Skip to content

INF Setup

Evidence: INF Setup
Description: Collect INF Setup Log Files
Category: System
Platform: windows
Short Name: infl
Is Parsed: No
Sent to Investigation Hub: Yes
Collect File(s): Yes

Windows maintains setupapi log files that record detailed information about device driver installations, including PnP device installations, driver package installations, and device configuration changes.

These logs can provide evidence of hardware changes, driver installations, and USB device connections that may not be captured elsewhere.

This collector gathers structured data about inf setup.

FieldDescriptionExample
NameArtifact nameINF Setup Logs
TypeFileFile
SourcePathOriginal file pathC:\Windows\INF\setupapi.dev.log
PathRelative path in evidenceOther/setupapi.dev.log

This collector collects INF setup log files from:

  • Windows\INF\setupapi*.log
  • Windows\setupapi*.log (legacy location)

INF setup logs provide detailed device installation history. Investigators use this data to track USB device installations, identify driver installation timelines, detect hardware changes, investigate PnP device activity, and correlate with USB history artifacts.