USB Read-Only Investigation Guide

Examine USB media without changing the source

Use GiliSoft USB Lock to allow reading while blocking write operations on the Windows examination PC.

  • Read files while blocking create, edit, rename, and delete actions
  • Test the policy before connecting the source USB drive
  • Review connection and blocked-action records after inspection
Windows computer applying read-only access rules to USB and removable media

How to Use USB Read-Only Mode for Digital Forensics

Updated on August 21, 2026   |   By GiliSoft Editorial Team

When a USB drive must be inspected, opening it with ordinary read-and-write access can change the source. A background process, an application, or an investigator can create metadata, rename a file, delete content, or write a thumbnail without intending to. A read-only USB policy reduces that risk by allowing files to be viewed or copied while rejecting write operations.

Quick answerOn a dedicated Windows examination PC, enable Computer Forensic Mode in GiliSoft USB Lock before attaching the source USB drive. Confirm that files can be opened and copied from the drive, then verify that creating, editing, renaming, and deleting files is blocked. Record the device details and the result of that verification before beginning the review.

What USB Read-Only Access Protects

NIST defines a write blocker as a tool that permits access to storage media while preventing modification of the media. In practical USB inspection, that means the examiner can read directories, open files, and copy selected data to a separate working location, but the source drive should reject operations that create or change content.

Reading remains availableBrowse folders, open supported files, and copy data from the USB drive to a separate analysis location.
Writes are rejectedBlock new files, edits, renames, deletions, and other write operations directed to the source USB drive.
The source stays separatePerform notes, exports, hashes, and analysis on another drive rather than saving results back to the source.
The policy can be checkedTest both successful reads and rejected writes before relying on the setup for an important inspection.

This workflow is useful for internal investigations, incident response, e-discovery preparation, compliance review, support cases, and malware triage where a Windows workstation needs controlled access to removable media.

Before Connecting the Source USB Drive

Prepare the Windows computer first. SWGDE acquisition guidance emphasizes minimizing changes to the source and using a hardware or software write blocker where possible. The order matters: if the USB drive is connected before the restriction is active, Windows or another application may already have written to it.

  1. Use a dedicated Windows PC or a controlled workstation with administrator access and current security updates.
  2. Disconnect unrelated removable drives so the source cannot be confused with another device.
  3. Choose a separate destination drive for copied evidence, notes, screenshots, reports, and hash records.
  4. Record the USB drive's label, capacity, make, model, serial number when available, date, time, and the person handling it.
  5. Enable and test the read-only policy with a disposable USB drive before attaching the source device.
Do not use the source drive as the working folder. Reports, extracted files, thumbnails, or exported data belong on the separate destination drive.

Configure GiliSoft USB Lock Computer Forensic Mode

GiliSoft USB Lock applies the control on the Windows endpoint. Computer Forensic Mode is designed for the specific case where the computer must read removable media but must not write back to it.

  1. Install and open GiliSoft USB Lock on the examination PC, then enter the administrator password.
  2. Open the USB and removable-media controls and enable Computer Forensic Mode.
  3. Confirm that USB reading is allowed and USB writing is blocked. Save or apply the policy before connecting the source drive.
  4. Keep activity logging enabled so device connections and blocked actions can be reviewed after the inspection.
  5. Connect a disposable test drive and complete the verification checks below. Attach the source USB only after the test passes.
Configure USB read and write access in GiliSoft USB LockApply the removable-media rule on the Windows examination PC before attaching the source USB drive.

Use one Windows policy for read-only USB inspection

USB Lock can control USB reading and writing separately, record device activity, and retain broader device-control options for normal company endpoints. For this task, keep the policy focused: allow reads, block writes, test it, then inspect the source.

GiliSoft USB Lock box

Verify That USB Writes Are Blocked

A displayed setting is not enough. SWGDE testing guidance for write blockers calls for attempts to write through the blocker and confirmation that reads are not disrupted. Use a disposable drive containing sample files, then run both sets of checks.

