⬤ Patent Pending

Know It's Safe
Before You Plug It In.

Hardware-enforced write blocking and air-gapped malware triage — before suspect media ever touches your system. No host PC. No configuration. No training. No risk.

Scanning
Clear
Threat
View the Device Watch the Video
43
Patent Claims
0
Bits Written to Media
2
Form Factors
100%
Air-Gapped
In Plain English

What This Actually Does

A USB drive, external hard drive, or SD card can carry a virus without looking any different from a safe one — there's no way to tell just by looking at it. Plug an infected one into your computer, and that virus can spread through your whole network in seconds. The antivirus software already on your computer often can't stop it, because some attacks happen the instant the drive is plugged in, before any scan even has a chance to start.

DF-X1 fixes this the simple way: plug the drive into DF-X1 first, not your computer. It checks the drive on its own, completely disconnected from everything else. A green light means it's safe to use. A red light means it's not — don't plug it in. No computer skills needed, and nothing to set up.

The Problem

One Drive Can Take Down
an Entire Network

In an era of cloud security and zero-trust networks, the USB port remains the one gap every firewall, endpoint agent, and cloud solution completely ignores. Attackers know it. The data proves it.

1 in 4
industrial cybersecurity incidents in 2025 were caused by a USB plug-and-play event — someone simply plugging in a drive.
Honeywell 2025 Cyber Threat Report  |  1,826 unique USB malware threats detected in Q1 2025 alone
Why USB attacks are rising — not falling — in the cloud era
As organizations hardened email gateways, patched VPNs, and added MFA, sophisticated threat groups shifted to physical media — because the USB port is the one attack surface cloud security cannot touch. Air-gapped military networks, classified law enforcement systems, hospital OT infrastructure, and industrial control environments all move data on physical media by design. One unscreened drive is all it takes.
FBI Confirmed
FIN7 BadUSB — Defense Firms
Malicious USB drives mailed to defense contractors. Plugging in deployed ransomware instantly — no clicks, no warnings. Zero antivirus detection.
Mandiant / Google Intelligence
SOGU USB Espionage — 29+ Agencies
China-linked actors infected USB drives that self-replicate across networks. Government, health, and transportation targets. No internet connection needed to spread.
Honeywell 2025 Report
80% of USB Malware Can Disrupt OT
Of 1,826 USB threats detected in Q1 2025, 80% were capable of causing industrial outages — loss of control, loss of visibility, or full system shutdown.
🪖
Military & Federal
Air-gapped classified networks move all data on physical media by mandate. One infected drive brought in by a contractor or analyst can compromise the entire network before a single alert fires.
🚔
Law Enforcement
Evidence drives collected at crime scenes contain unknown payloads. Plugging directly into a precinct workstation puts CJIS-regulated networks at immediate risk with no chain of custody protection.
🔍
Investigators & Forensics
Digital forensic analysts handle suspect media daily. Without hardware write-blocking, existing scanning tools modify files — a chain of custody violation that can render evidence inadmissible in court.
🏥
Healthcare
USB-delivered ransomware is the fastest-growing attack vector on hospital OT networks. A single infected drive can encrypt patient records, disable medical devices, and trigger HIPAA penalties exceeding $1M.
🏢
Enterprise
Contractors, vendors, and IT staff bring removable media into secure environments daily. One unscreened drive bypasses every firewall, zero-trust policy, and endpoint agent on your network.
🛡️
Insurance & Risk
Cyber insurers increasingly require documented USB screening procedures as a condition of coverage. Without a hardware-verified audit trail, USB-borne incidents may not be covered under existing policies.
How It Works

Five Steps. Zero Risk.

From insertion to safe connection — automated, hardware-enforced, and completely air-gapped.

01
🔌
Insert Media
USB-A, USB-C, or SD card inserted into the suspect media port.
02
🔒
Write Locked
Hardware write-blocker activates at silicon level. Zero bytes written. Impossible to bypass.
03
🔍
Scanning
LED: YELLOW. Air-gapped read-only threat engine analyzes every file. No network connection.
04
#️⃣
Hash Computed
SHA-256/SHA-3 cryptographic fingerprint computed. Immutable chain-of-custody established.
05
Result
GREEN = Safe to connect. RED = Threat detected. Do not connect. Quarantine media.
The Devices

Two Form Factors.
One Mission.

