From the computer's own records: Windows and macOS log every USB device ever connected, with serial numbers and timestamps, and artifacts like shellbags, link files, and jump lists record what was opened from the device. The drive itself is helpful but not required.
The computer remembers the device
Operating systems keep detailed records of removable media. On Windows, the registry retains an entry for every USB storage device ever connected — vendor, model, and unit serial number — alongside timestamps for first and last connection, and event logs add further connection records. macOS keeps equivalent records in its own logs and preference files. This means an examiner can typically establish that a specific, individually identifiable drive was plugged into a specific machine at a specific time, without ever seeing the drive.
The computer also remembers what happened
Proving the connection is step one; the copying is step two, and several artifact families carry it:
- Link files and jump lists record documents opened, including their full paths. A path pointing at the removable drive's letter proves a file was opened from the device after the copy.
- Shellbags record folder views — an examiner can often reconstruct the folder structure of the USB drive as it existed, from the computer alone.
- Recent-files lists and application histories show documents touched around the connection window.
- Volume shadow copies and backups can show a staging pattern: files gathered into one folder shortly before the device was connected.
- Cloud-sync and email records matter because USB is only one exit. A thorough examination checks the others before opining that the drive was the vector.
Timing does heavy lifting. A registry connection record at 9:42 p.m., link files referencing the drive at 9:47, and a resignation email the next morning tell a story timestamps make very hard to argue with — this is the timeline-reconstruction work at the core of a departing-employee investigation.
The honest limits
Windows does not keep a simple per-file "copied to USB" log, so copying is usually established by the convergence of artifacts rather than a single record — which is why the examination has to close off competing explanations (a backup routine, an IT migration, an authorized transfer) rather than stop at the first supportive artifact. An expert who cannot explain why the innocent explanations fail will meet that gap on cross-examination.
What to do now
Preserve the computer before anything else — a forensic image captures every artifact above, and continued use degrades them. Do not have IT "take a look" first. If the drive itself can be recovered through demand or discovery, its own file-system timestamps corroborate the story; in Calsep v. Dabral, destruction of exactly this kind of evidence ended the case by default judgment.
From our work
Need this looked at properly?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
