Shadow and Shield / Capability Catalog

Shield-399 capabilities.

Explore Shield-399 capabilities for evidence acquisition, drive sanitization, analysis, case management, reporting, and coordinated tool execution.

Rugged laptop displaying the Shield-399 dashboard tool catalog beside a Shield-399 unit
Close-up of the Shield-399 touchscreen showing Operator Mode being enabled for the active user
Operator ModeOperator Mode replaces the standard Home screen with three large tool buttons that automatically add the selected tool to the queue.Open full size
Operator using two Shield-399 units with connected media at a field table
Direct field operationReview and control queued work from the Shield-399 touchscreen.Open full size

Execution Engines

Choose your engine.

Supported tools can offer more than one execution engine. The selected engine determines the underlying method while configuration and execution remain within Shield-399.

Available choices depend on the tool, output format, and connected hardware. Queue status, progress, results, and execution history remain organized through the platform.

Shield-399 touchscreen showing Native Go, ewfacquire, and Unix dd engine choices for forensic imaging
At the unitSelect imaging engineOpen full-size image
  • Select a compatible engine for the chosen tool and output format.
  • Use available native or third-party engines where supported.
  • Keep configuration, queue status, progress, results, and history in the same platform.
  • Examples include Forensic Drive Imager, File Carver, Disk Cloner, The Overwriter, and Image Verify.

Touchscreen interface

Review key controls at the unit.

These representative Shield-399 interface views show dashboard connection, imaging-format selection, queued and running tools, case creation, and user-account controls. Select a view to inspect the touchscreen.

Capability catalog

Explore capabilities by operational need.

Open each capability for supported tools, interface views, operating boundaries, and technical details.

01 / Evidence operations

Acquire, prepare, examine, and move media.

USB flash drives connected to a hub beside portable storage
Multiple media inputsImage-acquisition spillover combines the capacity of multiple smaller Destination drives to acquire a larger Source drive.Representative media shown · Open full size
Shield-399 touchscreen showing queued work beside connected removable media
Queued work at the unitClone one Source drive to multiple Destination drives.Development-color unit shown · Open full size
Close view of the Shield-399 keyboard USB port and physical model marking
External keyboard connectionA dedicated USB port supports an optional physical keyboard alongside the on-screen keyboard.Development-color unit shown · Open full size
Close view of removable media and a cable connected to a Shield-399 unit
Physical media connectionProcess unlocked BitLocker and LUKS encrypted drives.Development-color unit shown · Open full size
01 / Acquire

Evidence Acquisition

Acquire physical media into supported forensic image formats and perform logical collection with source-drive protection, hashing, verification, and recorded acquisition history.

Explore capability
02 / Sanitize

Drive Sanitization

Sanitize Destination drives with configurable whole-drive software overwrite or eligible device-assisted methods selected for the connected hardware. Track progress, cancellation, verification, and run records where supported.

Explore capability
03 / Analyze

Drive Analysis

Examine connected drives and supported forensic images with file browsing, hashing and hash-set comparison, keyword search, file recovery, file-activity views, and encryption detection while source-drive protection remains enforced.

Explore capability
04 / Move

Migration and Cloning

Clone one source drive to one or more destinations, convert supported forensic image formats, or migrate a disk layout to an equal-size or larger drive with source protection, progress tracking, and recorded results.

Explore capability
05 / Health

Drive Readiness and Health

Review available device, partition, and filesystem context to inform operational decisions. Conditional SMART assessment and guarded NTFS checks are available for eligible media.

Explore capability
06 / Encrypt

Encryption Workflows

Detect and unlock supported encrypted volumes, provision LUKS-encrypted destination media, and manage supported credentials, key slots, and auto-unlock settings.

Explore capability

02 / Operations and governance

Keep work attributable, repeatable, and reviewable.

03 / Platform infrastructure

Connect units, services, and physical media.

Capability availability depends on the selected configuration, connected hardware, and deployment requirements. Confirm required formats, hardware paths, and validation criteria before purchase or deployment.