USBFT – USB Forensic Tracker

USB Forensic Tracker (USBFT) is a comprehensive forensic tool that extracts USB device connection artifacts from a range of locations within the live system, from mounted forensic images, from volume shadow copies, from extracted Windows system files and from both extracted Mac OSX and Linux system files.

The extracted information from each location is displayed within its own table view. The information can be exported to an Excel file. 

USBFT - USB Forensic Tracker
USBFT – USB Forensic Tracker

USBFT now has the ability to do the following:

  • Mount forensic images and volume shadow copies.
  • Display information about previously mounted TrueCrypt and VeraCrypt volumes.

Display information about files accessed from USB devices and link the files to specific USB devices. USBFT requires Net Framework 4.5 to be installed on the system.

You can read more and download this tool over here:

Notify of
Inline Feedbacks
View all comments