HKLM\System\MountedDevices
If you're using RegEdit, the Name column in the right-hand pane will list a series of entries. Right-click on one that looks like "\DosDevices\
Tools like the First Responder Unit, part of the Forensic Server Project, can be used to retrieve this data from a system. An interesting side effect is that the FRU will also get the LastWrite time of the Registry key, letting you know when the last entry was written to MountedDevices.
No comments:
Post a Comment