Field-deployable and office-ready — the DF-X1 meets you where the threat is.

Version 1
DF-X1 V1
Field Unit — Patrol Vehicle · Military
Headless · Stateless · LED Only
DeploymentField / Vehicle / Mobile
InterfaceLED Ring Only — No Screen
Media PortsUSB-A · USB-C · SD Card
Record OutputLED Only — No Storage
ArchitectureStateless — Zero Data Retained
Write BlockingHardware Silicon-Level
NetworkAir-Gapped During Intake
Encrypted MediaDetects & Refuses — No Unlock (LED Only)
UpdatesAir-Gapped Signed Package
Version 2
DF-X1 V2
Desk Console — Office · Detective · Prosecutor
Touchscreen · Dual Ports · BLE Output
DeploymentOffice · Lab · Enterprise · Field
InterfaceTouchscreen GUI + Per-Port LEDs
Media PortsDual Concurrent — 2 Devices at Once
Record OutputTouchscreen + Bluetooth to App
ArchitectureFull Tamper-Evident Record
Write BlockingHardware Silicon-Level
NetworkAir-Gapped During Intake
Encrypted MediaUnlocks & Scans — BitLocker · LUKS2 · VeraCrypt · FileVault2
UpdatesSecure Signed Package

DF-X1 Forensic Console

Full product and market overview — use the arrows to advance slides.

Slide 1 of 12
DF-X1 Forensic Console
Secure, Air-Gapped Media Intake & Threat Triage.
Know it's safe before you plug it in.
See It in Action

The DF-X1 in the Field

See what happens when unknown media connects to a secure network — and what happens when it doesn't.

Press play to watch the full DF-X1 walkthrough (3:36)

Competitive Advantage

Nothing Else Does This.

Enterprise kiosks cost $10,000–$50,000 and modify your evidence. The DF-X1 doesn't.

Capability DF-X1 Enterprise Kiosks AV Software
Hardware write blocking
Never modifies suspect media
No host PC required
Air-gapped during intake
Field / vehicle deployable
Cryptographic chain-of-custody
Dual concurrent device intake✓ V2
Unlocks & scans encrypted drives (BitLocker / LUKS2 / VeraCrypt / FileVault2)✓ V2
Bluetooth output to companion app✓ V2
Desk-deployable, no IT setup
Price rangeTBD$10K–$50K+Subscription
Who It's For

Any Desk. Any Organization.
Any Unknown Drive.

The threat doesn't care what industry you're in.

🚔
Law Enforcement
Municipal · State · Federal
Precinct intake, field booking, property rooms, vehicle MDTs. V1 for officers, V2 for desk use.
🪖
Military & Federal
DOD · JAG · DHS · FBI · CBP
CJIS-aligned intake. Military JAG requires the same chain-of-custody as civilian courts.
⚖️
Prosecution & Legal
DA Offices · Law Firms · eDiscovery
Pre-analysis intake records defeat admissibility challenges. Hash proves files were untouched.
🛡️
Insurance
Claims · Fraud Investigation
Clean, court-ready intake records before connecting suspect drives from incident scenes.
🏥
Healthcare
IT Security · HIPAA Compliance
Prevents patient data exposure from infected USB media in HIPAA-sensitive environments.
🏢
Corporate Security
IR Teams · Internal Investigations
Write-protected intake before forensic imaging in insider threat and IR investigations.
🏦
Financial Services
Compliance · Fraud Investigation
Cryptographic hash at intake satisfies discovery requirements for regulatory investigations.
🎓
Academia & Research
Universities · Research Labs
Affordable, standards-compliant media intake for shared or externally sourced storage.
Contact

Get in Touch

Interested in the DF-X1 for your agency, department, or organization? We'd like to hear from you.

Replies within 24–48 hours to mike@dfx1forensics.com