Should I plug an unknown USB device into a computer?¶
No. Do not plug an unknown USB device into an ordinary personal, office, operational or evidence-management computer merely to discover what it contains.
USB describes a connection, not a single behaviour¶
A device that looks like storage may identify itself to the computer as a keyboard, network adapter, installer or several device types at once. It may issue commands or exploit automatic operating-system behaviour before anyone opens a file. Apparent storage can also contain malicious programs, scripts or active documents.
Connection affects evidence even when nothing hostile happens. The computer may create device history, security events, thumbnail caches and recent-file records, while scanning, indexing or synchronisation may alter access metadata on the device. Antivirus detection reduces some risks but does not make uncontrolled connection neutral or complete.
Preserve first, examine under control¶
Record the device's appearance, identifiers, switches, adapters, condition, location and possessor. If examination is justified, use an approved specialist environment and document the interface, tools, operator, time and safeguards used.
If someone has already connected it, record the host computer, port, account, exact time, prompts, alerts and behavioural changes. This may identify both investigator-generated records and a potentially exposed host requiring assessment.
Key takeaway
An unknown USB device can act before a file is opened and ordinary connection changes both systems; preserve it and use a controlled specialist examination process.