
BlackBag Macintosh Forensic Suite
The BlackBag Macintosh Forensic Suite is a unique set of 19 tools that provide forensic examiners with a flexible, open environment within which to perform their analysis. The Suite is specifically designed for Mac OS X (version 10.1 & higher). The applications are designed to efficiently carve and copy the most pertinent sectors of a target hard drive speeding the examiners analysis time, while ensuring a thorough investigation of the drive.
Below are descriptions of three of the applications contained within our forensic suite.
Directory Scan
enables you to create a directory listing of a volume or specific folder. This scan will quickly retrieve all active file information (including invisible files) from a mounted volume.

FileSpy
enables you to obtain a quick preview of any file by displaying the ASCII text for that file. A user can move the file, sector by sector, jump to the start or end of a sector, or jump to any specific sector within the file.

HeaderBuilder
enables you to build the header of specific files. It will read the first 32 bytes of each file. The header CRC will calculate a 32 bit CRC check sum of the first 32 bytes of the file and create an MD5 checksum of the entire file.

Retail |
Government |
|
Macintosh Forensic Suite |
$679 |
$579 |
If you would like to receive additional information about these tools, or to purchase them, please contact us at sales@blackbagtech.com

