usbHistory - a forensic tool to extract usb history
I have finally published a tool that i've been sitting on since early January. It is called usbHistory and is a command-line tool to extract trace evidence of USB activity from the windows registry. It gathers information such as the last time the thumb drive or mp3 player was connected to the machine as well as the last drive letter.
you can check out the article on my site here.
you can check out the article on my site here.
Comments
morten forensics analisys
Is there a way to use this program with a registry file extracted from a
disk image?
With sleuthkit I extracted HLMK/system and I would like to give it as a input for your program