官术网_书友最值得收藏!

Setup API

The setupapi.dev.log file is a Windows log file that tracks device connections for a variety of devices including USB devices. Since USB device information plays an important role in many investigations, our script will help identify the earliest installation time of a USB device on a machine. This log is system-wide, not user-specific, and therefore provides only the installation time of a USB device's first connection to the system. In addition to logging this timestamp, the log contains the vendor ID (VID), product ID (PID), and serial number of the device. With this information, we can paint a better picture of removable storage activity. On Windows XP this file is located at C:\Windows\setupapi.log. On Windows 7 and higher, this file is found at C:\Windows\inf\setupapi.dev.log.

主站蜘蛛池模板: 基隆市| 灵石县| 沙雅县| 南城县| 大城县| 泾阳县| 阜南县| 华阴市| 绍兴市| 南溪县| 湟中县| 长宁区| 通渭县| 崇礼县| 大连市| 鲁山县| 湛江市| 三门峡市| 东安县| 五河县| 石台县| 鄂伦春自治旗| 玉龙| 靖边县| 三都| 凌云县| 万荣县| 玉林市| 江城| 永川市| 监利县| 文化| 开鲁县| 定西市| 昌吉市| 荆门市| 安顺市| 锦州市| 布尔津县| 凤台县| 松滋市|