: Investigators identify the primary user account as Erin and examine the directory structure under C:\Users\Erin .
: Registry keys (like USBSTOR ) reveal that a specific Kingston USB drive was plugged into the machine shortly before the "data leak" occurred.
: Frequently found using Steganography tools or by checking alternate data streams (ADS).
: Pinpointing exactly when the sensitive "Project X" file was copied to the USB.