About this tag
The forensic examination tag on WindowsForum.com covers topics related to extracting and analyzing digital evidence from Windows systems. Content includes methods for gathering USB artifacts, such as device connection history and registry traces, to determine if a USB device was used in malicious activity. Discussions focus on practical techniques for interpreting these artifacts on Windows 7 and other versions, aiding in security investigations and incident response.
  1. cybercore

    Windows 7 Extracting USB Artifacts from Windows 7

    Link Removed - Invalid URL USBDeview - View all installed/connected USB devices on your systemView any installed/connected USB device on your system Link Removed The article discusses some of the artifacts that a USB storage device leaves on a system when it has been plugged in, how...