The document provides guidance on investigating USB devices on Windows 7 and 8 systems by examining artifacts in the registry. It details how to identify the device serial number, vendor/product IDs, volume name, drive letter used, user account accessed, and first/last plug-in times by examining keys in the SYSTEM, SOFTWARE, and NTUSER hives along with the Setupapi log files. The summary provides an example of these techniques being used to analyze a USB device with the label "TIMMYSSTICK" that was plugged in and accessed by the user "TIMMY" between specific dates and times.