This is a list of forensic artifacts that can be used by DFIR community to perform cyber investigations. USB Devices Log Files: XP - c:\windows\setupapi.log W7+ - c:\windows\inf\setupapi.dev.log Recycle Bin: c:$Recycle.Bin* c:\Recycler*