How can i know that  the hard disk was used to steal data from my computer.

Claver Mutabazi
Claver Mutabazi used Ask the Experts™
on
How can i know that  the hard disk/memory stick was used to steal data from my computer.
and also which data was copied from my computer and when?
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Jeremy WeisingerSenior Network Consultant / Engineer
Commented:
From the disk you really can't. If it was out of your control there's no way to know. If it was done over the network then you would need something logging all the traffic. You then might be able to figure out what was taken... or hopefully know what IP was talking to to what. Best hope is to get a forensics team on it to see if they can find a trail but there's no guarantees.
Senior Software Developer
Commented:
If it's already happened then you really can't tell anything useful. If you want to set things up so you can track possible future attempts you will need to either apply auditing policies or get some kind of 3rd party software.

https://technet.microsoft.com/en-us/library/cc771070%28v=ws.11%29.aspx?f=255&MSPPError=-2147217396
https://www.netwrix.com/netwrix_change_notifier_for_file_servers.html

You can also restrict users from mounting USB devices by a variety of methods. Group policy is typically used for this. Some links that might help you with that.

https://support.microsoft.com/en-us/help/823732/how-can-i-prevent-users-from-connecting-to-a-usb-storage-device
https://www.youtube.com/watch?v=zXYJbrQenBo
Commented:
You can use usb device view to see the usb devices that have been connected to your computer.  I believe it may include a last used date.  That could be helpful to at least narrow down what may have happened.  

See:  http://www.nirsoft.net/utils/usb_devices_view.html
11/26 Forrester Webinar: Savings for Enterprise

How can your organization benefit from savings just by replacing your legacy backup solutions with Acronis' #CyberProtection? Join Forrester's Joe Branca and Ryan Davis from Acronis live as they explain how you can too.

Distinguished Expert 2017
Commented:
Unless you have auditing or tools in place before hand, unless you have the device into which your data was copied there only thing as Fred pointed out, all you can see if there was USB device connected at some point, by viewing hidden devices in device manager, but it also requires you to know which devices are yours and how many you used, common devices are commonly used by all distinguishing a sandisk USB stick that you own or owned versus the ones displayed in the list if you no longer have access to it. How do you determine whether the listed device is yours that you misplaced, or someone else's.
Commented:
You could potentially look at the "Last Modified" descriptor on the PC in question to see if anything was moved around.
Distinguished Expert 2018
Commented:
You would need to setup auditing for removable devices. This used not to be possible in windows versions prior to win8.
With 8/8.1 and 10, Microsoft introduced this: https://technet.microsoft.com/en-us/library/jj574128(v=ws.11).aspx
Again: this is not even available on windows 7.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial