MACQUISITION

Mac OS X

MacQuisition™ is a powerful 3-in-1 live data acquisition, targeted data collection, and forensic imaging solution. Tested and used by experienced examiners for over a decade, MacQuisition™ acquires data from over 185 different Macintosh computer models. Avoid complicated and time-consuming take-aparts. MacQuisition™ runs on the Mac OS X operating system and safely boots and collects data from Xserve, Mac, iMac, Mac mini, MacBook, and MacBook Air computers in their own native Mac OS X environment.

Note: All dongles must be activated and licensed before the software will recognize them. MacQuisition dongles are formatted as HFS+. Therefore, a Mac computer running OS X will be needed to license or update the dongle in order to use MacQuisition.

Request a Quote


    If possible, please use a valid agency/company email.

    RCMP DMFT Program?



    This is necessary to quote accurate shipping costs.


    Targeted Data Collection

    • Target and forensically acquire files, folders, and user directories while avoiding known system files and other unresponsive data.
    • Preserve valuable metadata by maintaining its association with the original file.
    • Authenticate collected data using any or all MD5, SHA-1, or SHA-256 hash functions.
    • Thoroughly log data acquisitions and source device attributes throughout the collection process.
    • Selectively acquire email, chat, address book, calendar, and stickies on a per user, per volume basis.

    Live Data Acquisition

    • Capture important live data such as Internet, chat, and multimedia files in real time.
    • Soundly acquire and save volatile Random Access Memory (RAM) contents to a destination device.
    • Choose from 26 unique system data collection options including active system processes, current system state, and print queue status.
    • Extensively log live data acquisition information throughout the collection process.

    Forensic Imaging

    • Avoid time-consuming take-aparts. Use the source machine’s own system to create a forensic image by booting from the MacQuisition USB dongle.
    • Image over 185 different Mac laptop, desktop, and OS X server models.
    • Write-protect source devices while maintaining read-write access on destination devices.
    • Extensively log forensic image acquisition processes, disk and volume attributes, and corresponding hash values