How To Collect Data Using MacQuisition Live

As more employees are required to work from home, we’ve heard from our customers that they need the ability to remotely collect data from Mac systems without having to send MacQuisition hardware to someone’s home. In order to help our customers in this unique time, BlackBag is making a new software only option available to MacQuisition customers for a limited time.  

Below we’ve answered some common questions about this new functionality. 

In addition, below is an easy to use how-to guide for the person running the application and completing the collection.

Using MacQuisition Live

So, you’ve downloaded MacQuisition Live, let’s take a look at some ways you can use it.

MacQuisition Live provides a mechanism to collect data from remote users in one of the following ways:


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

  • Provide the MacQuisition Live dmg and license information to the person who needs to complete the collection and they can run it live on any Mac that needs files extracted.
  • The examiner can drive the collection connecting to the Mac remotely to run the MacQuisition software.  There are several built in options on the Mac to allow remote access, for instance Mac Remote Access or Mac Screen Share, or commercial remote access tools.  For more information on remote access of Mac systems there are helpful suggestion in this article.

Once the data is collected on the macOS system, the collection can be transferred via a cloud storage solution such as Dropbox or email.  We recommend storing data collected in the logical evidence file format which preserves key file metadata.

Things To Keep In Mind

If you are having the user of device collect data, specific instructions must be provided.  The scope of the collection should be clearly defined in the instructions sent to the user. Our triage mode allows you to browse file content or search for files based on location, filename, extension, file size, dates, and keywords.  MacQuisition also has built-in collection options available in the Collection tab.

In addition to MacQuisition Live, a license file is required.  The license file will be saved to any system MacQuisition Live is run on.  Both of these must be provided for the user to run the application on their system.

A plan must be in place to transfer the collected data from the device the data was collected on to the people analyzing the collected data.

Possible Uses

MacQuisition Live provides a mechanism for eDiscovery data collections, collections related to HR requests, or even to find files that correlate to indicators of compromise when a threat is detected.  Let’s walk through how to run MacQuisition Live and then one collection scenario. This scenario can be used as a template for creating a set of instructions for data collection.

How To Run MacQuisition Live

MacQuisition Live is stored in MacQuisition_2020R1.dmg.  Open the dmg on the macOS system data will collected from.  A Finder window appears showing the MacQuisition Live application.

Double-click on MacQuisition.  The following dialog box appears:

The User Name box contains the user account user name.  Type in your login password in the Password box. Click Install Helper.  

The following dialog box will appear:

Click Enter License Key.  In the window that appears either manually enter the license information or if a license file has been provided click Load from File.

Note:  You cannot copy and paste the license file information.  It must either be manually typed in or loaded from a license file.

Once the license information is entered or loaded from a file, click Enter License.  

The MacQuisition EULA window will appear.  Click Agree

The following warning dialog box may appear:

Click OK.

MacQuisition Live is now running on the system.

Collecting Data

This section provides an instruction sample for collecting data that can be sent to users performing the data collection.  These instructions should be customized for your collection needs before they are sent. Keep in mind the level of expertise of the collector when creating your own data collection instructions.  The instructions should be tested by someone with data collection experience before they are distributed to users who are less familiar with data collection processes. Also remember running MacQuisition Live will create changes on the system.   At the end of this example, possible variations that you can use to customize these instructions are provided.

Example 1 – Collecting Data Based on Keyword

In this example we are going to search for files related to the flamingo project and the octopus project.  Specifically, we are looking for documents used on these projects.  The target for the collection is the user’s Documents folder.  

Step 1 – In MacQuisition, click on the Collection tab.  Right-click on the left side of the collection tab and choose Deselect All.

Step 2 – Click on the Search tab.

Step 3 – Use the Location drop-down menu and select your Documents directory.

Step 4 – In the Content section type the keyword “flamingo” and check the Search Documents check box.  Click Search.

Step 5 – The results returned are displayed in the middle window.  Highlight all of the files in the middle window, right-click and choose Add selected Items to Collection.

Step 6 – Repeat steps 4 and 5 using the second keyword “octopus.”

Step 7 – Click on the Collection tab.  The files added to the collection are displayed in the ADDITIONAL FILES section.  The total size of the collection is also listed.

Step 8 – Choose a location for the data collection by clicking Set….  In the Select Destination Volume Window, choose the data volume of the device and click Open.  In this example, the data volume is named MacSSD – Data

A Finder window appears.  Navigate to Desktop folder of your user profile.  MacSSD/Users/<username>/Desktop. Click Open.  The path to your Desktop appears in Destination.

Step 9 – From the drop-down menus select .L01 for Format, and 2GB for Segment Size.  Uncheck SHA1.  Click Start.

The Activity window appears showing the status of the collection.  Once the collection completes, the Finished acquiring data message appears with the collection storage path.

Step 10 – Close MacQuisition.  In Finder navigate to the collection folder.  Email the entire collection folder to thisperson@somecompany.com.  

Collection Variations

MacQuisition Live has a myriad of other features that can be used for data collection, so depending on what you are trying to collect, the above instructions can be altered fit your collection requirements.  

In the Search tab Data can be searched for by Location, Name, Extension, File Size, Date(s), and Contents (keyword).  You can search for multiple file extension at the same time by separating the file extension with a colon.  For example, pdf:png:doc.

The Browser tab can be used to navigate to specific file path to add items to a collection.  

The Collection tab has pre-defined sets of information that you can choose for collection. 

Refer to the MacQuisition User Guide to read more about Live data collection options. 

One of the most important steps to refine is Step 10.  Keep in mind the amount of data that may be in the collection.  Send large collections by email may not be feasible. Transferring collections via a cloud storage solution such as Dropbox may be a more appropriate option.   

If you have any other question or issues, search the BlackBag support portal https://support.blackbagtech.com or reach out to tech support via email support@blackbagtech.com.

Leave a Comment

Latest Videos

Subscribe to the Forensic Focus Podcast: https://www.forensicfocus.com/podcast/

Si and Desi are joined by Brittany and Ailsa from digital forensics software company ADF Solutions. They discuss how ADF is addressing key challenges for digital forensics practitioners, including handling the massive volumes of data from mobile devices and the cloud.

The guests outline ADF's focus on developing their software as an easy-to-use onsite triage tool that can help quickly identify pertinent evidence. Key features include advanced handling of video files, AI-assisted classification of images, and new screen recording capabilities for mobile devices that allow suspects to safely share relevant data. 

The hosts and guests also explore ADF's ongoing research into areas like facial recognition, handling new device types like games consoles and smart watches, and identifying deepfake media.

00:00 – Introduction to Ailsa and Brittany
03:00 – The challenge of vast amounts of data
05:50 – Recovering data from Chromebooks
08:50 – Triaging using ADF tools
12:30 – Benefits of using ADF Solutions’ tools
15:50 – Limitations in types of apps
17:20 – Keeping up with technological advancements
19:15 – ADF customer base
21:00 - Artificial intelligence in classifying images
30:00 – ADF Solutions’ triaging kit
37:00 – Training with ADF
40:00 – Target user
44:50 – Roadmap of future devices to examine
51:30 – Main focus for ADF Solutions going forwards

Show Notes:
AI-generated CSAM article on Sky News - https://news.sky.com/story/thousands-of-ai-generated-child-abuse-images-being-shared-online-research-finds-12991727

Subscribe to the Forensic Focus Podcast: https://www.forensicfocus.com/podcast/

Si and Desi are joined by Brittany and Ailsa from digital forensics software company ADF Solutions. They discuss how ADF is addressing key challenges for digital forensics practitioners, including handling the massive volumes of data from mobile devices and the cloud.

The guests outline ADF's focus on developing their software as an easy-to-use onsite triage tool that can help quickly identify pertinent evidence. Key features include advanced handling of video files, AI-assisted classification of images, and new screen recording capabilities for mobile devices that allow suspects to safely share relevant data.

The hosts and guests also explore ADF's ongoing research into areas like facial recognition, handling new device types like games consoles and smart watches, and identifying deepfake media.

00:00 – Introduction to Ailsa and Brittany
03:00 – The challenge of vast amounts of data
05:50 – Recovering data from Chromebooks
08:50 – Triaging using ADF tools
12:30 – Benefits of using ADF Solutions’ tools
15:50 – Limitations in types of apps
17:20 – Keeping up with technological advancements
19:15 – ADF customer base
21:00 - Artificial intelligence in classifying images
30:00 – ADF Solutions’ triaging kit
37:00 – Training with ADF
40:00 – Target user
44:50 – Roadmap of future devices to examine
51:30 – Main focus for ADF Solutions going forwards

Show Notes:
AI-generated CSAM article on Sky News - https://news.sky.com/story/thousands-of-ai-generated-child-abuse-images-being-shared-online-research-finds-12991727

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_4z-EgH54KZk

The Power Of Digital Forensics: How ADF Solutions Is Revolutionizing The Digital Forensics Industry

Forensic Focus 13 hours ago

Si and Desi interview Emi Polito from Amped about how to become an Amped FIVE Certified Examiner (AFCE). They discuss the exam requirements, format, timeline for certification, and Amped’s future plans. Emi explains that the certification is aimed at demonstrating competency with the Amped FIVE video analysis software after completing training. The exam consists of multiple choice questions on theory and practical exercises using the software. Emi talks about the online exam format and process for passing or failing.

