USB Detective

Detect. Investigate. Report.

Thorough Detection

USB Detective incorporates dozens of data points in identifying and correlating USB device artifacts.

Intelligent Investigation

USB Detective organizes its findings to allow you to quickly identify misleading timestamps and streamline the investigation process.

Pragmatic Reporting

Multiple reporting mechanisms allow for easily-digested Excel reports or verbose reports for deeper analysis and research.

 Purchase USB Detective Professional Request USB Detective Trial License Download USB Detective Community

USB Detective is an application for identifying, investigating, and reporting on USB storage devices that have been connected to a Windows system.  Using its consistency level color-coding, USB Detective gives you the ability to quickly distinguish attributes with corroborating data sources from those with potentially misleading or inaccurate timestamps.  USB Detective’s findings are organized to allow for a high-level view of USB device activity using the results grid as well as a more in-depth examination using the verbose view.

Highlighted Features

  • Visually represented timestamp consistency levels
  • Dozens of sources queried for USB device information
  • Identify multiple connection and disconnection times for each device
  • Source of every identified value preserved for later reporting and documentation
  • Correlation using multiple data points (device serial, disk ID, etc.)
  • Leverage Windows event logs for improved correlation and device history
  • Replay registry transaction logs to identify device data not yet written to the primary hive
  • Queried data points adjusted based on automatic OS version detection
  • Identify devices even after they’re removed via Windows 10 device cleanup
  • Automatic checking and exclusion of unreliable timestamps
  • Support for Windows versions from XP through Windows 10
  • Support for multiple versions of all accepted artifacts
  • USB Detective Results Grid

Additional Features

  • Create Excel spreadsheets for high-level USB device history reports
  • Create verbose reports for deeper analysis and research
  • Create timelines including all unique connection/disconnection and deletion timestamps for each device
  • Identify device removal time(s) from device cleanup in Windows 10
  • Search mounted forensic image instead of individual files/folders
  • Automatic detection of system timezone
  • Normalize local and UTC timestamps using system timezone
  • Alerts for suspicious timestamps
  • Advanced correlation of external hard drives
  • Advanced correlation for Apple devices
  • Identify prior volume names and serial numbers for formatted devices
  • Settings from prior session automatically reloaded
  • Search all control sets of all provided SYSTEM hives
  • Adjust consistency level threshold
  • And much more…

Enterprise and academic licenses are also available.  For more information, submit a request using the Contact page.

Special pricing for law enforcement agencies is available.  Please submit a request from your agency email address for more information.

This is fantastic and perfect for court!

"This is fantastic and perfect for court! I love that it not only gives a great summary of the USB analysis but it also give you a detailed log of the forensic artifacts it is using to give you the information for each device. It follows Rule 702 of expert witness testimony!"


 Purchase USB Detective Professional Request USB Detective Trial License Download USB Detective Community