Native toolset

Purpose-built engines for demanding operations.

Shield-399 includes first-party Go engines for imaging, cloning, sanitization, verification, and conversion. Direct platform integration keeps configuration, progress, error handling, verification, and structured execution records connected from start through review.

02

Disk Cloner

Native GoGNU dd1-to-many nativeVerify

Copies a source drive to one or more destinations with verification and bad-sector tracking.

03

The Overwriter

Native overwriteDevice-assisted when eligibleTRIM/UNMAPGNU shred / GNU dd
  • Device-assisted erase paths when the connected device and bridge expose an eligible method
  • Native software overwrite with deterministic patterns
  • Verification, progress, and wipe-operation records
04

Image Verify

Native E01/AFF4Ex01 via ewfverifyDAASH/BLAKE3
  • Reads Shadow & Shield advanced hash metadata (DAASH) where present
  • Native E01/AFF4 verification can compare MD5, SHA-1, SHA-256, and BLAKE3
  • Ex01 verification uses ewfverify and records MD5 and SHA-1
05

Image Converter

Native streamingE01 / DD / AFF4Cross-format conversionOptional verification

Converts supported E01, DD/RAW, and AFF4 images through supported cross-format paths, with optional read-back verification.

How the native E01 and Ex01 writers are constructed
  • The native Go engine uses separate writers for E01/EWF1, Ex01/EWF2, and AFF4.
  • E01 segments use EVF headers and canonical .E01.E99, .EAA.EZZ, then .FAA.ZZZ naming.
  • Ex01 segments use EVF2 headers and canonical .Ex01.Ex99, then .ExAA.EzZZ naming, up to 2,127 segments.
  • E01 segment 1 contains header2, legacy header, volume, and chunk-table structures. Later segments use data; intermediate segments end with next, and the final segment ends with done.
  • Native E01 acquisition uses 4 MiB chunks.
  • E01 supports none, empty-block, fast, and best compression. Compressed chunks use zlib and the table-offset high bit; chunks are stored raw when compression is not smaller. Turbo E01 uses raw chunks.
  • Adler-32 protects EWF1 section descriptors, format-defined payload structures, and uncompressed chunks.
  • Full-hash mode writes standard digest and hash sections plus a DAASH section containing MD5, SHA-1, SHA-256, and BLAKE3.
  • Shadow & Shield Image Info and Image Verify read DAASH. Current libewf/ewfverify testing successfully verifies generated E01 and Ex01 images.

Tool views in operation

From configuration to reviewed results.

These dashboard views show how available tools, saved profiles, imaging setup, execution records, and analysis results remain connected in one operational workspace.

Dashboard table showing saved tool configuration profiles
Saved tool profilesSave repeatable tool configurations for later use.Configuration · 1005
Dashboard modal for a configuration resource list
Reference-list configurationOrganize reusable reference material within managed configuration.Configuration · 1006
Dashboard modal configuring a hash-analysis job
Hash-analysis job setupConfigure analysis work before it enters the operational queue.Analysis · 1029
Dashboard imaging configuration with an engine selection menu open
Imaging engine selectionChoose the supported acquisition engine before execution.Imaging · 1030
Dashboard imaging modal showing destination capacity and output-folder configuration
Destination planningReview capacity and output location before acquiring media.Imaging · 1031
Dashboard modal configuring a destination drive and GPT partition setup in Drive Formatter
Drive Formatter setupSelect the destination drive and define a new partition layout before preparation work enters the queue.Preparation · 10005
Dashboard modal configuring a destination drive in Drive Encryption Manager
Encryption destination setupPrepare a selected destination for an encrypted volume with the chosen partition and filesystem defaults.Preparation · 10007
Dashboard view listing recorded execution history
Execution historyReview recorded work, timing, state, and linked operation context.History · 1039
Dashboard list of hash-analysis jobs
Hash job listReview queued and completed hash work from the investigation surface.Analysis · 1040
Dashboard list of keyword-search jobs
Keyword-search job listTrack configured keyword-search work alongside other analysis activity.Analysis · 1042
Dashboard modal displaying keyword-search results
Keyword-search resultsInspect matched results without losing the wider operational context.Analysis · 1043

Tools where the work happens

Prepared for the field, not tied to a workstation.

Configure and review work through the dashboard, then connect and operate directly at the Shield-399 unit when the environment calls for it.

