官术网_书友最值得收藏!

Setup API

The setupapi.dev.log file is a Windows log file that tracks connection information for a variety of devices, including USB devices. Since USB device information generally plays an important role in many investigations, our script will help identify the earliest installation time of a USB device on a machine. This log is system-wide, not user-specific, and therefore provides only the installation time of a USB device's first connection to the system. In addition to logging this timestamp, the log contains the vendor ID (VID), product ID (PID), and the serial number of the device. With this information, we can paint a better picture of removable storage activity. On Windows XP, this file can be found at C:\Windows\setupapi.log; on Windows 7 through 10, this file can be found at C:\Windows\inf\setupapi.dev.log.

主站蜘蛛池模板: 营口市| 中西区| 东丰县| 康乐县| 渭南市| 五河县| 柘城县| 郁南县| 通渭县| 平定县| 陵川县| 贺兰县| 故城县| 出国| 周口市| 安溪县| 兰西县| 江阴市| 平陆县| 湛江市| 晋江市| 大城县| 丹寨县| 分宜县| 孝义市| 城步| 宾川县| 三门峡市| 陈巴尔虎旗| 乌拉特后旗| 区。| 抚州市| 游戏| 林甸县| 兴城市| 万源市| 辽宁省| 泸西县| 镇赉县| 乐陵市| 九龙县|