How To Protect Your Acquired Evidence From Ransomware Attacks

SHIELD is a kernel-mode component of ACQUIRE and TACTICAL protecting all collected digital evidence by our solutions regardless of the device it resides in. 

As long as the ransomware SHIELD is green, all folders that are used for saving evidence are protected from any external modifications until you export the evidence to some external destination.

At its core, it’s a kernel-mode driver that is monitoring collected evidence against any type of ransomware modification thus giving you the possibility to continue collecting evidence in a safe mode.

How to use it

The feature is enabled by default and will stay active until you disable it by clicking the shield icon on the main page of TACTICAL/ACQUIRE or by clicking one of the two buttons on the acquisition summary page (Open Output Folder / Open Case Html). 


Get The Latest DFIR News!

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

Please note that these solutions will protect the case files they collect regardless of the location they reside in (i.e. USB drive or a network share) which is the reason we suggest you use a USB drive or a network share dedicated for this purpose only.

A little bit about TACTICAL and ACQUIRE

Light, powerful, and completely free. ACQUIRE is your digital evidence collection solution.

ACQUIRE gives you the following product feature highlights:

  • FREE forever
  • Powered by our IREC Engine
  • One-click installation and setup
  • Collect 40 types of digital evidence
  • Evidence collection time under 10 mins
  • Detailed investigation report (JSON / HTML Format, Export to XLS / CSV / PDF)
  • Unlimited no. of investigations
  • Ransomware shielding

You can download it now from www.binalyze.com/acquire.

TACTICAL – The Ultimate Evidence Collector for Incident Response

Designed as a natural successor to IREC, TACTICAL collects more than 120 types of digital evidence in less than 10 minutes. In addition, it comes with new features such as offline mode and remote evidence acquisition.

Here are the product feature highlights:

  • Powered by our IREC Engine
  • One-click installation and setup
  • Collect 120+ types of digital evidence
  • Evidence collection time under 10 mins
  • Detailed investigation report (JSON/HTML Format, Export to XLS / CSV / PDF)
  • Ransomware Shielding 
  • Command-line execution
  • Offline mode
  • Available as a hardware dongle or soft license
  • Perpetual license and PAYG options

You can download it now from www.binalyze.com/tactical.

Keep your digital evidence safe from ransomware.

Leave a Comment

Latest Videos

Magnet Forensics' Matt Suiche on the Rise of e-Crime and Info Stealers

Forensic Focus 12th January 2023 3:00 am

Just like your current holiday shopping for last minute presents a lot of the good stuff has gone off the shelves already. You reach to the back and find the toy nobody really wanted but it’s the thought that counts, you stare down at Si and Desi’s Holiday Special 2022 podcast. 

Please join these two as they lament over the year that was, discuss all the things they didn’t do but promise they will do them next year, query whether putting a NAS in the storage of a roller door is a good idea, and finally arrive at what they’re looking forward to bringing you in the new year.

Show Notes:

Arduino PLC IDE - https://docs.arduino.cc/software/plc-ide
Mycroft Mark II (open source Alexa) - https://www.kickstarter.com/projects/aiforeveryone/mycroft-mark-ii-the-open-voice-assistant
Christa’s new blog - https://christammiller.com/
Si’s holiday reading - https://amzn.to/3iJyGrR
Desi’s holiday reading -  https://inteltechniques.com/
Strange event for the end of the year - https://www.reuters.com/world/europe/25-suspected-members-german-far-right-group-arrested-raids-prosecutors-office-2022-12-07/
Si’s wishful thinking - https://www.youtube.com/watch?v=GXnRgXclLd0
Si’s list to do before the EOY - https://intrepidcamera.co.uk/products/intrepid-4x5-camera
Desi’s list to do before EOY - https://www.wired.com/story/how-to-reset-your-phone-before-you-sell-it/
“Cleaning your office” - https://www.manfrotto.com/uk-en/vintage-collapsible-1-5-x-2-1m-ink-sage-ll-lb5720/
Conference recorder - https://amzn.to/3UBmre5
Desi’s blog - https://www.hardlyadequate.com/

Just like your current holiday shopping for last minute presents a lot of the good stuff has gone off the shelves already. You reach to the back and find the toy nobody really wanted but it’s the thought that counts, you stare down at Si and Desi’s Holiday Special 2022 podcast.

Please join these two as they lament over the year that was, discuss all the things they didn’t do but promise they will do them next year, query whether putting a NAS in the storage of a roller door is a good idea, and finally arrive at what they’re looking forward to bringing you in the new year.

Show Notes:

Arduino PLC IDE - https://docs.arduino.cc/software/plc-ide
Mycroft Mark II (open source Alexa) - https://www.kickstarter.com/projects/aiforeveryone/mycroft-mark-ii-the-open-voice-assistant
Christa’s new blog - https://christammiller.com/
Si’s holiday reading - https://amzn.to/3iJyGrR
Desi’s holiday reading - https://inteltechniques.com/
Strange event for the end of the year - https://www.reuters.com/world/europe/25-suspected-members-german-far-right-group-arrested-raids-prosecutors-office-2022-12-07/
Si’s wishful thinking - https://www.youtube.com/watch?v=GXnRgXclLd0
Si’s list to do before the EOY - https://intrepidcamera.co.uk/products/intrepid-4x5-camera
Desi’s list to do before EOY - https://www.wired.com/story/how-to-reset-your-phone-before-you-sell-it/
“Cleaning your office” - https://www.manfrotto.com/uk-en/vintage-collapsible-1-5-x-2-1m-ink-sage-ll-lb5720/
Conference recorder - https://amzn.to/3UBmre5
Desi’s blog - https://www.hardlyadequate.com/

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_BhrBg5_sAKo

Si and Desi Holiday Special 2022

Forensic Focus 16th December 2022 12:00 am

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feed settings page to add an API key after following these instructions.

Latest Articles

Share to...