When a USB drive must be inspected, opening it with ordinary read-and-write access can change the source. A background process, an application, or an investigator can create metadata, rename a file, delete content, or write a thumbnail without intending to. A read-only USB policy reduces that risk by allowing files to be viewed or copied while rejecting write operations.
What USB Read-Only Access Protects
NIST defines a write blocker as a tool that permits access to storage media while preventing modification of the media. In practical USB inspection, that means the examiner can read directories, open files, and copy selected data to a separate working location, but the source drive should reject operations that create or change content.
This workflow is useful for internal investigations, incident response, e-discovery preparation, compliance review, support cases, and malware triage where a Windows workstation needs controlled access to removable media.
Before Connecting the Source USB Drive
Prepare the Windows computer first. SWGDE acquisition guidance emphasizes minimizing changes to the source and using a hardware or software write blocker where possible. The order matters: if the USB drive is connected before the restriction is active, Windows or another application may already have written to it.
- Use a dedicated Windows PC or a controlled workstation with administrator access and current security updates.
- Disconnect unrelated removable drives so the source cannot be confused with another device.
- Choose a separate destination drive for copied evidence, notes, screenshots, reports, and hash records.
- Record the USB drive's label, capacity, make, model, serial number when available, date, time, and the person handling it.
- Enable and test the read-only policy with a disposable USB drive before attaching the source device.
Configure GiliSoft USB Lock Computer Forensic Mode
GiliSoft USB Lock applies the control on the Windows endpoint. Computer Forensic Mode is designed for the specific case where the computer must read removable media but must not write back to it.
- Install and open GiliSoft USB Lock on the examination PC, then enter the administrator password.
- Open the USB and removable-media controls and enable Computer Forensic Mode.
- Confirm that USB reading is allowed and USB writing is blocked. Save or apply the policy before connecting the source drive.
- Keep activity logging enabled so device connections and blocked actions can be reviewed after the inspection.
- Connect a disposable test drive and complete the verification checks below. Attach the source USB only after the test passes.
Apply the removable-media rule on the Windows examination PC before attaching the source USB drive.
Use one Windows policy for read-only USB inspection
USB Lock can control USB reading and writing separately, record device activity, and retain broader device-control options for normal company endpoints. For this task, keep the policy focused: allow reads, block writes, test it, then inspect the source.
Verify That USB Writes Are Blocked
A displayed setting is not enough. SWGDE testing guidance for write blockers calls for attempts to write through the blocker and confirmation that reads are not disrupted. Use a disposable drive containing sample files, then run both sets of checks.
| Test | Expected result | What it confirms |
|---|---|---|
| Open folders and read sample files | Files open normally | Permitted read access still works |
| Copy a sample file from USB to the destination drive | Copy succeeds | Data can be collected without writing to the source |
| Create a new text file on the USB drive | Operation is denied | New writes are blocked |
| Edit and save an existing USB file | Save is denied | Existing content cannot be modified |
| Rename or delete a USB file | Operation is denied | Directory changes are blocked |
| Review USB Lock activity records | The connection and blocked action appear | The policy was applied and recorded |
Record the USB Lock version, Windows version, test drive identity, test time, and each result. If any write succeeds, stop and correct the policy before connecting the source media.
Examine and Copy the USB Data
- Connect the documented source USB drive only after the read-only test has passed.
- Confirm the expected drive letter, volume label, capacity, and device identity before opening files.
- Browse and preview only what the investigation requires. Copy selected files to the separate destination drive for detailed analysis.
- Use your approved hashing tool to calculate and record hashes for acquired files or a forensic image when the procedure requires integrity verification.
- Review USB Lock records, safely eject the source drive, and preserve the notes, hashes, copied data, and exported logs together.
Software Policy, DiskPart, or a Hardware Write Blocker?
| Method | Best use | Important detail |
|---|---|---|
| GiliSoft USB Lock Computer Forensic Mode | Controlled Windows inspections, internal investigations, incident response, and repeatable endpoint read-only access | Separates USB read and write policy and provides activity records on the examination PC |
| Hardware write blocker | Formal acquisition procedures that specify a validated physical blocker | Sits between the source media and examination computer; use a model appropriate for the interface |
| DiskPart read-only attribute | Temporary Windows administration on a known disk | A reversible disk attribute, not the same as an independently tested forensic write blocker |
| Physical lock switch | Media or adapters that provide a supported write-protect control | Availability and behavior depend on the hardware |
Useful Windows and USB Lock Records
USB Lock activity logs can help show when a device was connected and when a write attempt was denied. Windows also records device installation information in %SystemRoot%\inf\SetupAPI.dev.log. Microsoft documents this log as a record of device and driver installation activity.
Use each record for what it actually proves. A device-installation log can support a timeline of device recognition, but it does not by itself prove which files were copied. Preserve the USB Lock event record, Windows timestamps, destination-file details, examiner notes, and hashes together.
Review allowed and denied USB events after the inspection and export the records required by your procedure.
Common Mistakes to Avoid
USB Read-Only Mode FAQ
Can GiliSoft USB Lock allow reading but block writing?
Yes. Computer Forensic Mode is intended to let the Windows PC read the USB drive while blocking write operations to the source media.
Can files be copied from the USB drive in read-only mode?
Yes. Copying a file from the source USB to a separate destination is a read operation on the source. Copying files back to the source should be denied.
Should the source USB be connected before the mode is enabled?
No. Enable and verify the restriction first, then connect the source drive. This reduces the chance that Windows or an application writes to it before the policy is active.
Is DiskPart the same as a forensic write blocker?
No. DiskPart applies a reversible Windows disk attribute. A forensic workflow should use the method required by the organization's procedure and should test the selected blocker before use.
Does USB Lock calculate forensic hashes?
This workflow uses USB Lock to control read and write access. Calculate acquisition or file hashes with the approved forensic or hashing tool used by your organization.
References
- NIST CSRC: Write Blocker definition
- SWGDE Best Practices for Computer Forensic Acquisitions
- SWGDE Minimum Requirements for Testing Tools Used in Digital and Multimedia Forensics
- NIST SP 800-86: Integrating Forensic Techniques into Incident Response
- Microsoft: SetupAPI device installation log entries
- GiliSoft: Data integrity and security in digital forensics with USB Lock
Inspect USB media with read access and blocked writes
Configure Computer Forensic Mode, verify the restriction with a test drive, and review connection and blocked-action records from GiliSoft USB Lock.
View GiliSoft USB Lock