Operator using a Shield-399 unit with connected media while traveling
In-transit operationRun connected-media tools from the Shield-399 unit without relying on a fixed workstation.
Shield-399 unit beside removable media and connected storage
Media prepared for intakeKeep removable drives and connected storage organized around the operation.
Top-down view of a Shield-399 unit connected to removable media and a storage drive
Direct media transferConnect Source and Destination media at the unit and select the required tool from the touchscreen.

TOOL CATALOG

What Shield-399 includes.

Tool availability and options vary by configuration, connected hardware, and installed system components.

The catalog combines native Go tools, supported third-party engines, and locally run AI-assisted capabilities. Tools run through Shield-399’s shared queue, reporting, and execution-record framework.

Verification

Image Verify

Native E01/AFF4Ex01 via ewfverifyDAASH/BLAKE3
  • Reads Shadow & Shield advanced hash metadata (DAASH) where present
  • Native E01/AFF4 verification can compare MD5, SHA-1, SHA-256, and BLAKE3
  • Ex01 verification uses ewfverify and records MD5 and SHA-1
Conversion

Image Converter

Native streamingE01 / DD / AFF4Cross-format conversionOptional verification

Converts supported E01, DD/RAW, and AFF4 images through supported cross-format paths, with optional read-back verification.

Sanitization

The Overwriter

Native overwriteDevice-assisted when eligibleTRIM/UNMAPGNU shred / GNU dd
  • Device-assisted erase paths when the connected device and bridge expose an eligible method
  • Native overwrite with deterministic patterns
  • Verification, method-selection records, and wipe-to-format support
Preparation

Drive Formatter

GPT / MBRNTFSexFATFAT32ext4ext3XFSBtrfsF2FSHFS+

Creates partition tables and filesystems on destination media.

Preparation

Drive Encryption Manager

LUKS1 / LUKS2Destination driveNTFS / exFAT / FAT32ext4 / XFSBest-effort header backupKey maintenance
  • Provisions destination drives as LUKS-encrypted volumes
  • Creates the partition, LUKS container, and mapped filesystem; requested header backups must be confirmed after completion
  • Records encryption operations and supports selected key-management workflows
Migration

Disk Cloner

Native GoGNU dd1-to-many nativeVerify

Copies a source drive to one or more destinations with verification and bad-sector tracking.

Migration

Drive Migrator

Partition-levelPreview planCopy + growGPT / MBRLUKS unlock
  • Copies source partitions into a recreated destination layout
  • Shows a migration preview with the planned layout
  • Supports unlocked LUKS migration
Extraction

Logical File Extractor

Copies selected files from a source drive or mounted forensic image to destination media as loose files or an L01 logical evidence container.

Recovery

File Carver

PhotoRecForemostScalpelNative Go
  • Recovers files from source drives and supported forensic images by scanning file signatures independently of filesystem metadata
  • Provides configurable scan scope, file categories, optional SHA-256 hashing, deduplication, and JSON/CSV manifests
  • Records and provides the exact command used when running third-party carving tools
Hashing

Drive Hasher

Source driveMounted imageMD5 / SHA-1SHA-256 / SHA-512BLAKE2b-256
  • Hashes source drives and supported image-backed sources
  • Stores one hash record per selected algorithm
Hashing

Partition Hasher

Hashes selected Source partitions and records partition-linked digest results.

Analysis

File Hasher

Hashes enumerated files and compares them against registered reference sets for known-file classification workflows.

Analysis

Keyword Search

Searches filenames and readable file content from completed evidence scans for literal keywords and supported regular-expression patterns, with exportable results.

Analysis

Encryption Detector

Scans source-device partitions for encryption indicators and records structured detections and unlock attempts where configured.

AnalysisAI-assisted

Translate Filenames

Displays translated filenames alongside the original names in review surfaces without modifying the evidence or replacing the original filename.

Repair

NTFS Health Check

Performs a read-only health check on a selected destination NTFS partition, with an explicitly acknowledged Basic Metadata Maintenance (Beta) option.

Hardware

Bluetooth Scanner

Discovers nearby Bluetooth devices through the host adapter and records scan sessions with per-device metadata.

Product updates

Stay informed about Shield-399.

Receive Shield-399 product, software-release, capability, and availability updates from Shadow and Shield.