Vault7: CIA Hacking Tools Revealed
Navigation: » Directory » Knowledge Base » Tech Topics and Techniques Knowledge Base » Windows » Windows Configuration and Logging Storage
Interesting Log/Data Locations
SECRET//NOFORN
('toc' missing)
USB Devices
- %WINDIR%\setupapi.dev.log
- Contains install information for usb devices
- Windows Event Log - Microsoft-Windows-Kernel-PNP/Device Configuration (400,410, 420)
- Contains install dates of USBUniversal Serial Bus devices
- Windows Event Log - Microsoft-Windows-DeviceSetupManager
- Install dates of USBUniversal Serial Bus devices
- Microsoft-Windows-Security-Auditing
- USB insertion recent history
Network Connections
Machine State Changes (Startup, Shutdown, Logon, Logoff, Hibernate, Sleep, Wake)
SECRET//NOFORN