Shield-399 unit
Purpose-built hardware with tools, keyword lists, hash lists, and quick-queue buttons configured for the selected deployment.
Configured system
Run supported tools through one coordinated platform, with case and operation context synchronized across paired units.
Purpose-built hardware with tools, keyword lists, hash lists, and quick-queue buttons configured for the selected deployment.
Pair directly to access the fully configurable dashboard and execution interface. Each unit can provide its own hotspot with QR-code access, or users can connect without Wi-Fi over USB or Ethernet.
Write-protected file viewing, search, and download make it easy to quickly assess a drive and retrieve selected content.
Multi-unit loadout
Nanuk 908 and Pelican Storm iM2075 configurations can support a two-unit loadout. The photographed configuration is packed in a Nanuk 908.
Two operating surfaces
The touchscreen supports direct operation at the media. The local network dashboard provides deeper configuration, case management, status, results, and operational review.
Run prepared tools, monitor the queue, and review supported results directly from the Shield-399 unit.
Configure supported tools and review unit status, active work, cases, results, and operational history.
Interface views and demonstration data shown. Select an interface image to enlarge it.
Program overview
Technical leads can save profiles and defaults for recurring or approved procedures.
Authorized operators can quick-run supported tools from the touchscreen with configurable defaults and selectable case context.
Tool execution history, results, case-related tasks, and data metrics remain available through the dashboard.
Core evidence operations do not require a public-cloud connection.

In operation
The Shield-399 unit brings supported tools to the media and operator—at a desk, in a lab, or in the field.
Review hardware interactionTechnical detail
Focused pages explain supported tools, configuration options, operating boundaries, and technical details.
Imaging, extraction, hashing, verification, and source-drive handling.
→ 02Drive exploration, keyword and hash analysis, drive health, and encryption management.
→ 03Destination wiping, verification, and formatting.
→ 04Cases, assignments, execution records, reports, and exports.
→ 05Profiles, Quick Add, queues, dependencies, progress, and execution records.
→Ordering and procurement
Choose the Founding Edition or build a custom configuration, then continue to checkout or request an organizational quote.
Product updates
Receive product, software-release, capability, and availability updates from Shadow and Shield.
Shadow and Shield is operated by daarc, Inc. By subscribing, you agree to receive Shield-399 product emails and can unsubscribe at any time. Read our Privacy Policy.