Native Tooling

Ground-up Go tools, not wrappers.

These are first-party Go engines, not wrappers around open-source command-line tools. That gives Shield 399 direct control over long-running forensic work: progress, checkpointing, verification, error handling, and structured records are built into the workflow instead of inferred from command output.

02

Disk Cloner

Native Godd legacy1-to-many nativeVerify

One-to-one and one-to-many block cloning with checkpoint-backed resume, verification options, bad-sector tracking, and read-only handling for cloned destinations.

03

Wipe / Overwriter

Native overwriteHardware-assisted when verifiedTRIM/UNMAPshred/dd legacy
  • Hardware-assisted wipe paths when verified available from the connected device or bridge
  • Native software overwrite with deterministic patterns
  • Verification, progress, and wipe-operation records
04

Image Verify

Native E01/AFF4Ex01 via ewfverifyDAASH/BLAKE3
  • Reads Shadow & Shield advanced hash metadata (DAASH) where present
  • Validates MD5, SHA-1, SHA-256, and BLAKE3 hash material
  • Keeps E01 compatibility while adding stronger native verification
05

E01 Info

Native E01 infoDAASH-awareewfinfo-style
  • Inspects E01 segment layout, acquisition metadata, and media geometry
  • Shows compression and embedded legacy hash fields
  • Reads Shadow & Shield DAASH advanced hashes where present
06

Image Converter

Native streamingE01/DD/AFF4Synthetic decrypted E01Optional verify

Conversion workflows for E01, DD, AFF4, and decrypted synthetic E01 outputs where supported.

How the native E01 writer is constructed
  • The native Go imaging engine applies to E01 output; Ex01 uses ewfacquire.
  • Writes EWF-compatible segment files with standard file headers and .E01 to .E99, then .EAA rollover.
  • Builds EWF-style sections across segments, including header2, legacy header, volume/data, sectors, chunk data, table, table2, digest, hash, daash, next, and done.
  • Uses 4 MB E01 chunks during acquisition, with table offsets marking compressed chunks.
  • Supports compression modes and stores chunks uncompressed when compression would increase size, preserving compatibility.
  • Uses Adler32 checksums for section descriptors and section/hash/table payload structures; uncompressed chunks include a trailing 4-byte Adler32 checksum.
  • Compressed chunks are stored as zlib streams and marked through the table offset high bit.
  • Writes legacy digest and hash sections plus Shadow & Shield DAASH hashes: MD5, SHA-1, SHA-256, and BLAKE3.
  • DAASH does not affect industry-tool compatibility; tools that do not understand daash can ignore it, while Shadow & Shield Image Info and Image Verify can read it.

Full Tool Listing

What Shield 399 includes.

* Pre-release inventory. Minor names, defaults, and workflow details may change before launch.

The tool inventory includes native Go tools plus coordinated system and AI-assisted workflows. Each tool is surfaced through Shield 399's queue, records, permissions, and review model.

Verification

Image Verify

Native E01/AFF4Ex01 via ewfverifyDAASH/BLAKE3
  • Reads Shadow & Shield advanced hash metadata (DAASH) where present
  • Recomputes MD5, SHA-1, SHA-256, and BLAKE3 hash material
  • Records verification outcomes for supported image workflows
Conversion

Image Converter

Native streamingE01/DD/AFF4Synthetic decrypted E01Optional verify

Converts supported forensic image formats and handles selected synthetic-image workflows for decrypted output paths.

Sanitization

The Overwriter

Native overwriteHardware-assisted when verifiedTRIM/UNMAPshred/dd legacy
  • Hardware-assisted wipe paths when verified available from the connected device or bridge
  • Native overwrite with deterministic patterns
  • Verification, method-selection records, and wipe-to-format workflow support
Preparation

Drive Formatter

GPT / MBRNTFSexFATFAT32ext4XFSBtrfsF2FSHFS+

Creates partition tables and filesystems on destination media for post-wipe preparation or standalone formatting workflows.

Preparation

Drive Encryption Manager

LUKS1 / LUKS2Destination driveNTFS / exFAT / FAT32ext4 / XFSHeader backupKey slots
  • Provisions destination drives as LUKS-encrypted volumes
  • Creates the partition, LUKS container, mapped filesystem, and optional header backup
  • Records encryption operations and supports selected key-management workflows
Migration

Disk Cloner

Native Godd legacy1-to-many nativeVerify

Copies a source drive to one or more destinations with checkpoint-backed resume, verification, bad-sector tracking, and read-only handling for cloned destinations.

Migration

Drive Migrator

Partition-levelPreview planCopy + growGPT / MBRLUKS unlock
  • Copies source partitions into a recreated destination layout
  • Shows a migration preview with the planned layout
  • Supports unlocked LUKS migration
Extraction

Logical File Extractor

Copies selected files from a source drive or mounted forensic image to destination media as loose files or logical evidence output.

Hashing

Drive Hasher

Source driveMounted imageMD5 / SHA-1SHA-256 / SHA-512BLAKE2b
  • Hashes source drives or mounted forensic images
  • Stores one hash record per selected algorithm
Hashing

Partition Hasher

Computes hashes over a selected partition path and records partition-scoped digest results in the platform hash tables.

Analysis

File Hash Analyzer

Hashes enumerated files and compares them against registered reference sets for known-file classification workflows.

Analysis

Keyword Search

Searches enumerated filesystem records for literal keywords and optional regular-expression patterns, with exportable results.

Analysis

Encryption Detector

Scans source-device partitions for encryption indicators and records structured detections and unlock attempts where configured.

AnalysisAI-assisted

Translate Filenames

Detects non-English filenames from existing scan results and writes translated names back to review surfaces without modifying evidence.

Repair

NTFS Fix Tool

Runs selected NTFS repair and verification workflows against a partition when filesystem repair is appropriate.

Hardware

Smart Card Reader

Reads connected smart-card reader and card metadata, including PKCS#15-accessible details exposed through supported tooling.

Hardware

Bluetooth Scanner

Discovers nearby Bluetooth devices through the host adapter and records scan sessions with per-device metadata.

Pre-release Access

Join release updates.

Shadow and Shield is in active development and pre-release testing. Get product progress, launch details, and availability updates from daarc.