scholarly journals USB Artifact Analysis Using Windows Event Viewer, Registry and File System Logs

Electronics ◽  
2019 ◽  
Vol 8 (11) ◽  
pp. 1322
Author(s):  
Ashar Neyaz ◽  
Narasimha Shashidhar

A USB mass storage device yields a lot of artifacts when connected to a system. These artifacts are persistent in nature and are retained even after the system has been shut down and the information they contain may assist in carrying out forensic analysis on a suspect system. In this paper, we demonstrate how Windows Event Viewer can be used to find forensic artifacts in a suspect system for investigative purposes. We also discuss the potential that Windows registry holds to identify USB devices’ information that have been connected to the system, to corroborate our findings from Windows Event Viewer. Finally, we use the Windows 10 file system to extract log details that contain the setup information of a USB device that was connected to the system the very first time, and obtain the necessary identifiers and time stamp details.

2012 ◽  
Vol 588-589 ◽  
pp. 735-738
Author(s):  
Jie Zang ◽  
Xiao Li Wang ◽  
Zhong Hua Yan

This paper introduces the method of design a USB On-The-Go (OTG) mass storage module according to USB 2.0 specification, which bases on embedded systems LM3S9B90. This module’s hardware system and software system is described, focusing on the implementation of USB host system. The module realizes USB OTG function, not only can realize functions of read and write USB mass storage devices, but also can exchange data with USB host as a USB mass storage device, can be used as an extension of USB system and has good application value.


2020 ◽  
Vol 55 ◽  
pp. 102585
Author(s):  
Muhammad Faizan Ayub ◽  
Muhammad Asad Saleem ◽  
Izwa Altaf ◽  
Khalid Mahmood ◽  
Saru Kumari

2015 ◽  
Vol 87 ◽  
pp. 37-46 ◽  
Author(s):  
Kazuma Kaneko ◽  
Yuichi Kawamoto ◽  
Hiroki Nishiyama ◽  
Nei Kato ◽  
Morio Toyoshima

Sign in / Sign up

Export Citation Format

Share Document