MacQuisition is a unique forensic imaging and acquisition tool capable of booting hundreds of Mac OS X systems, as well as acquiring live targeted data. Write-protect source devices while maintaining read-write access on destination devices.Use the source machine’s own system to create a forensic image by booting from the MacQuisition USB dongle.If FileVault 2 exists, the examiner can, with use of the password, Keychain file or recovery key, mount the volume in a read-only fashion, allowing for either a triage or collection of the files.MacQuisition automatically recognizes a combined volume from a Fusion Drive and presents it for imaging.Extensively log live data acquisition information throughout the collection process.Choose from 26 unique system data collection options, including active system processes, current system state, and print queue status.Soundly acquire and save volatile Random Access Memory (RAM) contents to a destination device.Capture important live data such as Internet, chat, and multimedia files in real time.LIVE DATA ACQUISITION COLLECT FROM LIVE SYSTEMS
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |