Return to Computer Forensic Prerequisites

Windows OS Write-Protection With USB Devices

Tutorial Key Facts
Supported Operating SystemThe Manual Way: Windows XP, Vista, Win 7 (all versions)
The Automatic Way:
Solution 1: Windows xp , Vista , Windows 7 , Windows 8 ,Windows 8.1 (both x86 and x64)
Solution 2: Win7/Vista/XP
Solution 3: Win 32 – supports Vista, 7
NotesRequire Windows Registry modifications , use with caution for beginner users. Backup your registry first
Last Update2014/03/10
AuthorNihad Hassan
Before connecting the suspect drive to your forensic workstation, it is crucial to enable write-blocking protection on your USB devices as Operation Systems writes data and modify existing Meta data available on disks/usb devices while booting. In this tutorial Iam going to show you how to implement write-protection to USB|external hard drivers to prevent windows from contaminating your evidence drive. Both manual and automatic methods are shown, please note that there are hardware devices that can implement the same functionality, but Iam not going to cover it here in details , I will just mention the major vendors if you want to buy one; the software solutions described below once implemented correctly can give the same results with no costs.

First: The Manual Way:

Go to the start > run and type “regedit” in run console as follow 1 Browse you registry to the following location:  [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesUSBSTOR] 2 3 In the right pane you will find the “start” property , right click on it and select “Modify” , change its “value data” to [4] to disable writing to USB devices, by default it is set to [3] which allow writing to USB drives. 4 Plug your USB to your computer , it will not be able to recognize it anymore; to enable it again change the “start” property “value data” to [3].

Second: The Automatic Way

Solution 1:

Supported OS: Windows xp , Vista , Windows 7 , Windows 8 ,Windows 8.1 (both x86 and x64) Ratool v1.0 (Removable Access tool): is a very simple-to-use portable freeware Application it help us to control USB storage devices. Ratool can disable USB storage access or enable write protection on all USB Flash drives thus prevent data from being modified or deleted. 7 We have three options:

  1. Disable USB Disks Detection: It disables any USB storage / PenDrive access to your pc.
  2. Allow Read & Write. This option is the default option and provides normal access to USB devices.
  3. Allow Read Only: This option restricts users from writing anything on the USB device but lets them access any information stored on it.

After applying the changes, a system restart is needed to implement the desired action.

Solution 2:

USB Disabler (created by wittsoft) is a small, simple program designed to enable or disable USB storage access on your Windows computer, it supports Win7/Vista/XP. 6 You can choose “Disabled” to disable write blocking to USB device, “Read Only” to allow only reading the contents of the USB device without the ability to write inside it; and the normal mode which allow read/write to USB drive. This is a portable application and could be downloaded from the here: Or from here:

Solution 3:

We perform the same function as we did above by using a small utility called Zokif USB Flash Disabler/Enabler; this small tool (Win 32 – supports Vista, 7) will change the “Start” property “value data” to either [3] to enable writing to USB or [4] to disable writing without direct access to computer registry. You can download this tool rom the following location Click “Disable USB Flash” button to disable USB devices or “Enable USB Flash” button to enable writing to USB devices. 5

Third: Hardware Write-blocking Devices:

With hardware write-blockers, we can connect the drive that we want to inspect to our workstation and start the OS as usual. Hardware write-blocking devices prevents Windows or Linux OS from writing data to blocked drive while booting, hardware write-blocking works a s a layer between our forensic workstation and the inspection drive.

Please note, when attaching a hardware write-blocking device to a computer running windows OS and trying to copy or modify data in the blocked drive, window will issue no warning and will show data copy or modifications to a specific file was successful, however when we restart the machine the blocked drive (which the hardware write-blocking was attached to it) will return to its original state without the modifications we’ve done previously.

The following vendors provide Hardware-write blocking devices:

Demonstration of Voomtect Hard Drive Duplicator with built-in write blocking protection

Image of NoWrite FlashBlock II;Write Blocker add-on for Compact Flash & Digital Media from

Permanent link to this article: