BlackBag Tech Releases MacQuisition 2017R1 With Latest Mac Imaging Features

BlackBag Technologies releases MacQuisition™ 2017 and continues to offer the leading and most advanced forensic imaging software for Mac OS X and macOS.

MacQuisition™ is a powerful, 3-in-1 solution for live data acquisition, targeted data collection, and forensic imaging. Forensic examiners throughout the world depend on BlackBag Technologies’ software reliability to securely image hundreds of Macs. Uniquely versatile, MacQuisition™ is the only forensic solution that runs within a native OS X boot environment. The advanced imaging processes of MacQuisition™ 2017 provides examiners with the software to acquire live data (including RAM) or forensically image over 185 different Apple computers, including the latest MacBook Pro with Touch Bar and iMac.Tested and used by experienced examiners throughout the world for over a decade, MacQuisition™ runs on the Mac OS X operating system and safely boots and acquires data from Apple computers in their native environment – even Fusion Drives. MacQuisition automatically and proficiently identifies, displays and interprets Apple File System, FileVault, Fusion and CoreStorage Volumes. Through the MacQuisition boot environment, examiners can image Mac RAM with no password.

With changes in Apple’s hardware and software, forensic examiners will see and benefit from the improvements in MacQuisition™ 2017, with key features including:

• Image all Intel® based Macs including the new MacBook Pro with Touch Bar and iMac
• Native Mac OS boot environment
• Ability to image APFS drives
• CoreStorage support
• Image any drive with FileVault encryption
• Fusion Drive support
• RAM imager
• Write protection

The 3-in-1 solution for live data acquisition, targeted data collection, and forensic imaging provided by MacQuisition™ 2017 offers forensic examiners:


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

Live Data Acquisition

• Capture live data in real time
• Accurately acquire RAM
• Choose from 26 system data collection options, including active, current and print-queue status

Targeted Data Collection

• Target and forensically acquire files and user directories
• Avoid known system files and unneeded data
• Preserve valuable native metadata
• Authenticate & validate collected data
• Log data acquisitions and source device attributes
• Selectively acquire data by per-user, per-volume basis

Forensic Imaging

• Combined volume from a Fusion Drive automatically presented for imaging
• If FileVault 2 exists, through password, Keychain or recovery key, the examiner can mount the volume in a read-only fashion for triage or collection of files
• By booting from the MacQuisition™ USB, a forensic image can be created by using the source machine’s own system
• Write-protect source devices, whilst maintaining read-write access on destination devices

BlackBag Technologies’ software is used by hundreds of federal, state, and local law enforcement agencies around the world for criminal investigations, as well as leading corporations and consultants handling HR investigations and eDiscovery matters. This new release of MacQuisition™, allowing examiners to forensically image more than ever, is the latest update to Black Technologies’ range of software products.

MacQuisition™ 2017R1 is out now and available directly through BlackBag Technologies or one of their channel partners.

About the Company

BlackBag Technologies is a developer of innovative forensic acquisition, triage, and analysis software for Windows, Android, iPhone/iPad, and Mac OS X devices. The company’s flagship product, BlackLight, has been adopted worldwide by many digital forensics examiners as a primary analysis tool. Mobilyze, BlackBag’s groundbreaking mobile device triage tool, empowers virtually all law enforcement personnel, with or without specialized experience, to capably triage and report on data from smartphones.

In addition to software, BlackBag also develops and delivers expert forensic training and certification programs, designed to meet the needs of law enforcement, military and private sector examiners. Taught by an elite team with considerable law enforcement and digital forensics experience, the courses are tailored to address realistic, multi-platform scenarios simulating the daily challenges of digital evidence.

To learn more about BlackBag’s software and training, please contact us at 855-844-8890, visit us at blackbagtech.com, or subscribe to our blog.

Leave a Comment

Latest Videos

In this episode of the Forensic Focus podcast, Si and Desi explore how artificial intelligence is being leveraged to uncover crucial evidence in investigations involving child sexual abuse material (CSAM) and examine the importance of exercising caution when implementing these tools. 

They also discuss a recent murder case in which cyber experts played a vital role in securing a conviction, and explore the unique challenges associated with using digital evidence as an alibi.

Show Notes:

A Practitioner Survey Exploring the Value of Forensic Tools, AI, Filtering, & Safer Presentation for Investigating Child Sexual Abuse Material (CSAM) - https://dfrws.org/wp-content/uploads/2019/06/2019_USA_paper-a_practitioner_survey_exploring_the_value_of_forensic_tools_ai_filtering_safer_presentation_for_investigating_child_sexual_abuse_material_csam.pdf

Man charged with NI murder ‘faked live stream to provide alibi’ (The Guardian) - https://www.theguardian.com/uk-news/2023/feb/02/man-charged-with-ni-faked-live-stream-to-provide-alibi

A YouTuber accused of murder faked a 6-hour livestream to produce an alibi (Sportskeeda) - https://www.sportskeeda.com/esports/news-a-youtuber-accused-murder-faked-6-hour-livestream-produce-alibi

European Interdisciplinary Cybersecurity Conference (EICC) 2023 - https://www.forensicfocus.com/event/european-interdisciplinary-cybersecurity-conference-eicc-2023/#more-493234

YouTuber reportedly faked GTA livestream to have an alibi while he committed murder (Dexerto) - https://www.dexerto.com/entertainment/youtuber-reportedly-faked-gta-livestream-to-have-an-alibi-while-he-committed-murder-2052974/

Forensic Europe Expo - https://www.forensicfocus.com/event/forensic-europe-expo/#more-493225

In this episode of the Forensic Focus podcast, Si and Desi explore how artificial intelligence is being leveraged to uncover crucial evidence in investigations involving child sexual abuse material (CSAM) and examine the importance of exercising caution when implementing these tools.

