english | bahasa indonesia



MacQuisition is a powerful, 3-in-1 solution for live data acquisition, targeted data collection, and forensic imaging. Tested and used by experienced examiners for over a decade, MacQuisition runs on the Mac OS X operating system and safely boots and acquires data from over 185 different Macintosh computer models in their native environment - even Fusion Drives. There’s no need for complicated take-aparts when you’ve got MacQuisition.

Selectively Acquire

  • Target and forensically acquire files, folders, and user directories while avoiding known system files and other unneeded data
  • Preserve valuable metadata by maintaining its association with the original file
  • Authenticate collected data using any or all MD5, SHA-1, or SHA-256 hash functions
  • Thoroughly log data acquisitions and source device attributes throughout the collection process
  • Selectively acquire email, chat, address book, Calendar, and other data on a per-user, per-volume basis

Collect from Live Systems

  • Capture important live data such as Internet, chat, and multimedia files in real time
    • Soundly acquire and save volatile Random Access Memory (RAM) contents to a destination device
    • Choose from 26 unique system data collection options, including active system processes, current system state, and print queue status
    • Extensively log live data acquisition information throughout the collection process

    Create Forensic Images

    • MacQuisition automatically recognizes a combined volume from a Fusion Drive and presents it for imaging
    • If FileVault 2 exists, the examiner can, with use of the password, Keychain file or recovery key, mount the volume in a read-only fashion, allowing for either a triage or collection of the files
    • Write-protect source devices while maintaining read-write access on destination devices