MacQuisition™ is a powerful, 3-in-1 solution for live data acquisition, targeted data collection, and forensic imaging. Forensic examiners throughout the world depend on BlackBag Technologies’ software reliability to securely image hundreds of Macs. Uniquely versatile, MacQuisition™ is the only forensic solution that runs within a native OS X boot environment. The advanced imaging processes of MacQuisition™ 2017 provides examiners with the software to acquire live data (including RAM) or forensically image over 185 different Apple computers, including the latest MacBook Pro with Touch Bar and iMac.
Tested and used by experienced examiners throughout the world for over a decade, MacQuisition™ runs on the Mac OS X operating system and safely boots and acquires data from Apple computers in their native environment - even Fusion Drives. MacQuisition automatically and proficiently identifies, displays and interprets Apple File System, FileVault, Fusion and CoreStorage Volumes. Through the MacQuisition boot environment, examiners can image Mac RAM with no password.
With changes in Apple’s hardware and software, forensic examiners will see and benefit from the improvements in MacQuisition™ 2017, with key features including:
· Image all Intel® based Macs including the new MacBook Pro with Touch Bar and iMac
· Native Mac OS boot environment
· Ability to image APFS drives
· CoreStorage support
· Image any drive with FileVault encryption
· Fusion Drive support
· RAM imager
· Write protection
The 3-in-1 solution for live data acquisition, targeted data collection, and forensic imaging provided by MacQuisition™ 2017 offers forensic examiners:
Live Data Acquisition
· Capture live data in real time
· Accurately acquire RAM
· Choose from 26 system data collection options, including active, current and print-queue status
Targeted Data Collection
· Target and forensically acquire files and user directories
· Avoid known system files and unneeded data
· Preserve valuable native metadata
· Authenticate & validate collected data
· Log data acquisitions and source device attributes
· Selectively acquire data by per-user, per-volume basis
· Combined volume from a Fusion Drive automatically presented for imaging
· If FileVault 2 exists, through password, Keychain or recovery key, the examiner can mount the volume in a read-only fashion for triage or collection of files
· By booting from the MacQuisition™ USB, a forensic image can be created by using the source machine’s own system
· Write-protect source devices, whilst maintaining read-write access on destination devices
BlackBag Technologies’ software is used by hundreds of federal, state, and local law enforcement agencies around the world for criminal investigations, as well as leading corporations and consultants handling HR investigations and eDiscovery matters. This new release of MacQuisition™, allowing examiners to forensically image more than ever, is the latest update to Black Technologies’ range of software products.
MacQuisition™ 2017R1 is out now and available directly through BlackBag Technologies or one of their channel partners.