They also discuss a recent murder case in which cyber experts played a vital role in securing a conviction, and explore the unique challenges associated with using digital evidence as an alibi.

Show Notes:

A Practitioner Survey Exploring the Value of Forensic Tools, AI, Filtering, & Safer Presentation for Investigating Child Sexual Abuse Material (CSAM) - https://dfrws.org/wp-content/uploads/2019/06/2019_USA_paper-a_practitioner_survey_exploring_the_value_of_forensic_tools_ai_filtering_safer_presentation_for_investigating_child_sexual_abuse_material_csam.pdf

Man charged with NI murder ‘faked live stream to provide alibi’ (The Guardian) - https://www.theguardian.com/uk-news/2023/feb/02/man-charged-with-ni-faked-live-stream-to-provide-alibi

A YouTuber accused of murder faked a 6-hour livestream to produce an alibi (Sportskeeda) - https://www.sportskeeda.com/esports/news-a-youtuber-accused-murder-faked-6-hour-livestream-produce-alibi

European Interdisciplinary Cybersecurity Conference (EICC) 2023 - https://www.forensicfocus.com/event/european-interdisciplinary-cybersecurity-conference-eicc-2023/#more-493234

YouTuber reportedly faked GTA livestream to have an alibi while he committed murder (Dexerto) - https://www.dexerto.com/entertainment/youtuber-reportedly-faked-gta-livestream-to-have-an-alibi-while-he-committed-murder-2052974/

Forensic Europe Expo - https://www.forensicfocus.com/event/forensic-europe-expo/#more-493225

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_7QiFTiuY7Vw

AI In CSAM Investigations And The Role Of Digital Evidence In Criminal Cases

Forensic Focus 22nd March 2023 12:44 pm

Throughout the past few years, the way employees communicate with each other has changed forever.<br /><br />69% of employees note that the number of business applications they use at work has increased during the pandemic.<br /><br />Desk phones, LAN lines and even VOIP have become technologies of the past workplace environment as employees turn to cloud applications on their computers and phones to collaborate with each other in today’s workplace environment.<br /><br />Whether it’s conversations in Teams, file uploads in Slack chats, or confidential documents stored in Office 365, the amount of data stored and where it is stored, is growing quicker than IT and systems administrators can keep up with.<br /><br />Corporate investigators and eDiscovery professionals need to seamlessly collect relevant data from cloud sources and accelerate the time to investigative and discovery review.<br /><br />With the latest in Cellebrite’s remote collection suite of capabilities, investigators and legal professionals can benefit from secure collection with targeted capabilities for the most used workplace applications.<br /><br />Join Monica Harris, Product Business Manager, as she showcases how investigators can:<br /><br />- Manage multiple cloud collections through a web interface<br />- Cull data prior to collection to save time and money by gaining these valuable insights of the data available<br />- Collect data from the fastest growing cloud collaboration applications like Office365, Google Workspace, Slack and Box<br />- Login to a single source for workplace app collection without logging into every app and pulling data from multiple sources for every employee<br />- Utilize a single unified collection workflow for computer, mobile and workplace cloud applications without the need to purchase multiple tools for different types of collections – a solution unique to Cellebrite’s enterprise solution capabilities

Throughout the past few years, the way employees communicate with each other has changed forever.

69% of employees note that the number of business applications they use at work has increased during the pandemic.

Desk phones, LAN lines and even VOIP have become technologies of the past workplace environment as employees turn to cloud applications on their computers and phones to collaborate with each other in today’s workplace environment.

Whether it’s conversations in Teams, file uploads in Slack chats, or confidential documents stored in Office 365, the amount of data stored and where it is stored, is growing quicker than IT and systems administrators can keep up with.

Corporate investigators and eDiscovery professionals need to seamlessly collect relevant data from cloud sources and accelerate the time to investigative and discovery review.

With the latest in Cellebrite’s remote collection suite of capabilities, investigators and legal professionals can benefit from secure collection with targeted capabilities for the most used workplace applications.

Join Monica Harris, Product Business Manager, as she showcases how investigators can:

- Manage multiple cloud collections through a web interface
- Cull data prior to collection to save time and money by gaining these valuable insights of the data available
- Collect data from the fastest growing cloud collaboration applications like Office365, Google Workspace, Slack and Box
- Login to a single source for workplace app collection without logging into every app and pulling data from multiple sources for every employee
- Utilize a single unified collection workflow for computer, mobile and workplace cloud applications without the need to purchase multiple tools for different types of collections – a solution unique to Cellebrite’s enterprise solution capabilities

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_g6nTjfEMnsA

Tips And Tricks Data Collection For Cloud Workplace Applications

Forensic Focus 20th March 2023 12:00 pm

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feed settings page to add an API key after following these instructions.

Latest Articles

Share to...