The theft of IP is a constant concern for organizations. Most IP theft is removed from the premises via removable drives and cloud downloads. During this session, the presenter will share how to detect USB activity to verify IP theft through new Windows 10 event log. USB forensic artifacts have been used by examiners for years; however, earlier this year, it was revealed with Windows 10 that a new event log, the Microsoft-Windows-Partition%4Diagnostics.evtx (MWPD) file emerged with event ID 1006 containing detailed information of removable devices. This session will cover: A detailed discussion of MWPD; How this differs from previous forensics artifacts; and How to effectively mine this potential wealth of forensic information.