Technical Snapshot

Platform operating model.

A concise view of how Shield 399 organizes tools, profiles, operators, case context, and review surfaces for pre-release evaluation.

Profile-Driven WorkSaved configurations operators can run consistently
Source HandlingRead-only acquisition, scanning, and analysis paths
Review SurfaceDashboard access, reports, exports, and operator history
Sync ModelSelected case, user, organization, and operational metadata sync

Platform

Hardware unit
ASUS NUC 15 Pro Ultra 7 255H with 96GB of RAM and 1TB of NVMe
Software model
First-party tool execution tied to queue state, operational records, and dashboard review
Operator surface
Touchscreen operation or network dashboard when paired with a laptop, phone, or tablet
Origin
Built by daarc, Inc. from field, deployed forensics, and cyber experience

Execution

Tool profiles
Technical users save configurations for repeatable operator execution
Queue and status
Tool work can be queued, tracked, reviewed, and tied back to case context
Source controls
Automatic read-only source handling during acquisition, scanning, and analysis paths
Operational history
Tool execution and operator history remain available for review and reporting

Control and Review

Case management
Cases, evidence records, drive sessions, tool executions, exports, reports, and operators
Access control
PIN users, organizations, permissions, tool availability, and saved profiles
Dashboard access
Review from an approved network or directly paired laptop, tablet, or phone where configured
Sync model
Selected cases, users, organizations, and operational metadata can synchronize across configured deployments

Compatibility

Compatibility snapshot.

Representative formats, inputs, interfaces, and outputs for pre-release evaluation. Support varies by workflow, configuration, and detected device path.

Evidence Formats

E01Ex01AFF4RAW / DDSynthetic E01Individual file extraction

Hashing

MD5SHA-1SHA-256SHA-512BLAKE2b-256BLAKE3

Drive Interfaces + Signals

USB 3.xSATANVMeSMARTHPA / DCO indicators

Filesystems

NTFSexFATFAT32EXT4XFSBtrfsF2FSHFS+

Wipe + Verification

Single / multi-pass overwriteTRIM / UNMAPUSB-safe sanitize pathsNVMe sanitize where exposedSample-based verificationFull-drive verification

Encryption

LUKSLUKS1 / LUKS2BitLocker

Smart Cards

PIV / CACPKCS15USB CCIDATR captureCertificate metadata

Search + Reference Sets

Keyword listsRegex patternsNSRLCustom hash sets

Exports

CSVJSONTXTHTMLFile listings + metadataKeyword resultsHash outputs

Pre-release Access

Join release updates.

Shadow and Shield is in active development and pre-release testing. Get product progress, launch details, and availability updates from daarc.