官术网_书友最值得收藏!

Setup API

The setupapi.dev.log file is a Windows log file that tracks connection information for a variety of devices, including USB devices. Since USB device information generally plays an important role in many investigations, our script will help identify the earliest installation time of a USB device on a machine. This log is system-wide, not user-specific, and therefore provides only the installation time of a USB device's first connection to the system. In addition to logging this timestamp, the log contains the vendor ID (VID), product ID (PID), and the serial number of the device. With this information, we can paint a better picture of removable storage activity. On Windows XP, this file can be found at C:\Windows\setupapi.log; on Windows 7 through 10, this file can be found at C:\Windows\inf\setupapi.dev.log.

主站蜘蛛池模板: 四会市| 云浮市| 涿鹿县| 云安县| 城步| 外汇| 逊克县| 武胜县| 正镶白旗| 合水县| 宜川县| 桃江县| 阿拉善盟| 搜索| 电白县| 开封市| 平罗县| 英超| 广宗县| 赤城县| 东乡| 沈阳市| 潍坊市| 华安县| 峡江县| 汨罗市| 崇义县| 威海市| 花莲市| 凤冈县| 苏州市| 长海县| 黑水县| 隆安县| 伊宁市| 禹州市| 永吉县| 册亨县| 新昌县| 松阳县| 通许县|