A forensic analyst recovers a USB device from a suspect's computer. Which Windows registry key should be examined to determine the first time the USB device was connected?
Trap 1: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USB
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USB exposes PnP device nodes for every USB device and hub that has ever been enumerated on the system, organized by VID/PID and instance ID. While it confirms that a particular USB peripheral was present, its values are hardware identifiers and configuration data, not forensic timestamps — there is no first connection or install date stored in this key. It may show the parent hub or ContainerID, but it cannot answer when the device was first plugged in, so it is not the correct source.
Trap 2: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceClasses\{5…
The DeviceClasses key with GUID {53f56307-b6bf-11d0-94f2-00a0c91efb8b} represents the storage volume device-interface class, which Windows uses to surface volume symbolic links such as \\?\\Volume{GUID}. This key shows that a storage volume (which could be a partition on a USB drive or an internal hard disk) was exposed to user-mode applications, but it does not record the time the USB device was first attached. Because this GUID applies equally to fixed internal disks, it is neither USB-specific nor a first-connection timestamp source.
Trap 3: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer…
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 stores per-user, MRU-style mount point mappings for volumes the logged-in user has accessed, including entries that reference USBSTOR device paths. However, the timestamps visible in this hive are the LastWrite times of the mount point keys, reflecting when that specific user mounted or accessed the volume, not when the device was first connected system-wide. It can indicate user awareness or use of a USB volume in a user profile, but it cannot supply the device's first-connection timestamp and is therefore incorrect.
- A
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USB
Why it fails: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USB exposes PnP device nodes for every USB device and hub that has ever been enumerated on the system, organized by VID/PID and instance ID. While it confirms that a particular USB peripheral was present, its values are hardware identifiers and configuration data, not forensic timestamps — there is no first connection or install date stored in this key. It may show the parent hub or ContainerID, but it cannot answer when the device was first plugged in, so it is not the correct source.
- B
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Why it fails: The DeviceClasses key with GUID {53f56307-b6bf-11d0-94f2-00a0c91efb8b} represents the storage volume device-interface class, which Windows uses to surface volume symbolic links such as \\?\\Volume{GUID}. This key shows that a storage volume (which could be a partition on a USB drive or an internal hard disk) was exposed to user-mode applications, but it does not record the time the USB device was first attached. Because this GUID applies equally to fixed internal disks, it is neither USB-specific nor a first-connection timestamp source.
- C
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR is the correct answer because it is the dedicated registry hive for USB mass-storage device instances, with subkeys like USBSTOR\Disk&Ven_SanDisk&Prod_Ultra&Rev_1.00. Each subkey contains an Install Date value in UTC YYYYMMDD format that marks the first time the USB storage device was enumerated and installed on that Windows system, and newer builds also add Last Connected and Last Removed values. This timestamp makes USBSTOR the definitive registry location for determining when a USB device was first connected to a computer.
- D
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
Why it fails: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 stores per-user, MRU-style mount point mappings for volumes the logged-in user has accessed, including entries that reference USBSTOR device paths. However, the timestamps visible in this hive are the LastWrite times of the mount point keys, reflecting when that specific user mounted or accessed the volume, not when the device was first connected system-wide. It can indicate user awareness or use of a USB volume in a user profile, but it cannot supply the device's first-connection timestamp and is therefore incorrect.