How can i know that the hard disk was used to steal data from my computer.

How can i know that  the hard disk/memory stick was used to steal data from my computer.
and also which data was copied from my computer and when?
Claver MutabaziAsked:
Who is Participating?
 
Russ SuterCommented:
If it's already happened then you really can't tell anything useful. If you want to set things up so you can track possible future attempts you will need to either apply auditing policies or get some kind of 3rd party software.

https://technet.microsoft.com/en-us/library/cc771070%28v=ws.11%29.aspx?f=255&MSPPError=-2147217396
https://www.netwrix.com/netwrix_change_notifier_for_file_servers.html

You can also restrict users from mounting USB devices by a variety of methods. Group policy is typically used for this. Some links that might help you with that.

https://support.microsoft.com/en-us/help/823732/how-can-i-prevent-users-from-connecting-to-a-usb-storage-device
https://www.youtube.com/watch?v=zXYJbrQenBo
0
 
Jeremy WeisingerSenior Network Consultant / EngineerCommented:
From the disk you really can't. If it was out of your control there's no way to know. If it was done over the network then you would need something logging all the traffic. You then might be able to figure out what was taken... or hopefully know what IP was talking to to what. Best hope is to get a forensics team on it to see if they can find a trail but there's no guarantees.
0
 
fred hakimRetired ITCommented:
You can use usb device view to see the usb devices that have been connected to your computer.  I believe it may include a last used date.  That could be helpful to at least narrow down what may have happened.  

See:  http://www.nirsoft.net/utils/usb_devices_view.html
0
Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

 
arnoldCommented:
Unless you have auditing or tools in place before hand, unless you have the device into which your data was copied there only thing as Fred pointed out, all you can see if there was USB device connected at some point, by viewing hidden devices in device manager, but it also requires you to know which devices are yours and how many you used, common devices are commonly used by all distinguishing a sandisk USB stick that you own or owned versus the ones displayed in the list if you no longer have access to it. How do you determine whether the listed device is yours that you misplaced, or someone else's.
0
 
William MillerInventory/IT ConsultantCommented:
You could potentially look at the "Last Modified" descriptor on the PC in question to see if anything was moved around.
0
 
McKnifeCommented:
You would need to setup auditing for removable devices. This used not to be possible in windows versions prior to win8.
With 8/8.1 and 10, Microsoft introduced this: https://technet.microsoft.com/en-us/library/jj574128(v=ws.11).aspx
Again: this is not even available on windows 7.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.