官术网_书友最值得收藏!

Setup API

The setupapi.dev.log file is a Windows log file that tracks device connections for a variety of devices including USB devices. Since USB device information plays an important role in many investigations, our script will help identify the earliest installation time of a USB device on a machine. This log is system-wide, not user-specific, and therefore provides only the installation time of a USB device's first connection to the system. In addition to logging this timestamp, the log contains the vendor ID (VID), product ID (PID), and serial number of the device. With this information, we can paint a better picture of removable storage activity. On Windows XP this file is located at C:\Windows\setupapi.log. On Windows 7 and higher, this file is found at C:\Windows\inf\setupapi.dev.log.

主站蜘蛛池模板: 泗水县| 元氏县| 八宿县| 龙胜| 绥阳县| 台州市| 临沂市| 临漳县| 襄樊市| 德钦县| 建平县| 马关县| 金湖县| 板桥市| 安溪县| 桂东县| 青河县| 安化县| 平顺县| 潮州市| 阿拉善左旗| 兴安县| 苗栗市| 盐山县| 安徽省| 泗水县| 天台县| 岱山县| 富锦市| 垦利县| 盘山县| 比如县| 钦州市| 阳东县| 盐边县| 株洲市| 无棣县| 东阳市| 清苑县| 水富县| 广德县|