(800) 484-3946 info@derickdowns.com

MacQuisition®

A powerful, 4-in-1 forensic imaging software solution for Macs for triage, live data acquisition, targeted data collection, and forensic imaging. MacQuisition is the first and only computer forensic tool to create physical images of Macs with the Apple T2 chip. Tested and used by experienced examiners for over a decade, MacQuisition runs on the Mac OS X operating system and safely boots and acquires data from over 185 different Macintosh computer models in their native environment – even Fusion Drives. There’s no need for complicated take-aparts when you’ve got MacQuisition.
BEST SOLUTION FOR

Law Enforcement

Federal Agencies

Corporations

Consultants

Triage

Search, Browse, and Preview

R

Triage devices to determine if relevant data exists prior to imaging

R

Browse through files and folders of the device and any connected media

R

Search for data on devices using a combination of location , file name, file extension, file size, dates, and file content

R

Preview files in MacQuisition – file previews work on file types supported by macOS QuickLook: pictures, videos, office files, pdfs, etc.

Targeted Data Collection

Selectively Acquire

R

Ability to create physical images of Macs with the Apple T2 chip

R

Target and forensically acquire files, folders, and user directories while avoiding known system files and other unneeded data

R

Preserve valuable metadata by maintaining its association with the original file

R

Authenticate collected data using any or all MD5, SHA-1, or SHA-256 hash functions

R

Thoroughly log data acquisitions and source device attributes throughout the collection process

R

Selectively acquire email, chat, address book, Calendar, and other data on a per-user, per-volume basis

Live Data Acquisition

Collect From Live Systems

R

Soundly acquire and save volatile Random Access Memory (RAM) contents to a destination device

R

Capture important live data such as Internet, chat, and multimedia files in real time

R

Capture RAM and targeted collections live on Mojave

R

Choose from 26 unique system data collection options, including active system processes, current system state, and print queue status

R

Extensively log live data acquisition information throughout the collection process

Forensic Imaging

Create Forensic Images

R

Support for imaging APFS Fusion drives

R

Automatically recognizes a combined volume from a Fusion Drive and presents it for imaging

R

If FileVault 2 exists, the examiner can, with use of the password, Keychain file or recovery key, mount the volume in a read-only fashion, allowing for either a triage or collection of the files

R

Use the source machine’s own system to create a forensic image by booting from the MacQuisition USB dongle

R

Write-protect source devices while maintaining read-write access on destination devices

Google Certifications & Awards

Certified Examiner

Testimonials

” Derick is a dynamic marketing executive with superior technical know how. He makes the magic happen by driving revenue and business growth through his creativity and mastery of web-based technology. Simply put, Derick is a winner. Trust him! “

” Derick is a true force of nature. His unbounded energy, unfailing ability to “think outside the box” and his single minded focus on results is a tremendous asset. I count Derick as one of my most inspirational peers and look forward to every continuing opportunity we have to work together “