🖥️
Windows DFIR
⌘Ctrlk
🖥️
Windows DFIR
  • Introduction
    • Windows Quick Tips
    • Account Usage
    • Browser Usage
    • Processes
    • Cloud Storage
    • Deleted File or File Knowledge
    • File Download
    • Folder/File Opening/Creation
    • Persistence
    • Physical Location
    • Program Execution
    • Shadow Copies
    • USB Usage
      • Key Identification
      • Drive Letter and Volume Name
      • Connection Timestamps
      • User
      • Volume Name
      • Plug & Play Event Log
    • Windows Services
    • System Information
    • Event IDs
    • Initial Access
    • Execution
    • Persistence
    • Privilege Escalation
    • Defense Evasion
    • Credential Access
    • Discovery
    • Lateral Movement
    • Collection
    • Command and Control
    • Exfiltration
    • Impact
    • Cached Credentials
    • Domain Controller Password Spraying
Powered by GitBook
Page cover
For the complete documentation index, see llms.txt. This page is also available as Markdown.
  1. Windows Artifacts

USB Usage

Key IdentificationDrive Letter and Volume NameConnection TimestampsUserVolume NamePlug & Play Event Log
PreviousEvent ID 8193: Volume Shadow Copy Service ErrorNextKey Identification

Last updated 2 years ago