MacMarshal 3.0

Mac Marshal™ automatically extracts forensic evidence from Mac OS X systems.
Rating
Your vote:
Latest version:
3.0 See all
Developer:
Architecture Technology Corporation
Request
Download
link when available
Commercial
Used by 2 people
Info updated on:

ATC-NY's Mac Marshal™ automatically extracts forensic evidence from Mac OS X systems, letting you conduct your investigations faster and more thoroughly. Mac Marshal scans a Macintosh disk, automatically detects and displays Macintosh and Windows operating systems and virtual machine images, then runs a number of analysis tools to extract Mac OS X-specific forensic evidence written by the OS and common applications. Mac Marshal Forensic Edition focuses on the analysis of Mac disk images on an investigator's workstation. Mac Marshal Field Edition can also analyze volatile system state data from live, running systems prior to seizure and disk imaging.

Mac Marshal follows forensic best practices and maintains a detailed log file of all activities it performs. It produces reports in RTF, PDF, and HTML formats.

Screenshot (1)

Comments

User

Your vote: