|
| 1 | +Author: Hyun Yi @hyuunnn |
| 2 | +Description: USB Connection |
| 3 | +EventId: 1001 |
| 4 | +Channel: "Microsoft-Windows-Storsvc/Diagnostic" |
| 5 | +Provider: "Microsoft-Windows-Storsvc" |
| 6 | +Maps: |
| 7 | + - |
| 8 | + Property: PayloadData1 |
| 9 | + PropertyValue: "VendorId: %VendorId%" |
| 10 | + Values: |
| 11 | + - |
| 12 | + Name: VendorId |
| 13 | + Value: "/Event/EventData/Data[@Name=\"VendorId\"]" |
| 14 | + - |
| 15 | + Property: PayloadData2 |
| 16 | + PropertyValue: "ProductId: %ProductId%" |
| 17 | + Values: |
| 18 | + - |
| 19 | + Name: ProductId |
| 20 | + Value: "/Event/EventData/Data[@Name=\"ProductId\"]" |
| 21 | + - |
| 22 | + Property: PayloadData3 |
| 23 | + PropertyValue: "SerialNumber: %SerialNumber%" |
| 24 | + Values: |
| 25 | + - |
| 26 | + Name: SerialNumber |
| 27 | + Value: "/Event/EventData/Data[@Name=\"SerialNumber\"]" |
| 28 | + - |
| 29 | + Property: PayloadData4 |
| 30 | + PropertyValue: "Size: %Size% Bytes" |
| 31 | + Values: |
| 32 | + - |
| 33 | + Name: Size |
| 34 | + Value: "/Event/EventData/Data[@Name=\"Size\"]" |
| 35 | + - |
| 36 | + Property: PayloadData5 |
| 37 | + PropertyValue: "FileSystem: %FileSystem%" |
| 38 | + Values: |
| 39 | + - |
| 40 | + Name: FileSystem |
| 41 | + Value: "/Event/EventData/Data[@Name=\"FileSystem\"]" |
| 42 | + - |
| 43 | + Property: PayloadData6 |
| 44 | + PropertyValue: "BusType: %BusType%" |
| 45 | + Values: |
| 46 | + - |
| 47 | + Name: BusType |
| 48 | + Value: "/Event/EventData/Data[@Name=\"BusType\"]" |
| 49 | +Lookups: |
| 50 | + - |
| 51 | + Name: BusType |
| 52 | + Default: Unknown code |
| 53 | + Values: |
| 54 | + 0: The bus type is unknown. |
| 55 | + 1: SCSI |
| 56 | + 2: ATAPI |
| 57 | + 3: ATA |
| 58 | + 4: IEEE 1394 |
| 59 | + 5: SSA |
| 60 | + 6: Fibre Channel |
| 61 | + 7: USB |
| 62 | + 8: RAID |
| 63 | + 9: iSCSI |
| 64 | + 10: Serial Attached SCSI (SAS) |
| 65 | + 11: Serial ATA (SATA) |
| 66 | + 12: Secure Digital (SD) |
| 67 | + 13: Multimedia Card (MMC) |
| 68 | + 14: This value is reserved for system use. |
| 69 | + 15: File-Backed Virtual |
| 70 | + 16: Storage Spaces |
| 71 | + 17: NVMe |
| 72 | + 18: This value is reserved for system use. |
| 73 | + |
| 74 | +# Documentation: |
| 75 | +# https://forensixchange.com/posts/19_08_03_usb_storage_forensics_1/ |
| 76 | +# |
| 77 | +# Example Event Data: |
| 78 | +# <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"> |
| 79 | +# <System> |
| 80 | +# <Provider Name="Microsoft-Windows-Storsvc" Guid="{GUID}" /> |
| 81 | +# <EventID>1001</EventID> |
| 82 | +# <Version>0</Version> |
| 83 | +# <Level>4</Level> |
| 84 | +# <Task>0</Task> |
| 85 | +# <Opcode>0</Opcode> |
| 86 | +# <Keywords>0x8000000000000000</Keywords> |
| 87 | +# <TimeCreated SystemTime="2020-12-08T01:03:35.5243959Z" /> |
| 88 | +# <EventRecordID>220</EventRecordID> |
| 89 | +# <Correlation ActivityID="{ActivityID}" /> |
| 90 | +# <Execution ProcessID="7796" ThreadID="12988" /> |
| 91 | +# <Channel>Microsoft-Windows-Storsvc/Diagnostic</Channel> |
| 92 | +# <Computer>ComputerName</Computer> |
| 93 | +# <Security UserID="{UserID}" /> |
| 94 | +# </System> |
| 95 | +# <EventData> |
| 96 | +# <Data Name="Version">2</Data> |
| 97 | +# <Data Name="DiskNumber">1</Data> |
| 98 | +# <Data Name="VendorId">WD</Data> |
| 99 | +# <Data Name="ProductId">My Passport 25E2</Data> |
| 100 | +# <Data Name="ProductRevision">4005</Data> |
| 101 | +# <Data Name="SerialNumber">WX41D69CD7D1</Data> |
| 102 | +# <Data Name="ParentId">USB\VID_1058&PID_25E2\575834314436394344374431</Data> |
| 103 | +# <Data Name="FileSystem">NTFS</Data> |
| 104 | +# <Data Name="BusType">7</Data> |
| 105 | +# <Data Name="PartitionStyle">1</Data> |
| 106 | +# <Data Name="VolumeCount">1</Data> |
| 107 | +# <Data Name="ContainsRawVolumes">false</Data> |
| 108 | +# <Data Name="Size">4000752599040</Data> |
| 109 | +# </EventData> |
| 110 | +# </Event> |
0 commit comments