A powerful, 4-in-1 forensic imaging software solution for Macs for triage, live data acquisition, targeted data collection, and forensic imaging. MacQuisition is the first and only computer forensic tool to create physical images of Macs with the Apple T2 chip. Tested and used by experienced examiners for over a decade, MacQuisition runs on the Mac OS X operating system and safely boots and acquires data from over 185 different Macintosh computer models in their native environment – even Fusion Drives. There’s no need for complicated take-aparts when you’ve got MacQuisition.



Search, Browse, and Preview
  • Triage devices to determine if relevant data exists prior to imaging
  • Browse through files and folders of the device and any connected media
  • Search for data on devices using a combination of location , file name, file extension, file size, dates, and file content
  • Preview files in MacQuisition – file previews work on file types supported by macOS QuickLook: pictures, videos, office files, pdfs, etc.
  • Add selected files and folders to a data collection from the Browsing and Search views

Targeted Data Collection

Selectively Acquire
  • Ability to create physical images of Macs with the Apple T2 chip
  • Target and forensically acquire files, folders, and user directories while avoiding known system files and other unneeded data
  • Preserve valuable metadata by maintaining its association with the original file
  • Authenticate collected data using any or all MD5, SHA-1, or SHA-256 hash functions
  • Thoroughly log data acquisitions and source device attributes throughout the collection process
  • Selectively acquire email, chat, address book, Calendar, and other data on a per-user, per-volume basis

Read our MacQuisition Quick Start Guide here.

Live Data Acquisition

Collect From Live Systems
  • Soundly acquire and save volatile Random Access Memory (RAM) contents to a destination device
  • Capture important live data such as Internet, chat, and multimedia files in real time
  • Capture RAM and targeted collections live on Mojave
  • Choose from 26 unique system data collection options, including active system processes, current system state, and print queue status
  • Extensively log live data acquisition information throughout the collection process

Forensic Imaging

Create Forensic Images
  • Support for imaging APFS Fusion drives
  • Automatically recognizes a combined volume from a Fusion Drive and presents it for imaging
  • If FileVault 2 exists, the examiner can, with use of the password, Keychain file or recovery key, mount the volume in a read-only fashion, allowing for either a triage or collection of the files
  • Use the source machine’s own system to create a forensic image by booting from the MacQuisition USB dongle
  • Write-protect source devices while maintaining read-write access on destination devices

Compatibility & Requirements

MacQuisition Resources

Request a Quote

Interested in adding MacQuisition to your toolkit?
Request a quote and experience the powerful data capabilities of MacQuisition.