官术网_书友最值得收藏!

Setup API

The setupapi.dev.log file is a Windows log file that tracks device connections for a variety of devices including USB devices. Since USB device information plays an important role in many investigations, our script will help identify the earliest installation time of a USB device on a machine. This log is system-wide, not user-specific, and therefore provides only the installation time of a USB device's first connection to the system. In addition to logging this timestamp, the log contains the vendor ID (VID), product ID (PID), and serial number of the device. With this information, we can paint a better picture of removable storage activity. On Windows XP this file is located at C:\Windows\setupapi.log. On Windows 7 and higher, this file is found at C:\Windows\inf\setupapi.dev.log.

主站蜘蛛池模板: 旬阳县| 车险| 宣恩县| 临桂县| 阳城县| 福州市| 房山区| 光泽县| 图们市| 岳普湖县| 上蔡县| 陇西县| 定兴县| 古田县| 册亨县| 临海市| 增城市| 牡丹江市| 淮南市| 平定县| 尚志市| 时尚| 海淀区| 武安市| 额敏县| 司法| 凤山县| 凤山县| 固镇县| 西峡县| 建德市| 桐城市| 博湖县| 梅州市| 鹤壁市| 石狮市| 航空| 应城市| 大庆市| 岚皋县| 正镶白旗|