Observed arrival · 2026-09-30
USB Forensics turns Windows triage files into a sourced device timeline
A browser-based tool that brings Windows USB-device artifacts together into a timeline for each device.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- Windows incident responders and digital-forensics practitioners
- Worth noticing
- KAPE and Velociraptor layouts are accepted, and the page says unrelated files are skipped.
Field notes
The collection guide walks through an administrator PowerShell workflow, including saving locked registry hives and exporting selected event logs. It also copies user hives and Recent folders, then places the collected material in C:\triage for analysis. The built-in example is labeled synthetic: a fictional workstation with a rogue account and two older USB devices.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central
One card from the complete issue