"The Microsoft Windows operating systems records artifacts when USB removable storage devices (thumb drives, iPods, digital cameras, external HDD, etc.) are connected. These artifacts can be found in Plug and Play (PnP) log files as well as the Windows Registry." www.4discovery.com
DFIR Training Blog
- Guardonix Revisited. Keyword searching while imaging!
- You did a DFIR thing and wrote a blog post? What now?
- The DFIR Investigative Mindset: Getting out of a rabbit hole
- Review of Foxton Forensics' Browser History Examiner
- Belkasoft and Checkm8!
- You have an opportunity pounding on your door
- Making DFIR research a win-win
- DFIR SWAT Ops
- Latent Wireless Review