MacQuisition. The best just got better.

A powerful, 3-in-1 solution for live data acquisition, targeted data collection, and forensic imaging.


MacQuisition Targeted Data Collection


Proven forensic imaging software for Mac OS X

BlackBag Technologies is very excited to announce the release of MacQuisition 2017. MacQuisition continues to be the leading and most advanced forensic imaging software for Mac OS X and macOS. With the 2017 release, the best just got better.

Uniquely versatile and reliable, MacQuisition is the only forensic solution that runs within a native OS X boot environment. The advanced imaging processes of MacQuisition provides you with the software to acquire live data (including RAM) or forensically image over 185 different Apple computers, including the new MacBook Pro with Touch Bar.

Tested and used by experienced examiners throughout the world for over a decade, MacQuisition runs on the Mac OS X operating system and safely boots and acquires data from Apple computers in their native environment - even Fusion Drives. MacQuisition automatically and proficiently identifies, displays and interprets Apple File System, FileVault, Fusion and Core Storage Volumes. Through the MacQuisition boot environment, you can image Mac RAM with no password.


MacQuisition RAM Imaging

Key Features

  • Image all Intel® based Macs including the new MacBook Pro with Touch Bar
  • Mid-2017 iMac hardware support
  • Native Mac OS boot environment
  • Ability to image APFS drives
  • Core Storage support
  • Image any drive with FileVault encryption
  • Fusion Drive support
  • RAM imager
  • Write protection

Targeted Data Collection

  • Target and forensically acquire files and user directories
  • Avoid known system files and unneeded data
  • Preserve valuable native metadata
  • Authenticate & validate collected data
  • Log data acquisitions and source device attributes
  • Selectively acquire data on a per-user, per-volume basis

Live Data Acquisition

  • Capture live data in real time
  • Accurately acquire RAM
  • Choose from 26 system data collection options, including active, current and print-queue status

Forensic Imaging

  • Combined volume from a Fusion Drive automatically presented for imaging
  • If FileVault 2 exists, through password, Keychain or recovery key, the examiner can mount the volume in a read-only fashion for triage or collection of files
  • By booting from the MacQuisition USB, a forensic image can be created by using the source machine’s own system
  • Write-protect source devices, while maintaining read-write access on destination devices


MacQuisition Device Mounting


Upgrade to the latest version of MacQuisition, or renew your license.

Not using MacQuisition yet? Find out more about the proven Mac forensic imaging software by contacting a member of the BlackBag Sales Team or request a quote.

Leave a Reply

Sorry, you must be logged in to post a comment.