Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Udemy

Surviving Digital Forensics: Resolving Attached USBs

via Udemy

Overview

A forensic guide for linking USB activity to Windows computer systems

What you'll learn:
  • Learn to find information about attached USB devices on Windows 7 & Windows 8 systems
  • Learn how to tie a specific User account to USB activity
  • Learn to identify when USB devices were first and last attached to the system
  • Learn how to discover the volume name and assigned drive letter of attached USB devices
  • Learn how to extract data that will identify the make and model of attached USB devices
  • Learn to do all of this using freely available computer forensic tools

Have you ever been asked to find out what the "F" drive is? Have you ever needed to prove a USB drive was attached to a target system? Collecting and presenting this information is a core skill all computer forensic analysts need know. If you have ever struggled with this then this class is for you. This course breaks down the process of collecting and interpreting the data necessary to make the connection between USB device and Windows systems.

Using all freely available tools, this course walks you through the process of identifying USB devices that have been attached to a system and shows you how to determine the times they were attached, what the volume names are, what the assigned drive letters were and which user mounted the USB volumes - all of this in about an hour.

Taught by

Michael Leclair

Reviews

4.4 rating at Udemy based on 710 ratings

Start your review of Surviving Digital Forensics: Resolving Attached USBs

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.