What should be recorded about removable storage?¶
Removable storage may hold relevant files, provide access credentials or contain malicious code, and its state can change simply by connecting or removing it.
Evidential caution: that removable media can be safely inspected on any available computer. Connecting it may alter timestamps, create system files, trigger automatic software or expose the investigating device to malware.
What this means¶
Photograph it as found, including whether it was connected, where it was connected and any visible label, capacity, make, model or serial number.
Be alert to disguised devices. A USB object may be storage, a security key, a wireless adapter, a keystroke-injection device or something else entirely.
The first-response task is to preserve the media and its context, not to determine its contents through improvised examination.
What to check or do next¶
- Record the type of media, such as a USB drive, memory card, external solid-state drive, external hard drive, optical disc or removable device module.
- If it is already attached to a live system, do not remove it automatically. It may contain an open file, mounted volume, encrypted container, virtual machine or active application.
- Record any visible drive name, volume label, file path, warning, encryption prompt or application using the media. Do not browse its contents simply because it appears accessible.
- If the media is loose, preserve its physical condition and packaging. Avoid unnecessary handling and record who found it and where.
- Do not connect unknown media to a general-purpose device. Use appropriate specialist processes and equipment where examination is required.
- If urgent operational action requires removal or isolation, record the reason, the exact time and what changed on the host system.
Operational takeaway
Record removable storage exactly as found and avoid connecting, browsing or removing it until the likely evidential and technical effect is understood.