Web: https://www.reddit.com/r/computerforensics/comments/z1vk2v/evidence_a_live_usb_was_used/

Nov. 22, 2022, 2:53 p.m. | /u/CrazyKitty2016

Computer Forensics reddit.com

Curious what your experience is with finding evidence that someone booted from a live OS USB. Is there anything that could point to this being done?

I was thinking besides seeing the creation USB tools on the machine, you might notice if they turned off any USB protection/live boot security settings in the bios. But if they remembered to turn it back on, I'm not sure this would be detectable?

computerforensics live usb

Cyber Transformation Consultant - Energy & Utilities

@ PA Consulting | London, United Kingdom

Security Operations Lead

@ Vattenfall | Amsterdam, Netherlands

Technology - Energy and Natural Resources sector, Security Strategy & Governance, Cyber Defence, Identity & Access

@ KPMG Australia | Sydney, Australia

DevSecOps Manager

@ Nexient | United States

IT Security Manager (REF194D)

@ Deutsche Telekom IT Solutions | Budapest, Debrecen, Pécs, Szeged, Hungary

Security GRC Consultant

@ Devoteam | Zaventem, Belgium

Information Security & Data Privacy Specialist

@ SirionLabs | Gurugram, Haryana, India

Junior Security Engineer

@ Eurofins | Barcelona, Spain

Senior Application Security Engineer [Remote - UK]

@ Confluent, Inc. | Remote, England

Threat Analysis Security Engineer

@ MANGOPAY | Paris, France

Sr. Professional Services Consultant II

@ Palo Alto Networks | Denver, CO, United States

Senior Offensive Security Engineer

@ MANGOPAY | Paris, France