logo

Unveiling USB Artifacts: A Comparative Analysis

ID: 37bc5e99-6291-5ae7-91ca-5b682ea1383d

STIX ID: report--37bc5e99-6291-5ae7-91ca-5b682ea1383d

Feed Name: Group-IB Blog

Date Published: 2024-10-10

Date Updated: 2026-04-28

...
...

This research analyzes USB forensic artifacts generated when files are opened or modified across Windows, macOS, and Kali Linux using NTFS, FAT32, exFAT, and HFS+. Key findings include varied temporary file behaviors by application (e.g., MS Office, LibreOffice, editors) and file system, the usefulness of NTFS $Logfile journaling on Windows, HFS+ versioning records in .DocumentRevisions-V100/db.sqlite for GUI-edited files, and macOS “._” files storing extended attributes on FAT32/exFAT. It highlights that temporary files may be transient or absent, timestamps can be unreliable due to scans or timestomping, and investigators should correlate multiple artifacts to infer file access and tampering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.