All categories

MacMarshal 3.0

Free Mac Marshal™ automatically extracts forensic evidence from Mac OS X systems.
0 
Latest version:
3.0 See all
Collect

ATC-NY's Mac Marshal™ automatically extracts forensic evidence from Mac OS X systems, letting you conduct your investigations faster and more thoroughly. Mac Marshal scans a Macintosh disk, automatically detects and displays Macintosh and Windows operating systems and virtual machine images, then runs a number of analysis tools to extract Mac OS X-specific forensic evidence written by the OS and common applications. Mac Marshal Forensic Edition focuses on the analysis of Mac disk images on an investigator's workstation. Mac Marshal Field Edition can also analyze volatile system state data from live, running systems prior to seizure and disk imaging.

Mac Marshal follows forensic best practices and maintains a detailed log file of all activities it performs. It produces reports in RTF, PDF, and HTML formats.

Comments

Suggestions

File Rename Pro
File Rename Pro

File Rename Pro - Rename your files with a few clicks!

Tenorshare 4DDiG
Tenorshare 4DDiG
Free

Retrieve data in all instances

File Transfer
File Transfer

An Easy Way to Transfer Files Between Different Devices

Mounty for NTFS
Mounty for NTFS
Free

Easy alternative to remount NTFS

Compare Folders
Compare Folders
Free

Keep your folders organized for free with Compare Folders

Homebrew
Homebrew
Free

Free open-source software package

Download
Free