| name | analyzing-usb-device-connection-history |
| description | Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration. Use when working with analyzing usb device connection history. |
| domain | cybersecurity |
| tags | ["forensics","usb-forensics","removable-media","registry-analysis","data-exfiltration","device-history"] |
| subdomain | digital-forensics |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["RS.AN-01","RS.AN-03","DE.AE-02","RS.MA-01"] |
Analyzing Usb Device Connection History
Overview
Cybersecurity skill for analyzing usb device connection history. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"analyzing usb device connection history"
-
"Investigate USB device connection history from Windows registry, event logs, and"
-
When investigating potential data exfiltration via removable storage devices
-
During insider threat investigations to track USB device usage
-
For compliance audits verifying removable media policy enforcement
-
When correlating USB connections with file access and copy events
-
For establishing a timeline of device connections during an incident
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Forensic image or extracted registry hives and event logs
- Access to SYSTEM, SOFTWARE, and NTUSER.DAT registry hives
- SetupAPI logs (setupapi.dev.log)
- Windows Event Logs (System, Security, DriverFrameworks-UserMode)
- USBDeview, USB Forensic Tracker, or RegRipper
- Understanding of USB device identification (VID, PID, serial number)
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}