A process for identifying USB storage device activity in Windows 11
Presentation
Overview
Overview
Description
This presentation outlines a process for identifying USB storage device activities on Windows 11. Leveraging Sysinternals Procmon, we monitor registry changes related to USB insertions, removals, and persistent connections. As Windows evolves, adapting investigation methods becomes crucial. Objectives include interpreting registry key changes, associating timestamps with USB activities, and mastering Procmon for real-time monitoring. Vital for forensic professionals, it addresses the absence of public documentation on these registry keys in the latest Windows release, providing a documented approach applicable to newer OS versions.