When a PnP driver is initiated, the service will log an event and provide status details. It is important to note that this event will trigger for any PnP device, USB, Firewire, PCMIA, etc.
The above GUID will be used to identify the user that plugged in the device. The last write time of this key also corresponds to the last write time the device was plugged into the machine by that user. The number will be references in the number in the MountPoint registry key in the users NTUSER.DAT file.
Discover the last drive letter of the USB Device when it was pluigged into the machine.
WIN: XP+
SRV: Not Tested
Location
Interpretation and Investigative Notes
Identify the USB device that was last mapped to a specific drive letter. This technique will only work for the last drive mapped. It does not contain historical records of every drive letter mapped to a removable drive.
Shortcut files automatically created by windows when accessing recent items and opening local and remote data files and documents. Windows 11 contains a shortcut (.LNK) files that direct to the application, file, or directory.
# WINDOWS XP
C:\Windows\setupapi.log
# WINDOWS 7+
C:\Windows\setupapi.dev.log
HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR\Ven_Prod_Ver\USB_Serial_#\Properties{83da6326-####-####-####-############}####
%SYSTEM ROOT%\System32\winevt\logs\System.evtx
# WINDOWS XP
# Identify ParentIdPrefix
HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
# Use ParentIdPrefix to discover the last Mount Point
HKLM\SYSTEM\MountedDevices
# WINDOWS 7+
Software\Microsoft\Windows Portable Devices\Devices
HKLM\SYSTEM\MountedDevices