Access Investigation
OneDrive Investigation (if applicable)
Event Log Analysis
Timeline & Reporting
Essential DFIR Tools
Registry Analysis
LNK File Analysis
Event Log Analysis
USB-Specific Tools
Comprehensive Suites
Timeline Tools
Quick Command Reference
PowerShell USB Investigation Script
Batch USB Parsing Script
Timeline Creation with Plaso
Common Forensic Scenarios
Scenario 1: Data Exfiltration via USB
Scenario 2: Unauthorised USB Device
Scenario 3: Deleted File Recovery from USB
Scenario 4: Malware Delivery via USB
Investigation Gotchas & Notes
USB Device Serial Numbers
Timestamps
Drive Letter Assignments
Volume Serial Numbers
LNK Files
Event Logs
OneDrive
Best Practices
Evidence Preservation
Analysis Methodology
Reporting
PreviousDeleted Files & File Knowledge—DFIR Workflow & CheatsheetNextAccount Usage Investigation with KQL Cheatsheet
Last updated