TestExpected resultWhat it confirms
Open folders and read sample filesFiles open normallyPermitted read access still works
Copy a sample file from USB to the destination driveCopy succeedsData can be collected without writing to the source
Create a new text file on the USB driveOperation is deniedNew writes are blocked
Edit and save an existing USB fileSave is deniedExisting content cannot be modified
Rename or delete a USB fileOperation is deniedDirectory changes are blocked
Review USB Lock activity recordsThe connection and blocked action appearThe policy was applied and recorded

Record the USB Lock version, Windows version, test drive identity, test time, and each result. If any write succeeds, stop and correct the policy before connecting the source media.

Examine and Copy the USB Data

  1. Connect the documented source USB drive only after the read-only test has passed.
  2. Confirm the expected drive letter, volume label, capacity, and device identity before opening files.
  3. Browse and preview only what the investigation requires. Copy selected files to the separate destination drive for detailed analysis.
  4. Use your approved hashing tool to calculate and record hashes for acquired files or a forensic image when the procedure requires integrity verification.
  5. Review USB Lock records, safely eject the source drive, and preserve the notes, hashes, copied data, and exported logs together.
Read-only access is one control in the process. Chain-of-custody notes, timestamps, device identification, validated tools, hashes, and secure storage remain separate procedural requirements.

Software Policy, DiskPart, or a Hardware Write Blocker?

MethodBest useImportant detail
GiliSoft USB Lock Computer Forensic ModeControlled Windows inspections, internal investigations, incident response, and repeatable endpoint read-only accessSeparates USB read and write policy and provides activity records on the examination PC
Hardware write blockerFormal acquisition procedures that specify a validated physical blockerSits between the source media and examination computer; use a model appropriate for the interface
DiskPart read-only attributeTemporary Windows administration on a known diskA reversible disk attribute, not the same as an independently tested forensic write blocker
Physical lock switchMedia or adapters that provide a supported write-protect controlAvailability and behavior depend on the hardware

Useful Windows and USB Lock Records

USB Lock activity logs can help show when a device was connected and when a write attempt was denied. Windows also records device installation information in %SystemRoot%\inf\SetupAPI.dev.log. Microsoft documents this log as a record of device and driver installation activity.

Use each record for what it actually proves. A device-installation log can support a timeline of device recognition, but it does not by itself prove which files were copied. Preserve the USB Lock event record, Windows timestamps, destination-file details, examiner notes, and hashes together.

Review USB device connections and blocked operations in GiliSoft USB LockReview allowed and denied USB events after the inspection and export the records required by your procedure.

Common Mistakes to Avoid

Connecting the source too earlyActivate and test the policy before the source USB is attached.
Testing only file creationAlso test edits, renames, deletions, and successful reads.
Saving reports to the sourceUse a separate destination for every note, export, screenshot, and hash file.
Treating one log as complete proofCorrelate device records, policy events, copied-file details, notes, and hashes.

USB Read-Only Mode FAQ

Can GiliSoft USB Lock allow reading but block writing?

Yes. Computer Forensic Mode is intended to let the Windows PC read the USB drive while blocking write operations to the source media.

Can files be copied from the USB drive in read-only mode?

Yes. Copying a file from the source USB to a separate destination is a read operation on the source. Copying files back to the source should be denied.

Should the source USB be connected before the mode is enabled?

No. Enable and verify the restriction first, then connect the source drive. This reduces the chance that Windows or an application writes to it before the policy is active.

Is DiskPart the same as a forensic write blocker?

No. DiskPart applies a reversible Windows disk attribute. A forensic workflow should use the method required by the organization's procedure and should test the selected blocker before use.

Does USB Lock calculate forensic hashes?

This workflow uses USB Lock to control read and write access. Calculate acquisition or file hashes with the approved forensic or hashing tool used by your organization.

References

Inspect USB media with read access and blocked writes

Configure Computer Forensic Mode, verify the restriction with a test drive, and review connection and blocked-action records from GiliSoft USB Lock.

View GiliSoft USB Lock