
Tracking history of USB events on GNU/Linux
usbrip (inherited from "USB Ripper", not "USB R.I.P.") is a simple forensics tool with command line interface that lets you keep track of USB device artifacts (i.e., USB event history) on Linux machines.
Table of Contents:
usbrip is a small piece of software which analyzes Linux log data: journalctl output or contents of /var/log/syslog* (or /var/log/messages*) files. Based on the collected data usbrip can build USB event history tables with the following columns:
Besides, it also can:
-s flag* Create protected storages (7-Zip archives) to automatically backup and accumulate USB events with the help of cron scheduler.Way 1. Install with pip:
~$ sudo -H python3 -m pip install -U usbrip
~$ usbrip -h
Way 2. Install bleeding-edge with install.sh (recommended, extra features available):
~$ sudo apt install python3-venv p7zip-full -y
~$ git clone https://github.com/snovvcrash/usbrip && cd usbrip
~/usbrip$ sudo -H installers/install.sh
~/usbrip$ cd
~$ usbrip -h

Docker (*DEMO ONLY!*)
~$ docker run --rm -it snovvcrash/usbrip
usbrip supports two types of timestamps to parse within system log files:
"%b %d %H:%M:%S", ex. "Jan 1 00:00:00"). This type of timestamp does not provide the information about the year."%Y-%m-%dT%H:%M:%S.%f%z", ex. "1970-01-01T00:00:00.000000-00:00").If you do have journalctl installed, then there's nothing to worry about as it can convert timestamps on the fly. Otherwise, the desired syslog structure can be achieved by setting RSYSLOG_FileFormat format in rsyslog configuration.
/etc/rsyslog.conf:$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat
.conf file for usbrip:~$ echo '$ActionFileDefaultTemplate RSYSLOG_FileFormat' | sudo tee /etc/rsyslog.d/usbrip.conf
~$ sudo rm -f /var/log/syslog* /var/log/messages*
~$ sudo systemctl restart rsyslog
Firstly, usbrip will check if there is a chance to dump system events using journalctl as the most portable option. If not – it will search for and parse /var/log/syslog* or /var/log/messages* system log files.
storage module)For simplicity, lets agree that all the commands where ~/usbrip$ prefix is appeared are executed in the ~/usbrip directory which is created as a result of a git clone:
~$ git clone https://github.com/snovvcrash/usbrip
~$ cd usbrip
~/usbrip$ pwd
install.shBesides installing with pip, usbrip can also be installed with custom installers/install.sh script.
When using install.sh some extra features become available:
storage module – set a cron job to backup USB events on a schedule (example of a cron job can be found in usbrip/cron/usbrip.cron).⚠️ Warning: if you are using cron scheduling, you want to configure the crontab with sudo crontab -e in order to force the storage update submodule run as root. The storage passwords are kept in /var/opt/usbrip/usbrip.ini and accessible by root only by default.
To install usbrip with install.sh use:
~/usbrip$ sudo -H installers/install.sh [-l/--local] [-s/--storages]
~/usbrip$ cd
~$ usbrip -h
-l switch is enabled, Python dependencies are resolved from local .tar packages (3rdPartyTools directory) instead of PyPI.-s switch is enabled, not only the usbrip project is installed but also the list of trusted USB devices, history and violations storages are created.After the installation completes feel free to remove the ~/usbrip directory.
When installed with install.sh, usbrip uses the following paths:
/opt/usbrip/ – project's main directory./var/opt/usbrip/log/ – usbrip cron logs./var/opt/usbrip/storage/ – USB event storages (history.7z and violations.7z, created during the installation process)./var/opt/usbrip/trusted/ – lists of trusted USB devices (auth.json, created during the installation process)./var/opt/usbrip/usbrip.ini – usbrip configuration file (contains passwords for 7-Zip storages)./usr/local/bin/usbrip – symlink to the /opt/usbrip/venv/bin/usbrip script.Cron jobs can be set as follows:
~/usbrip$ sudo crontab -l > tmpcron && echo "" >> tmpcron
~/usbrip$ cat usbrip/cron/usbrip.cron | tee -a tmpcron
~/usbrip$ sudo crontab tmpcron
~/usbrip$ rm tmpcron
uninstall.sh