|
|
|
|
|
by pretty_lorelei
2519 days ago
|
|
They explain the reason in README: usbrip works with non-modified structure of system log files only, so, unfortunately, it won't be able to parse USB history if you change the format of syslogs (with syslog-ng or rsyslog, for example). That's why the timestamps of "Connected" and "Disconnected" fields don't have the year, by the way. Keep that in mind.
|
|
If the format of syslogs doesn't change there should be no issues (or should it be read as "the system logs don't have the year"? )
If you don't have the year, it is not a "full date" in the forensic sense of the term, and you simply cannot present such a result in a Court.
A statement like "A Netac USB device was connected on May 26, presumably in the year 2019, exactly at 00:51:54 and soon after disconnected, exactly at 00:52:21" won't be good.
If it is technically not possible to retrieve the year, then the whole stuff has very little relevance on itself.
It would be needed to create a complete timeline of the system under investigation and correlate the month, day, time with activities that have an objective timestamp including the year.