Version 1.3.6 (12/13/2018)

      • Improved correlation of composite devices listed in the Enum\USB subkey hierarchy.
      • Resolved issue where some Storport devices were listed with their ParentIdPrefix in the Results Grid instead of their serial number.
      • Resolved issue with the auto-save log being named with the incorrect month when the default log name was not changed.

Version 1.3.5 (11/28/2018)

      • Added official support for Storport drives.
      • Added support for identifying multiple volume names associated with external hard drives.
      • Added option to customize or remove the consistency level highlighting.
      • Added ability to change case/evidence name post-processing.
      • Added option to auto-save the USB Detective log file.
      • Added option to set a “case folder” for the default saving location.
      • Added “Processing Statistics” window that is displayed post-processing.
      • Improved correlation of external hard drives with the Windows Portable Devices subkey.
      • Improved parsing of System and Partition/Diagnostic event logs.
      • Improved correlation of devices leveraging the DeviceContainers subkey.
      • Improved correlation for USB composite devices.
      • Resolved issue that caused some setupapi log timestamps to be converted using the displayed timezone settings instead of being left in local time.
      • Resolved issue that caused an error to be displayed in the Select Logical Drive window when no logical drives were available for processing.

Version 1.3.0 (10/03/2018)

      • Added support for processing and aggregating artifacts from volume shadow copies.
      • Added last drive letter and timezone offset to the Timeline Report.
      • Improved handling of instances where device last connected times are not available.
      • Various UI improvements.
      • Various small bug fixes.

Version 1.2.0 (08/21/2018)

      • Added support for replaying registry transaction logs. See the user guide for more information.
      • Added ability to specify the case name and evidence number for the data set being processed.
      • Improved support for ambiguous devices identified in DriverFrameworksUserMode/Operational event log.
      • Various UI improvements.
      • Resolved issue that prevented some Windows Vista registry hives from being processed.

Version 1.1.7 (07/25/2018)

      • Added option to include operating system installation time(s) in the timeline report.
      • Added ability to save multiple device VBRs and MBRs, when available. This option is available via the Results Grid context menu.
      • Added option to include ambiguous devices in the results. Any ambiguous devices identified are logged in the USB Detective log regardless of whether this setting is enabled.
      • Added option to change USB Detective internal log to UTC timestamps instead of local.
      • Improved parsing of USB Attached SCSI (UASP) devices throughout.
      • Improved support for MTP and UASP devices that have been deleted via Windows 10 device cleanup.
      • Improved exclusion of unreliable timestamps in Enum\USB hierarchy. Now supports multiple timestamps that are repeated.
      • Improved correlation of devices identified only by disk ID in the event logs.
      • Improved parsing of MTP devices from event logs.
      • Various UI improvements.
      • Resolved issue in parsing some UMB devices from Windows 8.1 setupapi logs.

Version 1.1.6 (07/11/2018)

      • Improved support for images mounted using FTK Imager and X-Ways Forensics.
      • Improved correlation of devices in MountedDevices subkey. Allows for identification of multiple drive letters once associated with a USB device.
      • Added detection of the partition style (MBR or GPT) from event logs.
      • Improved setupapi log parsing for fixed devices. Records identifying a device by disk ID can now be parsed if the disk ID is already known. This can increase the number of available connection times associated with a device.
      • Improved setupapi log parsing for MTP devices.
      • Added detection of previous disk signatures for a device.
      • Added detection of previous volume GUIDs for a device.
      • Improved handling of corrupt event logs.
      • Improved handling of partially corrupt SOFTWARE hives.
      • Various small UI enhancements.

Version 1.1.5 (06/25/2018)

      • Added checks for unreliable timestamps before populating results. If a timestamp is deemed unreliable, it is logged and excluded from the results.
      • Report creation revamped. All reporting functions now available in the Report > Create Report menu option. Allows for multiple report types and formats to be created simultaneously.
      • Added time zone abbreviation added to timestamp column headers.
      • Added button to copy the value in SYSTEM Hive(s) text box to all other text boxes in Select Files/Folders window to prevent the need for repetitive copy/paste.
      • Resolved issue that caused some tool tip information to not be displayed.
      • Resolved issue that caused some VSNs to be displayed in Big Endian.
      • Various UI enhancements.
      • Various small bug fixes.

Version 1.1.0 (04/23/2018)

    • Added support for event logs in Windows 7-10. The following event logs are currently supported (where enabled):
      • System – exposes additional connection times and devices.
      • Microsoft-Windows-DriverFrameworks\UserMode – exposes additional connection/disconnection times and devices.
      • Microsoft-Windows-Kernel-PnP\Configuration – exposes additional connection times, deletion times, and devices.
      • Microsoft-Windows-Partition\Diagnostic – exposes additional connection/disconnection times, device volume serial numbers, and much more.
    • Added ability to save device volume boot record and master boot record for interpretation in other tools (Note: USB Detective parses information from these for correlation/reporting as well).
    • Added option to include device deletion times in Timeline Report.
    • Added option to show 64-bit volume serial numbers (when available).
    • Improved correlation for external hard drives by leveraging information available in event logs with registry-based data.
    • “Other Details” column removed from Results Grid. All information previously available in this column is now available in the Verbose Details view.
    • Various UI improvements.
    • Resolved issue that prevented the results grid from being displayed when certain non-English time zones were identified in the provided SYSTEM hive and the option to adjust timestamps based on the SYSTEM hive was enabled.
    • Various small bug fixes.

Version 1.0.4 (04/06/2018)

      • Improved handling of corrupt data throughout, including registry hives where the hive signature is in tact but core key hierarchies within the hive are corrupt or missing.
      • “View Other Connection Times” context menu option is now disabled if there are no other connection times available for the selected device.
      • Improved support for Windows XP setupapi logs with alternative formatting.
      • Boot volume of system on which USB Detective is running is no longer shown in the logical drive down-down list.

Version 1.0.3 (03/28/2018)

      • Export to Timeline added to Reporting options. Timeline includes all timestamp values displayed in the results grid as well as all other connection and disconnection timestamps identified for each device.
      • Timestamps with the same date, hour, minute, and second now deduplicated from the list of other connection and disconnection times. Timestamps in these lists were previously deduplicated based on entire FILETIME value.

Version 1.0.2 (03/21/2018)

      • Previous connection and disconnection times for each device now available in verbose details or via “View Other Connection Times” context menu option.  Previous connection and disconnection times can be extracted from previous versions of artifacts (available in volume shadow copies, etc.) and in some cases within standalone registry hives.
      • Additional timestamps now evaluated in first connected, last connected, and last disconnected consistency level calculations.
      • First Connected, Last Connected, and Last Disconnected columns of Results Grid are now sortable by date.

Version 1.0.1 (03/15/2018)

      • Resolved issue with some non-US local system cultures encountering errors during timestamp parsing.

Version 1.0.0 (03/13/2018)

    • Initial release