TARGETED DATA COLLECTION
SELECTIVELY ACQUIRE
- Target and forensically acquire files, folders, and user directories while avoiding known system files and other unneeded data
- Preserve valuable metadata by maintaining its association with the original file
- Authenticate collected data using any or all MD5, SHA-1, or SHA-256 hash functions
- Thoroughly log data acquisitions and source device attributes throughout the collection process
LIVE DATA ACQUISITION
COLLECT FROM LIVE SYSTEMS
- Capture important live data such as Internet, chat, and multimedia files in real time
- Soundly acquire and save volatile Random Access Memory (RAM) contents to a destination device
- Choose from 26 unique system data collection options, including active system processes, current system state, and print queue status
- Extensively log live data acquisition information throughout the collection process
- Selectively acquire email, chat, address book, Calendar, and other data on a per-user, per-volume basis
FORENSIC IMAGING
CREATE FORENSIC IMAGES
- MacQuisition automatically recognizes a combined volume from a Fusion Drive and presents it for imaging
- If FileVault 2 exists, the examiner can, with use of the password, Keychain file or recovery key, mount the volume in a read-only fashion, allowing for either a triage or collection of the files
- Use the source machine’s own system to create a forensic image by booting from the MacQuisition USB dongle
- Write-protect source devices while maintaining read-write access on destination devices
MacQuisition is a unique forensic imaging and acquisition tool capable of booting hundreds of Mac OS X systems, as well as acquiring live targeted data. As the only forensic solution that runs within a native OS X boot environment, MacQuisition’s compatibility with Mac hardware makes it uniquely versatile and universally reliable.