Skip to the card

Card 923 of 9832026-09-30 issue

Observed arrival · 2026-09-30

USB Forensics turns Windows triage files into a sourced device timeline

usbforensics.com Visit website
Editorial interest 84/100 Selection signal · not a rating of the site

A browser-based tool that brings Windows USB-device artifacts together into a timeline for each device.

Landing page captured for the 2026-09-30 issue.
For
Windows incident responders and digital-forensics practitioners
Worth noticing
KAPE and Velociraptor layouts are accepted, and the page says unrelated files are skipped.

Field notes

The collection guide walks through an administrator PowerShell workflow, including saving locked registry hives and exporting selected event logs. It also copies user hives and Recent folders, then places the collected material in C:\triage for analysis. The built-in example is labeled synthetic: a fictional workstation with a rogue account and two older USB devices.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central

One card from the complete issue

Ask the Descendants

390,826 arrived 1,000 judged 983 catalogued Enter the complete issue
usbforensics.com

Landing page observed 2026-09-30. The live site may have changed.