官术网_书友最值得收藏!

Setup API

The setupapi.dev.log file is a Windows log file that tracks connection information for a variety of devices, including USB devices. Since USB device information generally plays an important role in many investigations, our script will help identify the earliest installation time of a USB device on a machine. This log is system-wide, not user-specific, and therefore provides only the installation time of a USB device's first connection to the system. In addition to logging this timestamp, the log contains the vendor ID (VID), product ID (PID), and the serial number of the device. With this information, we can paint a better picture of removable storage activity. On Windows XP, this file can be found at C:\Windows\setupapi.log; on Windows 7 through 10, this file can be found at C:\Windows\inf\setupapi.dev.log.

主站蜘蛛池模板: 工布江达县| 腾冲县| 当阳市| 泰兴市| 闻喜县| 太仆寺旗| 云霄县| 景德镇市| 喜德县| 政和县| 辽阳市| 新疆| 离岛区| 灵川县| 济南市| 八宿县| 余干县| 盐亭县| 江都市| 措美县| 阿克苏市| 淅川县| 中卫市| 观塘区| 台南市| 罗城| 六盘水市| 宣汉县| 隆德县| 陕西省| 申扎县| 台南市| 彭山县| 昂仁县| 攀枝花市| 定安县| 那坡县| 奉节县| 田阳县| 丰顺县| 濉溪县|