{"podcast":{"title":"CyberCode Academy","slug":"cybercode-academy-7578615","podcast_index_feed_id":7578615,"rss_url":"https://www.spreaker.com/show/6790974/episodes/feed","website_url":"https://www.spreaker.com/podcast/cybercode-academy--6790974","image_url":"https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5f51ccc7b22fdba95149ffa6346f1533.jpg","author":"CyberCode Academy","episode_count":297,"summary":"Welcome to CyberCode Academy — your audio classroom for Programming and Cybersecurity. 🎧 Each course is divided into a series of short, focused episodes that take you from beginner to advanced level — one lesson at a time. From Python and web development to ethical hacking and digital defense, our content transforms complex concepts into simple, engaging audio learning. Study anywhere, anytime — and level up your skills with CyberCode Academy. 🚀 Learn. Code. Secure. You can listen and download our episodes for free on more than 10 different platforms: https://linktr.ee/cybercode_academy","last_synced_at":"2026-07-13T14:17:20.596630+00:00","page_url":"https://stenobird.com/podcast/cybercode-academy-7578615"},"episode":{"title":"Course 36 - Windows Forensics and Tools | Episode 13: Decoding Registry Artifacts and Connection History","slug":"course-36-windows-forensics-and-tools-episode-13-decoding-registry-artifacts-and-connection-history","published_at":"2026-06-11T06:00:02+00:00","page_url":"https://stenobird.com/podcast/cybercode-academy-7578615/course-36-windows-forensics-and-tools-episode-13-decoding-registry-artifacts-and-connection-history","show_page_url":"https://stenobird.com/podcast/cybercode-academy-7578615","url":"https://www.spreaker.com/episode/course-36-windows-forensics-and-tools-episode-13-decoding-registry-artifacts-and-connection-history--72013803","audio_url":"https://dts.podtrac.com/redirect.mp3/api.spreaker.com/download/episode/72013803/how_windows_records_every_external_device.mp3","summary":"In this lesson, you’ll learn about: Windows USB forensics and how external device activity is tracked through the Windows Registry1. What Is Windows USB Forensics?USB forensics focuses on identifying and analyzing traces left by: USB flash drives External hard drives Digital cameras and mobile storage devices 🔹 Key Idea Even after a device is unplugged or removed, Windows keeps permanent evidence of its connection.2. Why USB Devices Leave Forensic EvidenceWhen a USB device is connected, Windows automatically: Logs device identity Stores serial numbers Records connection history Links devices to specific users 🔹 Forensic Value This allows investigators to reconstruct: Who used the device When it was connected What machine it was connected to 3. USBSTOR Registry Key (Device Identity Tracking)🔹 What it is A registry location that stores details of USB storage devices🔹 What it records Vendor name (e.g., SanDisk, Kingston) Product model Unique serial number 👉 Key Insight This is the digital fingerprint of every USB device ever connected4. MountedDevices Key (Drive Letter Mapping)🔹 What it is Links physical USB devices to assigned drive letters (E:, F:, etc.)🔹 What it reveals Which USB got which drive letter How Windows mapped the storage at connection time 👉 Key Insight Helps reconstruct how the system interacted with external storage5. MountPoints2 Key (User-Level Evidence)🔹 What it is Stores per-user information about mounted devices🔹 What it reveals Which user connected the device Access history from user profile perspective 👉 Key Insight Connects USB activity directly to a specific Windows user account6. Forensic Significance of USB Artifacts🔹 What investigators can determine: First time a device was plugged in Last time it was used Frequency of usage Possible data tran…","meta_description":"In this lesson, you’ll learn about: Windows USB forensics and how external device activity is tracked through the Windows Registry1. What Is Windows USB F…","key_points":[],"chapters":[],"topics":[],"duration_seconds":770,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-36-windows-forensics-and-tools-episode-13-decoding-registry-artifacts-and-connection-history/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/cybercode-academy-7578615/course-36-windows-forensics-and-tools-episode-13-decoding-registry-artifacts-and-connection-history.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}