Emi also discusses the broader challenges many organizations face with validation and accreditation. He emphasizes Amped's commitment to developing tools that facilitate that process. The hosts reflect on the confusing accreditation landscape and Amped’s passion for improving training and certification in forensics. This episode provides an overview of Amped's new certification and perspective on challenges in the field of video forensics.

Show Notes:

Introducing The AFCE Certification (Amped FIVE Certified Examiner) - https://www.forensicfocus.com/news/introducing-the-afce-certification-amped-five-certified-examiner/

Video Evidence Principles With Amped Software - https://www.forensicfocus.com/podcast/video-evidence-principles-with-amped-software/

Digital Image Authenticity And Integrity With Amped Authenticate - https://www.forensicfocus.com/podcast/digital-image-authenticity-and-integrity-with-amped-authenticate/

File Analysis And DVR Conversion Training From Amped Software - https://www.forensicfocus.com/reviews/file-analysis-and-dvr-conversion-training-from-amped-software/

Amped FIVE Speed Estimation 2d Filter And Training From Amped Software - https://www.forensicfocus.com/reviews/amped-five-speed-estimation-2d-filter-and-training-from-amped-software/

Amped Software’s Martino Jerian on Key Challenges and Opportunities for Video Evidence - https://www.forensicfocus.com/podcast/amped-softwares-martino-jerian-on-key-challenges-and-opportunities-for-video-evidence/

LEVA 2023 Training Symposium - https://www.leva.org/

Forensic Collision Investigation & Reconstruction Ltd - https://www.fcir.co.uk/

Amped FIVE Certified Examiner - https://ampedsoftware.com/afce-certification 

Introducing the Amped FIVE Certification Program - https://blog.ampedsoftware.com/2023/10/04/introducing-the-amped-five-certification-program

Amped Software YouTube - https://www.youtube.com/ampedsoftware
How to Use the Validation Tool in Amped FIVE - https://blog.ampedsoftware.com/2023/03/29/how-to-use-the-validation-tool-in-amped-five

Si and Desi interview Emi Polito from Amped about their new certification called Amped Five Certified Examiner (AFCE). They discuss the exam requirements, format, timeline for certification, and Amped’s future plans. Emi explains that the certification is aimed at demonstrating competency with the Amped FIVE video analysis software after completing training. The exam consists of multiple choice questions on theory and practical exercises using the software. Emi talks about the online exam format and process for passing or failing.

Emi also discusses the broader challenges many organizations face with validation and accreditation. He emphasizes Amped's commitment to developing tools that facilitate that process. The hosts reflect on the confusing accreditation landscape and Amped’s passion for improving training and certification in forensics. This episode provides an overview of Amped's new certification and perspective on challenges in the field of video forensics.

Show Notes:

Introducing The AFCE Certification (Amped FIVE Certified Examiner) - https://www.forensicfocus.com/news/introducing-the-afce-certification-amped-five-certified-examiner/

Video Evidence Principles With Amped Software - https://www.forensicfocus.com/podcast/video-evidence-principles-with-amped-software/

Digital Image Authenticity And Integrity With Amped Authenticate - https://www.forensicfocus.com/podcast/digital-image-authenticity-and-integrity-with-amped-authenticate/

File Analysis And DVR Conversion Training From Amped Software - https://www.forensicfocus.com/reviews/file-analysis-and-dvr-conversion-training-from-amped-software/

Amped FIVE Speed Estimation 2d Filter And Training From Amped Software - https://www.forensicfocus.com/reviews/amped-five-speed-estimation-2d-filter-and-training-from-amped-software/

Amped Software’s Martino Jerian on Key Challenges and Opportunities for Video Evidence - https://www.forensicfocus.com/podcast/amped-softwares-martino-jerian-on-key-challenges-and-opportunities-for-video-evidence/

LEVA 2023 Training Symposium - https://www.leva.org/

Forensic Collision Investigation & Reconstruction Ltd - https://www.fcir.co.uk/

Amped FIVE Certified Examiner - https://ampedsoftware.com/afce-certification

Introducing the Amped FIVE Certification Program - https://blog.ampedsoftware.com/2023/10/04/introducing-the-amped-five-certification-program

Amped Software YouTube - https://www.youtube.com/ampedsoftware
How to Use the Validation Tool in Amped FIVE - https://blog.ampedsoftware.com/2023/03/29/how-to-use-the-validation-tool-in-amped-five

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_atEaNas9xnE

The Amped FIVE Certified Examiner (AFCE)

Forensic Focus 29th November 2023 10:28 am

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feed settings page to add an API key after following these instructions.

Latest Articles