Briefing Room

The port decides

Shield-399 drive monitor showing source and destination counts with write protection verified

USB ports on the Shield-399 have pre-assigned roles. Source ports are write protected for evidence while destination ports can receive extracted files, reports, and formatting. When a drive is connected, the unit recognizes the drive's position in the USB topology and classifies it from the port mapping. A source-port drive already has read-only enforcement applied before anything touches it. The unit will also verify the write protection mechanisms separately for each session.

The status bar and front display count SRC, DEST, and UTIL drives separately. Tool dialogs only offer eligible drives: acquisition selects from source drives and a wipe selects from destination-class drives. You cannot aim The Overwriter or formatting tool at a source-port drive; the option just isn't there.

Once the unit verifies the write protection for a session it is recorded in the VAULT database. Additionally, if your SOP calls for a hardware write blocker, you can use that with the unit. As long as Linux can see it as a drive, the protections should stack just fine.

I'll do a deeper dive on the read-only enforcement and what exactly gets applied and verified in a future post.