How To Protect Your Acquired Evidence From Ransomware Attacks

SHIELD is a kernel-mode component of ACQUIRE and TACTICAL protecting all collected digital evidence by our solutions regardless of the device it resides in. 

As long as the ransomware SHIELD is green, all folders that are used for saving evidence are protected from any external modifications until you export the evidence to some external destination.

At its core, it’s a kernel-mode driver that is monitoring collected evidence against any type of ransomware modification thus giving you the possibility to continue collecting evidence in a safe mode.

How to use it

The feature is enabled by default and will stay active until you disable it by clicking the shield icon on the main page of TACTICAL/ACQUIRE or by clicking one of the two buttons on the acquisition summary page (Open Output Folder / Open Case Html). 


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

Please note that these solutions will protect the case files they collect regardless of the location they reside in (i.e. USB drive or a network share) which is the reason we suggest you use a USB drive or a network share dedicated for this purpose only.

A little bit about TACTICAL and ACQUIRE

Light, powerful, and completely free. ACQUIRE is your digital evidence collection solution.

ACQUIRE gives you the following product feature highlights:

  • FREE forever
  • Powered by our IREC Engine
  • One-click installation and setup
  • Collect 40 types of digital evidence
  • Evidence collection time under 10 mins
  • Detailed investigation report (JSON / HTML Format, Export to XLS / CSV / PDF)
  • Unlimited no. of investigations
  • Ransomware shielding

You can download it now from www.binalyze.com/acquire.

TACTICAL – The Ultimate Evidence Collector for Incident Response

Designed as a natural successor to IREC, TACTICAL collects more than 120 types of digital evidence in less than 10 minutes. In addition, it comes with new features such as offline mode and remote evidence acquisition.

Here are the product feature highlights:

  • Powered by our IREC Engine
  • One-click installation and setup
  • Collect 120+ types of digital evidence
  • Evidence collection time under 10 mins
  • Detailed investigation report (JSON/HTML Format, Export to XLS / CSV / PDF)
  • Ransomware Shielding 
  • Command-line execution
  • Offline mode
  • Available as a hardware dongle or soft license
  • Perpetual license and PAYG options

You can download it now from www.binalyze.com/tactical.

Keep your digital evidence safe from ransomware.

Leave a Comment

Latest Videos

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feeds settings page to add an API key after following these instructions.

Latest Articles