Shadow and Shield / Capability Catalog
Shield-399 capabilities.
Explore Shield-399 capabilities for evidence acquisition, drive sanitization, analysis, case management, reporting, and coordinated tool execution.
Execution Engines
Choose your engine.
Supported tools can offer more than one execution engine. The selected engine determines the underlying method while configuration and execution remain within Shield-399.
Available choices depend on the tool, output format, and connected hardware. Queue status, progress, results, and execution history remain organized through the platform.
- Select a compatible engine for the chosen tool and output format.
- Use available native or third-party engines where supported.
- Keep configuration, queue status, progress, results, and history in the same platform.
- Examples include Forensic Drive Imager, File Carver, Disk Cloner, The Overwriter, and Image Verify.
Touchscreen interface
Review key controls at the unit.
These representative Shield-399 interface views show dashboard connection, imaging-format selection, queued and running tools, case creation, and user-account controls. Select a view to inspect the touchscreen.
Capability catalog
Explore capabilities by operational need.
Open each capability for supported tools, interface views, operating boundaries, and technical details.
01 / Evidence operations
Acquire, prepare, examine, and move media.
Evidence Acquisition
Acquire physical media into supported forensic image formats and perform logical collection with source-drive protection, hashing, verification, and recorded acquisition history.
Explore capability →Drive Sanitization
Sanitize Destination drives with configurable whole-drive software overwrite or eligible device-assisted methods selected for the connected hardware. Track progress, cancellation, verification, and run records where supported.
Explore capability →Drive Analysis
Examine connected drives and supported forensic images with file browsing, hashing and hash-set comparison, keyword search, file recovery, file-activity views, and encryption detection while source-drive protection remains enforced.
Explore capability →Migration and Cloning
Clone one source drive to one or more destinations, convert supported forensic image formats, or migrate a disk layout to an equal-size or larger drive with source protection, progress tracking, and recorded results.
Explore capability →Drive Readiness and Health
Review available device, partition, and filesystem context to inform operational decisions. Conditional SMART assessment and guarded NTFS checks are available for eligible media.
Explore capability →Encryption Workflows
Detect and unlock supported encrypted volumes, provision LUKS-encrypted destination media, and manage supported credentials, key slots, and auto-unlock settings.
Explore capability →02 / Operations and governance
Keep work attributable, repeatable, and reviewable.
Case Management
Organize case records, user and organization assignments, evidence-related activity, tool executions, reports, and case-scoped operational history.
Explore capability →Reporting and Exports
Generate Case Summary and Tool Execution reports in HTML, PDF, CSV, and JSON. Export file listings and supported results, download completed reports, or copy them to mounted Destination media.
Explore capability →Accounts, Organizations, and Permissions
Manage PIN-authenticated users, organizations, roles, permissions, organization-scoped tool access, and supported user or organization settings.
Explore capability →Tool Execution Framework
Configure tools for each run, save reusable profiles, or use Quick Add with resolved defaults. Shield-399 coordinates dependencies, reports progress, and retains durable execution history with operator and case context where available.
Explore capability →03 / Platform infrastructure
Connect units, services, and physical media.
Warden Network
Pair Shield-399 units with a Warden server to synchronize selected case, user, organization, assignment, drive, session, report, and metrics metadata while each unit continues operating locally when disconnected. Evidence-image files are not synchronized.
Explore capability →Hardware Interaction
Detect and classify Source, Destination, and Utility media in real time, enforce and verify source-drive write protection, maintain drive history, and account for supported USB-bridge behavior.
Explore capability →Capability availability depends on the selected configuration, connected hardware, and deployment requirements. Confirm required formats, hardware paths, and validation criteria before purchase or deployment.
