MACQUISITION
Mac OS X
MacQuisition™ is a powerful 3-in-1 live data acquisition, targeted data collection, and forensic imaging solution. Tested and used by experienced examiners for over a decade, MacQuisition™ acquires data from over 185 different Macintosh computer models. Avoid complicated and time-consuming take-aparts. MacQuisition™ runs on the Mac OS X operating system and safely boots and collects data from Xserve, Mac, iMac, Mac mini, MacBook, and MacBook Air computers in their own native Mac OS X environment.
Note: All dongles must be activated and licensed before the software will recognize them. MacQuisition dongles are formatted as HFS+. Therefore, a Mac computer running OS X will be needed to license or update the dongle in order to use MacQuisition.
Targeted Data Collection
- Target and forensically acquire files, folders, and user directories while avoiding known system files and other unresponsive data.
- Preserve valuable metadata by maintaining its association with the original file.
- Authenticate collected data using any or all MD5, SHA-1, or SHA-256 hash functions.
- Thoroughly log data acquisitions and source device attributes throughout the collection process.
- Selectively acquire email, chat, address book, calendar, and stickies on a per user, per volume basis.
Live Data Acquisition
- Capture important live data such as Internet, chat, and multimedia files in real time.
- Soundly acquire and save volatile Random Access Memory (RAM) contents to a destination device.
- Choose from 26 unique system data collection options including active system processes, current system state, and print queue status.
- Extensively log live data acquisition information throughout the collection process.
Forensic Imaging
- Avoid time-consuming take-aparts. Use the source machine’s own system to create a forensic image by booting from the MacQuisition USB dongle.
- Image over 185 different Mac laptop, desktop, and OS X server models.
- Write-protect source devices while maintaining read-write access on destination devices.
- Extensively log forensic image acquisition processes, disk and volume attributes, and corresponding hash values