analyzing-usb-device-connection-history
mukul975/Anthropic-Cybersecurity-Skills
This tool correlates multiple system artifacts, including Windows registry keys (USBSTOR, MountedDevices), Event Logs, and SetupAPI logs, to reconstruct a detailed timeline of USB device usage. It determines first/last connection timestamps, tracks device provenance, and maps drive letter assignments. Essential for digital forensics investigations, insider threat detection, and verifying compliance regarding removable media usage.