Live forensics, data recovery and eDiscovery over an IP network – using your choice of tools.
Adding F-Response to your arsenal turns your favorite imaging and analysis tools into enterprise class products with the ability to connect to computers across any network.
Any of the Classic versions of (TACTICAL, Consultant, Consultant + Covert, and Enterprise), as well as Universal, work fine with USB Detective. Simply attach the device (volume) from the remote machine and point USB Detective at the Windows mounted drive letter. The tool takes over from there and reads through the files to gather valuable information, including:
- Processes USB device artifacts from Windows XP through Windows 11
- Support for live system, individual files/folders, and logical drive processing
- Processes multiple versions of all accepted artifacts
- Source of every identified value preserved for later reporting and documentation
- Leverage the latest changes in Windows to obtain even more device information
- Visually represented timestamp consistency levels
- Dozens of sources queried for USB device information
- Automatically correlates LNK file and jump list records to show opened/accessed files on USB devices
- Processes shellbags to reveal directory interactions and creations on removable media
Learn more about F-Response and USB Detective.