BlackBag Macintosh Forensic Suite 2.5

Data Forensics > Software > BlackBag Macintosh Forensic Suite 2.5

Summary

The BlackBag Macintosh Forensic Suite is a unique set of 19 tools that provide forensic examiners with a flexible, open environment within which to perform their analysis. The Suite is specifically designed for Mac OS X (version 10.1 & higher). The applications are designed to efficiently carve and copy the most pertinent sectors of a target hard drive speeding the examiners analysis time, while ensuring a thorough investigation of the drive.

System requirements: Universal (Intel or PowerPC); OS X 10.4 or later; min 1GB RAM; min 500MB available disk space.

Description

Below are descriptions of three of the applications contained within our forensic suite.

Directory Scan

enables you to create a directory listing of a volume or specific folder. This scan will quickly retrieve all active file information (including invisible files) from a mounted volume.

directoryscanscreenshot

FileSpy

enables you to obtain a quick preview of any file by displaying the ASCII text for that file. A user can move through the file, sector by sector, jump to the start or end of a sector, or jump to any specific sector within the file.

filespyscreenshot

HeaderBuilder

enables you to build the header of specific files. It will read the first 32 bytes of each file. The header CRC will calculate a 32 bit CRC check sum of the first 32 bytes of the file and create an MD5 checksum of the entire file.

headerbuilderscreenshot

 

Download the demo here...

Options

This product comes in the following options:

Private Sector

Govt.

This pricing is only available for government agencies and non-profit clients.