Open In App

Write Blockers- An Introduction

Digital evidence is our major issue of concern in Forensic investigation. Forensic investigators need to absolutely assure of the fact that the data they obtain as digital evidence is not altered during the capture, analysis, and control. In the courtroom everyone including attorneys, judges, jurors need to feel confident that digital evidence has not been tampered and is legitimate. How can you be assured that digital evidence has not tampered?

According to the NIST-National Institute of Standards and Technology, the investigator follows a certain set of rules and procedures to prevent the execution of any program that might modify the contents of the disk. Some of these procedures are:



In this article we will be discussing the following key areas:

  1. What are Write Blockers?
  2. What are the Types of Write Blockers?
  3. What to look for in a Write Blocker?

What are Write Blockers?

Write Blocker is a tool designed to prevent any write access to the hard disk, thus permitting read-only access to the data storage devices without compromising the integrity of the data. A write blocking if used correctly can guarantee the protection of the chain of custody. NIST has issued a set of general guidelines for write blocking requirements:



  1. The write-blocker tool shall not allow a protected drive to be changed.
  2. The write-blocker tool shall not prevent any operations to a drive that is not protected.
  3. The write-blocker tool shall not prevent obtaining any information from or about any drive.

What are the different types of Write Blockers?

Write Blockers are basically of 2 types: Hardware Write Blocker and Software Write Blocker. Both types of write blockers are meant for the same purpose that is to prevent any writes to the storage devices. Let’s discuss each type of write blocker in detail.

Hardware Write Blocker:

Hardware write blockers are used to intercept and block any modifying command from ever reaching the storage device. Some of its features include:

Challenges of using Hardware Write Blockers:
Let’s discuss some of the challenges of using hardware-based write blockers.

Software Write Blocker:

Software write blockers are installed on a forensic workstation. According to NIST’s specification on software Write Blocker, a software write blocker tool operates by monitoring and filtering drive I/O commands sent from an application or OS through a given access interface. They provide the ability to simultaneously write block as many disk devices as are connected to a computer without the need for multiple expensive hardware write blocking devices. Some of the features that are provided by different write blocking tools are:

Benefits of using Software Write Blockers:
There are some benefits in using Software Write Blockers instead of Hardware Write Blockers.

What to look for in a Write Blocker?

When buying a write blocker, the required features depend on your specific needs. However, there are some general points to keep in mind that we recommend to customers:

References:https://en.wikipedia.org/wiki/Forensic_disk_controller

Article Tags :