Taking instructions now — the first conversation is freeExhibits posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
FDRForensic Data Recovery 0800 6890668 Price my job
FDR / What the evidence can show / USB device history

USB history · USBSTOR · serial numbers · first and last connected · registry · setupapi

USB device history. A Windows computer keeps a record of every USB storage device ever plugged into it, long after the device is gone.

The single most useful artefact in a data-theft case is the one most people do not know exists: Windows keeps a permanent record, in the registry and the system logs, of every USB storage device ever connected to the computer. For each one it holds the make, the model, the serial number the manufacturer burned into the device, and the dates it was first and last connected. The record survives the device being unplugged, and it survives files being deleted. So when the question is whether an unknown USB stick or portable drive was ever used on a machine, the computer itself usually answers it, and ties each device to the files that were opened from it. This page explains where the record comes from and what it proves, which is that a particular device was connected to the machine at particular times, under a particular user session, not who physically plugged it in.

Owner-only, authority requiredFree first conversationStandard report £800 + VATWe say what it cannot prove

Rather talk it through? An engineer answers the bench line
0800 6890668

Before anything else: stop using the device, and do not let anyone have a look at it. Every time a computer is switched on and used, the very artefacts an examination relies on, the timeline, the recently-opened lists, the deleted-file space, are overwritten a little more. Do not reinstall, do not run recovery software, do not let IT open it to check, and keep it powered off. Preserve it as it is, record who has held it, and send it with the authority documents we ask for. If proceedings are contemplated, the duty to preserve evidence has already begun.

Where the record comes from, and what it proves.

When a USB storage device is first connected to a Windows computer, the system records it in several places at once: the USBSTOR key in the registry stores the device's make, model and serial number; the setupapi device log records the first-install time; the MountedDevices and MountPoints2 keys tie the device to the drive letter and volume it was given; and the Partition/Diagnostic and other event logs record connections. Together these give the device's identity and its first and last connection times, and the records persist indefinitely.

The serial number is the key to it. Because it is burned into the device by the manufacturer, it lets an examiner say that this particular device, not merely some device, was connected, and if the same device is later found in someone's possession, the serial ties the two together. The examination lists every device, flags any first connected in a period of interest, and shows how often each was used.

The record is then joined to the files opened from the device. Each volume has its own serial, recorded in the jump lists, shortcut files and shellbags, so the examiner can show which files and folders were opened from a specific USB device, and when. That join is what turns a list of devices into evidence about data.

What it records, and what it means.

Describe your situation →
What is recorded Where it comes from What it shows, and does not
Device make, model and serialThe USBSTOR registry keyThat a specific device was connected; not who connected it
First and last connection timessetupapi log and event logsWhen the device was used; not what was copied
The drive letter and volumeMountedDevices, MountPoints2Which volume the device presented, to tie to opened files
Files opened from the deviceJump lists, LNK, shellbags by volume serialThat files were opened from it; not that they were copied

From the exhibit arriving to the report.

Work we have closed →
01

The first conversation, and the authority check Free

Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.

FreeOwner-only; authority established firstThe honest answer about what is possible
02

Imaging behind a write blocker, and the hashes

When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.

Bit-for-bit, behind a write blockerMD5 and SHA-256, verifiedThe original never altered
03

The examination, on the image

The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.

Scoped to your questionsConfirmed in a second toolPrivate material filtered out
04

The report

The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.

Factual, tool-generated, self-containedChain-of-custody and case-log reports5–10 working days

From the bench

  • Preserve the computer before it is used again; the USB record survives, but the files opened from a device sit in artefacts that daily use can roll over.
  • If you recover the suspected device, keep it; its serial can be matched to the computer's record.
  • Ask for the join to opened files; the device list is far stronger tied to the folders opened from each device.

The serial number a manufacturer burns into a USB device lets an examiner say that a specific device, not merely some device, was connected, and tie it to one later found.

What helps, and what harms.

Do this much first

  • Stop using the device and keep it powered off
  • Preserve it as it is; record who has held it
  • Gather your proof of ownership or authority
  • Tell us the questions you need answered

What sets us back

  • Letting IT or anyone open it to have a look
  • Reinstalling, wiping or running recovery software
  • Carrying on using the device
  • Assuming artefacts prove who was at the keyboard
We examine devices only for the people and organisations with lawful authority over them. Before any work begins we ask for proof that the device is yours, or documented authority to have it examined: proof of ownership, a director's or HR letter for a company device with the lawful basis, a solicitor's instruction, a court order, or an executor's grant. It is a condition of the work, not a formality, and it is what keeps the examination on the right side of the Computer Misuse Act 1990. We will not access another adult's device or accounts without their consent or a court order, we will not install monitoring software or bypass anyone's security, and we do not undertake covert surveillance. A device with no proof of authority is returned unexamined.

Questions answered before you instruct.

Can you tell what was copied to a USB stick?

Windows does not log copy operations, so an examination cannot directly show that a file was copied to a device. What it shows is which USB devices were connected and when, and which files and folders were opened from each device's volume. That combination is often compelling, but it is evidence of access, not a copy log, and we say so.

Does the record survive the USB stick being removed?

Yes. The device's identity and connection history are held in the computer's registry and logs, and they persist after the device is unplugged and after files are deleted. That is what makes the artefact so useful long after the event.

Can you match a USB stick we have found to the computer?

Often, yes, by its serial number, which the manufacturer burns into the device and which the computer records. If the serial in the computer's history matches the serial of the device in hand, that ties the specific device to the machine and its connection dates.

Does this prove the employee took the data?

It proves that a specific device was connected at specific times and that particular files were opened from it, under a user account. It does not prove who was at the keyboard. In practice that, with the deletions and cloud activity, is often enough to act on, and a solicitor can advise; but we state the limit.

What does it cost?

USB history is part of the standard forensic report, £800 + VAT for a one-disk system. The first conversation is free.

The record is on the device; preserve it first.

The first conversation is free. Tell us the situation and who owns the device, and we will tell you what the evidence can show, what it cannot, and whether we can take it on. Until then, stop using the device and preserve it as it is.

0800 6890668