Macintosh Forensics
Discover the leading Macintosh Forensics Tools from Sumuri
Built on deep expertise and experience from their team, they are unparalleled in performance for speedy acquisition and analysis of Mac computers and devices.
Broad System Support
Supports Apple Silicon, Intel T2 macs, APFS File Systems, Local TIme Machine Snapshots
Boot & Live Acquisition Modes
Two modes to perform acquisition for both Intel & Silicon Macs. Acquire straight to the RECON ITR SSD
Triage With Hundreds Of Plugins
Automatically parse thousands of macOS & iOS Backups, Boot Camp in seconds.
Process Mac Native Metadata & Artifacts
Apple Extended Attributes contain important metadata that can only be properly interpreted using Mac tools.
Why use macOS for Mac Forensics?
Only Mac-native tools give investigators full and accurate access to Apple’s proprietary data—covering metadata, APFS structures, snapshots, and encryption—ensuring evidence is preserved, interpreted correctly, and nothing critical is overlooked.




