I'm in the process of downloading Kali and have used Backtrack in the past for multiple uses, however I've never really done any digital forensics.

Scneario: Data was copied over the internet (VPN) to a USB device connected to a Windows machine. I was asked if I could investigate the Windows image to determine if said data was copied to said USB device. Aside from checking the USBSTOR registry hit and comparing that with the data's accessed times/network activity, is there any forensic tools that will be able to give me more information about the data transferred to the USB device without having physical access to the USB device?

Sorry if that's confusing and thanks in advance.